PCI Compliance Merchant Release 1.8

June 15, 2026

Qualys Managed Tokens for API Access

PCI Compliance APIs now support authentication using Qualys-managed access tokens. 

API authentication using Qualys-managed tokens provides the following benefits for secure API access:

  • Enables secure, token‑based API access without embedding usernames and passwords, using industry‑standard authentication.
  • Supports granular role‑based access control and complete tracking by mapping tokens to specific users.
  • Simplifies credential management using existing Qualys infrastructure.

 This feature has limited availability. Contact Qualys Support to enable it for your account.

To set up Qualys-managed authentication, in the PCI Merchant user interface, navigate to the Account > Auth ID Token Management tab. Click New Token to generate Client ID and Client Secret. You need a client ID and a client secret to generate an authentication token.

To learn more about this feature, refer to Auth ID Token Management.

API Enhancement: PCI Compliance Release 1.8 API

Issues Addressed

There are no notable and important customer issues for this release.