Skip to main content
Display sensitive card details (PAN, CVV, expiry date) to your users without handling raw card data. Reap API provides an iframe-based reveal flow that keeps your integration PCI-compliant.

How it works

1

Your backend requests a reveal URL

Call Create reveal session from your server. Reap returns a short-lived, single-use revealUrl.
2

Your frontend loads the URL in an iframe

Pass the revealUrl to your client and render it as the src of an <iframe> (web) or WebView (mobile).
3

Card details are displayed

The cardholder sees PAN, CVV, and expiry date inside the iframe. No sensitive data touches your servers or client code.

Security


Integration

1. Request a reveal URL

Call Create reveal session from your backend. The response includes a revealUrl and an expiresAt timestamp.

2. Display in an iframe

Pass revealUrl from your backend to your client and load it as the src of an iframe or WebView.
Client-side only. The revealUrl must be loaded directly in a browser iframe or mobile WebView. Do not fetch, parse, or proxy the URL on your backend. Doing so exposes your servers to raw card data (PAN, CVV, expiry) and shifts PCI DSS compliance responsibilities onto your system.

Customization

The reveal endpoint accepts two optional parameters: Pass these as optional fields in the Create reveal session request body.

Best practices

  • Generate on demand. Request a new revealUrl each time the user taps “Show card details”. Do not cache or store URLs.
  • Authenticate the cardholder first. Only request a reveal URL after your application has verified the user’s identity. The revealUrl does not require authentication to load, so treat it as sensitive.
  • Handle expiration. If the iframe shows an error page, the URL has expired or was already used. Prompt the user to try again and request a fresh URL.
  • Use HTTPS for stylesheets. If you provide a custom stylesheetUrl, serve it over HTTPS.