import { createHmac } from "node:crypto";
const apiKey = process.env.NUMERO_API_KEY;
const publicKey = process.env.NUMERO_PUBLIC_KEY;
const reference = process.env.NUMERO_CARD_REFERENCE;
if (!apiKey || !publicKey || !reference) throw new Error("Card API configuration is missing");
const signature = createHmac("sha256", Buffer.from(publicKey, "utf8"))
.update("")
.digest("base64");
const response = await fetch(
`https://api.usenumero.com/numeroaccount/api/v1/business/card/${encodeURIComponent(reference)}/reveal`,
{
method: "POST",
cache: "no-store",
headers: {
"X-Numero-Api-Key": apiKey,
"X-Numero-Signature": signature,
"X-Numero-Signature-Version": "v2"
}
}
);
if (!response.ok) throw new Error("Card reveal request failed");
const result = await response.json();
if (result.error || !result.data?.pan || !result.data?.cvv)
throw new Error("Complete card details are unavailable");
// Display result.data only in the authorised cardholder's temporary reveal view.
// Never console.log(result), persist it, or send it to analytics.