> ## Documentation Index
> Fetch the complete documentation index at: https://docs.henrylabs.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Card Reveal (Beta)

> **Beta.** Card reveal is in beta and enabled per account, separately from card issuance. Contact support@henrylabs.ai to request access; until then this endpoint returns `403`.

Return the card number, expiry and security code of a card issued to your app, for checkouts you run yourself rather than through `cart.checkout.purchase`. Only issued cards can be revealed — a tokenized customer card never can — and only while the card is open and unexpired.



## OpenAPI

````yaml /v1/api-reference/openapi.documented.json post /card/{cardToken}/reveal
openapi: 3.1.0
info:
  title: Henry Labs API
  version: 1.17.0
  description: Playground for Henry Labs API endpoints
  contact:
    name: Henry Labs API Support
    email: support@henrylabs.ai
servers:
  - url: https://api.henrylabs.ai/v1
    description: Production server
security:
  - ApiKeyAuth: []
tags:
  - name: Product
    description: Product search, details, and data enrichment
  - name: Cart
    description: Universal user shopping cart management
  - name: Orders
    description: Order management post purchase
  - name: Merchants
    description: Merchant information and status
  - name: Card
    description: Card tokenization and management
paths:
  /card/{cardToken}/reveal:
    post:
      tags:
        - Card
      summary: Card Reveal (Beta)
      description: >-
        **Beta.** Card reveal is in beta and enabled per account, separately
        from card issuance. Contact support@henrylabs.ai to request access;
        until then this endpoint returns `403`.


        Return the card number, expiry and security code of a card issued to
        your app, for checkouts you run yourself rather than through
        `cart.checkout.purchase`. Only issued cards can be revealed — a
        tokenized customer card never can — and only while the card is open and
        unexpired.
      operationId: cardReveal
      parameters:
        - in: path
          name: cardToken
          schema:
            type: string
            description: Token returned by `POST /card/issue`
            example: card_live_abc123xyz
          required: true
          description: Token returned by `POST /card/issue`
      responses:
        '200':
          description: Card details
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/cardRevealResponse'
        '401':
          description: Invalid or missing API key
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                  status:
                    type: string
                  message:
                    type: string
                required:
                  - success
                  - status
                  - message
                additionalProperties: false
        '403':
          description: >-
            Card reveal is a beta feature and isn't enabled for your account.
            Contact support@henrylabs.ai to request access.
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                  status:
                    type: string
                  message:
                    type: string
                required:
                  - success
                  - status
                  - message
                additionalProperties: false
        '404':
          description: >-
            No card with this token was issued to your app. Tokenized (customer)
            cards can never be revealed.
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                  status:
                    type: string
                  message:
                    type: string
                required:
                  - success
                  - status
                  - message
                additionalProperties: false
        '409':
          description: >-
            Not revealed: the card is closed, expired, or no longer open at the
            issuer, or its state couldn't be confirmed (safe to retry).
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                  status:
                    type: string
                  message:
                    type: string
                required:
                  - success
                  - status
                  - message
                additionalProperties: false
        '429':
          description: Reveal rate limit exceeded for this app
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                  status:
                    type: string
                  message:
                    type: string
                required:
                  - success
                  - status
                  - message
                additionalProperties: false
      security:
        - ApiKeyAuth: []
      x-codeSamples:
        - lang: JavaScript
          source: |-
            import HenrySDK from '@henrylabs/sdk';

            const client = new HenrySDK({
              apiKey: process.env['HENRY_SDK_API_KEY'], // This is the default and can be omitted
            });

            const response = await client.card.reveal('card_live_abc123xyz');

            console.log(response.data);
components:
  schemas:
    cardRevealResponse:
      type: object
      properties:
        success:
          type: boolean
        status:
          type: string
        message:
          type: string
        data:
          $ref: '#/components/schemas/cardRevealData'
      required:
        - success
        - status
        - message
        - data
      additionalProperties: false
    cardRevealData:
      type: object
      properties:
        cardToken:
          type: string
          example: card_live_abc123xyz
        cardNumber:
          type: string
          description: Full card number (PAN).
          example: '4111111111111111'
        expiryMonth:
          type: string
          description: Two digits
          example: '06'
        expiryYear:
          type: string
          description: Two digits
          example: '28'
        cvv:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Security code, or null if it's no longer held. Issued cards keep it
            until `expiresAt`.
          example: '123'
      required:
        - cardToken
        - cardNumber
        - expiryMonth
        - expiryYear
        - cvv
      additionalProperties: false
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.