Skip to main content
POST

Update Card Data Guide

Modify expiration dates and creator references on tokens
Once the Duplicate Token method has been completed successfully, a new card token will be created and the token URI will be returned in the response header Location. The result of this process would be that there are two card tokens in PCI Booking for the same card. It is your responsibility to delete one of them to avoid getting charged for storage on both tokens.

Error Responses

Parameter Constraints

Parameters

Authentication

API key, access token or session token. Use the API key for server-to-server calls, and an access token or a session token when the call is made from a browser. Send one of the three.
string
Your API key prefixed with APIKEY. Example: APIKEY your-api-key. The x-pcibooking-api-key header is also accepted. See the Authentication guide.
string
Generated on your side. Single use, and valid for up to 72 hours. How to generate.
string
Returned by an API call. Valid for 5 minutes, and can be used more than once within that time. How to generate.

Query String

string
required
The card URI (resource identifier for the card location within PCI Booking). For example, https://service.pcibooking.net/api/payments/paycard/865ed8bec1f84366b97112a69cdbf915. The card URI should be URL encoded.
string
Security code, as returned from the iFrame or other sources. If not provided, the new token will not contain any CVV.
string
A reference value that can be used to query for this card token.
string
The Property’s Username (user ID) found within PCI Booking (under “Property settings”) which has been given permission to view the card. The owner (Booker) always has permission to view the card.
string
The region where the new token is stored. One of: US, IN, AU, JP, CA, IE, GB, BR. If omitted, the new token is stored in the same region as the original token. See Card Storage Regions.

Response

200 - Card duplicated. A Location header is returned with the new token URI.
Remember to set the CVV Retention Policy on the new token if it includes a CVV.