# List saved tokens

> List saved payment method or subscription tokens for a merchant customer.

```yaml
openapi: 3.1.0
info:
  title: List saved tokens
  version: 1.0.0
  description: List saved payment method or subscription tokens for a merchant customer.
paths:
  /v1/txn/queryTokenList:
    post:
      summary: List saved tokens
      description: List saved payment method or subscription tokens for a merchant customer.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                merchantNo:
                  type: string
                  description: Merchant number assigned by Onerway when the merchant account is
                    created.
                appId:
                  type: string
                  description: Merchant application ID. When omitted, Onerway queries saved tokens
                    under the merchant number. When provided, the query is
                    limited to tokens under the specified `appId`.
                merchantCustId:
                  type: string
                  description: Unique customer identifier in the merchant system, used to limit
                    the token query to a specific customer.
                subProductType:
                  type: string
                  description: Token type to query. When omitted, Onerway queries card tokens.
                    Submit `SUBSCRIBE` to query subscription tokens.
                  enum:
                    - TOKEN
                    - SUBSCRIBE
                  x-enum-descriptions:
                    TOKEN: Saved payment method token query.
                    SUBSCRIBE: Subscription token query.
                sign:
                  type: string
                  description: Request signature string. See [Request
                    signing](/payments/get-started/request-signing) for how to
                    generate it.
              required:
                - merchantNo
                - merchantCustId
                - sign
            examples:
              list-saved-card-tokens:
                summary: List saved payment method tokens
                value:
                  merchantCustId: cust_demo_token_202606150001
                  merchantNo: replace_with_merchant_no
                  sign: "{{SIGN}}"
                  subProductType: TOKEN
      responses:
        "200":
          description: Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  respCode:
                    type: string
                    description: "`20000` means the query request was processed successfully. It
                      does not guarantee that token details are returned. Other
                      values are error codes. See [Response
                      codes](/payments/api-reference/response-codes)."
                  respMsg:
                    type: string
                    description: Human-readable message for the response code.
                  data:
                    type: object
                    properties:
                      merchantNo:
                        type: string
                        description: Merchant number assigned by Onerway, matching the merchant for this
                          query result.
                      tokenInfos:
                        type: array
                        description: Token details that match the query conditions, covering saved
                          payment method tokens or subscription tokens. Onerway
                          generates a separate subscription token for each
                          subscription contract, even when the same card is
                          used.
                        items:
                          type: object
                          properties:
                            id:
                              type: string
                              description: Binding record ID. Submit this value as `id` when calling [Delete
                                card
                                token](/payments/api-reference/endpoints/delete-card-token).
                            tokenId:
                              type: string
                              description: Token identifier used for later token payments or
                                subscription-related operations. This value is
                                distinct from the binding record `id`.
                            appId:
                              type: string
                              description: Merchant application ID that owns the token.
                            cardNumber:
                              type: string
                              description: Masked card number, keeping only the first 6 and last 4 digits.
                            paymentMethod:
                              type: string
                              description: Specific payment method, covering card brands or local payment
                                method types.
                            cardBinCountry:
                              type: string
                              description: Country or region code for the card BIN.
                            year:
                              type: string
                              description: Card expiration year.
                            month:
                              type: string
                              description: Card expiration month.
                        x-onerway-value:
                          empty: true
                          when:
                            en: Returns an empty array `[]` when no token matches the query conditions. The
                              field is not `null` and is not omitted.
                            zh: 没有符合条件的 token 时返回空数组 `[]`，不是 `null`，也不是省略字段。
                    description: Business data object carrying the merchant number and token
                      details.
```
