API reference · Owned cards
List owned cards
GET
/v1/wallets/{walletId}/cardsThe cards a wallet has bought, with their codes hidden. Pages with a cursor.
Permission
cards:readAuthenticationSigned read
Staff-set limits it counts towardAll requests
.NET SDK
anis.OwnedCards.ListAsync(walletId)Parameters
| Name | In | Type | Notes |
|---|---|---|---|
walletIdrequired | path | UUID | A UUID, lower-case with hyphens. |
cursoroptional | query | string | The nextCursor of the previous page, passed back exactly as received. Leave it out for the first page. |
Request
Signed with your key. No body, no nonce.
Headers: Signature-Input, Signature, X-Anis-Date, Accept-Language (optional). The SDKs set all of them for you.
Body: none.
Responses
| Status | Meaning | Body |
|---|---|---|
| 200 | Success. | MaskedCardCollection |
| 401 | Refused: not authenticated. | Problem |
| 403 | Refused: not allowed. | Problem |
| 404 | Refused: not found, or not yours. | Problem |
| 422 | Refused: the request breaks a rule. | Problem |
| 429 | Refused: a limit was reached. | Problem |
| 503 | No decision: a dependency was unavailable. | Problem |
Every answer is signed by Anis; the SDKs check it before you see it.
Refusals
Every refusal is a signed problem. Branch on its code; each links to what it means and what to do.
| Error | Code | Status |
|---|---|---|
| Invalid credentials | invalid_credentials | 401 |
| Insufficient scope | insufficient_scope | 403 |
| Source address not allowed | source_ip_not_allowed | 403 |
| Rate limited | rate_limited | 429 |
| Account not authorised | binding_not_authorized | 403 |
| Account inactive | account_inactive | 403 |
| Wallet not granted | wallet_not_granted | 404 |
| Validation failed | validation_failed | 422 |
| Service unavailable | dependency_unavailable | 503 |
| Request timeout | request_timeout | 504 |
| Internal error | internal_error | 500 |
Types
MaskedCardCollection
| Field | Type | Notes |
|---|---|---|
itemsalways present | list of MaskedCard | The owned cards on this page. |
nextCursor | string | Pass it as cursor to get the next page. Absent on the last page. |
MaskedCard
| Field | Type | Notes |
|---|---|---|
idalways present | UUID | The sold card’s id — what revealing one card takes. |
orderOperationId | UUID | The operation id of the order that bought it. |
invoiceId | any | The invoice it is on — what revealing a whole invoice takes. |
card | object | The catalogue card it was sold from. |
card.id | UUID | The catalogue card’s id. |
card.name | LocalizedText | The catalogue card’s name, in Arabic and English. |
serialNumberMasked | string | The serial number, partly hidden. The full codes come only from a reveal. |
credentialAvailablealways present | boolean | Whether this card’s codes can be revealed. |
purchasedAt | string (date-time) | When it was bought. |
LocalizedText
| Field | Type | Notes |
|---|---|---|
ar | string | The Arabic text. |
en | string | The English text. |