Z Zise Developers 简体中文

Retrieve the card number, CVV, and expiry date in real time

POST /v1/cards/{id}/secure-session scope: cards:secure
On behalf of a member · x-on-behalf-of required

After verifying that the card belongs to both the current merchant and the member specified by x-on-behalf-of, each request queries the upstream in real time and returns the card number, CVV, and expiry date in plaintext. PIN is not included.

The response includes Cache-Control: no-store. We do not store the data in our database, logs, or idempotency cache; the downstream merchant is responsible for compliance when storing or displaying these fields.

⚠ If the upstream has blocked the card's CVV (cvv_blocked: true in card details), the endpoint returns state_invalid. Read cvv_blocked first to avoid an unnecessary request.

Prerequisites

  • The card belongs to this member and merchant.

Path Parameters

FieldTypeRequiredDescription
id string Required Card ID. Accepted with or without the crd_ prefix.
FieldTypeRequiredDescription
x-on-behalf-of string Required The member on whose behalf to call.

Response

200Real-time lookup succeeded; the response must not be cached.
{
  "pan": "5240123412345678",
  "cvv": "123",
  "expiry_month": "08",
  "expiry_year": "29"
}
400state_invalid: CVV has been blocked by the upstream. service_unavailable: the card's upstream is not configured or cannot currently be queried.
404not_found: the card does not exist or does not belong to this member/merchant.
502upstream_error: the upstream is temporarily unable to return sensitive card details.
Request
curl -X POST 'https://api.zinfra.vip/v1/cards/{id}/secure-session' \
  -H 'x-auth-token: Bearer $TOKEN' \
  -H 'x-on-behalf-of: $MEMBER_ID'
const res = await fetch("https://api.zinfra.vip/v1/cards/{id}/secure-session", {
  method: "POST",
  headers: {
    "x-auth-token": "Bearer $TOKEN",
    "x-on-behalf-of": "$MEMBER_ID",
  },
});
// Keep monetary amounts as strings, never numbers.
const data = await res.json();
import requests

res = requests.post(
    "https://api.zinfra.vip/v1/cards/{id}/secure-session",
    headers={
        "x-auth-token": "Bearer $TOKEN",
        "x-on-behalf-of": "$MEMBER_ID",
    },
)
# Use Decimal(str(...)) for amounts, not float.
data = res.json()
req, _ := http.NewRequest("POST", "https://api.zinfra.vip/v1/cards/{id}/secure-session",
    nil)
req.Header.Set("x-auth-token", "Bearer $TOKEN")
req.Header.Set("x-on-behalf-of", "$MEMBER_ID")
res, err := http.DefaultClient.Do(req)
// Decode amount fields as string, not float64.
HttpRequest req = HttpRequest.newBuilder()
    .uri(URI.create("https://api.zinfra.vip/v1/cards/{id}/secure-session"))
    .header("x-auth-token", "Bearer $TOKEN")
    .header("x-on-behalf-of", "$MEMBER_ID")
    .method("POST", HttpRequest.BodyPublishers.noBody())
    .build();
// Use String / BigDecimal for amounts, not double.
$ch = curl_init('https://api.zinfra.vip/v1/cards/{id}/secure-session');
curl_setopt_array($ch, [
  CURLOPT_CUSTOMREQUEST => 'POST',
  CURLOPT_RETURNTRANSFER => true,
  CURLOPT_HTTPHEADER => [
    'x-auth-token: Bearer $TOKEN',
    'x-on-behalf-of: $MEMBER_ID',
  ],
]);
$res = curl_exec($ch);
// Use bcmath / strings for amounts, not floatval.
200
{
  "pan": "5240123412345678",
  "cvv": "123",
  "expiry_month": "08",
  "expiry_year": "29"
}