Unblock CVV
On behalf of a member ·
x-on-behalf-of required
Requires x-idempotency-key
After repeated failed attempts to view sensitive card details, the upstream blocks CVV (cvv_blocked: true in card details). Previously there was no unlock entry point: sensitive details became permanently inaccessible, and POST /v1/cards/{id}/secure-session revealed the block only at the last step.
No step-up authentication is required: unlocking itself reveals no data. Perform a new real-time lookup after unlocking.
⚠ Rate-limited to 5 calls per member per hour. This calls the upstream, and repeated unlocking has no legitimate use.
⚠ The response only confirms unlocking. The source of truth for cvv_blocked is GET /v1/cards/{id}; query it there. Returning independent copies in two places would eventually diverge.
Path Parameters
| Field | Type | Required | Description |
|---|---|---|---|
id |
string | Required | Card ID. Accepted with or without the crd_ prefix. |
Request Headers
| Field | Type | Required | Description |
|---|---|---|---|
x-idempotency-key |
string | Required | |
x-on-behalf-of |
string | Required |
Response
200Unlocked
{
"unblocked": true
}400
state_invalid: card status does not allow the action. idempotency_key_required.404
not_found: the card does not exist or does not belong to this member/merchant.429
rate_limited: back off according to Retry-After.Request
curl -X POST 'https://api.zinfra.vip/v1/cards/{id}/cvv/unblock' \
-H 'x-auth-token: Bearer $TOKEN' \
-H 'x-on-behalf-of: $MEMBER_ID' \
-H 'x-idempotency-key: $IDEMPOTENCY_KEY'const res = await fetch("https://api.zinfra.vip/v1/cards/{id}/cvv/unblock", {
method: "POST",
headers: {
"x-auth-token": "Bearer $TOKEN",
"x-on-behalf-of": "$MEMBER_ID",
"x-idempotency-key": "$IDEMPOTENCY_KEY",
},
});
// Keep monetary amounts as strings, never numbers.
const data = await res.json();import requests
res = requests.post(
"https://api.zinfra.vip/v1/cards/{id}/cvv/unblock",
headers={
"x-auth-token": "Bearer $TOKEN",
"x-on-behalf-of": "$MEMBER_ID",
"x-idempotency-key": "$IDEMPOTENCY_KEY",
},
)
# Use Decimal(str(...)) for amounts, not float.
data = res.json()req, _ := http.NewRequest("POST", "https://api.zinfra.vip/v1/cards/{id}/cvv/unblock",
nil)
req.Header.Set("x-auth-token", "Bearer $TOKEN")
req.Header.Set("x-on-behalf-of", "$MEMBER_ID")
req.Header.Set("x-idempotency-key", "$IDEMPOTENCY_KEY")
res, err := http.DefaultClient.Do(req)
// Decode amount fields as string, not float64.HttpRequest req = HttpRequest.newBuilder()
.uri(URI.create("https://api.zinfra.vip/v1/cards/{id}/cvv/unblock"))
.header("x-auth-token", "Bearer $TOKEN")
.header("x-on-behalf-of", "$MEMBER_ID")
.header("x-idempotency-key", "$IDEMPOTENCY_KEY")
.method("POST", HttpRequest.BodyPublishers.noBody())
.build();
// Use String / BigDecimal for amounts, not double.$ch = curl_init('https://api.zinfra.vip/v1/cards/{id}/cvv/unblock');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
'x-auth-token: Bearer $TOKEN',
'x-on-behalf-of: $MEMBER_ID',
'x-idempotency-key: $IDEMPOTENCY_KEY',
],
]);
$res = curl_exec($ch);
// Use bcmath / strings for amounts, not floatval.
200
{
"unblocked": true
}