# 查询卡片敏感信息

> 从安全的服务端环境查询卡号、CVV 和有效期等敏感信息。

```yaml
openapi: 3.1.0
info:
  title: 查询卡片敏感信息
  version: 1.0.0
  description: 从安全的服务端环境查询卡号、CVV 和有效期等敏感信息。
paths:
  /api/v1/merchant/card/getSensitiveInfo:
    post:
      summary: 查询卡片敏感信息
      description: 从安全的服务端环境查询卡号、CVV 和有效期等敏感信息。
      parameters:
        - name: ApiKey
          in: header
          required: true
          description: Onerway 分配的发卡 API key 请求 Header。
          schema:
            type: string
            description: Onerway 分配的发卡 API key 请求 Header。
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                cardId:
                  type: integer
                  description: 卡片 ID。
              required:
                - cardId
            examples:
              default:
                summary: 查询卡片敏感信息
                value:
                  cardId: 100001
      responses:
        "200":
          description: 成功
          content:
            application/json:
              schema:
                type: object
                properties:
                  respCode:
                    type: string
                    description: 业务响应码；`20000` 表示成功。
                  respMsg:
                    type: string
                    description: 响应信息。
                  data:
                    type:
                      - object
                      - "null"
                    properties:
                      cardId:
                        type: integer
                        description: 卡片 ID。
                      cardNumber:
                        type: string
                        description: 卡号；请按 PCI DSS 要求处理和保存。
                      cvv:
                        type: string
                        description: CVV 安全码；请按 PCI DSS 要求处理。
                      expiryTime:
                        type: string
                        description: 卡片有效期，格式为 `MM/YY`。
                    description: 卡片敏感信息。
                    x-onerway-value:
                      nullable: true
                      when:
                        en: Returned as `null` when the query fails or access is not available.
                        zh: 查询失败或无访问权限时返回 `null`。
              examples:
                success:
                  summary: 成功
                  value:
                    respCode: "20000"
                    respMsg: success
                    data:
                      cardId: 100001
                      cardNumber: 411111******1111
                      cvv: "***"
                      expiryTime: 12/28
      x-onerway-lifecycle:
        phase: active
        access:
          description:
            en: Call this endpoint only from secure server-side environments with approved
              sensitive-data access.
            zh: 仅在已获准访问敏感卡数据的安全服务端环境中调用此接口。
```
