PCI-certified Merchants APIs

Secure endpoints for PCI-certified merchants that collect and submit raw card data directly to Bamboo.

This integration path is exclusively for PCI-certified merchants who collect cardholder data within their own infrastructure and submit raw card data (the CardData object) directly to Bamboo. The endpoints are functionally equivalent to their standard counterparts — the only difference is that they accept card data in clear instead of a token.


⚠️

These endpoints require an active PCI DSS certification. If your business is not PCI-certified, do not use this path — use the Standard Integration endpoints with tokenization, which keep cardholder data out of your systems.


These endpoints run on the secure host (secure-api.bamboopayment.com) and accept the CardData object in place of a token.



📘

For the full flow, validation rules, and card scheme considerations, see the Create a Purchase Integration Guide.