> ## Documentation Index
> Fetch the complete documentation index at: https://docs.apocor.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Reveal token for Widget.js (PAN/CVV)

> **Method 1 — Widget reveal (default).** Returns a short-lived `revealToken` (~5 minutes). Load Apocor Widget.js, then pass the token as `clientAccessToken` to `widget.bootstrap(...)`.

**Script URLs:**
- Sandbox/TEST: `https://api.apocor.ai/sdk/card/sandbox/1.0.0/index.min.js`
- Live: `https://api.apocor.ai/sdk/card/1.0.0/index.min.js`

Ask Apocor to allowlist your frontend page origin. Full walkthrough: https://docs.apocor.ai/guides/viewing-card-details

For PCI DSS Level 1 server-side access, use `POST /v1/cards/{id}/payment-details` (Method 2).



## OpenAPI

````yaml /openapi.json get /v1/cards/{id}/secure-details
openapi: 3.1.0
info:
  title: Apocor Core API
  version: 1.0.0
  description: >-
    The Apocor Cards API is the integration surface for issuing and managing
    cards. Authenticate with your Apocor API key, onboard applicants, run KYC,
    and issue virtual or physical cards — all through one white-labeled API.
  contact:
    name: Apocor Support
    url: https://apocor.ai
servers:
  - url: https://sandbox.apocor.ai
    description: Sandbox (live)
  - url: https://api.apocor.ai
    description: Production
  - url: http://localhost:4000
    description: Local development
security:
  - bearerAuth: []
tags:
  - name: Authentication
    description: Exchange Apocor API keys for a short-lived access token.
  - name: Applicants
    description: End-users and businesses, plus their identity verification (KYC).
  - name: KYC
    description: >-
      Identity verification settings, hosted sessions, BYOK share tokens, direct
      document upload, and issuer readiness.
    x-group: Identity verification (KYC)
  - name: Accounts
    description: Funding accounts that back issued cards.
  - name: Programs
    description: Card programs that define product type, currency, and BIN.
  - name: Cardholders
    description: Approved applicants turned into cardholders.
  - name: Cards
    description: Issue and manage virtual and physical cards.
  - name: Transactions
    description: Card transaction history from the issuer or local ledger.
  - name: Widget SDK
    description: >-
      Public Apocor-branded proxy for Method 1 Widget.js (no auth). PAN/CVV
      still render in issuer PCI iframes.
  - name: Card funding
    description: >-
      Fund prepaid cards with stablecoins: Apocor wallet service or
      bring-your-own (BYO) external wallet.
    x-group: Card funding
paths:
  /v1/cards/{id}/secure-details:
    get:
      tags:
        - Cards
      summary: Reveal token for Widget.js (PAN/CVV)
      description: >-
        **Method 1 — Widget reveal (default).** Returns a short-lived
        `revealToken` (~5 minutes). Load Apocor Widget.js, then pass the token
        as `clientAccessToken` to `widget.bootstrap(...)`.


        **Script URLs:**

        - Sandbox/TEST:
        `https://api.apocor.ai/sdk/card/sandbox/1.0.0/index.min.js`

        - Live: `https://api.apocor.ai/sdk/card/1.0.0/index.min.js`


        Ask Apocor to allowlist your frontend page origin. Full walkthrough:
        https://docs.apocor.ai/guides/viewing-card-details


        For PCI DSS Level 1 server-side access, use `POST
        /v1/cards/{id}/payment-details` (Method 2).
      operationId: getCardsByIdSecureDetails
      parameters:
        - $ref: '#/components/parameters/IdPath'
      responses:
        '200':
          description: Reveal token.
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
                    properties:
                      revealToken:
                        type: string
                      expiresIn:
                        type: integer
                        example: 300
              example:
                data:
                  reveal_token: reveal_abc123
                  expires_in: 300
        '400':
          $ref: '#/components/responses/BadRequest'
components:
  parameters:
    IdPath:
      name: id
      in: path
      required: true
      schema:
        type: string
      description: Resource identifier.
  responses:
    BadRequest:
      description: The request was invalid.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: INVALID_REQUEST
              message: Applicant must be approved
  schemas:
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              description: Stable, machine-readable error code.
            message:
              type: string
              description: Human-readable explanation.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Bearer access token obtained from `POST /v1/oauth/token` using your
        Apocor API key.

````