Retrieve encrypted card secrets
curl --request POST \
--url https://api.machines.cash/partner/v1/cards/{cardId}/secrets \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"sessionId": "<string>"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({sessionId: '<string>'})
};
fetch('https://api.machines.cash/partner/v1/cards/{cardId}/secrets', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.machines.cash/partner/v1/cards/{cardId}/secrets"
payload = { "sessionId": "<string>" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"ok": true,
"data": {
"encryptedPan": {
"data": "<string>",
"iv": "<string>"
},
"encryptedCvc": {
"data": "<string>",
"iv": "<string>"
},
"expirationMonth": 123,
"expirationYear": 123,
"last4": "<string>",
"brand": "<string>",
"keyId": "<string>"
},
"summary": "<string>",
"errors": [
{
"code": "invalid_request",
"message": "missing required field",
"field": "<string>"
}
],
"next": {
"pollAfterMs": 1,
"suggestedTool": "<string>",
"suggestedArgs": {}
}
}{
"ok": false,
"summary": "invalid request",
"errors": [
{
"code": "invalid_request",
"message": "missing required field",
"field": "<string>"
}
],
"next": {
"pollAfterMs": 1,
"suggestedTool": "<string>",
"suggestedArgs": {}
}
}{
"ok": false,
"summary": "invalid request",
"errors": [
{
"code": "invalid_request",
"message": "missing required field",
"field": "<string>"
}
],
"next": {
"pollAfterMs": 1,
"suggestedTool": "<string>",
"suggestedArgs": {}
}
}{
"ok": false,
"summary": "invalid request",
"errors": [
{
"code": "invalid_request",
"message": "missing required field",
"field": "<string>"
}
],
"next": {
"pollAfterMs": 1,
"suggestedTool": "<string>",
"suggestedArgs": {}
}
}{
"ok": false,
"summary": "invalid request",
"errors": [
{
"code": "invalid_request",
"message": "missing required field",
"field": "<string>"
}
],
"next": {
"pollAfterMs": 1,
"suggestedTool": "<string>",
"suggestedArgs": {}
}
}Cards API
Retrieve encrypted card secrets
Requires a secrets sessionId and cards.secrets.read scope.
POST
/
partner
/
v1
/
cards
/
{cardId}
/
secrets
Retrieve encrypted card secrets
curl --request POST \
--url https://api.machines.cash/partner/v1/cards/{cardId}/secrets \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"sessionId": "<string>"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({sessionId: '<string>'})
};
fetch('https://api.machines.cash/partner/v1/cards/{cardId}/secrets', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.machines.cash/partner/v1/cards/{cardId}/secrets"
payload = { "sessionId": "<string>" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"ok": true,
"data": {
"encryptedPan": {
"data": "<string>",
"iv": "<string>"
},
"encryptedCvc": {
"data": "<string>",
"iv": "<string>"
},
"expirationMonth": 123,
"expirationYear": 123,
"last4": "<string>",
"brand": "<string>",
"keyId": "<string>"
},
"summary": "<string>",
"errors": [
{
"code": "invalid_request",
"message": "missing required field",
"field": "<string>"
}
],
"next": {
"pollAfterMs": 1,
"suggestedTool": "<string>",
"suggestedArgs": {}
}
}{
"ok": false,
"summary": "invalid request",
"errors": [
{
"code": "invalid_request",
"message": "missing required field",
"field": "<string>"
}
],
"next": {
"pollAfterMs": 1,
"suggestedTool": "<string>",
"suggestedArgs": {}
}
}{
"ok": false,
"summary": "invalid request",
"errors": [
{
"code": "invalid_request",
"message": "missing required field",
"field": "<string>"
}
],
"next": {
"pollAfterMs": 1,
"suggestedTool": "<string>",
"suggestedArgs": {}
}
}{
"ok": false,
"summary": "invalid request",
"errors": [
{
"code": "invalid_request",
"message": "missing required field",
"field": "<string>"
}
],
"next": {
"pollAfterMs": 1,
"suggestedTool": "<string>",
"suggestedArgs": {}
}
}{
"ok": false,
"summary": "invalid request",
"errors": [
{
"code": "invalid_request",
"message": "missing required field",
"field": "<string>"
}
],
"next": {
"pollAfterMs": 1,
"suggestedTool": "<string>",
"suggestedArgs": {}
}
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Headers
Return Open Responses-compatible output when set (replaces the default response envelope).
Available options:
1, true Tool call id used for function_call_output items when Open Responses mode is enabled.
Minimum string length:
1Path Parameters
Machines card id.
Minimum string length:
8Body
application/json
SessionId returned from the secrets session helper.