1. Cards
PIK
  • Start
    • Getting Started
  • Authentication
    • Authentication Token
      POST
  • Global Account
    • Contacts
      • Create Contact
      • List Contacts
      • Get Contact
      • Count Contacts
    • Virtual Accounts
      • Create Virtual Account
      • List Virtual Accounts
      • Get Virtual Account
    • Transactions
      • List Transactions
      • Get Transaction
    • Account Balance
      • List Account Balances
      • Get Balance by Currency
    • Payout
      • Create Payout
  • Payment Links
    • Payment Links
      • Create Payment Link
      • Update Payment Link
      • Get Payment Link Detail
      • Get Payment Link List
    • Transactions
      • Get Transaction List
  • Webhook
    • Global Account
      • Deposit Webhook
      • Payout Webhook
      • Virtual Account Webhook
    • Payment Links
      • Overview
      • Order Collect Out Webhook
      • Customer Payment Webhook
      • Customer Refund Webhook
      • Master Recharge Webhook
      • Web3 Direct Payment Webhook
      • Withdraw Out Webhook
    • Issuing
      • Card Activated
      • Card Failed
      • Transaction Completed
      • Transaction Declined
  • Issuing
    • Card Products
      • List Card Products
    • Cardholders
      • Create Cardholder
      • List Cardholders
      • Get Cardholder
    • Cards
      • Issue Card
        POST
      • List Cards
        GET
      • Get Card
        GET
      • Create Card Secure Session
        POST
    • Transactions
      • List Transactions
      • Get Transaction
  1. Cards

Create Card Secure Session

POST
/api/v1/issuing/card/{cardNo}/secureSession
Create a single-use session for displaying the full card number, expiry date and CVV to your end user.
The response contains an iframe URL. Render it in your frontend:
<iframe src="{displayUrl}" width="400" height="240" frameborder="0"></iframe>
The credentials are rendered by the card network directly into the end user's browser. They never pass through your backend or ours, which means there is no server-side way to read the card number or CVV.
Constraints:
Only cards in ACTIVE status are eligible.
displayUrl is single-use and expires in about 60 seconds. Request a new session each time you need to display credentials.
Do not persist, log, screenshot or forward the URL or the rendered credentials.

Request

Path Params

Responses

🟢200
application/json
Secure session created successfully
Bodyapplication/json

🟠401Unauthorized
🟠404NotFound
🟠422CardNotActive
🔴500InternalError
Request Request Example
Shell
JavaScript
Java
Swift
curl --location --request POST '/api/v1/issuing/card/CD260811X9Y8Z7/secureSession'
Response Response Example
200 - Example 1
{
    "code": 200,
    "message": "success",
    "data": {
        "displayUrl": "string",
        "expiresAt": "2019-08-24T14:15:22.123Z"
    }
}
Modified at 2026-08-11 10:11:22
Previous
Get Card
Next
List Transactions
Built with