Skip to main content
PCI Booking allows multiple users per account. Each user has their own permissions and up to 5 API keys.

Users

When your account is created, it has one administrator user. You can add more users as needed.

View Users

  1. Log in to the PCI Booking portal.
  2. Navigate to Account Settings > View Accounts.
  3. The list shows all currently active users. Check Show closed to include deactivated users.
  4. Click a user row to edit their information, permissions, and relay restrictions.

Add a User

  1. Navigate to Account Settings > Add Account.
  2. Fill in the required fields:
    • User ID (must be unique within the account)
    • Temporary Password (the user receives an email to change it on first login)
    • Email, Name, Phone
  3. Assign permissions based on the user’s role. See Permissions below.

Inactive Users

A user who has not logged in successfully for 90 days is suspended automatically. To restore access, a user with the Account management permission can resume the user in the portal, or you can ask our support team. After the resume, the user must log in within 48 hours. Otherwise the next automatic check suspends them again. Each user must log in themselves: resuming the user does not count as a login.

Permissions

Each endpoint accepts one or more of these permissions, and a user needs only one of them to use it. For example, the card display form accepts either Retrieve cards or Perform Card display operations. A request from a user without any of the accepted permissions returns 403; see Authentication and Permission Failures.
To limit what an integration can do, create a separate user for it and grant only the narrow permission it needs, for example Perform Upg operations for a system that only processes payments, instead of the broad Retrieve cards. Use a sandbox account and key for lower-stakes integrations.

API Keys

Each user can have up to 5 API keys. All authentication methods are based on API keys.

Generate a New API Key

  1. Navigate to Account Settings > Account Settings.
  2. Under the API Access section, click Generate API Key.
  3. Enter a name for the key (useful when managing multiple keys).
  4. The API key is displayed.
Copy and store the API key immediately. Once you close the dialog, you cannot view the key again. If you lose a key, you must generate a new one.

Delete an API Key

  1. Find the key in the API keys list.
  2. Click the delete icon.
  3. Confirm deletion.
Deleting an API key cannot be undone. Make sure the key is no longer in use before deleting it.

Verify an API Key

Use the Authenticate endpoint to check if an API key is valid.