Enable Raw Card Data Access
To route payments through your Stripe account, Dodo Payments sends card details to Stripe on your behalf through Stripe’s raw card data APIs. By default, a Stripe account can’t send raw card numbers (PANs) to its APIs. Stripe enables this access only after it confirms that the systems handling raw card data are PCI DSS compliant. With BYOP, the system that handles card data is Dodo Payments, which is PCI DSS Level 1 compliant, so you prove compliance with the Dodo Payments certification rather than your own. You request this access once per account. When you request access, Stripe asks for a short description of how card data is handled. State that Dodo Payments, your PCI DSS Level 1 compliant payment provider, processes the raw card data, and that your own systems never store or touch raw card numbers. Because you fully outsource card handling to Dodo Payments, you don’t need your own SAQ D if you qualify for SAQ A. Submit your own SAQ A that lists Dodo Payments as the third-party service provider in Part 2f, and include the Dodo Payments Attestation of Compliance (AOC) as supporting proof:Dodo Payments PCI DSS Attestation of Compliance (AOC)
Download the current Dodo Payments AOC and submit it to Stripe when you request raw card data access.
Enabling access to raw card data APIs
Stripe’s guide to requesting raw card data API access on your account.
What You’ll Need
After Stripe confirms raw card data access, connect Stripe in Settings → BYOP. You need two values from your Stripe Dashboard:Stripe keeps sandbox (test) and live mode credentials separate. Use a Stripe sandbox for Dodo Payments test mode, and Stripe live mode for Dodo Payments live mode.
Step 1: Get Your Secret Key
1
Open API Keys
In the Stripe Dashboard, open the API keys page. Switch between sandbox and live mode to match the Dodo Payments mode you’re configuring.
2
Copy Your Secret Key
Copy the Secret key. It starts with
sk_test_ in a sandbox and sk_live_ in live mode. Use a standard secret key: restricted keys (rk_...) aren’t supported. In live mode, Stripe shows a secret key that you create only once, so copy it before you close the dialog.Paste the key into the Secret Key field in Dodo Payments.Step 2: Set Up the Webhook and Signing Secret
When you save the Stripe connection, Dodo Payments generates a Webhook Endpoint URL. Add it to Stripe as a webhook endpoint, then copy the endpoint’s signing secret.1
Create an Event Destination
In the Stripe Dashboard, open the Webhooks tab in Workbench and select Create an event destination. Select Your account, then select all events. Dodo Payments needs the endpoint to receive every event type.
2
Add the Endpoint URL
Choose Webhook endpoint as the destination type. In Endpoint URL, paste the Webhook Endpoint URL that Dodo Payments generated. Stripe accepts only publicly accessible HTTPS URLs.
3
Reveal the Signing Secret
On the endpoint’s settings page, select Reveal secret to view the Signing secret. It starts with
whsec_. Each endpoint has its own secret, so sandbox and live endpoints have different secrets.4
Paste the Signing Secret into Dodo
In Settings → BYOP, paste the signing secret into the Webhook Signing Secret field, then select Save & continue to finish the connection.
Set up BYOP
Follow the full Bring Your Own Processor setup flow.
Frequently Asked Questions
Do I need my own PCI certification (SAQ D)?
Do I need my own PCI certification (SAQ D)?
No, if you qualify for SAQ A. Dodo Payments handles the raw card data on your behalf and is PCI DSS Level 1 compliant, so you submit your own SAQ A that lists Dodo Payments in Part 2f, together with the Dodo Payments Attestation of Compliance (AOC), instead of completing SAQ D or a separate audit.
Why doesn't Stripe enable this by default?
Why doesn't Stripe enable this by default?
Sending raw card numbers to an API brings the sending system into PCI DSS scope. Stripe requires proof of PCI compliance before it enables raw card data APIs, so that cardholder data stays protected. Dodo Payments is PCI DSS Level 1 compliant, so you provide the Dodo Payments AOC as that proof.
Can I test BYOP before getting live approval?
Can I test BYOP before getting live approval?
Yes. Ask Stripe to enable raw card data APIs in test mode, which needs no PCI documentation, and connect Stripe in test mode in Dodo Payments. You need live mode approval before you process real payments.
I lost my secret key or signing secret, what now?
I lost my secret key or signing secret, what now?
To view the signing secret again, open the webhook endpoint in Stripe and select Reveal secret. To update it in Dodo Payments, open Settings → BYOP, select Edit Configuration, edit the Stripe connection, paste the secret into Webhook Signing Secret, and select Save & continue.If you lose a live secret key that you created, Stripe can’t show it again, so rotate it or create a new key on the API keys page. The Dodo dashboard doesn’t let you change a saved secret key. To replace the secret key on an existing connection, contact support@dodopayments.com.