Skip to main content
GET
Get a PIN-entry URL

Authorizations

Authorization
string
header
required

API token authentication using format <api token id>:<api client secret>

Path Parameters

id
string
required

System-generated unique card identifier

Response

A fresh PIN-entry URL and its expiration.

A temporary PIN-entry iframe URL, its credential, and expiration.

iframeUrl
string<uri>
required

Ready-to-use URL for the secure PIN-entry iframe. Set this as your iframe's src without modifying it. The cardholder enters their PIN inside the iframe, so the plaintext PIN never reaches your servers or Grid's. Use the message flow in the Card PIN guide to submit and confirm the result.

The URL contains a temporary credential. Never store, cache, or log it. It expires at expiresAt and permits one successful PIN submission.

Example:

"https://embed.example.com/pin?session=eyJhbGciOiJIUzI1NiJ9..."

sessionToken
string
required

Temporary credential authorizing one successful PIN submission. It is already included in iframeUrl; use that URL to load the form. Never store, cache, or log the token. Use the iframe's submission result to confirm a change; status OK alone cannot prove that an existing PIN was changed. Read GET /cards/{id} for its pinStatus.

Example:

"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."

expiresAt
string<date-time>
required

When the URL stops working. Request a new URL rather than reusing an expired URL or token.

Example:

"2026-05-08T14:16:00Z"

environment
enum<string>
required

Session environment. The iframeUrl already selects the matching environment.

Available options:
SANDBOX,
PRODUCTION
Example:

"SANDBOX"