Skip to main content
POST

Hosted Card Entry Form Guide

API session approach for embedded card capture
The successful response of this method will include the following:
  • RequestID for this Card Entry Form session. You will need to use this request ID in future requests relating to this Card Entry Form session.
  • Location header for the URL of the card form. You will need to set this URL as the value of the SRC attribute of your iframe in your webpage.
All URLs should be HTTPS.

Error Responses

Parameter Constraints

Parameters

Authentication

API key only. This endpoint does not accept access tokens or session tokens.
string
required
Your API key prefixed with APIKEY. Example: APIKEY your-api-key. The x-pcibooking-api-key header is also accepted. See the Authentication guide.

Request Body

string
URL where PCI Booking will push the status of the request.
integer
default:"120"
required
Number of seconds the request will be valid for. Minimum 30, maximum 600.
string
Your own reference, stored on the token that this session produces, so you can find the token later with Query Tokens. It does not identify the session and need not be unique.
object
The settings of the card entry form. The request example shows common ones.
  • The 3DS challenge window has a 5 minute timeout. If the cardholder does not respond in time, authentication is rejected.
  • Do not use merchantName unless you have configured your 3DS merchant information. To use PCI Booking’s merchant, set ThreeDs to True and leave merchantName blank (Visa and Mastercard only). An unregistered merchantName does not return an error - PCI Booking silently falls back to its default merchant and the cardholder sees PCI Booking’s name.

Response

201 - Session created. A Location header is returned with the card form URL. Set this URL as the src of your iframe.
Remember to set the CVV Retention Policy on the token once the card is captured.