Qualys PCI Compliance Release 6.5

March 05, 2026

With this release of PCI Compliance, we are introducing the following new features and enhancements.

Configure OIDC Authentication with API External ID

The PCI Compliance APIs support IdP-based authentication using OpenID Connect (OIDC). We have optimized this authentication process.

With this release of PCI Merchant, we are introducing a new parameter, API External ID, to manage the user permissions. The API External ID is a unique identifier used to implement role-based API access. Also, you can enable the OIDC authentication independently, without enabling the SAML-based authentication.

 Only the Super Admin user can enable the API External ID for a merchant or bank user, and only Point of Contact users can edit it.

To learn more about configuring OIDC authentication, refer to the Token-based Authentication using IdP.

The Prerequisites section of the Token-based Authentication using IdP mention External ID as the prerequisites. For PCI Merchant, you can provide API External ID.

Issues Addressed

There are no notable and important customer issues for this release.