Authorize a single-use grant for revealing the card PAN
POST
/v1/cards/{id}/secure-dataRequires an API client bearer token.
Authorizes a 60-second, single-use grant over this card and returns where to redeem it. The caller generates the grant token and sends only its sha256 digest, so nothing redeemable appears in this request or response — the PAN, the expiry and a freshly derived CVV2 come back from the vault reveal endpoint named in `reveal_url`, not from this service. Not idempotency-keyed.
Parameters
Path parameters
| Name | Required | Description |
|---|---|---|
| id | required |
Request body
token_hashstringrequired
Example
curl -X POST https://api.rigid.fi/v1/cards/{id}/secure-data \
-H "Authorization: Bearer $RIGID_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"token_hash": "string"
}'Responses
201Grant authorized. Carries the reveal endpoint and the expiry — nothing secret.
reveal_urlstringrequired
expires_atstringrequired
400Validation error
typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
401Authentication required
typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
403Forbidden
typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
404Card not found
typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
500Internal server error
typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring