> For the complete documentation index, see [llms.txt](https://docs.ur.app/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.ur.app/api-reference/api/account/managed-custody-mode/get-card-info.md).

# Get card info

Fetch card metadata and a short-lived cardToken for secure card display. The response never exposes real PAN, CVV, or expiry; render them through UR's card display script using cardToken, which expires after 5 minutes.

```json
{"openapi":"3.1.0","info":{"title":"UR API","version":"1.0.0"},"tags":[{"name":"Managed Custody Mode","description":"Server-to-server APIs where UR custodies user funds. Partner Auth (EIP-191) with user identity headers."}],"servers":[{"url":"https://openapi.ur.app","description":"Production (partner API)"},{"url":"https://uropenapi-qa.ur-inc.xyz","description":"Testnet (partner API)"}],"security":[{"partnerAuth":[]},{"userWalletAuth":[]}],"components":{"securitySchemes":{"partnerAuth":{"type":"apiKey","in":"header","name":"X-Api-Signature","description":"Partner Auth: EIP-191 signature by the partner's registered backend key, with X-Api-Deadline and optional X-Api-PublicKey headers. See the Signature and verify guide."},"userWalletAuth":{"type":"apiKey","in":"header","name":"sign","description":"User wallet auth (External Wallet Access Mode): EIP-191 signature by the user's wallet key, with tokenId, network, hash, and deadline headers. See the Signature and verify guide."}},"schemas":{"McCardResponse":{"allOf":[{"$ref":"#/components/schemas/McBaseResponse"},{"type":"object","properties":{"data":{"$ref":"#/components/schemas/McCardData"}}}]},"McBaseResponse":{"type":"object","description":"Standard UR OpenAPI response envelope. code 0 means success; a non-zero code is a business error described by message.","required":["code","message"],"properties":{"code":{"type":"integer","description":"0 on success; non-zero business error code."},"message":{"type":"string","description":"Human-readable explanation. May be empty on success."}}},"McCardData":{"type":"object","properties":{"security":{"$ref":"#/components/schemas/McCardSecurity"},"currencies":{"type":"array","items":{"type":"string"},"description":"Currencies available for card transactions."},"tokenId":{"type":"integer","description":"The user's URID token ID."},"limits":{"$ref":"#/components/schemas/McCardLimits"},"cardDesign":{"type":"string"},"cardHolder":{"type":"string"},"status":{"type":"string","description":"Card status, for example Active."},"currency":{"type":"string","description":"Default card transaction currency."},"masked":{"$ref":"#/components/schemas/McCardMasked"},"cardToken":{"type":"string","description":"Short-lived token for card detail display only. Expires after 5 minutes. Do not store or log it."},"activeTokens":{"type":"array","items":{"$ref":"#/components/schemas/McCardTokenInfo"}},"inactiveTokens":{"type":"array","items":{"$ref":"#/components/schemas/McCardTokenInfo"}},"externalId":{"type":"string","description":"Stable card management ID. Use it for card management APIs."}}},"McCardSecurity":{"type":"object","properties":{"contactlessEnabled":{"type":"boolean"},"withdrawalEnabled":{"type":"boolean"},"internetPurchaseEnabled":{"type":"boolean"},"overallLimitsEnabled":{"type":"boolean"}}},"McCardLimits":{"type":"object","properties":{"account":{"$ref":"#/components/schemas/McCardLimitItem"},"withdrawal":{"$ref":"#/components/schemas/McCardLimitItem"},"internetPurchase":{"$ref":"#/components/schemas/McCardLimitItem"}}},"McCardLimitItem":{"type":"object","properties":{"restartDate":{"type":"string","description":"Date when the limit window restarts."},"restartDateMs":{"type":"integer","description":"Restart timestamp in milliseconds."},"used":{"type":"number","description":"Used allowance."},"available":{"type":"number","description":"Remaining allowance."},"max":{"type":"number","description":"Maximum allowance."}}},"McCardMasked":{"type":"object","description":"Masked card fields. Real PAN, CVV, and expiry are rendered only through UR's card display script.","properties":{"cardNumber":{"type":"string"},"cvv2":{"type":"string"},"expiry":{"type":"string"}}},"McCardTokenInfo":{"type":"object","description":"Device wallet token, such as Apple Pay. Do not use its id for card detail display or currency settings.","properties":{"id":{"type":"string"},"type":{"type":"string"},"createdAt":{"type":"string"}}}}},"paths":{"/api/fma/v1/card":{"get":{"tags":["Managed Custody Mode"],"operationId":"mcGetCardInfo","summary":"Get card info","description":"Fetch card metadata and a short-lived cardToken for secure card display. The response never exposes real PAN, CVV, or expiry; render them through UR's card display script using cardToken, which expires after 5 minutes.","parameters":[{"name":"X-Api-Signature","in":"header","required":true,"schema":{"type":"string"},"description":"0x-prefixed 65-byte hex EIP-191 signature over the Partner Auth message. See the Signature and verify guide."},{"name":"X-Api-Deadline","in":"header","required":true,"schema":{"type":"string"},"description":"Unix seconds. UR rejects the request when the current time is past the deadline. Keep the validity window at or under 5 minutes."},{"name":"X-Api-PublicKey","in":"header","required":true,"schema":{"type":"string"},"description":"0x-prefixed partner signer address registered with UR."},{"name":"X-Ur-Id","in":"header","required":false,"schema":{"type":"string"},"description":"Send at least one of X-Ur-Id or X-External-User-Id. When both are present, UR resolves the user by X-Ur-Id first."},{"name":"X-External-User-Id","in":"header","required":false,"schema":{"type":"string"},"description":"Send at least one of X-Ur-Id or X-External-User-Id. When both are present, UR resolves the user by X-Ur-Id first."}],"responses":{"200":{"description":"Standard envelope. Business errors return HTTP 200 with a non-zero code.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/McCardResponse"}}}}}}}}}
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.ur.app/api-reference/api/account/managed-custody-mode/get-card-info.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
