> ## Documentation Index
> Fetch the complete documentation index at: https://docs.reap.global/llms.txt
> Use this file to discover all available pages before exploring further.

# Encrypted Card Details Retrieval

> Retrieve card PAN, CVV, and expiry as an encrypted payload for PCI-compliant partners.

Retrieve the full card details (PAN, CVV, expiry date) as an encrypted payload that only you can decrypt. The details are encrypted with the public half of an RSA key pair registered with Reap; you decrypt them with the private half on your backend.

<Warning>
  **Approval required.** This capability is enabled per program by Reap. Your system handles raw card data after decryption, so **your environment must be PCI DSS compliant**, and Reap enables it only after reviewing your compliance status. Projects without it receive `403 PAN_REVEAL_NOT_ENABLED`.

  You are responsible for the decrypted values: never store, log, cache, or transmit them beyond the immediate use.
</Warning>

Most integrations do not need this. If you only need to display card details to the cardholder, use the [iframe reveal flow](/cards/secure-display) instead - it keeps raw card data out of your systems entirely and needs no approval.

***

## Prerequisites

* The capability is enabled for your project by Reap. Talk to your account manager to request it; Reap reviews your PCI DSS compliance status before enabling. Calls from projects without it receive `403 PAN_REVEAL_NOT_ENABLED`.
* You hold the RSA private key:
  * **Production**: Reap generates a dedicated RSA-2048 key pair for your program and hands you the key pair over a secure channel during onboarding.
  * **Sandbox**: a single, publicly documented key pair is shared by all sandbox programs (see [Sandbox keys](#sandbox-keys)). It provides no confidentiality, sandbox cards are test cards.

***

## Request

See [Reveal PAN](/api-reference/cards/reveal-pan) for the full endpoint reference.

```bash theme={null}
curl -X POST https://sandbox.api.reap.global/cards/{cardId}/reveal-pan \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Reap-Version: 2025-02-14"
```

No request body. The card must exist, must not be in a terminal or inactive status, and its account must be active.

***

## Response

```json theme={null}
{
	"encryptedData": "hEJ2X8QeZ...base64...",
	"encryption": "RSA_OAEP_SHA1"
}
```

| Field           | Description                                                                                                   |
| --------------- | ------------------------------------------------------------------------------------------------------------- |
| `encryptedData` | Base64-encoded ciphertext of the card details JSON.                                                           |
| `encryption`    | Encryption scheme of `encryptedData`. Dispatch your decryption on this value; new schemes may be added later. |

Decrypting `encryptedData` yields a JSON document:

```json theme={null}
{
	"pan": "5200000000001005",
	"cvv": "123",
	"expiryDate": "12/28"
}
```

***

## Decryption

For `encryption: "RSA_OAEP_SHA1"`: base64-decode `encryptedData`, then decrypt with your RSA private key using OAEP padding with SHA-1.

<Tabs>
  <Tab title="OpenSSL">
    ```bash theme={null}
    echo "$ENCRYPTED_DATA" | base64 -d > /tmp/blob.bin
    openssl pkeyutl -decrypt -inkey private-key.pem -in /tmp/blob.bin \
      -pkeyopt rsa_padding_mode:oaep -pkeyopt rsa_oaep_md:sha1
    ```
  </Tab>

  <Tab title="Node.js">
    ```javascript theme={null}
    import { privateDecrypt, constants } from 'node:crypto';

    const cardDetails = JSON.parse(
    	privateDecrypt(
    		{
    			key: privateKeyPem,
    			padding: constants.RSA_PKCS1_OAEP_PADDING,
    			oaepHash: 'sha1',
    		},
    		Buffer.from(encryptedData, 'base64')
    	).toString('utf8')
    );
    ```
  </Tab>
</Tabs>

<Warning>
  Always decrypt on your backend. Never ship the private key to a browser or mobile client, and never proxy the decrypted details through systems outside your PCI scope.
</Warning>

***

## Errors

| Status | Code                         | Meaning                                                |
| ------ | ---------------------------- | ------------------------------------------------------ |
| 403    | `PAN_REVEAL_NOT_ENABLED`     | The capability is not enabled for your project.        |
| 404    | `CARD_NOT_FOUND`             | The card does not exist or has been deleted.           |
| 400    | `CARD_OPERATION_NOT_ALLOWED` | The card status does not permit revealing its details. |
| 400    | `ACCOUNT_NOT_ACTIVE`         | The account the card belongs to is not active.         |

***

## Sandbox keys

All sandbox programs share one RSA key pair. Use this private key to decrypt sandbox responses:

```
-----BEGIN RSA PRIVATE KEY-----
MIIEpAIBAAKCAQEAzn88MgWItkxYeUt5jWeRBYIiQEUFxstgYJx8tYblZ55psnYd
HwhsyoPDwG6eq0r60WFSEeP2QFqV1qceYuDNM2RziIaMMGYgYlCPjgYaiMda3wlX
0w6pMv/5VaJA6N0jcb2m5xBC3I7XqKkP3l9AfL5xCtWN71wmVA/WXVZQ755pC3YE
A4IMoOcXs/+143HWZarX7wULhK55c8uAeA1q3ZmL7boLkzBZdMQM6Qlv9DDVcgUH
dahk4MiibmOubXrOk12KAyEXZlLH8Sc3qTDQnYP60ZOz95Ffly2c5/6/vLEBP99y
J9baXwgoBpQ7amA2o+X7v+eomV5CUItJITR0FwIDAQABAoIBAQDJvT529DcjOqU5
I0aGoobpJcEGnyhMlkb7PAcOZdLbj8Vdp809k0KN+3sUFj6HxMIUKws+FUNwjc9T
nYOvQEbZjard1+1AH5ZF1sTZERd9R558xij6NpmRDMlwIwtdNSa6qXlUxus7hYYl
7b1mGBLtjDTuS8LV9WYwvCRGndyGq6489o5OHzkHrCSabPXhBWai9LLgYkjrF1v4
mo4LCCqJEjaLAdqOlUXLiM1DrDWYlGUqJhdqYmcdl85BBQjisfOrQoET5yKb+afP
r8ZNyY3AFKhwmSl5wHNcu1aY7E8UCzLYBboXd1vaWsXzo28UrUEk6jAQFW3otd3r
bUM+RhqBAoGBAP1r8fhSTh/DBaCU3CGPX6p3tRNhfWbpMt6nYVvuDVVWb46BvSmJ
W2BHK4Me8W+Bx6TKFGFI9eBsa6mevAT1R4283c1ji2pMe6W9uuojAe2ei3nRIYIi
eHrmMGLv/3EVO8ctn9OyevQuBXjEIcaNoxkTNwgln4mKonVwJctkDIlXAoGBANCZ
EkO840ZRQV8rYjEYJrE7W6hP+7FdTc/O62Gx5g6Kv11M7WY0dGJ0V/deio5sgmmV
+Hi4SYQEzG30VZS8QIzaXFOO3etuIbobf7HW7wP3sCsY0kYZpxGiu30luO3OOnvs
MLZ6wkdaArxAn1CPpmC3VngPy09cUVjAmun4mPNBAoGADP0eXsrhJDGbtTpL+hBe
J9+Q0Vh60+554/2SOOL/nfMbLqOprVpT66BaM5M/bqapM+IDn2Tc7U7BSeVP37Uu
oK4gdCl4+M7Iu5r43I1EyQgKQAke/YuEv0/TBQ8l+YbMFI5bFb+dG6zMLP9od8PE
q0FX3bwH7EXFw90mosES/2sCgYBKlcDTGZHGDb2rEq8MUM9c5ZVzTA35sBvnZtwA
1YQlxPSBnsTvm2fV4DWnzFUMcb37lNUADRy0KKcT1Z5YDSujcVw7wESXLoy+p6Bz
7R8PMxv5fOmKiReUlbQmHjvOQ8PjlWMhjCk1K/j4aL7OJl7eDA/N5A/U83ReoJeD
exDtQQKBgQD51uzxVgwUZNLkJbXCp64TNqUXdvy8+PlhqD9zU9QSpdsf2F0xM4gX
eF2r3FU8Ps9WD6SijD715A4o4/xVV7vUXKn11nVqeEkaEkn3KIZpFQiEdWQR2J9e
vErFndT9x8gfBgnKj4o6XvqHHPOPoqAC2piaXkLMhQGupqF922bj+Q==
-----END RSA PRIVATE KEY-----
```

***

## Security obligations

* Decrypt only on PCI DSS compliant backend systems.
* Never log, persist, or cache the decrypted PAN, CVV, or expiry date.
* Never expose the private key or decrypted details to client-side code.
* Every retrieval is audited by Reap.
