# Raw Card APIs and PCI Compliance: A SaaS Reality Check

DevFeed: [Raw Card APIs and PCI Compliance: A SaaS Reality Check](<https://devfeed.tech/articles/raw-card-apis-and-pci-compliance-a-saas-reality-check-10298.md>)

Original publisher: [Read original article](<https://dodopayments.com/blogs/raw-card-api-pci-compliance/>)

Author: Ayush Agarwal

Published: 2026-05-16T00:00:00Z

Content type: article

Language: en

Sources: [Dodo Payments Blog](<https://devfeed.tech/sources/dodo-payments-blog.md>)

Topics: [Software as a service](<https://devfeed.tech/topics/saas.md>), [Security](<https://devfeed.tech/topics/security.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [apis](<https://devfeed.tech/tags/apis.md>), [card](<https://devfeed.tech/tags/card.md>), [checkout](<https://devfeed.tech/tags/checkout.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [payment](<https://devfeed.tech/tags/payment.md>), [saas](<https://devfeed.tech/tags/saas.md>), [scope](<https://devfeed.tech/tags/scope.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

This article explains how raw card APIs give SaaS products greater control over payment flows while significantly expanding PCI compliance scope, engineering responsibilities, and audit costs. It compares raw card handling with hosted or embedded payment forms and identifies integration scenarios where the trade-off may be justified.

## Source excerpt

Raw card APIs give you full control over the payment form but expand PCI scope dramatically. When the trade off makes sense and when it absolutely does not.