curl --request GET \
--url https://api.staging.payrails.io/payment/instruments \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.staging.payrails.io/payment/instruments"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.staging.payrails.io/payment/instruments', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.staging.payrails.io/payment/instruments",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.staging.payrails.io/payment/instruments"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.staging.payrails.io/payment/instruments")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.staging.payrails.io/payment/instruments")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"paging": {
"next": "?createdAtOrAfter=2022-02-11+00%3A00%3A00&createdAtOrBefore=2022-02-11+20%3A17%3A52.885&limit=50&pagingIdBefore=payment-acceptance%2Fa43c3080-7357-582b-bed3-7f68606c708b"
},
"results": [
{
"id": "b8fe6271-5d71-4d28-b8e8-89e64acc0c49",
"holderId": "788c7c09-a490-4603-915a-e2a957a6cca1",
"createdAt": "2022-04-22T17:53:36.814Z",
"updatedAt": "2022-04-22T17:53:36.814Z",
"paymentMethod": "card",
"displayName": "Visa **** 1111",
"description": "Personal card.",
"merchantReference": "ref_C47C47",
"fingerprint": "739abff0-406a-4d32-8cfb-701e12be5848",
"status": "created",
"futureUsage": "CardOnFile",
"networkTransactionReference": "987654321234567",
"data": {
"network": "visa",
"bin": "411111",
"suffix": "1111",
"expiryMonth": "10",
"expiryYear": "2026",
"holderName": "John Doe",
"billingAddress": {
"country": {
"code": "DE",
"name": "Germany"
},
"postalCode": "10117"
}
}
},
{
"id": "b8fe6271-5d71-4d28-b8e8-89e64acc0c49",
"holderId": "788c7c09-a490-4603-915a-e2a957a6cca1",
"createdAt": "2022-04-22T17:53:36.814Z",
"updatedAt": "2022-04-22T17:53:36.814Z",
"paymentMethod": "bankAccount",
"description": "Personal bank account.",
"merchantReference": "ref_C47C47",
"fingerprint": "739abff0-406a-4d32-8cfb-701e12be5848",
"status": "created",
"data": {
"holder": {
"firstName": "John",
"lastName": "Doe",
"companyName": "ABC Corp",
"address": {
"streetName": "Example St",
"streetNumber": "123",
"postalCode": "12345",
"city": "Anytown",
"stateOrProvince": "CA",
"country": "US"
},
"email": "john.doe@example.com",
"dob": "1990-01-15",
"country": {
"code": "US",
"name": "United States"
},
"city": "New York",
"type": "personal"
},
"bank": {
"name": "Example Bank",
"branchCode": "1234",
"code": "56789",
"address": {
"streetName": "Bank St",
"streetNumber": "5",
"postalCode": "98765",
"city": "Banktown",
"stateOrProvince": "NY",
"country": "US"
},
"swiftCode": "EXABUS33XXX",
"country": {
"code": "US",
"name": "United States"
}
},
"account": {
"number": "1234567890",
"iban": "US123456789012345678901234567890",
"currency": "USD",
"type": "savings"
}
}
}
]
}{
"errors": [
{
"id": "a24bc325-3929-4d9d-9c08-b3aa532685b7",
"code": "request.malformed",
"detail": "The request has malformed syntax",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestmalformed"
}
]
}{
"errors": [
{
"id": "a24bc325-3929-4d9d-9c08-b3aa532685b7",
"code": "request.unauthorized",
"detail": "The request lacks necessary credentials to perform the specified action",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestunauthorized"
}
]
}{
"errors": [
{
"id": "e7db22b3-914e-4975-928e-9edfb0885bea",
"code": "request.forbidden",
"detail": "The request credentials lack the required permissions to perform the specified action",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestforbidden"
}
]
}{
"errors": [
{
"id": "a24bc325-3929-4d9d-9c08-b3aa532685b7",
"code": "request.rate-limit",
"detail": "Too many requests",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestrate-limit"
}
]
}Search & list instruments
Fetch a list of payment instruments for the given query parameters.
curl --request GET \
--url https://api.staging.payrails.io/payment/instruments \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.staging.payrails.io/payment/instruments"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.staging.payrails.io/payment/instruments', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.staging.payrails.io/payment/instruments",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.staging.payrails.io/payment/instruments"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.staging.payrails.io/payment/instruments")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.staging.payrails.io/payment/instruments")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"paging": {
"next": "?createdAtOrAfter=2022-02-11+00%3A00%3A00&createdAtOrBefore=2022-02-11+20%3A17%3A52.885&limit=50&pagingIdBefore=payment-acceptance%2Fa43c3080-7357-582b-bed3-7f68606c708b"
},
"results": [
{
"id": "b8fe6271-5d71-4d28-b8e8-89e64acc0c49",
"holderId": "788c7c09-a490-4603-915a-e2a957a6cca1",
"createdAt": "2022-04-22T17:53:36.814Z",
"updatedAt": "2022-04-22T17:53:36.814Z",
"paymentMethod": "card",
"displayName": "Visa **** 1111",
"description": "Personal card.",
"merchantReference": "ref_C47C47",
"fingerprint": "739abff0-406a-4d32-8cfb-701e12be5848",
"status": "created",
"futureUsage": "CardOnFile",
"networkTransactionReference": "987654321234567",
"data": {
"network": "visa",
"bin": "411111",
"suffix": "1111",
"expiryMonth": "10",
"expiryYear": "2026",
"holderName": "John Doe",
"billingAddress": {
"country": {
"code": "DE",
"name": "Germany"
},
"postalCode": "10117"
}
}
},
{
"id": "b8fe6271-5d71-4d28-b8e8-89e64acc0c49",
"holderId": "788c7c09-a490-4603-915a-e2a957a6cca1",
"createdAt": "2022-04-22T17:53:36.814Z",
"updatedAt": "2022-04-22T17:53:36.814Z",
"paymentMethod": "bankAccount",
"description": "Personal bank account.",
"merchantReference": "ref_C47C47",
"fingerprint": "739abff0-406a-4d32-8cfb-701e12be5848",
"status": "created",
"data": {
"holder": {
"firstName": "John",
"lastName": "Doe",
"companyName": "ABC Corp",
"address": {
"streetName": "Example St",
"streetNumber": "123",
"postalCode": "12345",
"city": "Anytown",
"stateOrProvince": "CA",
"country": "US"
},
"email": "john.doe@example.com",
"dob": "1990-01-15",
"country": {
"code": "US",
"name": "United States"
},
"city": "New York",
"type": "personal"
},
"bank": {
"name": "Example Bank",
"branchCode": "1234",
"code": "56789",
"address": {
"streetName": "Bank St",
"streetNumber": "5",
"postalCode": "98765",
"city": "Banktown",
"stateOrProvince": "NY",
"country": "US"
},
"swiftCode": "EXABUS33XXX",
"country": {
"code": "US",
"name": "United States"
}
},
"account": {
"number": "1234567890",
"iban": "US123456789012345678901234567890",
"currency": "USD",
"type": "savings"
}
}
}
]
}{
"errors": [
{
"id": "a24bc325-3929-4d9d-9c08-b3aa532685b7",
"code": "request.malformed",
"detail": "The request has malformed syntax",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestmalformed"
}
]
}{
"errors": [
{
"id": "a24bc325-3929-4d9d-9c08-b3aa532685b7",
"code": "request.unauthorized",
"detail": "The request lacks necessary credentials to perform the specified action",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestunauthorized"
}
]
}{
"errors": [
{
"id": "e7db22b3-914e-4975-928e-9edfb0885bea",
"code": "request.forbidden",
"detail": "The request credentials lack the required permissions to perform the specified action",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestforbidden"
}
]
}{
"errors": [
{
"id": "a24bc325-3929-4d9d-9c08-b3aa532685b7",
"code": "request.rate-limit",
"detail": "Too many requests",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestrate-limit"
}
]
}Authorizations
You can use an OAuth2 JWT bearer token in the Authorization header of your API requests for supported endpoints: Authorization: Bearer <YOUR_JWT_HERE>.
These tokens are valid for 10 minutes and can be requested via the access token endpoint endpoint.
Query Parameters
Boolean indicating if the holder reference should be included in the response.
Filter for a list of instruments by holder reference.
Filter for a list of instruments by holder id.
Filter for a list of instruments by latest instruments status.
Filter for a list of instruments only ones with tokens.
Filter for a list of instruments by token type.
Filter for a list of instruments by token status.
Filter for a list of instruments by future usage.
Filter for a list of instruments by BIN.
Filter for a list of instruments by suffix.
Filter for a list of instruments by card network.
Filter for a list of instruments by issuer.
Filter for a list of instruments by country name.
Filter for a list of instruments by payment method.
Filter by createdAt field using interval notation.
1973-02-03T04:32:11.596Z - exact date value
(1973-02-03T04:32:11.596Z - after the date excluding it
[1973-02-03T04:32:11.596Z - after the date including it
1973-02-03T04:32:11.596Z) - before the date excluding it
1973-02-03T04:32:11.596Z] - before the date including it
(1973-02-03T04:32:11.596Z,1973-04-03T03:20:11.436Z) - between two dates excluding both
(1973-02-03T04:32:11.596Z,1973-04-03T03:20:11.436Z] - between two dates excluding on the left
[1973-02-03T04:32:11.596Z,1973-04-03T03:20:11.436Z) - between two dates excluding on the right
[1973-02-03T04:32:11.596Z,1973-04-03T03:20:11.436Z] - between two dates including both.
"[2026-04-01T00:00:00Z,2026-05-01T00:00:00Z)"
Search collection items from that cursor. Cursor for paging results.
Search collection items after that cursor. Cursor for paging results.
Search collection items before that cursor. Cursor for paging results.
Length of the collection to search.
Response
Success.
List of results for the query.
Hide child attributes
Hide child attributes
Id of the instrument.
Date and time when the Instrument was created in Payrails.
When the Instrument was last updated.
Unique identifier of the Holder in Payrails.
Represents the payment method type.
alexBankMa7fazty, applePay, audi2pay, bankAccount, card, 2c2p, vietQR, cibSmartWallet, easypaisa, etisalatCash, fawryMobileWallet, fawryPay, googlePay, jazzCash, nbePhoneCash, orangeCash, payPal, qnbEWallet, weCash, genericRedirect, alfa, konnect, eftPro, netBanking, upi, cashFreeWallet, paytmWallet, phonePe, iDeal, bancontact, klarnaPayLater, klarnaPayNow, klarnaPayOverTime, scalapay Status of the instrument.
created, deleted, enabled, disabled, transient Instrument name suitable for display.
Description of the instrument.
True if this instrument is set as default for the holder.
Merchant-provided reference for the instrument.
System-wide unique identifier of the Instrument. If two Holders have the same instrument stored, this value will be the same for both, but the instrument and token IDs will be different. Cannot be used for payments, should only be used for analytics and fraud prevention.
Represents the future usage to define the payment flows that the stored instrument will be used for.
Subscription, CardOnFile, UnscheduledCardOnFile Identifier of the initial payment made with this instrument on the Networks, e.g. Mastercard Trace ID or Visa Transaction ID.
Mastercard Transaction Link Identifier (TLID) of the transaction series this instrument belongs to. Returned by the card network on the initial cardholder-initiated transaction and required on economically related merchant-initiated transactions, such as recurring payments and installments, when the series spans payment providers.
Type-specific information about the instrument.
- Card
- BankAccount
- PayPal
- GooglePay
- ApplePay
- DCB
- MBWay
Hide child attributes
Hide child attributes
Network of the instrument.
unspecified, visa, visadankort, mastercard, amex, diners, discover, unionpay, unionpayuzcard, maestro, maestrobancontact, hipercard, jcb, jcblankapay, argencard, aura, belkart, bpfuelcard, cabal, carnet, cirrus, chjonesfuelcard, uzcard, codensa, dankort, dinacard, duet, ebt, eftpos, elo, euroshellfuelcard, gecapital, bc, hrgstore, humo, lankapay, lukoilfuelcard, bancontact, meeza, newday, mir, ourocard, pagobancomat, paypak, paypal, phhfuelcard, prostir, rupay, sbercard, sodexo, starrewards, cencosud, naranja, troy, uatp, ukfuelcard, verve, voyager, vpay, wex, cmi, atm, bankcard, localbrand, loyalty, privatelabel, fuelcard, redfuelcard, redliquidfuelcard First 6-8 digits of the Card number. Also known as IIN (Issuer Identification Number).
6 - 8"416598"
Last digits of the Card number.
4Network of the instrument.
unspecified, visa, visadankort, mastercard, amex, diners, discover, unionpay, unionpayuzcard, maestro, maestrobancontact, hipercard, jcb, jcblankapay, argencard, aura, belkart, bpfuelcard, cabal, carnet, cirrus, chjonesfuelcard, uzcard, codensa, dankort, dinacard, duet, ebt, eftpos, elo, euroshellfuelcard, gecapital, bc, hrgstore, humo, lankapay, lukoilfuelcard, bancontact, meeza, newday, mir, ourocard, pagobancomat, paypak, paypal, phhfuelcard, prostir, rupay, sbercard, sodexo, starrewards, cencosud, naranja, troy, uatp, ukfuelcard, verve, voyager, vpay, wex, cmi, atm, bankcard, localbrand, loyalty, privatelabel, fuelcard, redfuelcard, redliquidfuelcard Information about an issuer by the given BIN (or IIN).
Hide child attributes
Hide child attributes
First 6-8 digits of the Card number. Also known as IIN (Issuer Identification Number).
6 - 8"416598"
Network of the instrument.
unspecified, visa, visadankort, mastercard, amex, diners, discover, unionpay, unionpayuzcard, maestro, maestrobancontact, hipercard, jcb, jcblankapay, argencard, aura, belkart, bpfuelcard, cabal, carnet, cirrus, chjonesfuelcard, uzcard, codensa, dankort, dinacard, duet, ebt, eftpos, elo, euroshellfuelcard, gecapital, bc, hrgstore, humo, lankapay, lukoilfuelcard, bancontact, meeza, newday, mir, ourocard, pagobancomat, paypak, paypal, phhfuelcard, prostir, rupay, sbercard, sodexo, starrewards, cencosud, naranja, troy, uatp, ukfuelcard, verve, voyager, vpay, wex, cmi, atm, bankcard, localbrand, loyalty, privatelabel, fuelcard, redfuelcard, redliquidfuelcard Card local network that supports the card, e.g. CartesBancaires, Dankort, Mada, Bancontact.
bancontact, cartesbancaires, dankort, mada Name of the bank or institution that issued the card.
Country of the bank or institution that issued the card.
Hide child attributes
Hide child attributes
ISO 3166-1 alpha-2 country code.
^[A-Z]{2}$ISO 3-letter country code. Returned by Payrails, but not interpreted in requests.
^[A-Z]{3}$The English name of the country. Returned by Payrails, but not interpreted in requests.
Segment of the card, e.g. gold, black, business.
Type of the card, e.g. credit, debit, prepaid, gift.
More information about the card type, e.g. personal, commercial.
Indicates whether the card credential represents a network token rather than a primary account number (PAN).
Indicates whether the card is enrolled in a Flexible Credential or Flex Card program supported by the network - e.g. Visa Flexible Credential, Mastercard FlexCard.
Billing Address of the instrument.
Hide child attributes
Hide child attributes
The name of the street of a postal address.
The number on the door, building, or room.
Additional addressing information, 2nd line of postal address.
The name of the suburb or area within a city.
The name of the city of a postal address.
The postal code.
The name of the state a postal address is in.
The country where the address is in.
Hide child attributes
Hide child attributes
ISO 3166-1 alpha-2 country code.
^[A-Z]{2}$ISO 3-letter country code. Returned by Payrails, but not interpreted in requests.
^[A-Z]{3}$The English name of the country. Returned by Payrails, but not interpreted in requests.
Latitude of the address in the GPS coordinate system.
Longitude of the address in the GPS coordinate system.
The phone to contact in the address (can be different that the customer's).
Name of the address, e.g. home, work.
Name of the person to whom the address belongs to.
Last name of the person to whom the address belongs to.
Email of the person to whom the address belongs to.
Expiry month of the Card.
2Expiry year of the Card.
4Name of the owner of the Card.
Payer-provided tax identification number (e.g. CPF in Brazil) collected on the instrument.
List of tokens inside the instrument. Not included by default, includeTokens query parameter must be used.
Hide child attributes
Hide child attributes
Id of the token in Payrails.
Date and time when the Token was created in Payrails.
When the Token was last updated.
Id of the payment instrument the token belongs to.
Status of the token.
created, enabled, disabled, deleted Type of the token.
network, vault, psp, networkOffers, networkGateway Id of the provider the token belongs to.
Unique identifier of the token in the provider's system.
Id of the configuration in the provider the token belongs to.
Any merchant or provider-specific data that should be stored for context in the token.