1. Cards
Framnex for Developers
  • Introduction
    • Overview
    • Quick Start
    • Authentication
    • Environments
  • Guides
    • Onboard a client
    • Open an account
    • Create an outgoing transfer
    • Handle webhooks
  • Accounts
    • Open account
      POST
    • List accounts
      GET
    • Get account
      GET
  • Auth
    • Get access token
      POST
  • Clients
    • Create client
    • List clients
    • Get client creation schema
    • Get client
    • Get client state
  • Transfers
    • Create transfer
    • List transfers
    • Get transfer
  • Webhooks
    • Register webhook URL
    • Get webhook URL
    • List webhook deliveries
    • Get webhook delivery
    • Retry webhook delivery
  • Cards
    • List card products
      GET
    • List cardholders
      GET
    • Issue card
      POST
    • List cards
      GET
    • Get card
      GET
    • Activate card
      POST
    • Freeze card
      POST
    • Unfreeze card
      POST
    • Close card
      POST
    • Set card limits
      PUT
    • Create encryption envelope
      POST
    • Reveal card details
      POST
    • Set PIN
      PUT
  • Card Transactions
    • List card transactions
    • Get card transaction
  • Exchange Rates
    • Get exchange rate
  • Incoming Transfers
    • Simulate incoming transfer
  • Transfer Documents
    • Download document
    • List documents
    • Upload documents
  • Schemas
    • BaaS API
      • Account
      • AccountCredentials
      • AccountOpenedWebhookPayload
      • AccountOpeningFailedWebhookPayload
      • AccountPagedDataDto
      • AccountState
      • AccountType
      • AchCredentials
      • Address
      • AuthTokenRequest
      • AuthTokenResponse
      • BankDetails
      • BusinessClient
      • BusinessEntity
      • Client
      • CreateBusinessClientRequest
      • ClientCreateType
      • CreateClientRequest
      • ClientCreatedResponse
      • ClientPagedDataDto
      • CreateIndividualClientRequest
      • ClientState
      • ClientStateResponse
      • ClientType
      • ClientsFilter
      • CreateAccountRequest
      • CreateExchangeTransferRequest
      • CreateIncomingTransferRequest
      • CreateOutgoingTransferRequest
      • CredentialsState
      • CreateTransferRequest
      • ExchangeRate
      • CreateTransferType
      • CreatedResponse
      • Credentials
      • CredentialsIssueFailedWebhookPayload
      • CredentialsIssuedWebhookPayload
      • ExchangeTransferProcessingWebhookPayload
      • CryptoCredentials
      • IError
      • CryptoTransferDetails
      • IReason
      • DocumentDto
      • ISuccess
      • EmptyResponse
      • ErrorDetailsDto
      • IdentificationDocument
      • IdentificationDocumentType
      • ExchangeTransfer
      • ExchangeTransferCancelledWebhookPayload
      • ExchangeTransferExecutedWebhookPayload
      • FasterUkCredentials
      • FedWireCredentials
      • ForeignTransferParty
      • GasPaymentWebhookPayload
      • IncomingTransfer
      • IncomingTransferReceivedWebhookPayload
      • OutgoingTransferProcessingWebhookPayload
      • IndividualClient
      • IndividualEntity
      • LegalEntity
      • InternalCredentials
      • Participant
      • LegalEntityType
      • LocalAEDCredentials
      • LocalXafCredentials
      • NeftCredentials
      • Result
      • OnboardingCompletedWebhookPayload
      • OutgoingTransfer
      • RiskLevel
      • OnboardingFailedWebhookPayload
      • OutgoingTransferCancelledWebhookPayload
      • PageInfoDto
      • OutgoingTransferExecutedWebhookPayload
      • TransferPagedDataDto
      • PagedFilterDto
      • PaymentMethod
      • ProblemDetails
      • TransfersFilter
      • PixCredentials
      • RegisterWebhookRequest
      • WebhookDelivery
      • SortOrderDto
      • WebhookDeliveryPagedDataDto
      • SepaCredentials
      • SortDto
      • Transfer
      • WebhookSubscription
      • SwiftCredentials
      • TedPayCredentials
      • WebhooksFilter
      • TransferDetails
      • TransferDetailsType
      • TransferGas
      • TransferState
      • TransferType
      • ValidationProblemDetails
      • UaeFtsCredentials
      • UaeIppCredentials
      • WebhookPayload
      • WebhookState
      • WebhookType
      • YeePayKesLocalCredentials
      • YeePayMxnLocalCredentials
      • YeePayNgnLocalCredentials
    • CardProduct
    • Cardholder
    • IssueCardRequest
    • Card
    • CardType
    • CardState
    • CardPagedDataDto
    • CloseCardRequest
    • SetCardLimitsRequest
    • CardEncryptionEnvelope
    • CardEncryptedDetailsRequest
    • CardEncryptedDetails
    • SetCardPinRequest
    • CardTransaction
    • CardTransactionState
    • CardTransactionPagedDataDto
    • CardNetwork
    • CardIssuanceFee
    • CardShipping
    • CardSpendingLimit
    • CardLimitInterval
    • CardCloseReason
    • CardSecretType
    • CardEncryptedValue
    • CardMerchant
    • CardWebhookType
    • CardWebhookPayload
    • CardIssuedWebhookPayload
    • CardIssuanceFailedWebhookPayload
    • CardStateChangedWebhookPayload
    • CardTransactionAuthorizedWebhookPayload
    • CardTransactionCompletedWebhookPayload
    • CardTransactionReversedWebhookPayload
GuidesBaaS API Reference
Bank Client API Reference
GuidesBaaS API Reference
Bank Client API Reference
  1. Cards

Reveal card details

POST
/baas/Cards/{id}/encrypted-details
Early access - contact your account manager to enable card issuing for your platform.
Returns sensitive card data encrypted with your session key: the full card number and CVC for operation = cardDetails, or the PIN for operation = pin.
Each value is AES-GCM ciphertext (data) with its initialization vector (iv), both base64-encoded. Decrypt them on the cardholder's device with the session key from POST /baas/Cards/{id}/encrypted-envelope, and never store or log the decrypted values.
Errors: 400 Bad Request if the encrypted session key is invalid or the envelope has expired; 404 Not Found if the card does not exist; 422 Unprocessable Content if the card is not active or frozen.

Request

Authorization
JWT Bearer
Add the parameter
Authorization
to Headers
Example:
Authorization: ********************
or
Path Params

Body Params application/json

Example
{
    "protocol": "string",
    "encryptedSessionKey": "string",
    "operation": "cardDetails"
}

Request Code Samples

Shell
JavaScript
Java
Swift
Go
PHP
Python
HTTP
C
C#
Objective-C
Ruby
OCaml
Dart
R
Request Request Example
Shell
JavaScript
Java
Swift
curl --location 'https://my.test-1.account.finlego.com/api/child-brand-integration/baas/Cards//encrypted-details' \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{
    "protocol": "string",
    "encryptedSessionKey": "string",
    "operation": "cardDetails"
}'

Responses

🟢200OK
application/json
OK
Bodyapplication/json

Example
{
    "operation": "cardDetails",
    "pan": {
        "iv": "q3Jd2fX0bP1k9sLw",
        "data": "N2Y4ZTFhYzQ5ZDJiM2M1ZTZmN2E4YjljMGQxZTJmM2E="
    },
    "cvc": {
        "iv": "q3Jd2fX0bP1k9sLw",
        "data": "N2Y4ZTFhYzQ5ZDJiM2M1ZTZmN2E4YjljMGQxZTJmM2E="
    },
    "pin": {
        "iv": "q3Jd2fX0bP1k9sLw",
        "data": "N2Y4ZTFhYzQ5ZDJiM2M1ZTZmN2E4YjljMGQxZTJmM2E="
    }
}
🟠400Bad Request
🟠404Record Not Found
🟠422Parameter Error
🔴500Server Error
Modified at 2026-09-29 11:12:37
Previous
Create encryption envelope
Next
Set PIN
Built with