Skip to main content
POST
Reveal a purchase card

Authorizations

Authorization
string
header
required

Bearer token authentication for agent-scoped endpoints. The token is the accessToken returned when redeeming a device code via POST /agents/device-codes/redeem. Agent credentials are user-scoped: all requests are automatically bound to the agent's associated customer and subject to the agent's policy.

Path Parameters

cardId
string
required

Unique identifier of the card

Response

Reveal URL minted

panEmbedUrl
string<uri>
required

Signed URL of the card processor's iframe that securely displays the PAN, CVV, and expiry to the cardholder. The full PAN and CVV never cross Grid's servers — render this URL in an iframe in your client to reveal card details. The URL is a short-lived bearer secret: render it immediately and never store, cache, or log it.

Example:

"https://embed.lithic.com/iframe/...?t=..."

expiresAt
string<date-time>
required

When the signed URL stops loading. Request a new reveal rather than re-rendering an expired URL.

Example:

"2026-05-08T14:16:00Z"