Validate card
Confirms the card can be paid towards, using the last four digits and the registered mobile — never the full card number.
Sample reference
This shows the shape of the call — the operation, its fields and what comes back. The exact paths, base URL and any extra fields are confirmed with your sandbox credentials.
{BASE_URL}/v1/cards/validate🚧 Never send the full card number
📘 Show the cardholder name back
Headers
AuthorizationstringrequiredBearer <your API key>. Sandbox and production keys are separate.
Content-Typestringrequiredapplication/json on every request that has a body.
Request body
issuerstringrequiredIssuer code, e.g. HDFC, ICICI, SBI.
cardLast4stringrequiredLast four digits only.
registeredMobilestringrequiredMobile number registered with the issuer.
Response fields
validbooleanrequiredFalse if the issuer does not match the card and mobile.
networkstringoptionalVISA, MASTERCARD or RUPAY.
Errors
Every API returns the same envelope on failure, so one handler covers the whole catalogue.
VALIDATION_ERRORA field is missing or malformed. The message names the field.
UNAUTHORIZEDThe API key is missing, wrong, or for the other environment.
NOT_FOUNDNo resource with that ID or reference exists.
DUPLICATE_REFERENCEThis clientReference was already used. Safe to treat as a repeat of the first call.
RATE_LIMITEDToo many requests. Back off and retry after the Retry-After header.
UPSTREAM_UNAVAILABLEThe biller, bank or network is down. Retry later; nothing was charged.
