POST

Authorizations

Authorization
string
header
required

The user's id_token from authentication — the ID token, not the access_token. The program and environment come from the token.

Path Parameters

customerId
string
required

The customer's id.

accountId
string
required

The account the card belongs to. A customer can have several accounts; cards are issued against one.

cardId
string
required

The card id from create / get cards.

Body

application/json
confirmation
Passkey · object
required

Step-up confirmation. Set method to passkey, totp, or pin and include that method's fields. pin is a program capability — see Program capabilities.

cipher
string

The cipher from Get secure key.

Response

Secure card data

success
boolean
Example:

true

data
object

Sensitive values, encrypted with the secretKey from Get secure key. Decrypt client-side; never log or store them.