curl --request GET \
--url https://api.staging.payrails.io/token/records/{recordId} \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.staging.payrails.io/token/records/{recordId}"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.staging.payrails.io/token/records/{recordId}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.staging.payrails.io/token/records/{recordId}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.staging.payrails.io/token/records/{recordId}"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.staging.payrails.io/token/records/{recordId}")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.staging.payrails.io/token/records/{recordId}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"type": "<string>",
"fingerprint": "<string>",
"fields": [
{
"alias": "<string>",
"recordId": "<string>",
"recordType": "<string>",
"fieldType": "<string>",
"displayableValue": "<string>",
"allowedDetokenizationCount": 0,
"allowedSdkRevealCount": 0,
"hasValue": true,
"maximumExpirationDate": "2024-12-31T23:59:59Z",
"detokenizations": [
{
"lastAttemptedAt": "2024-01-01T12:00:00Z",
"count": 1,
"type": "detokenization"
}
]
}
]
}{
"errors": [
{
"id": "a24bc325-3929-4d9d-9c08-b3aa532685b7",
"code": "request.unauthorized",
"detail": "The request lacks necessary credentials to perform the specified action",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestunauthorized"
}
]
}{
"errors": [
{
"id": "e7db22b3-914e-4975-928e-9edfb0885bea",
"code": "request.forbidden",
"detail": "The request credentials lack the required permissions to perform the specified action",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestforbidden"
}
]
}{
"errors": [
{
"id": "a24bc325-3929-4d9d-9c08-b3aa532685b7",
"code": "request.not-found",
"detail": "The requested resource was not found",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestnot-found"
}
]
}{
"errors": [
{
"id": "07a1d642-dbf5-47d3-8563-700514b38e46",
"code": "request.header.missing",
"detail": "The request is missing a required header",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestheadermissing"
}
]
}Get record and its fields by ID
Get a record and all fields associated with the record by the given ID.
curl --request GET \
--url https://api.staging.payrails.io/token/records/{recordId} \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.staging.payrails.io/token/records/{recordId}"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.staging.payrails.io/token/records/{recordId}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.staging.payrails.io/token/records/{recordId}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.staging.payrails.io/token/records/{recordId}"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.staging.payrails.io/token/records/{recordId}")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.staging.payrails.io/token/records/{recordId}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"type": "<string>",
"fingerprint": "<string>",
"fields": [
{
"alias": "<string>",
"recordId": "<string>",
"recordType": "<string>",
"fieldType": "<string>",
"displayableValue": "<string>",
"allowedDetokenizationCount": 0,
"allowedSdkRevealCount": 0,
"hasValue": true,
"maximumExpirationDate": "2024-12-31T23:59:59Z",
"detokenizations": [
{
"lastAttemptedAt": "2024-01-01T12:00:00Z",
"count": 1,
"type": "detokenization"
}
]
}
]
}{
"errors": [
{
"id": "a24bc325-3929-4d9d-9c08-b3aa532685b7",
"code": "request.unauthorized",
"detail": "The request lacks necessary credentials to perform the specified action",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestunauthorized"
}
]
}{
"errors": [
{
"id": "e7db22b3-914e-4975-928e-9edfb0885bea",
"code": "request.forbidden",
"detail": "The request credentials lack the required permissions to perform the specified action",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestforbidden"
}
]
}{
"errors": [
{
"id": "a24bc325-3929-4d9d-9c08-b3aa532685b7",
"code": "request.not-found",
"detail": "The requested resource was not found",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestnot-found"
}
]
}{
"errors": [
{
"id": "07a1d642-dbf5-47d3-8563-700514b38e46",
"code": "request.header.missing",
"detail": "The request is missing a required header",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestheadermissing"
}
]
}Authorizations
You can use an OAuth2 JWT bearer token in the Authorization header of your API requests for supported endpoints: Authorization: Bearer <YOUR_JWT_HERE>.
These tokens are valid for 10 minutes and can be requested via the access token endpoint endpoint.
Path Parameters
Identifier of the resource in Payrails.
Query Parameters
Boolean indicating if additional information regarding volatile fields should be included in the response.
Boolean indicating if additional information regarding performed detokenization attempts should be returned.
Response
Record and its fields.
Payrails unique identifier of the record.
Type of this record, e.g. card or networkToken.
The fingerprint of the record. Depending on type can be used to match with other records.
Fields belong to this record.
Hide child attributes
Hide child attributes
Merchant-facing unique alias for the field. Used as an identifier.
Identifier of the record to which the alias belongs.
Record type to which this field belongs, e.g. card and networkToken.
Field type of the alias, e.g. cardNumber, expiryMonth,
expiryYear, securityCode, holderName, networkToken, cryptogram.
Displayable value for the field.
It will be restricted if used on a proxy and reaches the limit mentioned in this field.
0
It will be restricted if used on a SDK reveal and reaches the limit mentioned in this field.
0
Indicates whether the volatile field has a value associated with it. If false or not present, the field has been deleted or was never set.
The maximum expiration date for the volatile field value. After this date, the field value will be deleted. Please note that depending on usage of volatile field, value can be deleted even earlier, for example if allowed detokenization or reveal counts are exceeded, or when you explicitly call delete operation on the field.
"2024-12-31T23:59:59Z"
List of detokenization attempts performed on this field. This field is returned only when requested via includeDetokenizations query parameter.
Hide child attributes
Hide child attributes
Timestamp when the detokenization was attempted.
"2024-01-01T12:00:00Z"
Number of times this type of detokenization was successfully performed.
1
Type of detokenization attempt. detokenization indicates a standard detokenization, while sdkReveal indicates a detokenization performed via SDK reveal.
detokenization, sdkReveal "detokenization"