curl --request GET \
--url https://api.staging.payrails.io/token/instruments/{instrumentId}/records \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.staging.payrails.io/token/instruments/{instrumentId}/records"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.staging.payrails.io/token/instruments/{instrumentId}/records', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.staging.payrails.io/token/instruments/{instrumentId}/records",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.staging.payrails.io/token/instruments/{instrumentId}/records"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.staging.payrails.io/token/instruments/{instrumentId}/records")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.staging.payrails.io/token/instruments/{instrumentId}/records")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"instrumentId": "882da741-c493-491c-9d11-993e4d709f4a",
"records": [
{
"id": "a5e219cd-1707-4dd7-b963-115c382c57e4",
"type": "card",
"fingerprint": "581a61af-d92d-4b7e-bfe4-303bd500d06e",
"fields": [
{
"recordId": "a5e219cd-1707-4dd7-b963-115c382c57e4",
"recordType": "card",
"alias": "0cdedf0b-6ea7-4d7f-9942-0a4ddda0f7fd",
"fieldType": "cardNumber",
"displayableValue": "411111**1111",
"allowedDetokenizationCount": null,
"allowedSdkRevealCount": 0
},
{
"recordId": "a5e219cd-1707-4dd7-b963-115c382c57e4",
"recordType": "card",
"alias": "651e66f1-7c09-4ba2-baef-d29050e6362e",
"fieldType": "expiryMonth",
"displayableValue": "01",
"allowedDetokenizationCount": null,
"allowedSdkRevealCount": 0
},
{
"recordId": "a5e219cd-1707-4dd7-b963-115c382c57e4",
"recordType": "card",
"alias": "5c862e69-22b3-4eaf-92fa-5068813c863f",
"fieldType": "expiryYear",
"displayableValue": "25",
"allowedDetokenizationCount": null,
"allowedSdkRevealCount": 0
},
{
"recordId": "a5e219cd-1707-4dd7-b963-115c382c57e4",
"recordType": "card",
"alias": "52661250-8140-4d92-8b44-bc9a6f17fd48",
"fieldType": "holderName",
"displayableValue": "Foo",
"allowedDetokenizationCount": null,
"allowedSdkRevealCount": 0
},
{
"recordId": "a5e219cd-1707-4dd7-b963-115c382c57e4",
"recordType": "card",
"alias": "db821554-6f4c-4cd8-87d0-f22dd3cdcc40",
"fieldType": "securityCode",
"displayableValue": null,
"allowedDetokenizationCount": 1,
"allowedSdkRevealCount": 0
}
]
},
{
"id": "f1dd67f4-771d-465f-bb2e-bed7e7e8bf39",
"type": "networkToken",
"fingerprint": "581a61af-d92d-4b7e-bfe4-303bd500d06e",
"fields": [
{
"recordId": "f1dd67f4-771d-465f-bb2e-bed7e7e8bf39",
"recordType": "networkToken",
"alias": "88774a64-9bc7-4641-b4b9-4800896a5303",
"fieldType": "cryptogram",
"displayableValue": null,
"allowedDetokenizationCount": 1,
"allowedSdkRevealCount": 0
},
{
"recordId": "f1dd67f4-771d-465f-bb2e-bed7e7e8bf39",
"recordType": "networkToken",
"alias": "ebd69b8d-1e9e-46fc-a197-91d5993b2c89",
"fieldType": "expiryMonth",
"displayableValue": "01",
"allowedDetokenizationCount": null,
"allowedSdkRevealCount": 0
},
{
"recordId": "f1dd67f4-771d-465f-bb2e-bed7e7e8bf39",
"recordType": "networkToken",
"alias": "9322f77c-b093-48e6-a628-bccab0a606dd",
"fieldType": "expiryYear",
"displayableValue": "35",
"allowedDetokenizationCount": null,
"allowedSdkRevealCount": 0
},
{
"recordId": "f1dd67f4-771d-465f-bb2e-bed7e7e8bf39",
"recordType": "networkToken",
"alias": "8fad08c9-1c2b-4f45-9ddc-2d6d53f7033d",
"fieldType": "networkToken",
"displayableValue": "411111**1111",
"allowedDetokenizationCount": null,
"allowedSdkRevealCount": 0
}
]
}
]
}Get record and aliases for a given instrumentId.
Get record, aliases, and all associated fields for a given instrumentId.
curl --request GET \
--url https://api.staging.payrails.io/token/instruments/{instrumentId}/records \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.staging.payrails.io/token/instruments/{instrumentId}/records"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.staging.payrails.io/token/instruments/{instrumentId}/records', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.staging.payrails.io/token/instruments/{instrumentId}/records",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.staging.payrails.io/token/instruments/{instrumentId}/records"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.staging.payrails.io/token/instruments/{instrumentId}/records")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.staging.payrails.io/token/instruments/{instrumentId}/records")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"instrumentId": "882da741-c493-491c-9d11-993e4d709f4a",
"records": [
{
"id": "a5e219cd-1707-4dd7-b963-115c382c57e4",
"type": "card",
"fingerprint": "581a61af-d92d-4b7e-bfe4-303bd500d06e",
"fields": [
{
"recordId": "a5e219cd-1707-4dd7-b963-115c382c57e4",
"recordType": "card",
"alias": "0cdedf0b-6ea7-4d7f-9942-0a4ddda0f7fd",
"fieldType": "cardNumber",
"displayableValue": "411111**1111",
"allowedDetokenizationCount": null,
"allowedSdkRevealCount": 0
},
{
"recordId": "a5e219cd-1707-4dd7-b963-115c382c57e4",
"recordType": "card",
"alias": "651e66f1-7c09-4ba2-baef-d29050e6362e",
"fieldType": "expiryMonth",
"displayableValue": "01",
"allowedDetokenizationCount": null,
"allowedSdkRevealCount": 0
},
{
"recordId": "a5e219cd-1707-4dd7-b963-115c382c57e4",
"recordType": "card",
"alias": "5c862e69-22b3-4eaf-92fa-5068813c863f",
"fieldType": "expiryYear",
"displayableValue": "25",
"allowedDetokenizationCount": null,
"allowedSdkRevealCount": 0
},
{
"recordId": "a5e219cd-1707-4dd7-b963-115c382c57e4",
"recordType": "card",
"alias": "52661250-8140-4d92-8b44-bc9a6f17fd48",
"fieldType": "holderName",
"displayableValue": "Foo",
"allowedDetokenizationCount": null,
"allowedSdkRevealCount": 0
},
{
"recordId": "a5e219cd-1707-4dd7-b963-115c382c57e4",
"recordType": "card",
"alias": "db821554-6f4c-4cd8-87d0-f22dd3cdcc40",
"fieldType": "securityCode",
"displayableValue": null,
"allowedDetokenizationCount": 1,
"allowedSdkRevealCount": 0
}
]
},
{
"id": "f1dd67f4-771d-465f-bb2e-bed7e7e8bf39",
"type": "networkToken",
"fingerprint": "581a61af-d92d-4b7e-bfe4-303bd500d06e",
"fields": [
{
"recordId": "f1dd67f4-771d-465f-bb2e-bed7e7e8bf39",
"recordType": "networkToken",
"alias": "88774a64-9bc7-4641-b4b9-4800896a5303",
"fieldType": "cryptogram",
"displayableValue": null,
"allowedDetokenizationCount": 1,
"allowedSdkRevealCount": 0
},
{
"recordId": "f1dd67f4-771d-465f-bb2e-bed7e7e8bf39",
"recordType": "networkToken",
"alias": "ebd69b8d-1e9e-46fc-a197-91d5993b2c89",
"fieldType": "expiryMonth",
"displayableValue": "01",
"allowedDetokenizationCount": null,
"allowedSdkRevealCount": 0
},
{
"recordId": "f1dd67f4-771d-465f-bb2e-bed7e7e8bf39",
"recordType": "networkToken",
"alias": "9322f77c-b093-48e6-a628-bccab0a606dd",
"fieldType": "expiryYear",
"displayableValue": "35",
"allowedDetokenizationCount": null,
"allowedSdkRevealCount": 0
},
{
"recordId": "f1dd67f4-771d-465f-bb2e-bed7e7e8bf39",
"recordType": "networkToken",
"alias": "8fad08c9-1c2b-4f45-9ddc-2d6d53f7033d",
"fieldType": "networkToken",
"displayableValue": "411111**1111",
"allowedDetokenizationCount": null,
"allowedSdkRevealCount": 0
}
]
}
]
}Authorizations
You can use an OAuth2 JWT bearer token in the Authorization header of your API requests for supported endpoints: Authorization: Bearer <YOUR_JWT_HERE>.
These tokens are valid for 10 minutes and can be requested via the access token endpoint endpoint.
Path Parameters
Identifier of the resource in Payrails.
Query Parameters
Boolean indicating if additional information regarding volatile fields should be included in the response.
Response
Successful retrieval of records and aliases by instrumentId.
Hide child attributes
Hide child attributes
card, networkToken Hide child attributes
Hide child attributes
Merchant-facing unique alias for the field. Used as an identifier.
Identifier of the record to which the alias belongs.
Record type to which this field belongs, e.g. card and networkToken.
Field type of the alias, e.g. cardNumber, expiryMonth,
expiryYear, securityCode, holderName, networkToken, cryptogram.
Displayable value for the field.
It will be restricted if used on a proxy and reaches the limit mentioned in this field.
0
It will be restricted if used on a SDK reveal and reaches the limit mentioned in this field.
0
Indicates whether the volatile field has a value associated with it. If false or not present, the field has been deleted or was never set.
The maximum expiration date for the volatile field value. After this date, the field value will be deleted. Please note that depending on usage of volatile field, value can be deleted even earlier, for example if allowed detokenization or reveal counts are exceeded, or when you explicitly call delete operation on the field.
"2024-12-31T23:59:59Z"
List of detokenization attempts performed on this field. This field is returned only when requested via includeDetokenizations query parameter.
Hide child attributes
Hide child attributes
Timestamp when the detokenization was attempted.
"2024-01-01T12:00:00Z"
Number of times this type of detokenization was successfully performed.
1
Type of detokenization attempt. detokenization indicates a standard detokenization, while sdkReveal indicates a detokenization performed via SDK reveal.
detokenization, sdkReveal "detokenization"