PCI Compliance Merchant Release 1.8
June 15, 2026
Qualys Managed Tokens for API Access
PCI Compliance APIs now support authentication using Qualys-managed access tokens.
API authentication using Qualys-managed tokens provides the following benefits for secure API access:
- Enables secure, token‑based API access without embedding usernames and passwords, using industry‑standard authentication.
- Supports granular role‑based access control and complete tracking by mapping tokens to specific users.
- Simplifies credential management using existing Qualys infrastructure.
This feature has limited availability. Contact Qualys Support to enable it for your account.
To set up Qualys-managed authentication, in the PCI Merchant user interface, navigate to the Account > Auth ID Token Management tab. Click New Token to generate Client ID and Client Secret. You need a client ID and a client secret to generate an authentication token.

To learn more about this feature, refer to Auth ID Token Management.
API Enhancement: PCI Compliance Release 1.8 API
Issues Addressed
There are no notable and important customer issues for this release.