const response = await fetch(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/cvv/Restriction/HostName/gateway.example.com',
{
method: 'DELETE',
headers: {
'Authorization': 'APIKEY your-api-key'
}
}
);
console.log(response.status);
import requests
response = requests.delete(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/cvv/Restriction/HostName/gateway.example.com',
headers={'Authorization': 'APIKEY your-api-key'}
)
print(response.status_code)
CVV retention policy type data deleted successfully. No content returned.
Empty response body.
Authentication failed: the API key, session token or access token is missing or was not accepted.
See "Authentication and Permission Failures" on the Error Handling page.
CVV Management
Delete CVV Retention Policy by Destination
Remove a single destination from the CVV retention policy.
DELETE
/
api
/
payments
/
paycard
/
{cardToken}
/
cvv
/
Restriction
/
{DestinationType}
/
{DestinationData}
const response = await fetch(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/cvv/Restriction/HostName/gateway.example.com',
{
method: 'DELETE',
headers: {
'Authorization': 'APIKEY your-api-key'
}
}
);
console.log(response.status);
import requests
response = requests.delete(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/cvv/Restriction/HostName/gateway.example.com',
headers={'Authorization': 'APIKEY your-api-key'}
)
print(response.status_code)
CVV retention policy type data deleted successfully. No content returned.
Empty response body.
Authentication failed: the API key, session token or access token is missing or was not accepted.
See "Authentication and Permission Failures" on the Error Handling page.
Removes a single destination (matching both type and data) from this token’s retention policy. Other destinations remain unaffected. If no destinations remain, the token follows the system-wide default.
CVV Retention Policy Guide
Control how long CVV data is retained and who can use it
These
cvv/Restriction endpoints manage what the documentation calls the CVV retention policy and what the PCI Booking portal calls CVV Store Rules. All three names refer to the same feature.Error Responses
| Code | HTTP Status | Condition |
|---|---|---|
| none | 401 | API key is missing or invalid. The response body is empty. |
-1003 | 401 | Authenticated user does not have ForceCVVRetentionPolicy permission. |
-1003 | 401 | Token does not belong to the authenticated user. |
-125 | 400 | The token does not have a CVV stored. |
-1010 | 423 | The retention policy is locked. Either the 60-minute update window has passed, or the CVV has already been used. |
-150 | 500 | An internal system error occurred. |
Parameters
Authentication
API key only. This endpoint does not accept access tokens or session tokens.string
required
Your API key prefixed with
APIKEY. Example: APIKEY your-api-key. The x-pcibooking-api-key header is also accepted. See the Authentication guide.Path Parameters
string
required
The token ID as returned by one of the tokenization methods.
string
required
One of:
HostName, Owner, OtherMerchant, SFTP, OtherUser. See destination types.string
required
The target identifier for this destination (e.g. hostname, user ID, IP address).
const response = await fetch(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/cvv/Restriction/HostName/gateway.example.com',
{
method: 'DELETE',
headers: {
'Authorization': 'APIKEY your-api-key'
}
}
);
console.log(response.status);
import requests
response = requests.delete(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/cvv/Restriction/HostName/gateway.example.com',
headers={'Authorization': 'APIKEY your-api-key'}
)
print(response.status_code)
Response
200 - Destination removed. Empty JSON object.CVV retention policy type data deleted successfully. No content returned.
Empty response body.
Authentication failed: the API key, session token or access token is missing or was not accepted.
See "Authentication and Permission Failures" on the Error Handling page.

