Compliance Hub
- SAQ A scope map
- 3-D Secure 2 exemptions
- Current attestation
PCI DSS scope, SCA rules and SEPA scheme notes in plain words. Read what stays with us and what stays with you.
BazPay is the EU payment gateway built for low-risk merchants. Card acquiring, open banking, payouts and fraud sit under one API contract. This page collects the docs behind that claim. Guides, reference pages, compliance notes and merchant write-ups are grouped by the job you are doing. Nothing here is gated.
Every collection is public. Read it, copy from it, share it with your auditor.
PCI DSS scope, SCA rules and SEPA scheme notes in plain words. Read what stays with us and what stays with you.
Six step-by-step guides, in the order the work happens: sandbox keys, the first payment, 3-D Secure, webhooks and go-live.
Every endpoint, field and error code for the payments API. Copy a request, paste it into the sandbox, read the trace.
How merchants moved off a legacy gateway. Each write-up names the rails used and the routing changes made.
Short definitions for the payments words that show up in contracts. One term, one paragraph, no sales language.
Notes from the payments team on EU rules, scheme changes and gateway releases. We post when there is something to say.
Merchants arrive here at different stages. Pick the row that matches yours. Each one names the two pages to read first.
Check the plugin list first. If a plugin fits your stack, the build is config work, not custom code.
Hosted fields keep card data out of your servers. The scope map and our attestation cover the rest.
Watch decline reasons daily. Small routing and exemption fixes lift approval rates more than a re-platform.
| Document | Format | Updated | Owner |
|---|---|---|---|
| API Reference | Web + OpenAPI file | Every release | Platform team |
| Documentation | Web + sample repo | Per API version | Solutions team |
| Compliance Hub | Web + PDF | On scheme change | Risk & compliance |
| Changelog | Web + RSS | Weekly | Platform team |
Note Breaking API changes ship behind a version header. Old versions keep working while you migrate. The changelog carries the dates.
Questions about the product rather than the library — onboarding files, settlement timing, PCI scope, disputes — live on the gateway FAQ.
No. The reference, guides and glossary are open. A sandbox account only matters when you want to send a real test call.
Use the plugin guide, not the REST guide. Most shops reach a first test capture in about three days that way.
We publish them on the blog and in the changelog. Card scheme mandates get a note before the deadline, not after it.
Mail us at the address below. Doc corrections go to the team that owns the page in the table above.
The sandbox mirrors production, including webhooks and decline codes. Most teams go live in days. Mail us if a page here leaves a question open.