Skip to main content
GET
Get field details by alias list

Authorizations

Authorization
string
header
required

You can use an OAuth2 JWT bearer token in the Authorization header of your API requests for supported endpoints: Authorization: Bearer <YOUR_JWT_HERE>. These tokens are valid for 10 minutes and can be requested via the access token endpoint endpoint.

Query Parameters

aliases
string
required

Comma-separated aliases of fields in Payrails Vault. There should be at least one alias provided and in one call you can provide up to 10 aliases.

includeVolatileInfo
boolean
default:false

Boolean indicating if additional information regarding volatile fields should be included in the response.

includeDetokenizations
boolean
default:false

Boolean indicating if additional information regarding performed detokenization attempts should be returned.

Response

Array of Field objects.

alias
string

Merchant-facing unique alias for the field. Used as an identifier.

recordId
string

Identifier of the record to which the alias belongs.

recordType
string

Record type to which this field belongs, e.g. card and networkToken.

fieldType
string

Field type of the alias, e.g. cardNumber, expiryMonth, expiryYear, securityCode, holderName, networkToken, cryptogram.

displayableValue
string | null

Displayable value for the field.

allowedDetokenizationCount
integer | null

It will be restricted if used on a proxy and reaches the limit mentioned in this field.

Example:

0

allowedSdkRevealCount
integer | null

It will be restricted if used on a SDK reveal and reaches the limit mentioned in this field.

Example:

0

hasValue
boolean | null

Indicates whether the volatile field has a value associated with it. If false or not present, the field has been deleted or was never set.

maximumExpirationDate
string<date-time> | null

The maximum expiration date for the volatile field value. After this date, the field value will be deleted. Please note that depending on usage of volatile field, value can be deleted even earlier, for example if allowed detokenization or reveal counts are exceeded, or when you explicitly call delete operation on the field.

Example:

"2024-12-31T23:59:59Z"

detokenizations
Detokenization attempts. · object[] | null

List of detokenization attempts performed on this field. This field is returned only when requested via includeDetokenizations query parameter.

Last modified on October 1, 2026