Skip to main content
Full card details are never returned in plain text. Once you register an RSA public key, Get card secrets returns an encrypted pan field that only your private key can decrypt.

1. Generate a key pair

Generate the key pair on your own server. Never generate or paste your private key into a third-party website.

2. Register the public key

Send the contents of card_public.pem to Set public key:

3. Decrypt card data

Get card secrets returns masked card_no, cvv and expire_date, plus the encrypted pan:
pan is Base64 and encrypted with RSA/NONE/OAEPWithSHA1AndMGF1Padding. Decrypt it with your private key:
Decrypted card data is sensitive. Show it only to the cardholder, never log it, and follow PCI DSS rules if you store it.