Card details
curl --request GET \
--url https://api.cartevo.co/api/v1/cards/{id} \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.cartevo.co/api/v1/cards/{id}"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.cartevo.co/api/v1/cards/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.cartevo.co/api/v1/cards/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.cartevo.co/api/v1/cards/{id}"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.cartevo.co/api/v1/cards/{id}")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.cartevo.co/api/v1/cards/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"success": true,
"statusCode": 200,
"message": "Data retrieved successfully",
"data": {
"id": "91b3c6d6-111b-44da-9f81-16f019bebe8c",
"status": "ACTIVE",
"balance": 0.45,
"currency": "USD",
"number": "tkAlsp_eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ2YWx1ZSI6IjUzNjAyNTI0ODM0NjU0MDciLCJpYXQiOjE3NjExNDg5NzR9.7sNid1b1pxmkpseiCR45E8Xj9hdmenZDovBcjVatBF0",
"masked_pan": "**** **** **** 5407",
"cvv": "tkAlsp_eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ2YWx1ZSI6Ijg1NyIsImlhdCI6MTc2MTE0ODk3NH0.K7YHl0nzZTsScjUma_G5fyxYZFNnK-2SczstVtdMK1A",
"expiry_month": 10,
"expiry_year": 28,
"is_virtual": true,
"is_physical": false,
"created_at": "2023-11-07T05:31:56Z"
}
}Cards
Get Card Details
Retrieve full details of a single card. Optionally reveal the unmasked card number and CVV (audit-logged).
GET
/
cards
/
{id}
Card details
curl --request GET \
--url https://api.cartevo.co/api/v1/cards/{id} \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.cartevo.co/api/v1/cards/{id}"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.cartevo.co/api/v1/cards/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.cartevo.co/api/v1/cards/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.cartevo.co/api/v1/cards/{id}"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.cartevo.co/api/v1/cards/{id}")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.cartevo.co/api/v1/cards/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"success": true,
"statusCode": 200,
"message": "Data retrieved successfully",
"data": {
"id": "91b3c6d6-111b-44da-9f81-16f019bebe8c",
"status": "ACTIVE",
"balance": 0.45,
"currency": "USD",
"number": "tkAlsp_eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ2YWx1ZSI6IjUzNjAyNTI0ODM0NjU0MDciLCJpYXQiOjE3NjExNDg5NzR9.7sNid1b1pxmkpseiCR45E8Xj9hdmenZDovBcjVatBF0",
"masked_pan": "**** **** **** 5407",
"cvv": "tkAlsp_eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ2YWx1ZSI6Ijg1NyIsImlhdCI6MTc2MTE0ODk3NH0.K7YHl0nzZTsScjUma_G5fyxYZFNnK-2SczstVtdMK1A",
"expiry_month": 10,
"expiry_year": 28,
"is_virtual": true,
"is_physical": false,
"created_at": "2023-11-07T05:31:56Z"
}
}Overview
GET /cards/{id} returns full details of a single card. By default, the card number and CVV are returned as masked or as opaque encrypted tokens (PCI DSS requirement). Append ?reveal=true to receive the cleartext PAN and CVV — every reveal call is audit-logged and visible in your dashboard.
When to use it
- Display a card’s status and balance to the cardholder.
- One-time reveal of the PAN/CVV for the cardholder to use the card (e.g. in a “show card” UI immediately after creation).
- Reconcile your local cache against Cartevo’s source of truth (use
?sync=true).
Prerequisites
- The card must belong to your company.
- For
?reveal=true: nothing extra — but be aware every reveal is audit-logged.
Request
Headers
| Name | Required | Description |
|---|---|---|
Authorization | Yes | Bearer <access_token> |
Path parameters
| Name | Type | Description |
|---|---|---|
id | string | Card ID (UUID). |
Query parameters
| Name | Type | Default | Description |
|---|---|---|---|
reveal | boolean | false | If true, the response includes the cleartext number and cvv instead of opaque tokens. Audit-logged. |
includeRaw | boolean | false | If true, includes the raw upstream-issuer payload under raw. Useful for debugging; not for production UI. |
sync | boolean | true | If true (default), force-refresh from the upstream issuer. Set false to read from Cartevo’s local cache only (faster). |
Response
200 — Success (default, masked)
{
"success": true,
"statusCode": 200,
"message": "Data retrieved successfully",
"data": {
"id": "550e8400-e29b-41d4-a716-446655440000",
"status": "ACTIVE",
"balance": 100.0,
"currency": "USD",
"masked_pan": "**** **** **** 1111",
"number": "tkMplr_eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
"cvv": "tkMplr_eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
"expiry_month": 12,
"expiry_year": 2028,
"is_virtual": true,
"is_physical": false,
"brand": "VISA",
"created_at": "2026-05-09T10:15:00.000Z"
}
}
200 — With ?reveal=true
{
"success": true,
"statusCode": 200,
"message": "Data retrieved successfully",
"data": {
"id": "550e8400-e29b-41d4-a716-446655440000",
"status": "ACTIVE",
"balance": 100.0,
"currency": "USD",
"masked_pan": "**** **** **** 1111",
"number": "4111111111111111",
"cvv": "123",
"expiry_month": 12,
"expiry_year": 2028,
"is_virtual": true,
"is_physical": false,
"brand": "VISA",
"created_at": "2026-05-09T10:15:00.000Z"
}
}
Field reference
| Field | Type | Description |
|---|---|---|
id | string | Card ID (UUID). |
status | string | One of PENDING, ACTIVE, FROZEN, SUSPENDED, TERMINATED, FAILED. See Glossary → Card. |
balance | number | Available balance in currency. |
currency | string | Always USD. |
masked_pan | string | Always returned. Last 4 digits visible. |
number | string | Without reveal: opaque encrypted token (begins tkMplr_). With reveal: cleartext 16-digit PAN. |
cvv | string | Without reveal: opaque encrypted token. With reveal: cleartext 3-digit CVV. |
expiry_month | integer | 1–12. |
expiry_year | integer | 4-digit year. |
is_virtual | boolean | Always true today. |
is_physical | boolean | Always false today. |
brand | string | VISA or MASTERCARD. |
About the opaque tokens: Whenrevealis not set, thenumberandcvvfields contain encrypted tokens (e.g.tkMplr_...). These are not decryptable client-side and not usable as a real card number. They exist so that field shapes are stable across both response variants. Always store them only if you are sure why.
Error responses
| Status | Trigger |
|---|---|
401 | Missing or expired Bearer token. |
404 | Card does not exist or belongs to another company. |
5xx | Upstream issuer unreachable (only when sync=true). |
Security and PCI DSS
- Every call with
?reveal=trueis audit-logged. - Never store revealed PAN/CVV in your own logs, databases, or analytics.
- Pass revealed data only over HTTPS, only to the cardholder, and never to third parties.
- For more details, see the Cards Overview → PCI DSS section.
Code examples
cURL
# Masked
curl https://api.cartevo.co/api/v1/cards/550e8400-e29b-41d4-a716-446655440000 \
-H "Authorization: Bearer $TOKEN"
# Revealed (audit-logged)
curl 'https://api.cartevo.co/api/v1/cards/550e8400-e29b-41d4-a716-446655440000?reveal=true' \
-H "Authorization: Bearer $TOKEN"
Node.js (axios)
const { data } = await axios.get(
`https://api.cartevo.co/api/v1/cards/${cardId}`,
{
headers: { Authorization: `Bearer ${token}` },
params: { reveal: true },
}
);
const { number, cvv, expiry_month, expiry_year } = data.data;
Related
- Cards Overview — security model and statuses.
GET /cards/{id}/transactions— transaction history for this card.
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
Query Parameters
Set to true to reveal unmasked card details (number, CVV). Default is false.