Virtual Card Details
Fetch virtual card details (name, PAN, expiry, CVV) as encrypted HTML and open them with the decrypt steps below.
Virtual Card Details
Use this API when a customer needs to view full card details (name, PAN, expiry, CVV) in your app.
GET /cards/{cardId}/card-display returns EncryptedHtml directly under ResponseData, alongside Encryption.
Requires session-token. Use cardId from GET /cards/{userId}.
Response — Encryption JSON
{
"ResponseCode": 200,
"ResponseMessage": "Success",
"ResponseData": {
"EncryptedHtml": "<32-hex-salt><32-hex-iv><base64-ciphertext>",
"Encryption": {
"Algorithm": "AES-256-CBC",
"Padding": "PKCS7",
"KeyDerivation": "PBKDF2",
"KeySizeBits": 256,
"Iterations": 100,
"KeyName": "API_Client_Secret",
…| Field | Type | Description |
|---|---|---|
ResponseData.EncryptedHtml | string | Salt (32 hex) + IV (32 hex) + ciphertext |
ResponseData.Encryption | object | Cipher settings used to decrypt EncryptedHtml |
How to decrypt
You can decrypt EncryptedHtml using the following steps.
Cipher settings
| Algorithm | AES-256-CBC |
| Padding | PKCS7 |
| Key derivation | PBKDF2-HMAC-SHA256 using API_Client_Secret |
| Key size | 256 bits |
| Iterations | 100 |
| Payload | salt (32 hex chars) + iv (32 hex chars) + ciphertext |
Step 1: Take EncryptedHtml as one string. You also need the broker API_Client_Secret (same secret as today).
Step 2: First 32 characters = salt (hex).
Step 3: Next 32 characters = iv (hex).
Step 4: Remainder = ciphertext.
Step 5: Derive a 256-bit key using PBKDF2-HMAC-SHA256 with API_Client_Secret, the decoded salt, and 100 iterations.
Step 6: Decrypt AES-256-CBC with that key, iv, and PKCS7 padding.
Step 7: Result is UTF-8 HTML. Show it in an iframe or WebView.
Example (Node)
const crypto = require('crypto');
function decryptCardHtml(encryptedHtml, apiClientSecret) {
const salt = Buffer.from(encryptedHtml.slice(0, 32), 'hex');
const iv = Buffer.from(encryptedHtml.slice(32, 64), 'hex');
const ciphertext = Buffer.from(encryptedHtml.slice(64), 'base64');
const key = crypto.pbkdf2Sync(apiClientSecret, salt, 100, 32, 'sha256');
const decipher = crypto.createDecipheriv('aes-256-cbc', key, iv);
return Buffer.concat([decipher.update(ciphertext), decipher.final()]).toString('utf8');
}
```Java / .NET / Python: PBKDF2-HMAC-SHA256 → AES-256-CBC with PKCS7 padding.
…Virtual Card Details endpoints