Server-to-server API (restricted access)
API v1Restricted access. This is not a self-serve path. You cannot start this integration on your own today: it requires merchant PCI certification and a URL provisioned individually by Tilopay.
What it is#
The path where card data passes through the merchant's server, which then sends it to the Tilopay API.
Who it is for#
- It is a service exclusive to merchants holding PCI certification.
- The URL is customized per merchant, with its own key. It is not a public URL.
That is why this page has no endpoint, no executable examples and no request bodies: there is no common address that works for everyone.
Requirements#
- Valid PCI certification for the merchant.
- An active Tilopay account.
- An approved request, with the URL and key provisioned by Tilopay for your merchant.
How to request it#
Write to sac@tilopay.com with the merchant name and the status of your PCI certification. The URL
and key are delivered directly to the approved merchant.
Alternatives without PCI certification#
If you do not hold PCI certification, these paths avoid that scope entirely:
- Hosted payment page — Tilopay hosts the form.
- JavaScript SDK — the form lives on your page, but the data travels from the browser straight to Tilopay.
- No code — a plugin or an already-integrated platform.
Last verified: 2026-08-28 · Owner: equipo-integraciones