From a mobile app
This page describes a RESTful JSON interface that you can call from your mobile app to get card information.
Overall flow
- From your server, get a client access token
- Securely transfer the client access token to the app on the client device
- Use the JSON endpoint from your app
Get a client access token
From your server, get a client access token using the client authorisation API. The expiry time of each client access token will be 4 hours. You may cache these tokens for reuse across several different consumers.
Client authorisation
POST /acceptor/rest/authorisation/{instId}/authoriseClient{
"scopes": [
"CARDINFO"
]
}HTTP/1.1 200
{
"clientToken": "eyJ0eXAiOiJKV1QiLCJhbGciOiJFUzI1NiJ9.eyJpYXQiOjE0MTM5MzE0OTUsImV4cCI6MTQxMzkzNTE1NSwiYXVkIjoicHAvY2wiLCJzdWIiOiJhcGlfdXNlciJ9.MD4CHQDbh5oAbz122AVNeyJyoeQ7D0irpCx65m9XeNzmAh0AuqoipfjmFlTOJkWT4mH2ZsWo4V_iqbaO5f_10Q",
"status": "S100",
"message": "OK",
"expires": "2026-10-21T23:44:55.000Z"
}Use the JSON endpoint from your app
Call POST /cardinfo/getCardInfo with the PAN or PAN prefix in the request body. The full request and response fields are documented in the get card information mobile endpoint under Cards & Wallets API Endpoints.
Send the client access token as a Bearer token in the request header. For example:
POST /cardinfo/getCardInfo
Authorization: Bearer eyJpc3...
Content-Type: application/jsonThe endpoint supports full and partial PANs from 2 to 19 digits. Calling it with 2 to 11 digits is recommended; most six-digit prefixes return a full set of card information.
You may need to deal with token expiry in your app. You can recognise this situation in the service response. See Response Codes and Messages — CardInfo.
Note that your servers can get a new token, but the browser cannot do so directly.
API examples
Card information retrieval
POST /cardinfo/getCardInfo{
"pan": "9900000000000010"
}HTTP/1.1 200
{
"cardType": "VISA_DEBIT",
"cardUsageType": "DEBIT",
"cardScheme": "VISA",
"issuer": "DATACASH",
"issuerCountry": "GBR",
"moreData": false,
"valid": true,
"status": "SUCCESS",
"reasonCode": "S00",
"reasonMessage": "Authorised"
}Card information retrieval with expired client access token
POST /cardinfo/getCardInfo{
"pan": "9900000000000010"
}HTTP/1.1 401
{
"status": "FAILED",
"reasonCode": "V03",
"reasonMessage": "Access denied - client access token expired"
}