const response = await fetch(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/meta',
{
headers: {
'Authorization': 'APIKEY your-api-key'
}
}
);
const data = await response.json();
console.log(data);
import requests
response = requests.get(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/meta',
headers={'Authorization': 'APIKEY your-api-key'}
)
print(response.json())
{
"CreatorReference": "myRef",
"VirtualInfo": null,
"CreateDate": "2020-05-19T16:51:00",
"CardType": "Visa",
"LastDigits": "5005",
"LeadingDigits": "491891",
"ExpirationYear": 2020,
"ExpirationMonth": 7,
"OwnerID": "",
"OwnerName": "Juan Dela Cruz",
"UserID": "myUser",
"IssueNumber": "2",
"URI": "https://service.pcibooking.net/api/payments/paycard/eb454e0462d548ddbc6e6c2193b749a9",
"EndRetentionDate": "2017-07-08T00:00:00",
"CvvExists": true,
"AssociatedMerchants": ["userID1", "userID2"],
"AssociatedProperties": ["hotel1", "hotel2"],
"DelegationChain": [
{ "From": "CompanyA", "To": "CompanyB", "ToUserType": "Booker", "CreateDate": "2026-09-25T10:00:00" }
],
"ThreeDSecureInfo": {
"Token": "42c775efa8b04b1d8bf14ef49a9e45e5",
"ThreeDSSessionID": "uOrDbh0dEimUDmB3Vvn2f5CAM9B1bMQX",
"ThreeDSecIndication": "Authenticated",
"AuthenticationValue": "AJkBAoEREQAAAAB4hABwcAAAAAA=",
"Eci": "05",
"XID": "861433f4-abff-4c40-b2fd-fea208856a33",
"Universal_TransactionId": null,
"AcsTransactionId": "e7a46959-9630-413e-ab56-4e399b96244a",
"Version": "2.1.0",
"MerchantName": "PCI Booking * Hotelreservation",
"SLI": null
},
"NetworkTokenScheme": null,
"NetworkTokenId": null,
"TokenLocation": null
}
Empty response body.
Authentication failed: the API key, session token or access token is missing or was not accepted.
See "Authentication and Permission Failures" on the Error Handling page.
Query & Update
Retrieve Token Metadata
Returns non-sensitive metadata for a single token, including card type, masked card number, expiration, CVV status, 3DS data, and associations.
GET
/
api
/
payments
/
paycard
/
{cardtoken}
/
meta
const response = await fetch(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/meta',
{
headers: {
'Authorization': 'APIKEY your-api-key'
}
}
);
const data = await response.json();
console.log(data);
import requests
response = requests.get(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/meta',
headers={'Authorization': 'APIKEY your-api-key'}
)
print(response.json())
{
"CreatorReference": "myRef",
"VirtualInfo": null,
"CreateDate": "2020-05-19T16:51:00",
"CardType": "Visa",
"LastDigits": "5005",
"LeadingDigits": "491891",
"ExpirationYear": 2020,
"ExpirationMonth": 7,
"OwnerID": "",
"OwnerName": "Juan Dela Cruz",
"UserID": "myUser",
"IssueNumber": "2",
"URI": "https://service.pcibooking.net/api/payments/paycard/eb454e0462d548ddbc6e6c2193b749a9",
"EndRetentionDate": "2017-07-08T00:00:00",
"CvvExists": true,
"AssociatedMerchants": ["userID1", "userID2"],
"AssociatedProperties": ["hotel1", "hotel2"],
"DelegationChain": [
{ "From": "CompanyA", "To": "CompanyB", "ToUserType": "Booker", "CreateDate": "2026-09-25T10:00:00" }
],
"ThreeDSecureInfo": {
"Token": "42c775efa8b04b1d8bf14ef49a9e45e5",
"ThreeDSSessionID": "uOrDbh0dEimUDmB3Vvn2f5CAM9B1bMQX",
"ThreeDSecIndication": "Authenticated",
"AuthenticationValue": "AJkBAoEREQAAAAB4hABwcAAAAAA=",
"Eci": "05",
"XID": "861433f4-abff-4c40-b2fd-fea208856a33",
"Universal_TransactionId": null,
"AcsTransactionId": "e7a46959-9630-413e-ab56-4e399b96244a",
"Version": "2.1.0",
"MerchantName": "PCI Booking * Hotelreservation",
"SLI": null
},
"NetworkTokenScheme": null,
"NetworkTokenId": null,
"TokenLocation": null
}
Empty response body.
Authentication failed: the API key, session token or access token is missing or was not accepted.
See "Authentication and Permission Failures" on the Error Handling page.
Query & Retrieve Guide
Search for tokens and retrieve their metadata
Error Responses
| Code | HTTP Status | Condition |
|---|---|---|
| -1003 | 401 | The token does not exist, was deleted, or you are not the owner and not associated with it. See Token Not Found or Not Accessible. |
| -150 | 500 | Internal system error |
Parameters
Authentication
API key only. This endpoint does not accept access tokens or session tokens.string
required
Your API key prefixed with
APIKEY. Example: APIKEY your-api-key. The x-pcibooking-api-key header is also accepted. See the Authentication guide.Path Parameters
string
required
The token ID as returned by one of the tokenization methods. For example,
2821a46d80e14d1b96a7f18f1b81926d.const response = await fetch(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/meta',
{
headers: {
'Authorization': 'APIKEY your-api-key'
}
}
);
const data = await response.json();
console.log(data);
import requests
response = requests.get(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/meta',
headers={'Authorization': 'APIKEY your-api-key'}
)
print(response.json())
Response
200string
The reference value set when the card was tokenized.
string
The date and time the token was created (ISO 8601).
string
The card brand (e.g.
Visa, Mastercard, Amex). See supported card types. Returns unspecified when no card type was provided at tokenization.string
The first 6 digits (BIN) of the card number.
string
The last 4 digits of the card number.
integer
The card expiration year.
integer
The card expiration month.
string
The cardholder ID, if provided at tokenization time.
string
The name on the card, if provided at tokenization time.
string
The PCI Booking user ID that owns this token.
string
The card issue number (used by some card schemes).
string
The full token URI for use in API calls.
boolean
Whether CVV data is currently stored on this token.
string
The date after which the CVV will be automatically deleted (ISO 8601). Reflects the CVV retention policy.
string[]
List of PCI Booking customer (booker) user IDs associated with this token.
string[]
List of property user IDs associated with this token. Property Management only. Property Management is closed to new accounts; see Property Management.
object[]
Who shared this token with whom, one entry per association. Each entry has
From (the user ID that created the association), To (the user ID that received it), ToUserType (for example Booker for a customer, or Property4Booker for a property) and CreateDate. Empty if the token has not been shared.object
3D Secure authentication data, if stored on this token. See 3D Secure Authentication for field details.
string
The card network scheme if this is a network token (e.g.
Visa, Mastercard). null for regular cards.string
The network token identifier assigned by the card scheme.
null for regular cards.string
The region where the card data is stored, as a code such as
IE or US. null means the card is in PCI Booking’s main card store in Ireland and has no region code. See Card Storage Regions.object
Virtual card metadata, if this token was created from a virtual card. Contains
IsMultiUse, Currency, MaxAmount, CardRules, and validity date fields. null for regular cards.{
"CreatorReference": "myRef",
"VirtualInfo": null,
"CreateDate": "2020-05-19T16:51:00",
"CardType": "Visa",
"LastDigits": "5005",
"LeadingDigits": "491891",
"ExpirationYear": 2020,
"ExpirationMonth": 7,
"OwnerID": "",
"OwnerName": "Juan Dela Cruz",
"UserID": "myUser",
"IssueNumber": "2",
"URI": "https://service.pcibooking.net/api/payments/paycard/eb454e0462d548ddbc6e6c2193b749a9",
"EndRetentionDate": "2017-07-08T00:00:00",
"CvvExists": true,
"AssociatedMerchants": ["userID1", "userID2"],
"AssociatedProperties": ["hotel1", "hotel2"],
"DelegationChain": [
{ "From": "CompanyA", "To": "CompanyB", "ToUserType": "Booker", "CreateDate": "2026-09-25T10:00:00" }
],
"ThreeDSecureInfo": {
"Token": "42c775efa8b04b1d8bf14ef49a9e45e5",
"ThreeDSSessionID": "uOrDbh0dEimUDmB3Vvn2f5CAM9B1bMQX",
"ThreeDSecIndication": "Authenticated",
"AuthenticationValue": "AJkBAoEREQAAAAB4hABwcAAAAAA=",
"Eci": "05",
"XID": "861433f4-abff-4c40-b2fd-fea208856a33",
"Universal_TransactionId": null,
"AcsTransactionId": "e7a46959-9630-413e-ab56-4e399b96244a",
"Version": "2.1.0",
"MerchantName": "PCI Booking * Hotelreservation",
"SLI": null
},
"NetworkTokenScheme": null,
"NetworkTokenId": null,
"TokenLocation": null
}
Empty response body.
Authentication failed: the API key, session token or access token is missing or was not accepted.
See "Authentication and Permission Failures" on the Error Handling page.

