Early access - contact your account manager to enable cards for your organization.
Starts a session for reading or changing sensitive card data: the full card number, CVC and PIN. The response contains the publicKey to encrypt your session key with and the protocol to send back unchanged.Card data is encrypted end to end. Your server calls the endpoints, while the session key is generated and used only on the cardholder's device, for example in your mobile app or web frontend. Your server passes the encrypted session key and the encrypted card data through without being able to read them, which keeps card data out of your server environment.
1.
Call this endpoint and pass publicKey to the device.
2.
On the device, generate a random 256-bit AES session key, encrypt it with publicKey using RSA-OAEP with SHA-256, and base64-encode the result.
3.
Before expiresAt, call POST /integration/cards/{id}/encrypted-details or PUT /integration/cards/{id}/pin with protocol and the encrypted session key.
4.
On the device, decrypt the returned values with the session key.
Errors: 404 Not Found if the card does not exist; 422 Unprocessable Content if the card is not active or frozen.
Request
Authorization
JWT Bearer
Add the parameter
Authorization
to Headers
Example:
Authorization: ********************
or
Path Params
Request Code Samples
Shell
JavaScript
Java
Swift
Go
PHP
Python
HTTP
C
C#
Objective-C
Ruby
OCaml
Dart
R
Request Request Example
Shell
JavaScript
Java
Swift
curl--location--request POST 'https://my.test-1.account.finlego.com/api/merchant/integration/cards//encrypted-envelope' \
--header'Authorization: Bearer <token>'
Responses
🟢200OK
application/json
OK
Bodyapplication/json
Example
{"protocol":"rsa-oaep-aes-gcm-v1","publicKey":"-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...\n-----END PUBLIC KEY-----","expiresAt":"2026-09-29T10:05:00Z"}