Skip to content

Authorize a single-use grant for revealing the card PAN

POST/v1/cards/{id}/secure-data

Requires an API client bearer token.

Authorizes a 60-second, single-use grant over this card and returns where to redeem it. The caller generates the grant token and sends only its sha256 digest, so nothing redeemable appears in this request or response — the PAN, the expiry and a freshly derived CVV2 come back from the vault reveal endpoint named in `reveal_url`, not from this service. Not idempotency-keyed.

Parameters

Path parameters

NameRequiredDescription
idrequired

Request body

token_hashstringrequired

Example

curl -X POST https://api.rigid.fi/v1/cards/{id}/secure-data \
  -H "Authorization: Bearer $RIGID_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "token_hash": "string"
}'

Responses

201

Grant authorized. Carries the reveal endpoint and the expiry — nothing secret.

reveal_urlstringrequired
expires_atstringrequired
400

Validation error

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
401

Authentication required

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
403

Forbidden

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
404

Card not found

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
500

Internal server error

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring