Reveal a purchase card
Mint a short-lived signed URL that displays one of the agent’s purchase cards. The full card number and CVV never pass through Grid; hand the URL to the customer’s client immediately and never store or log it. Each reveal is audit-logged with the agent as the actor. Standard cards are revealed only on the platform. Requires the MANAGE_CARDS permission.
Authorizations
Bearer token authentication for agent-scoped endpoints. The token is the accessToken returned when redeeming a device code via POST /agents/device-codes/redeem. Agent credentials are user-scoped: all requests are automatically bound to the agent's associated customer and subject to the agent's policy.
Path Parameters
Unique identifier of the card
Response
Reveal URL minted
Signed URL of the card processor's iframe that securely displays the PAN, CVV, and expiry to the cardholder. The full PAN and CVV never cross Grid's servers — render this URL in an iframe in your client to reveal card details. The URL is a short-lived bearer secret: render it immediately and never store, cache, or log it.
"https://embed.lithic.com/iframe/...?t=..."
When the signed URL stops loading. Request a new reveal rather than re-rendering an expired URL.
"2026-05-08T14:16:00Z"