const response = await fetch(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/cvv/Restriction',
{
headers: {
'Authorization': 'APIKEY your-api-key'
}
}
);
const data = await response.json();
console.log(data);
import requests
response = requests.get(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/cvv/Restriction',
headers={'Authorization': 'APIKEY your-api-key'}
)
print(response.json())
{
"CvvEndRetentionDate": "2027-12-12T12:32:45",
"DeleteCardUponCvvCleanup": "true",
"CvvRetentionPolicyList": [
{
"DestinationType": "HostName",
"DestinationData": "gateway.example.com",
"Quota": 10,
"Usage": 3
}
]
}
<CvvRetentionPolicy>
<CvvEndRetentionDate>2027-12-12T12:32:45</CvvEndRetentionDate>
<DeleteCardUponCvvCleanup>true</DeleteCardUponCvvCleanup>
<CvvRetentionPolicyList>
<CvvRetentionPolicyDestinationUsage>
<DestinationType>HostName</DestinationType>
<DestinationData>gateway.example.com</DestinationData>
<Quota>10</Quota>
<Usage>3</Usage>
</CvvRetentionPolicyDestinationUsage>
<CvvRetentionPolicyDestinationUsage>
<DestinationType>Owner</DestinationType>
<DestinationData></DestinationData>
<Quota>5</Quota>
<Usage>0</Usage>
</CvvRetentionPolicyDestinationUsage>
<CvvRetentionPolicyDestinationUsage>
<DestinationType>OtherMerchant</DestinationType>
<DestinationData>property123</DestinationData>
<Quota>2</Quota>
<Usage>1</Usage>
</CvvRetentionPolicyDestinationUsage>
<CvvRetentionPolicyDestinationUsage>
<DestinationType>SFTP</DestinationType>
<DestinationData>sftp.example.com</DestinationData>
<Quota>1</Quota>
<Usage>0</Usage>
</CvvRetentionPolicyDestinationUsage>
</CvvRetentionPolicyList>
</CvvRetentionPolicy>
{
"CvvEndRetentionDate": "2027-01-12T20:02:26",
"CvvRetentionPolicyList": []
}
Empty response body.
Authentication failed: the API key, session token or access token is missing or was not accepted.
See "Authentication and Permission Failures" on the Error Handling page.
CVV Management
Get CVV Retention Policy
Retrieve the full CVV retention policy for a token, including per-destination usage counts.
GET
/
api
/
payments
/
paycard
/
{cardToken}
/
cvv
/
Restriction
const response = await fetch(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/cvv/Restriction',
{
headers: {
'Authorization': 'APIKEY your-api-key'
}
}
);
const data = await response.json();
console.log(data);
import requests
response = requests.get(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/cvv/Restriction',
headers={'Authorization': 'APIKEY your-api-key'}
)
print(response.json())
{
"CvvEndRetentionDate": "2027-12-12T12:32:45",
"DeleteCardUponCvvCleanup": "true",
"CvvRetentionPolicyList": [
{
"DestinationType": "HostName",
"DestinationData": "gateway.example.com",
"Quota": 10,
"Usage": 3
}
]
}
<CvvRetentionPolicy>
<CvvEndRetentionDate>2027-12-12T12:32:45</CvvEndRetentionDate>
<DeleteCardUponCvvCleanup>true</DeleteCardUponCvvCleanup>
<CvvRetentionPolicyList>
<CvvRetentionPolicyDestinationUsage>
<DestinationType>HostName</DestinationType>
<DestinationData>gateway.example.com</DestinationData>
<Quota>10</Quota>
<Usage>3</Usage>
</CvvRetentionPolicyDestinationUsage>
<CvvRetentionPolicyDestinationUsage>
<DestinationType>Owner</DestinationType>
<DestinationData></DestinationData>
<Quota>5</Quota>
<Usage>0</Usage>
</CvvRetentionPolicyDestinationUsage>
<CvvRetentionPolicyDestinationUsage>
<DestinationType>OtherMerchant</DestinationType>
<DestinationData>property123</DestinationData>
<Quota>2</Quota>
<Usage>1</Usage>
</CvvRetentionPolicyDestinationUsage>
<CvvRetentionPolicyDestinationUsage>
<DestinationType>SFTP</DestinationType>
<DestinationData>sftp.example.com</DestinationData>
<Quota>1</Quota>
<Usage>0</Usage>
</CvvRetentionPolicyDestinationUsage>
</CvvRetentionPolicyList>
</CvvRetentionPolicy>
{
"CvvEndRetentionDate": "2027-01-12T20:02:26",
"CvvRetentionPolicyList": []
}
Empty response body.
Authentication failed: the API key, session token or access token is missing or was not accepted.
See "Authentication and Permission Failures" on the Error Handling page.
Returns the retention policy for this token, including how many times the CVV has been sent to each destination.
CVV Retention Policy Guide
Control how long CVV data is retained and who can use it
These
cvv/Restriction endpoints manage what the documentation calls the CVV retention policy and what the PCI Booking portal calls CVV Store Rules. All three names refer to the same feature.Error Responses
| Code | HTTP Status | Condition |
|---|---|---|
| none | 401 | API key is missing or invalid. The response body is empty. |
-1003 | 401 | Authenticated user does not have ForceCVVRetentionPolicy permission. |
-1003 | 401 | Token does not belong to the authenticated user. |
-125 | 400 | The token does not have a CVV stored. |
-160 | 404 | No CVV retention policy has been set on this token. |
-150 | 500 | An internal system error occurred while retrieving the policy. |
Parameters
Path Parameters
string
required
The token ID as returned by one of the tokenization methods.
Authentication
API key only. This endpoint does not accept access tokens or session tokens.string
required
Your API key prefixed with
APIKEY. Example: APIKEY your-api-key. The x-pcibooking-api-key header is also accepted. See the Authentication guide.Headers
string
default:"application/json"
Set to
application/xml to receive the response in XML format.const response = await fetch(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/cvv/Restriction',
{
headers: {
'Authorization': 'APIKEY your-api-key'
}
}
);
const data = await response.json();
console.log(data);
import requests
response = requests.get(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/cvv/Restriction',
headers={'Authorization': 'APIKEY your-api-key'}
)
print(response.json())
Response
The response mirrors the structure of the Set CVV Retention Policy request body, with an additionalUsage field per destination showing how many times the CVV has already been sent there.
{
"CvvEndRetentionDate": "2027-12-12T12:32:45",
"DeleteCardUponCvvCleanup": "true",
"CvvRetentionPolicyList": [
{
"DestinationType": "HostName",
"DestinationData": "gateway.example.com",
"Quota": 10,
"Usage": 3
}
]
}
<CvvRetentionPolicy>
<CvvEndRetentionDate>2027-12-12T12:32:45</CvvEndRetentionDate>
<DeleteCardUponCvvCleanup>true</DeleteCardUponCvvCleanup>
<CvvRetentionPolicyList>
<CvvRetentionPolicyDestinationUsage>
<DestinationType>HostName</DestinationType>
<DestinationData>gateway.example.com</DestinationData>
<Quota>10</Quota>
<Usage>3</Usage>
</CvvRetentionPolicyDestinationUsage>
<CvvRetentionPolicyDestinationUsage>
<DestinationType>Owner</DestinationType>
<DestinationData></DestinationData>
<Quota>5</Quota>
<Usage>0</Usage>
</CvvRetentionPolicyDestinationUsage>
<CvvRetentionPolicyDestinationUsage>
<DestinationType>OtherMerchant</DestinationType>
<DestinationData>property123</DestinationData>
<Quota>2</Quota>
<Usage>1</Usage>
</CvvRetentionPolicyDestinationUsage>
<CvvRetentionPolicyDestinationUsage>
<DestinationType>SFTP</DestinationType>
<DestinationData>sftp.example.com</DestinationData>
<Quota>1</Quota>
<Usage>0</Usage>
</CvvRetentionPolicyDestinationUsage>
</CvvRetentionPolicyList>
</CvvRetentionPolicy>
{
"CvvEndRetentionDate": "2027-01-12T20:02:26",
"CvvRetentionPolicyList": []
}
Empty response body.
Authentication failed: the API key, session token or access token is missing or was not accepted.
See "Authentication and Permission Failures" on the Error Handling page.

