Skip to main content
This guide describes how to back up Stripe.com payment-method data to Commerce.

Backup Approach

Stripe.com offers a forward API to forward payment-method data to third-party services.
The API is a gated feature on the Stripe.com platform. You need to request access from support.
Conceptually, the backup process is a call to the forward API with a reference to a payment method. Stripe.com then forwards the sensitive cardholder data (CHD) to Commerce. Commerce imports the data and returns a Commerce token in exchange; this token is returned by the forward API to the caller.
Stripe Token BackupStripe Token Backup
As the forward API is gated, you need to request access first. Create a Stripe.com support request on your account with the following information:
You will need the PCI DSS Attestation of Compliance from Starfish, which you can get from your account representative.
Commerce accepts imports on /cde-import only when CDE import is enabled for your account, which requires at least SAQ D PCI DSS compliance. Requests forwarded by Stripe.com are no exception.

Back Up a Payment Method

Trigger the forward API once for each payment method you want to back up.

Request

Replace the placeholders with your actual values:
  • STRIPE_API_KEY: Your Stripe.com API key
  • STRIPE_PAYMENT_METHOD_ID: The payment-method id from Stripe.com
  • COMMERCE_API_KEY: Your Commerce API key

Response

The response includes the created Commerce token; you can store its ID in your system. If you send the Stripe.com payment-method id as metadata, you can trace the token back via the business_key attribute.