## EmbedRequest Parameters

### embed_request
- **Type**: string
- **Required**: Yes  
A base64 encoded JSON string of an EmbedRequest to specify which card to load.

### hmac
- **Type**: string
- **Required**: Yes  
SHA256 HMAC of the embed_request JSON string with base64 digest.

### accept
- **Type**: string
- **Enum**: Defaults to application/json  
Generated from available response content types
  
Allowed:
- `application/json`
- `text/html`

## HTTP Status Codes

### 200
The endpoint returns an HTML document similar to the one below.  
It is up to the API client to provide css styles for these elements in the EmbedRequest. You can always rely on the `card`, `pan`, `expiry`, `cvv`, and `alert` ids, as well as the `pan-separator` class. You shouldn't make any other assumptions about the structure of the document as it could change at any time.  
Note that using the default style sheet there is no visual indication that copying is happening on-click, and you may need to add on-click styling yourself.

### 400
A parameter in the query given in the request does not match the valid queries for the endpoint.

### 401
| Condition | Message |
| --- | --- |
| User has not been authenticated | Invalid or missing API key |
| API key is not active | The API key used is no longer active |
| Could not find API key | The API key provided is not associated with any user |
| Please provide API key in Authorization header | The Authorization header is not in the request |
| Please provide API key in the form Authorization: [api-key] | The Authorization header is not formatted properly |
| Insufficient privileges. Issuing API key required | Write access requires an Issuing API key. Reach out at [lithic.com/contact](/content/contact/index.html) |
| Insufficient privileges to create virtual cards. | Creating virtual cards requires an additional privilege |

### 404
The specified resource was not found.

### 422
Unprocessable entity.

### 429
Client has exceeded the number of allowed requests in a given time period.  
| Condition | Message |
| --- | --- |
| Rate limited, too many requests per second | User has exceeded their per second rate limit |
| Rate limited, reached daily limit | User has exceeded their daily rate limit |
| Rate limited, too many keys tried | One IP has queried too many different API keys |

## Example Curl Command

```shell
curl --request GET \
     --url https://sandbox.lithic.com/v1/embed/card \
     --header 'accept: application/json'
```

## HTML Structure Example

```html
<div id="card">
    <div id="pan" onclick="copyToClip('pan')">9999<span class='pan-separator'></span>9999<span class='pan-separator'></span>9999<span class='pan-separator'></span>9999</div>
    <div id="expiry">
        <span id="month" onclick="copyToClip('month')">08</span>
        <span id="separator">/</span>
        <span id="year" onclick="copyToClip('year')">27</span>
    </div>
    <div id="cvv" onclick="copyToClip('cvv')">574</div>
    <div id="alert" class="empty"></div>
</div>
```
