Cards & Wallets · Common features · Card Info library

From a mobile app

This page describes a RESTful JSON interface that you can call from your mobile app to get card information.

Overall flow

  1. From your server, get a client access token
  2. Securely transfer the client access token to the app on the client device
  3. Use the JSON endpoint from your app

Get a client access token

From your server, get a client access token using the client authorisation API. The expiry time of each client access token will be 4 hours. You may cache these tokens for reuse across several different consumers.

Client authorisation
EndpointDefinition
POST /acceptor/rest/authorisation/{instId}/authoriseClient
Request body
{
  "scopes": [
    "CARDINFO"
  ]
}
Response
HTTP/1.1 200

{
  "clientToken": "eyJ0eXAiOiJKV1QiLCJhbGciOiJFUzI1NiJ9.eyJpYXQiOjE0MTM5MzE0OTUsImV4cCI6MTQxMzkzNTE1NSwiYXVkIjoicHAvY2wiLCJzdWIiOiJhcGlfdXNlciJ9.MD4CHQDbh5oAbz122AVNeyJyoeQ7D0irpCx65m9XeNzmAh0AuqoipfjmFlTOJkWT4mH2ZsWo4V_iqbaO5f_10Q",
  "status": "S100",
  "message": "OK",
  "expires": "2026-10-21T23:44:55.000Z"
}

Use the JSON endpoint from your app

Call POST /cardinfo/getCardInfo with the PAN or PAN prefix in the request body. The full request and response fields are documented in the get card information mobile endpoint under Cards & Wallets API Endpoints.

Send the client access token as a Bearer token in the request header. For example:

Request header
POST /cardinfo/getCardInfo
Authorization: Bearer eyJpc3...
Content-Type: application/json

The endpoint supports full and partial PANs from 2 to 19 digits. Calling it with 2 to 11 digits is recommended; most six-digit prefixes return a full set of card information.

You may need to deal with token expiry in your app. You can recognise this situation in the service response. See Response Codes and Messages — CardInfo.

Note that your servers can get a new token, but the browser cannot do so directly.

API examples

Card information retrieval
EndpointDefinition
POST /cardinfo/getCardInfo
Request body
{
  "pan": "9900000000000010"
}
Response
HTTP/1.1 200

{
  "cardType": "VISA_DEBIT",
  "cardUsageType": "DEBIT",
  "cardScheme": "VISA",
  "issuer": "DATACASH",
  "issuerCountry": "GBR",
  "moreData": false,
  "valid": true,
  "status": "SUCCESS",
  "reasonCode": "S00",
  "reasonMessage": "Authorised"
}
Card information retrieval with expired client access token
EndpointDefinition
POST /cardinfo/getCardInfo
Request body
{
  "pan": "9900000000000010"
}
Response
HTTP/1.1 401

{
  "status": "FAILED",
  "reasonCode": "V03",
  "reasonMessage": "Access denied - client access token expired"
}