Get payment token
GET
/api/tokens/{id}
deprecated
No permission required.
Retrieves information about a specific payment token.
Example request
Every block below sends the same request. Replace {{BASE_URL}} with the address of the API you are calling and {{API_KEY}} with your own key.
The request body is a . See the Request body section below for its fields.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
id
required |
path | string (uuid) | |
suppressNulls
required |
query | boolean | If true, omit properties with null values. |
Request body
application/json
, required
| Field | Type | Description |
|---|
This request body has no documented fields.
Responses
200 OK
Body: PaymentTokenDto
Each item has these fields.
| Field | Type | Description |
|---|---|---|
extraProperties
required |
object | nullableread only |
id
required |
string (uuid) | |
creationTime
required |
string (date-time) | The date and time when this entity was created. |
creatorId
required |
string (uuid) | The ID of the user who created this entity. nullable |
lastModificationTime
required |
string (date-time) | The date and time when this entity was last modified. nullable |
lastModifierId
required |
string (uuid) | The ID of the user who last modified this entity. nullable |
isDeleted
required |
boolean | Indicates whether this entity has been deleted. |
deleterId
required |
string (uuid) | The ID of the user who deleted this entity, if it is deleted. nullable |
deletionTime
required |
string (date-time) | The date and time when this entity was deleted, if it is deleted. nullable |
tenantId
required |
string (uuid) | Id of the related tenant. nullableread only |
concurrencyStamp
required |
string | nullable |
numericToken
required |
integer (int64) | The numeric representation of the token. nullable |
cardFormatToken
required |
string | The card format representation of the token. nullable |
transactionId
required |
string (uuid) | The unique identifier of the associated transaction when the token was created. nullable |
paymentDetails
required |
all of PaymentDetailSnapshot | The payment details snapshot associated with this token. |
type
required |
all of TokenType | The underlying payment type of the token. |
category
required |
all of TokenCategory | The category of the token (e.g., internal, network). |
merchantId
required |
string (uuid) | Id of the related Merchant. nullable |
customerId
required |
string (uuid) | The customer this stored credential is bound to, or `null` when it is not bound to one. nullable |
tokenSharing
required |
boolean | The sharing status of the token. |
label
required |
string | Optional human-readable label for the token. nullable |
status
required |
all of TokenStatus | The status of the token (Active, Inactive, Invalidated). |
invalidatedByTokenId
required |
string (uuid) | The ID of the token that replaced this one (if invalidated and regenerated). nullable |
replacesTokenId
required |
string (uuid) | The ID of the token that this token replaced (if this is a regenerated token). nullable |
regenerationReason
required |
all of TokenRegenerationReason | The reason for token regeneration (if applicable). nullable |
lastRegeneratedAt
required |
string (date-time) | The timestamp when this token was last regenerated. nullable |
redactedAt
required |
string (date-time) | When the token's stored card or bank account details were erased, or `null` for a token that has not been redacted. nullable |
redactionReason
required |
string | The reason recorded when the token's stored details were erased, or `null` for a token that has not been redacted. nullable |
publicReference
required |
string | The stable, opaque `pt_`-prefixed handle for this token: the only token identifier permitted to leave the gateway, and the value to charge against on a merchant-initiated transaction. Distinct from the internal id, which correlates to a card number and is never treated as a merchant-facing handle. nullable |
This response has no documented body fields.
403 Forbidden
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
401 Unauthorized
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
400 Bad Request
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
404 Not Found
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
501 Not Implemented
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
500 Internal Server Error
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
default The request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
429 The request was refused because a rate limit was exceeded. Wait at least the interval `Retry-After` names before retrying, then back off. Limits are tuned per deployment, so read the allowance from the response headers rather than assuming a fixed ceiling.
Body: RateLimitProblemDetails
Each item has these fields.
| Field | Type | Description |
|---|---|---|
type
required |
string | The problem type identifier. Always the same value: the failure is the status code itself, so there is no sub-type for a caller to branch on. nullable |
title
required |
string | A short, human-readable summary of the problem type. nullable |
status
required |
integer (int32) | The HTTP status code, repeated in the body as the problem-details format defines. |
detail
required |
string | A human-readable explanation of this occurrence of the problem. nullable |
retryAfterSeconds
required |
integer (int32) | How long to wait before retrying, in whole seconds, carrying the same figure as the `Retry-After` header. Always at least one: a value of zero would invite an immediate retry that is certain to be rejected again. |
This response has no documented body fields.
Errors
A failed request returns the platform error envelope. The
error reference lists every value
error.code can carry and shows the four response shapes.