Detokenize records and aliases
Reveal data stored in the Payrails Vault. An item is addressed by record identifier, by record alias, or by field alias, and a single request can mix all three.
The response returns one entry per requested item. Match a result to what you sent by the keys it carries rather than by its position - a failed item echoes the key it was addressed by. An item that cannot be resolved carries an error and does not fail the rest of the request:
request.not-found: nothing matches the key the item was addressed by. Thedetailsays which key that was -recordId,recordAliasoralias.vault.field.not-available: the field holds no value that can be revealed - it was never given one, it expired out of volatile storage, or it reached the number of reveals allowed for it. A record addressed byrecordIdorrecordAliasreports this only when none of its fields could be revealed; otherwise it comes back with the fields that could.
A request holds at most 50 items. One carrying more is rejected with 413 and nothing is revealed.
Every reveal counts against what the field is allowed, so a record addressed by several items of one request is revealed once - repeating an item costs no more of that allowance than asking once does.
This endpoint is served on the Payrails Vault host and accepts a Vault access token. It is available by request and requires an approval by Payrails.
Authorizations
You can use an OAuth2 JWT bearer token in the Authorization header of your API requests for supported endpoints: Authorization: Bearer <YOUR_JWT_HERE>.
These tokens are short-lived (the exact lifetime is returned in expires_in) and can be requested via the vault access token endpoint.
They are accepted only on the Payrails Vault host and grant access to the tokenization and detokenization endpoints.
Body
Items to detokenize.
Items to reveal. A request holds at least 1 and at most 50 items. Records and aliases can be mixed in one request, and the same record or alias may be addressed by more than one item - each item gets its own result, and the record is revealed once however many items ask for it.
1 - 50 elementsA single item to reveal, addressed by exactly one key. The three addressing modes mirror the record retrieval endpoints: a whole record by its identifier, a whole record by the alias of one of its fields, or a single field by its alias.
- Record by ID.
- Record by alias.
- Field by alias.
Response
Detokenization completed. Check per-item errors in the response.
One entry per requested item. The order in which items are returned may not match the order in which you passed them. An item that cannot be resolved carries an error and does not fail the rest of the request.
Result for a single requested item. It carries either the revealed data or an error, never both.
A record addressed by alias comes back the same way as a record addressed by its identifier: the alias it was addressed by appears among the fields of the record.
- Record.
- Field by alias.
- Failed item.