API · Four integration paths
API v1Four paths#
There are four ways to take payments with Tilopay. They differ in two things: how much you build yourself, and where the card fields appear. Pick one and follow its guide; all of them start with your sandbox credentials, requested at developer registration.
1 · No code#
Extensions and plugins for existing platforms. You do not write a line of code.
2 · Hosted payment page#
Your server requests a URL from the API, redirects the customer to that Tilopay page and receives the result on your callback URL.
3 · JavaScript SDK#
The card fields live in your page; the SDK captures them and sends them straight to Tilopay.
4 · Server-to-server API#
Restricted access: a service exclusive to PCI-certified merchants. The URL is provisioned per merchant and is not public.
How to choose#
Choosing the wrong path is expensive. The difference that matters most is where the card data travels.
| Path | Who builds the form | Where card data travels | What you need to know | Compliance implication |
|---|---|---|---|---|
| 1 · No code | The platform | Never pass through your systems | Setup inside the platform admin | Check with your compliance team |
| 2 · Hosted payment page | Tilopay | Your customer types them on a secure Tilopay page; you never see a card number | Backend: request the URL and handle the callback | Check with your compliance team |
| 3 · JavaScript SDK | Your site | Typed on your page but sent from the browser straight to Tilopay; they do not pass through your server | JavaScript frontend, plus backend for credentials | Check with your compliance team |
| 4 · Server-to-server (restricted access) | Your site | Card data passes through your server | Requires your PCI certification and a URL provisioned by Tilopay | Check with your compliance team |
Path 4 is not self-serve: it is exclusive to merchants holding PCI certification, and the URL is provisioned individually. It is also the only path that puts your server inside PCI DSS scope. Paths 2 and 3 avoid that cost and you can start them today.
After you choose#
With the path picked, continue with response conventions to learn how amounts are typed, and how to read an error response before you put the code into production.
Last verified: 2026-10-10 · Owner: equipo-integraciones