Early access - contact your account manager to enable cards for your organization.
operation = cardDetails, or the PIN for operation = pin.data) with its initialization vector (iv), both base64-encoded. Decrypt them on the cardholder's device with the session key from POST /integration/cards/{id}/encrypted-envelope, and never store or log the decrypted values.400 Bad Request if the encrypted session key is invalid or the envelope has expired; 404 Not Found if the card does not exist; 422 Unprocessable Content if the card is not active or frozen.