const response = await fetch('https://service.pcibooking.net/api/card-view-request/initView', {
method: 'POST',
headers: {
'Authorization': 'APIKEY your-api-key',
'Content-Type': 'application/json'
},
body: JSON.stringify({
Card_token: '555fd7b49f134b42a5dbe4d576b2e527',
Email: 'customer@example.com',
Phone: '353858622255',
PersonName: 'Jane Smith',
TtlMinutes: 15,
Language: 'en'
})
});
const data = await response.json();
console.log(data);
import requests
response = requests.post(
'https://service.pcibooking.net/api/card-view-request/initView',
headers={
'Authorization': 'APIKEY your-api-key',
'Content-Type': 'application/json'
},
json={
'Card_token': '555fd7b49f134b42a5dbe4d576b2e527',
'Email': 'customer@example.com',
'Phone': '353858622255',
'PersonName': 'Jane Smith',
'TtlMinutes': 15,
'Language': 'en'
}
)
print(response.json())
{
"verifyId": "s4iMrBQioE0JBCJIMN9kjnsLNDeGZUmG",
"status": "Pending",
"completedAt": null,
"expiresAt": "2026-01-12T14:15:00Z",
"phoneNumber": "353858622255",
"personName": "Jane Smith",
"language": "en",
"metadata": null,
"senderName": "My Travel Brand"
}
Empty response body.
Authentication failed: the API key, session token or access token is missing or was not accepted.
See "Authentication and Permission Failures" on the Error Handling page.
{
"code": -1003,
"message": "You are not authorized to access this resource. Please contact customer support.",
"moreInfo": "User <userId> is not associated with bank card [<token>]",
"errorList": null
}
Card Display
Initiate Card Display with OTP
Send a secure card viewing link with OTP verification to a cardholder.
POST
/
api
/
card-view-request
/
initView
const response = await fetch('https://service.pcibooking.net/api/card-view-request/initView', {
method: 'POST',
headers: {
'Authorization': 'APIKEY your-api-key',
'Content-Type': 'application/json'
},
body: JSON.stringify({
Card_token: '555fd7b49f134b42a5dbe4d576b2e527',
Email: 'customer@example.com',
Phone: '353858622255',
PersonName: 'Jane Smith',
TtlMinutes: 15,
Language: 'en'
})
});
const data = await response.json();
console.log(data);
import requests
response = requests.post(
'https://service.pcibooking.net/api/card-view-request/initView',
headers={
'Authorization': 'APIKEY your-api-key',
'Content-Type': 'application/json'
},
json={
'Card_token': '555fd7b49f134b42a5dbe4d576b2e527',
'Email': 'customer@example.com',
'Phone': '353858622255',
'PersonName': 'Jane Smith',
'TtlMinutes': 15,
'Language': 'en'
}
)
print(response.json())
{
"verifyId": "s4iMrBQioE0JBCJIMN9kjnsLNDeGZUmG",
"status": "Pending",
"completedAt": null,
"expiresAt": "2026-01-12T14:15:00Z",
"phoneNumber": "353858622255",
"personName": "Jane Smith",
"language": "en",
"metadata": null,
"senderName": "My Travel Brand"
}
Empty response body.
Authentication failed: the API key, session token or access token is missing or was not accepted.
See "Authentication and Permission Failures" on the Error Handling page.
{
"code": -1003,
"message": "You are not authorized to access this resource. Please contact customer support.",
"moreInfo": "User <userId> is not associated with bank card [<token>]",
"errorList": null
}
Card Display with OTP Guide
How the OTP verification flow works end-to-end
Error Responses
| Code | HTTP Status | Condition |
|---|---|---|
| none | 400 | The request body failed validation: Email or Phone is missing, Email is not a valid email address, Phone is not a valid phone number, PersonName is longer than 100 characters, TtlMinutes is outside 1 to 30, or Language is not a supported code. The body is a standard validation problem object with an errors object that names each field. |
| none | 401 | The Authorization header is missing, badly formatted, or the API key is not valid. The response body is empty. See Authentication and Permission Failures. |
| -1003 | 403 | Your user does not have the Retrieve cards or the Perform Card display operations permission, or your IP address is not in your account’s allowed IP list. message names the reason. |
| -1003 | 403 | Your account has exceeded its usage quota. message is empty. |
| -1003 | 401 | Card_token is missing, the token does not exist, was deleted, is malformed, or you are not the owner and not associated with it. See Token Not Found or Not Accessible. |
| -150 | 500 | The request could not be stored, or the email could not be sent. |
Parameter Constraints
| Parameter | Constraint |
|---|---|
Phone | Required. Must be a valid phone number. Send digits only, including the country code, with no + prefix. |
Email | Required. Must be a valid email address. |
PersonName | Max 100 characters. |
TtlMinutes | Integer, range 1 to 30 (minutes). Default: 10. |
Language | 2-letter code from the supported languages list. Default: en. |
| OTP code (entered by the viewer) | 6-digit numeric code. Regex: ^\d{6}$. |
| Session ID (CVRT, in the viewer’s link) | 32-character alphanumeric string. Regex: ^[a-zA-Z0-9]{32}$. |
Parameters
Authentication
API key only. This endpoint does not accept access tokens or session tokens.string
required
Your API key prefixed with
APIKEY. Example: APIKEY your-api-key. The x-pcibooking-api-key header is also accepted. See the Authentication guide.Request Body
string
required
The PCI Booking card token to display.
string
required
Email address to send the secure viewing link to. (Legacy alias:
ViewrEmail.)string
required
Phone number for SMS verification. Format: country code + number, no
+ prefix (e.g. 1555123456 for US, 353858622255 for Ireland). (Legacy alias: ViewrPhone.)string
Name of the viewer, used to personalize the email and verification screens. Max 100 characters. (Legacy alias:
ViewerName.)string
SMS sender name. Defaults to your account name.
number
default:"10"
How long the viewing link stays valid, in minutes. Range 1 to 30.
string
default:"en"
Two-letter language code for the email and verification screens, from the supported languages list.
const response = await fetch('https://service.pcibooking.net/api/card-view-request/initView', {
method: 'POST',
headers: {
'Authorization': 'APIKEY your-api-key',
'Content-Type': 'application/json'
},
body: JSON.stringify({
Card_token: '555fd7b49f134b42a5dbe4d576b2e527',
Email: 'customer@example.com',
Phone: '353858622255',
PersonName: 'Jane Smith',
TtlMinutes: 15,
Language: 'en'
})
});
const data = await response.json();
console.log(data);
import requests
response = requests.post(
'https://service.pcibooking.net/api/card-view-request/initView',
headers={
'Authorization': 'APIKEY your-api-key',
'Content-Type': 'application/json'
},
json={
'Card_token': '555fd7b49f134b42a5dbe4d576b2e527',
'Email': 'customer@example.com',
'Phone': '353858622255',
'PersonName': 'Jane Smith',
'TtlMinutes': 15,
'Language': 'en'
}
)
print(response.json())
Response
{
"verifyId": "s4iMrBQioE0JBCJIMN9kjnsLNDeGZUmG",
"status": "Pending",
"completedAt": null,
"expiresAt": "2026-01-12T14:15:00Z",
"phoneNumber": "353858622255",
"personName": "Jane Smith",
"language": "en",
"metadata": null,
"senderName": "My Travel Brand"
}
Empty response body.
Authentication failed: the API key, session token or access token is missing or was not accepted.
See "Authentication and Permission Failures" on the Error Handling page.
{
"code": -1003,
"message": "You are not authorized to access this resource. Please contact customer support.",
"moreInfo": "User <userId> is not associated with bank card [<token>]",
"errorList": null
}

