Skip to main content
Use this endpoint only when the cardholder explicitly asks to see their full card number and CVV. Ordinary card reads and card lists return masked details instead. With a live API key, Numero retrieves the sensitive details from the issuer. With a test_key_ API key, Numero returns simulated test-card details; no real card credentials are returned. Both modes use https://api.usenumero.com/numeroaccount/api/v1. A card reference belongs to its business and mode: a test key cannot reveal a live card, and a live key cannot reveal a test card. Sensitive — Numero does not persist the full PAN or CVV in the card record. Make the signed request from your server, keep both keys out of browser code, and expose the returned details only to the authorised cardholder. Never write the response to logs, analytics, persistent browser storage or screenshots.
Card endpoints use the same base URL and API key as the rest of the API, and are signature-gated: send X-Numero-Signature and X-Numero-Signature-Version: v2 as well. See Request signing.

Endpoint

Signature required: Yes

Headers

Path parameters

Request body and signature

This endpoint has no request body. Send zero body bytes and compute the v2 signature over the empty string, using the raw UTF-8 bytes of your signing Public Key. Do not sign {} and then send an empty body; those bytes do not match. The API key identifies the business and selects test or live mode; the Public Key is the separate signing secret.

Request example

Response

The response above is illustrative test data. Treat nullable fields as unavailable; never invent a missing number, CVV, expiry or name. A pending card returns an error while issuance is still processing. If the issuer cannot reveal the card, handle the returned error instead of showing partial credentials.

Server-side example

Use the matching API key and Public Key for the selected mode. NUMERO_CARD_REFERENCE must be the Numero cardReference returned by issuance or the card list, not an issuer card ID.

Display and lifecycle

  • Start masked and reveal only after an explicit action.
  • Offer a Hide action and clear details when the user leaves the view or signs out.
  • The Numero dashboard additionally hides details after 30 seconds or when the window loses focus. Your API integration implements its own display timeout; the API response does not enforce a 30-second expiry.
  • Revealing a card does not fund it, unfreeze it or change its balance.