Skip to content

Sensitive Card Details

Wise is a PCI DSS compliant provider and stores all card data securely. The scope for PCI compliance depends on your use case and will impact how you integrate. For all sensitive card details endpoints, follow the detailed guide.

Key capabilities:

  • Access sensitive card data (PAN, CVV, PIN) via encrypted JWE payloads

Related operations:

Fetch RSA encryption key

Request

Fetches Wise's RSA public key required for encrypting sensitive card data requests.

This key is used in the sensitive card details flow to create JWE (JSON Web Encryption) payloads.

Security
UserToken
Headers
X-External-Correlation-Idstring, (uuid), <= 36 characters

Optional UUID for correlating requests across systems. If provided, Wise echoes it back in the response. Maximum 36 characters. Learn more.

Example:f47ac10b-58cc-4372-a567-0e02b2c3d479
curl -i -X GET \
  https://twcard.wise.com/twcard-data/v1/clientSideEncryption/fetchEncryptingKey \
  -H 'Authorization: Bearer <YOUR_JWT_HERE>' \
  -H 'X-External-Correlation-Id: f47ac10b-58cc-4372-a567-0e02b2c3d479'

Responses

RSA encryption key retrieved successfully.

Headers
X-External-Correlation-Idstring, (uuid), <= 36 characters

Echoed back when X-External-Correlation-Id was included in the request. Learn more.

Example:"f47ac10b-58cc-4372-a567-0e02b2c3d479"
x-trace-idstring

Unique trace identifier assigned by Wise. Useful when contacting support about a specific request.

Example:"fba501b6d453b96789f52338f019341f"
Bodyapplication/json
versioninteger, (int32)

Version of the encryption key.

Example:1
keystring

The RSA public key.

Example:"<encryption key>"
Response
{ "version": 1, "key": "<encryption key>" }