> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kemycard.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get Card Sensitive Data

> Returns the full card number, the CVV and the expiry date. This is the only endpoint that returns them:
every other response only shows `last_four`.

Available once the card is `active` or `frozen`. Call it from your server, only when your customer needs
to see the card, and never store or log the response. The response is never cached.




## OpenAPI

````yaml GET /cards/{code}/sensitive
openapi: 3.1.0
info:
  title: KemyCard API
  version: '1.0'
  description: >
    KemyCard API allows you to issue virtual and physical cards, manage KYC/POA
    verification,

    create crypto wallets, virtual bank accounts, and purchase gift cards.
  contact:
    name: KemyCard API Support
    email: hi@kemycard.com
servers:
  - url: https://api.kemycard.com/v1
    description: Production
security:
  - BearerAuth: []
tags:
  - name: Customers
    description: Manage your customers
  - name: Card Products
    description: Browse the card product catalog
  - name: Cards
    description: Issue and manage cards
  - name: KYC
    description: Identity verification
  - name: POA
    description: Proof of address verification
  - name: Wallets
    description: Crypto wallets
  - name: Virtual Accounts
    description: Virtual bank accounts
  - name: Gift Cards
    description: Gift card catalog and purchases
  - name: Balance
    description: Operational balances and transaction history
  - name: Webhooks
    description: Webhook endpoints and delivery management
paths:
  /cards/{code}/sensitive:
    get:
      tags:
        - Cards
      summary: Get card number, CVV and expiry
      description: >
        Returns the full card number, the CVV and the expiry date. This is the
        only endpoint that returns them:

        every other response only shows `last_four`.


        Available once the card is `active` or `frozen`. Call it from your
        server, only when your customer needs

        to see the card, and never store or log the response. The response is
        never cached.
      operationId: getCardSensitiveData
      parameters:
        - $ref: '#/components/parameters/code'
      responses:
        '200':
          description: Card sensitive data
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CardSensitiveResponse'
        '404':
          $ref: '#/components/responses/NotFound'
        '422':
          $ref: '#/components/responses/ValidationError'
components:
  parameters:
    code:
      name: code
      in: path
      required: true
      schema:
        type: string
        format: uuid
      description: Resource UUID
  schemas:
    CardSensitiveResponse:
      type: object
      properties:
        success:
          type: boolean
          example: true
        data:
          type: object
          properties:
            card_code:
              type: string
              format: uuid
            card_number:
              type: string
              description: Full card number, without spaces
              example: '4000000000000000'
            cvv:
              type: string
              example: '000'
            expiry_month:
              type: integer
              example: 12
            expiry_year:
              type: integer
              example: 2029
            name_on_card:
              type: string
              example: John Doe
        meta:
          $ref: '#/components/schemas/Meta'
    Meta:
      type: object
      properties:
        request_id:
          type: string
          example: a4f8e2c1b3d97056
        mode:
          type: string
          enum:
            - test
            - live
          example: test
        timestamp:
          type: string
          format: date-time
    ErrorResponse:
      type: object
      properties:
        success:
          type: boolean
          example: false
        error:
          type: object
          properties:
            code:
              type: string
              example: VALIDATION_ERROR
            message:
              type: string
              example: Missing required fields.
            details:
              type: object
              nullable: true
        meta:
          $ref: '#/components/schemas/Meta'
  responses:
    NotFound:
      description: Resource not found
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            success: false
            error:
              code: RESOURCE_NOT_FOUND
              message: Resource not found.
              details: null
    ValidationError:
      description: Validation error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: API key (sk_test_... or sk_live_...)

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.