Server-to-server API (restricted access)

API v1

Restricted access. This is not a self-serve path. You cannot start this integration on your own today: it requires merchant PCI certification and a URL provisioned individually by Tilopay.

What it is#

The path where card data passes through the merchant's server, which then sends it to the Tilopay API.

Who it is for#

  • It is a service exclusive to merchants holding PCI certification.
  • The URL is customized per merchant, with its own key. It is not a public URL.

That is why this page has no endpoint, no executable examples and no request bodies: there is no common address that works for everyone.

Requirements#

  1. Valid PCI certification for the merchant.
  2. An active Tilopay account.
  3. An approved request, with the URL and key provisioned by Tilopay for your merchant.

How to request it#

Write to sac@tilopay.com with the merchant name and the status of your PCI certification. The URL and key are delivered directly to the approved merchant.

Alternatives without PCI certification#

If you do not hold PCI certification, these paths avoid that scope entirely:

  • Hosted payment page — Tilopay hosts the form.
  • JavaScript SDK — the form lives on your page, but the data travels from the browser straight to Tilopay.
  • No code — a plugin or an already-integrated platform.

Last verified: 2026-08-28 · Owner: equipo-integraciones

View as raw Markdown