1. Cards
Framnex for Developers
  • Introduction
    • Overview
    • Quick Start
    • Authentication
    • Environments
  • Guides
    • Create an outgoing transfer
    • Handle webhooks
    • Transfer documents
  • Bulk Payouts
    • Upload bulk payout
      POST
    • List bulk payouts
      GET
    • Get bulk payout
      GET
    • List bulk payout items
      GET
    • Submit bulk payout
      POST
    • Cancel bulk payout
      POST
  • Cards
    • List card products
      GET
    • List cardholders
      GET
    • Issue card
      POST
    • List cards
      GET
    • Get card
      GET
    • Activate card
      POST
    • Freeze card
      POST
    • Unfreeze card
      POST
    • Close card
      POST
    • Set card limits
      PUT
    • Create encryption envelope
      POST
    • Reveal card details
      POST
    • Set PIN
      PUT
  • Card Transactions
    • List card transactions
    • Get card transaction
  • Accounts
    • Get account
    • List accounts
  • Auth
    • Get access token
  • Exchange Rates
    • Get exchange rate
  • Transfer Documents
    • Download document
    • List documents
    • Upload documents
  • Transfers
    • Create transfer
    • List transfers
    • Get transfer
  • Webhooks
    • Register webhook URL
    • Get webhook URL
    • List webhook deliveries
    • Get webhook delivery
    • Retry webhook delivery
  • Schemas
    • BankClientAPI
      • Account
      • AccountCredentials
      • AccountState
      • AccountType
      • AchCredentials
      • Address
      • BankDetails
      • BusinessEntity
      • ClientIntegrationAuthRequest
      • ClientIntegrationAuthResponse
      • ClientIntegrationErrorResponse
      • CreateExchangeTransferRequest
      • CreateOutgoingTransferRequest
      • CreateTransferRequest
      • CreateTransferType
      • CreatedResponse
      • Credentials
      • CredentialsState
      • CryptoCredentials
      • CustomerTransferStateDto
      • CryptoTransferDetails
      • ExchangeRate
      • DocumentDto
      • ExchangeTransferCancelledWebhookPayload
      • ExchangeTransfer
      • ExchangeTransferExecutedWebhookPayload
      • FasterUkCredentials
      • FedWireCredentials
      • IError
      • GasPaymentWebhookPayload
      • IReason
      • IncomingTransfer
      • LegalEntityType
      • ISuccess
      • IndividualEntity
      • IncomingTransferReceivedWebhookPayload
      • InternalCredentials
      • InternalServerError
      • OperationTypeDto
      • LegalEntity
      • LocalAEDCredentials
      • LocalXafCredentials
      • NeftCredentials
      • OutgoingTransfer
      • OutgoingTransferCancelledWebhookPayload
      • PageInfoDto
      • Participant
      • PaymentMethod
      • OutgoingTransferExecutedWebhookPayload
      • PagedFilterDto
      • TransferGas
      • TransferPagedDataDto
      • PixCredentials
      • TransferState
      • TransferType
      • ProblemDetails
      • TransferTypeDto
      • PaymentSystem
      • SepaCredentials
      • RegisterWebhookRequest
      • SortOrderDto
      • Result
      • SwiftCredentials
      • TedPayCredentials
      • Transfer
      • TransferDetails
      • TransferDetailsType
      • UaeFtsCredentials
      • UaeIppCredentials
      • ValidationProblemDetails
      • WebhookDelivery
      • WebhookDeliveryPagedDataDto
      • WebhookPayload
      • WebhookState
      • WebhookSubscription
      • WebhookType
      • YeePayKesLocalCredentials
      • YeePayMxnLocalCredentials
      • YeePayNgnLocalCredentials
    • BulkPayout
    • CardProduct
    • BulkPayoutState
    • Cardholder
    • BulkPayoutItemState
    • IssueCardRequest
    • BulkPayoutPagedDataDto
    • Card
    • BulkPayoutItemPagedDataDto
    • CardType
    • CardState
    • CardPagedDataDto
    • CloseCardRequest
    • SetCardLimitsRequest
    • CardEncryptionEnvelope
    • CardEncryptedDetailsRequest
    • CardEncryptedDetails
    • BulkPayoutFileFormat
    • SetCardPinRequest
    • BulkPayoutItemCounts
    • CardTransaction
    • CardTransactionState
    • BulkPayoutItem
    • CardTransactionPagedDataDto
    • CardNetwork
    • CardIssuanceFee
    • CardShipping
    • CardSpendingLimit
    • CardLimitInterval
    • CardCloseReason
    • CardSecretType
    • CardEncryptedValue
    • CardMerchant
    • CardWebhookType
    • CardWebhookPayload
    • CardIssuedWebhookPayload
    • CardIssuanceFailedWebhookPayload
    • CardStateChangedWebhookPayload
    • CardTransactionAuthorizedWebhookPayload
    • CardTransactionCompletedWebhookPayload
    • CardTransactionReversedWebhookPayload
    • BulkPayoutItemError
    • BulkPayoutFile
    • BulkPayoutFileItem
    • BulkPayoutWebhookType
    • BulkPayoutWebhookPayload
    • BulkPayoutValidatedWebhookPayload
    • BulkPayoutValidationFailedWebhookPayload
    • BulkPayoutCompletedWebhookPayload
GuidesBaaS API ReferenceBank Client API Reference
GuidesBaaS API ReferenceBank Client API Reference
  1. Cards

Create encryption envelope

POST
/integration/cards/{id}/encrypted-envelope
Early access - contact your account manager to enable cards for your organization.
Starts a session for reading or changing sensitive card data: the full card number, CVC and PIN. The response contains the publicKey to encrypt your session key with and the protocol to send back unchanged.
Card data is encrypted end to end. Your server calls the endpoints, while the session key is generated and used only on the cardholder's device, for example in your mobile app or web frontend. Your server passes the encrypted session key and the encrypted card data through without being able to read them, which keeps card data out of your server environment.
1.
Call this endpoint and pass publicKey to the device.
2.
On the device, generate a random 256-bit AES session key, encrypt it with publicKey using RSA-OAEP with SHA-256, and base64-encode the result.
3.
Before expiresAt, call POST /integration/cards/{id}/encrypted-details or PUT /integration/cards/{id}/pin with protocol and the encrypted session key.
4.
On the device, decrypt the returned values with the session key.
Errors: 404 Not Found if the card does not exist; 422 Unprocessable Content if the card is not active or frozen.

Request

Authorization
JWT Bearer
Add the parameter
Authorization
to Headers
Example:
Authorization: ********************
or
Path Params

Request Code Samples

Shell
JavaScript
Java
Swift
Go
PHP
Python
HTTP
C
C#
Objective-C
Ruby
OCaml
Dart
R
Request Request Example
Shell
JavaScript
Java
Swift
curl --location --request POST 'https://my.test-1.account.finlego.com/api/merchant/integration/cards//encrypted-envelope' \
--header 'Authorization: Bearer <token>'

Responses

🟢200OK
application/json
OK
Bodyapplication/json

Example
{
    "protocol": "rsa-oaep-aes-gcm-v1",
    "publicKey": "-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...\n-----END PUBLIC KEY-----",
    "expiresAt": "2026-09-29T10:05:00Z"
}
🟠400Bad Request
🟠401Unauthorized
🟠403Forbidden
🟠404Record Not Found
🟠422Parameter Error
🔴500Server Error
Modified at 2026-09-29 11:11:16
Previous
Set card limits
Next
Reveal card details
Built with