const response = await fetch(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/cvv/Restriction/HostName',
{
method: 'DELETE',
headers: {
'Authorization': 'APIKEY your-api-key'
}
}
);
console.log(response.status);
import requests
response = requests.delete(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/cvv/Restriction/HostName',
headers={'Authorization': 'APIKEY your-api-key'}
)
print(response.status_code)
CVV retention policy type deleted successfully. No content returned.
Empty response body.
Authentication failed: the API key, session token or access token is missing or was not accepted.
See "Authentication and Permission Failures" on the Error Handling page.
CVV Management
Delete CVV Retention Policy by Destination Type
Remove all destinations of a specific type from the CVV retention policy.
DELETE
/
api
/
payments
/
paycard
/
{cardToken}
/
cvv
/
Restriction
/
{DestinationType}
const response = await fetch(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/cvv/Restriction/HostName',
{
method: 'DELETE',
headers: {
'Authorization': 'APIKEY your-api-key'
}
}
);
console.log(response.status);
import requests
response = requests.delete(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/cvv/Restriction/HostName',
headers={'Authorization': 'APIKEY your-api-key'}
)
print(response.status_code)
CVV retention policy type deleted successfully. No content returned.
Empty response body.
Authentication failed: the API key, session token or access token is missing or was not accepted.
See "Authentication and Permission Failures" on the Error Handling page.
Removes all destinations matching the given type from this token’s retention policy. Other destination types remain unaffected. If no destinations remain, the token follows the system-wide default.
CVV Retention Policy Guide
Control how long CVV data is retained and who can use it
These
cvv/Restriction endpoints manage what the documentation calls the CVV retention policy and what the PCI Booking portal calls CVV Store Rules. All three names refer to the same feature.Error Responses
| Code | HTTP Status | Condition |
|---|---|---|
| none | 401 | API key is missing or invalid. The response body is empty. |
-1003 | 401 | Authenticated user does not have ForceCVVRetentionPolicy permission. |
-1003 | 401 | Token does not belong to the authenticated user. |
-125 | 400 | The token does not have a CVV stored. |
-1010 | 423 | The retention policy is locked. Either the 60-minute update window has passed, or the CVV has already been used. |
-150 | 500 | An internal system error occurred. |
Parameters
Authentication
API key only. This endpoint does not accept access tokens or session tokens.string
required
Your API key prefixed with
APIKEY. Example: APIKEY your-api-key. The x-pcibooking-api-key header is also accepted. See the Authentication guide.Path Parameters
string
required
The token ID as returned by one of the tokenization methods.
string
required
One of:
HostName, Owner, OtherMerchant, SFTP, OtherUser. See destination types.const response = await fetch(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/cvv/Restriction/HostName',
{
method: 'DELETE',
headers: {
'Authorization': 'APIKEY your-api-key'
}
}
);
console.log(response.status);
import requests
response = requests.delete(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/cvv/Restriction/HostName',
headers={'Authorization': 'APIKEY your-api-key'}
)
print(response.status_code)
Response
200 - Destinations removed. Empty JSON object.CVV retention policy type deleted successfully. No content returned.
Empty response body.
Authentication failed: the API key, session token or access token is missing or was not accepted.
See "Authentication and Permission Failures" on the Error Handling page.

