Reputation: 443
I am planning on setting up a Paypal Payments Pro account and posting to their Direct Payment API with credit card billing information via our website. In an effort not to worry about PCI compliance, I would rather not have the credit card information pass through our web server and post directly to PayPal from client code. What is the most simple way to do this? Perhaps use a PayPal hosted form and imbed it withing our webiste via an iframe? Can someone please list out a few recommended solutions and where to start looking? Thanks!
Upvotes: 1
Views: 265
Reputation: 26056
Payments Pro (DoDirectPayment) won't do that. What you want, per your explanation, is PayPal Payments Advanced (or sometimes they do call it Payments Pro Hosted, which just confuses people and is annoying.)
I personally prefer the full Pro, DDP over Advanced/Hosted. For PCI compliance, all you need to do is make sure you're using a valid SSL certificate on your server, and also make sure you're not saving any credit card details to your database.
Upvotes: 0