Z Zise Developers 简体中文

Card list (first four and last four digits; never full card numbers)

GET /v1/cards scope: cards:read
On behalf of a member · x-on-behalf-of required

Cards belonging to a member, ordered by creation time descending. Uses real cursor pagination: do not hardcode has_more: false, as that can silently miss entries while new items are inserted at the front.

⚠ form_factor here contains the stored values (virtual_card / physical_card), while GET /v1/cards/{id} returns the short forms (virtual / physical), which are also used in application requests. The same concept has two representations across three places. Parse them per endpoint rather than sharing one parser branch.

product_id has the same form as the id from GET /v1/cards/products (cpd_…). For historical cards without a product row, it is null; do not invent one.

Query Parameters

FieldTypeRequiredDescription
cursor string Optional The next_cursor returned by the previous page. An opaque string; do not construct it yourself. An undecodable cursor restarts from the beginning without an error.
limit integer Optional Items per page. Defaults to 20, maximum 100; invalid values use the default.
FieldTypeRequiredDescription
x-on-behalf-of string Required The member on whose behalf to call. Accepts your own external_member_id or our mem_<uuid>.

Response

200OK
{
  "data": [
    {
      "id": "crd_9f2c1b7a-3d51-4a2e-9c08-6b1f0d4e77aa",
      "product_id": "cpd_1",
      "status": "active",
      "form_factor": "virtual_card",
      "currency": "USD",
      "masked_pan": "5240********7890",
      "created_at": "2026-08-01T02:11:43.000Z"
    }
  ],
  "next_cursor": "MjAyNi0wOC0wMVQwMjoxMTo0My4wMDBafDlmMmM",
  "has_more": true
}
400member_context_required: missing x-on-behalf-of.
404member_not_found: the member does not exist, does not belong to you, or is disabled (the same response for all three cases).
Request
curl -X GET 'https://api.zinfra.vip/v1/cards' \
  -H 'x-auth-token: Bearer $TOKEN' \
  -H 'x-on-behalf-of: $MEMBER_ID'
const res = await fetch("https://api.zinfra.vip/v1/cards", {
  method: "GET",
  headers: {
    "x-auth-token": "Bearer $TOKEN",
    "x-on-behalf-of": "$MEMBER_ID",
  },
});
// Keep monetary amounts as strings, never numbers.
const data = await res.json();
import requests

res = requests.get(
    "https://api.zinfra.vip/v1/cards",
    headers={
        "x-auth-token": "Bearer $TOKEN",
        "x-on-behalf-of": "$MEMBER_ID",
    },
)
# Use Decimal(str(...)) for amounts, not float.
data = res.json()
req, _ := http.NewRequest("GET", "https://api.zinfra.vip/v1/cards",
    nil)
req.Header.Set("x-auth-token", "Bearer $TOKEN")
req.Header.Set("x-on-behalf-of", "$MEMBER_ID")
res, err := http.DefaultClient.Do(req)
// Decode amount fields as string, not float64.
HttpRequest req = HttpRequest.newBuilder()
    .uri(URI.create("https://api.zinfra.vip/v1/cards"))
    .header("x-auth-token", "Bearer $TOKEN")
    .header("x-on-behalf-of", "$MEMBER_ID")
    .method("GET", HttpRequest.BodyPublishers.noBody())
    .build();
// Use String / BigDecimal for amounts, not double.
$ch = curl_init('https://api.zinfra.vip/v1/cards');
curl_setopt_array($ch, [
  CURLOPT_CUSTOMREQUEST => 'GET',
  CURLOPT_RETURNTRANSFER => true,
  CURLOPT_HTTPHEADER => [
    'x-auth-token: Bearer $TOKEN',
    'x-on-behalf-of: $MEMBER_ID',
  ],
]);
$res = curl_exec($ch);
// Use bcmath / strings for amounts, not floatval.
200
{
  "data": [
    {
      "id": "crd_9f2c1b7a-3d51-4a2e-9c08-6b1f0d4e77aa",
      "product_id": "cpd_1",
      "status": "active",
      "form_factor": "virtual_card",
      "currency": "USD",
      "masked_pan": "5240********7890",
      "created_at": "2026-08-01T02:11:43.000Z"
    }
  ],
  "next_cursor": "MjAyNi0wOC0wMVQwMjoxMTo0My4wMDBafDlmMmM",
  "has_more": true
}