> ## Documentation Index
> Fetch the complete documentation index at: https://docs.payluk.ng/llms.txt
> Use this file to discover all available pages before exploring further.

# List customer debit cards

> Requires the merchant to have the save-debit-cards feature enabled. Requires the `customer-id` header.



## OpenAPI

````yaml openapi.json GET /v1/cards
openapi: 3.0.3
info:
  title: Payluk ThirdParty API
  version: 1.0.0
  description: >-
    Merchant / Business API for the Payluk escrow and payments platform.


    All routes are mounted under `/v1` and authenticated with a secret key.
    Every response uses the standard envelope `{ status, message, data }`.
  contact:
    name: Payluk Developer Support
    email: support@payluk.ng
    url: https://payluk.ng
servers:
  - url: https://staging.api.payluk.ng
    description: 'Staging: use sk_test_ keys here for safe testing'
  - url: https://api.payluk.ng
    description: 'Production: use sk_live_ keys'
security:
  - bearerAuth: []
tags:
  - name: Escrow
    description: Create and manage standard escrow payment links.
  - name: Milestone Escrow
    description: Escrows that release funds in parts as milestones are confirmed.
  - name: Vault Escrow
    description: >-
      Merchant-only pooled-stake escrows: customers stake from their wallets and
      the merchant declares the winner.
  - name: Categories
    description: Organise escrows into merchant-defined categories.
  - name: Merchant Customers
    description: Manage the buyers and sellers that transact under your merchant account.
  - name: Disputes
    description: Confirm deliveries, raise disputes and resolve them.
  - name: Payments
    description: Fund wallets and escrows, verify references and manage payout details.
  - name: Debit Cards
    description: List and remove customers' saved debit cards.
  - name: Crypto Whitelist
    description: Manage whitelisted crypto withdrawal addresses.
  - name: Misc
    description: Supporting reference data.
paths:
  /v1/cards:
    get:
      tags:
        - Debit Cards
      summary: List customer debit cards
      description: >-
        Requires the merchant to have the save-debit-cards feature enabled.
        Requires the `customer-id` header.
      operationId: getCards
      parameters:
        - $ref: '#/components/parameters/CustomerIdHeader'
      responses:
        '200':
          description: Cards fetched.
          content:
            application/json:
              example:
                status: 200
                message: Cards fetched successfully
                data:
                  - id: 665f1b2c9a1e4d0012ab3c50
                    cardInfo:
                      last4: '4081'
                      exp_month: '12'
                      exp_year: '2030'
                      card_type: visa DEBIT
                      brand: visa
                      customer: Ada Eze
                      bank: TEST BANK
                    isDefault: true
                    createdAt: '2026-05-29T15:49:20.041Z'
        '403':
          description: Feature not enabled on the merchant account.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
              example:
                status: 403
                message: >-
                  This feature is not enabled on your merchant account, please
                  enable to access this route
                data: {}
components:
  parameters:
    CustomerIdHeader:
      name: customer-id
      in: header
      required: true
      description: The merchant customer this request acts on behalf of.
      schema:
        type: string
      example: 665f1b2c9a1e4d0012ab3c01
  schemas:
    ApiError:
      type: object
      description: Standard error envelope.
      properties:
        status:
          type: integer
          example: 400
        message:
          type: string
          example: Action not allowed
        data:
          type: object
          example: {}
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        Your secret key as a Bearer token. The key prefix selects the
        environment: `sk_test_...` (test) or `sk_live_...` (live).

````