> ## Documentation Index
> Fetch the complete documentation index at: https://docs.dodopayments.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Stripe - Connect & Raw Card API Access

> Enable raw card data API access on Stripe with the Dodo Payments PCI DSS AOC, then connect your Stripe account to Bring Your Own Processor (BYOP).

This guide prepares your Stripe account for [Bring Your Own Processor (BYOP)](/features/byop): you request raw card data API access from Stripe, then collect the secret key and webhook signing secret that Dodo Payments needs. If you need help, [talk to us](mailto:founders@dodopayments.com).

## Enable Raw Card Data Access

To route payments through your Stripe account, Dodo Payments sends card details to Stripe on your behalf through Stripe's **raw card data APIs**.

By default, a Stripe account can't send raw card numbers (PANs) to its APIs. Stripe enables this access only after it confirms that the systems handling raw card data are **PCI DSS compliant**. With BYOP, the system that handles card data is **Dodo Payments**, which is PCI DSS Level 1 compliant, so you prove compliance with the Dodo Payments certification rather than your own. You request this access once per account.

When you request access, Stripe asks for a short description of how card data is handled. State that **Dodo Payments**, your PCI DSS Level 1 compliant payment provider, processes the raw card data, and that your own systems never store or touch raw card numbers. Because you fully outsource card handling to Dodo Payments, you don't need your own SAQ D if you qualify for SAQ A. Submit your own **SAQ A** that lists Dodo Payments as the third-party service provider in Part 2f, and include the **Dodo Payments Attestation of Compliance (AOC)** as supporting proof:

<Card title="Dodo Payments PCI DSS Attestation of Compliance (AOC)" icon="file-shield" href="https://pub-2a89184e4c954b599464449d23f506bb.r2.dev/dodo-payments-pci-dss-aoc.pdf">
  Download the current Dodo Payments AOC and submit it to Stripe when you request raw card data access.
</Card>

<Tip>
  **Test mode requires no documentation.** If you need the raw card data APIs only for testing and can't use Stripe's pre-tokenized test cards, ask Stripe support to enable them, so you can build and check your BYOP setup. Live mode still requires your SAQ A and the Dodo Payments AOC.
</Tip>

To request access, follow Stripe's guide, and submit the Dodo Payments AOC when Stripe asks for PCI documentation:

<Card title="Enabling access to raw card data APIs" icon="stripe" href="https://support.stripe.com/questions/enabling-access-to-raw-card-data-apis">
  Stripe's guide to requesting raw card data API access on your account.
</Card>

## What You'll Need

After Stripe confirms raw card data access, connect Stripe in **Settings → BYOP**. You need two values from your Stripe Dashboard:

| Value | Where it comes from |
| - | - |
| **Secret key** | The **API keys** page |
| **Webhook signing secret** | The webhook endpoint you add for Dodo Payments |

<Info>
  Stripe keeps sandbox (test) and live mode credentials separate. Use a Stripe sandbox for Dodo Payments test mode, and Stripe live mode for Dodo Payments live mode.
</Info>

## Step 1: Get Your Secret Key

<Steps>
  <Step title="Open API Keys">
    In the Stripe Dashboard, open the **API keys** page. Switch between sandbox and live mode to match the Dodo Payments mode you're configuring.
  </Step>

  <Step title="Copy Your Secret Key">
    Copy the **Secret key**. It starts with `sk_test_` in a sandbox and `sk_live_` in live mode. Use a standard secret key: restricted keys (`rk_...`) aren't supported. In live mode, Stripe shows a secret key that you create only once, so copy it before you close the dialog.

    Paste the key into the **Secret Key** field in Dodo Payments.
  </Step>
</Steps>

## Step 2: Set Up the Webhook and Signing Secret

When you save the Stripe connection, Dodo Payments generates a **Webhook Endpoint** URL. Add it to Stripe as a webhook endpoint, then copy the endpoint's signing secret.

<Steps>
  <Step title="Create an Event Destination">
    In the Stripe Dashboard, open the **Webhooks** tab in Workbench and select **Create an event destination**. Select **Your account**, then select all events. Dodo Payments needs the endpoint to receive every event type.
  </Step>

  <Step title="Add the Endpoint URL">
    Choose **Webhook endpoint** as the destination type. In **Endpoint URL**, paste the **Webhook Endpoint** URL that Dodo Payments generated. Stripe accepts only publicly accessible HTTPS URLs.
  </Step>

  <Step title="Reveal the Signing Secret">
    On the endpoint's settings page, select **Reveal secret** to view the **Signing secret**. It starts with `whsec_`. Each endpoint has its own secret, so sandbox and live endpoints have different secrets.
  </Step>

  <Step title="Paste the Signing Secret into Dodo">
    In **Settings → BYOP**, paste the signing secret into the **Webhook Signing Secret** field, then select **Save & continue** to finish the connection.

    <Card title="Set up BYOP" icon="shuffle" href="/features/byop">
      Follow the full Bring Your Own Processor setup flow.
    </Card>
  </Step>
</Steps>

<Tip>
  Until you save the signing secret, the Stripe connection shows as **Incomplete** under **Edit Configuration** in **Settings → BYOP**. After you save it, the connection shows as **Connected**.
</Tip>

## Frequently Asked Questions

<AccordionGroup>
  <Accordion title="Do I need my own PCI certification (SAQ D)?">
    No, if you qualify for SAQ A. **Dodo Payments handles the raw card data on your behalf** and is **PCI DSS Level 1 compliant**, so you submit your own SAQ A that lists Dodo Payments in Part 2f, together with the **Dodo Payments Attestation of Compliance (AOC)**, instead of completing SAQ D or a separate audit.
  </Accordion>

  <Accordion title="Why doesn't Stripe enable this by default?">
    Sending raw card numbers to an API brings the sending system into PCI DSS scope. Stripe requires proof of PCI compliance before it enables raw card data APIs, so that cardholder data stays protected. Dodo Payments is **PCI DSS Level 1 compliant**, so you provide the Dodo Payments AOC as that proof.
  </Accordion>

  <Accordion title="Can I test BYOP before getting live approval?">
    Yes. Ask Stripe to enable raw card data APIs in test mode, which needs no PCI documentation, and connect Stripe in test mode in Dodo Payments. You need live mode approval before you process real payments.
  </Accordion>

  <Accordion title="I lost my secret key or signing secret, what now?">
    To view the signing secret again, open the webhook endpoint in Stripe and select **Reveal secret**. To update it in Dodo Payments, open **Settings → BYOP**, select **Edit Configuration**, edit the Stripe connection, paste the secret into **Webhook Signing Secret**, and select **Save & continue**.

    If you lose a live secret key that you created, Stripe can't show it again, so rotate it or create a new key on the **API keys** page. The Dodo dashboard doesn't let you change a saved secret key. To replace the secret key on an existing connection, contact [support@dodopayments.com](mailto:support@dodopayments.com).
  </Accordion>
</AccordionGroup>

## References

* [Dodo Payments PCI DSS Attestation of Compliance (AOC)](https://pub-2a89184e4c954b599464449d23f506bb.r2.dev/dodo-payments-pci-dss-aoc.pdf)
* [Stripe Support: Enabling access to raw card data APIs](https://support.stripe.com/questions/enabling-access-to-raw-card-data-apis)
* [Stripe: API keys](https://docs.stripe.com/keys)
* [Stripe: Webhook signing secret](https://docs.stripe.com/webhooks/signature)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.