Skip to main content
POST
Detokenize records and aliases

Authorizations

Authorization
string
header
required

You can use an OAuth2 JWT bearer token in the Authorization header of your API requests for supported endpoints: Authorization: Bearer <YOUR_JWT_HERE>. These tokens are short-lived (the exact lifetime is returned in expires_in) and can be requested via the vault access token endpoint. They are accepted only on the Payrails Vault host and grant access to the tokenization and detokenization endpoints.

Body

application/json

Items to detokenize.

items
(Record by ID. · object | Record by alias. · object | Field by alias. · object)[]
required

Items to reveal. A request holds at least 1 and at most 50 items. Records and aliases can be mixed in one request, and the same record or alias may be addressed by more than one item - each item gets its own result, and the record is revealed once however many items ask for it.

Required array length: 1 - 50 elements

A single item to reveal, addressed by exactly one key. The three addressing modes mirror the record retrieval endpoints: a whole record by its identifier, a whole record by the alias of one of its fields, or a single field by its alias.

Response

Detokenization completed. Check per-item errors in the response.

items
(Record. · object | Field by alias. · object | Failed item. · object)[]
required

One entry per requested item. The order in which items are returned may not match the order in which you passed them. An item that cannot be resolved carries an error and does not fail the rest of the request.

Result for a single requested item. It carries either the revealed data or an error, never both.

A record addressed by alias comes back the same way as a record addressed by its identifier: the alias it was addressed by appears among the fields of the record.

Last modified on October 7, 2026