Hosted Card Entry Form Guide
API session approach for embedded card capture
CallBackURL, PCI Booking sends a POST request to that URL when a card is stored, when a card is rejected, and when the session expires. Your endpoint must accept the following payload.
Webhook Payload
string
The ID of the card entry form session. Matches the
RequestID returned by Create Card Entry Form Session.string
The current status of the session. Possible values:
string
The PCI Booking token URL for the stored card. Only present when
CaptureCardRequestStatus is OK.Expected Response
Each callback is sent once, as a single POST, and PCI Booking waits at most 10 seconds for your endpoint. There are no retries, and your response code does not change anything: PCI Booking does not resend a callback whatever you return. Respond quickly, and handle the payload after you respond if processing takes time. Keep in mind:- One session can produce several callbacks: one
BadDatafor each rejected attempt, thenOKorExpired. - If the card cannot be stored because of an error on PCI Booking’s side, no callback is sent. The form shows the error to the cardholder, and the session stays open until its TTL.
- If a callback does not reach you, you can check the session with Retrieve Card Entry Session while it still exists, that is, before
OKorExpired.

