Search for card by PAN

`200 OK

object

Card details without PCI information

account_token

string

required

Globally unique identifier for the account to which the card belongs.

auth_rule_tokens

array of strings

deprecated

List of identifiers for the Auth Rule(s) that are applied on the card. This field is deprecated and will no longer be populated in the Card object. The key will be removed from the schema in a future release. Use the /auth_rules endpoints to fetch Auth Rule information instead.

card_program_token

string

required

Globally unique identifier for the card program on which the card exists.

bulk_order_token

uuid | null

Globally unique identifier for the bulk order associated with this card. Only applicable to physical cards that are part of a bulk shipment

replacement_for

string | null

If the card is a replacement for another card, the globally unique identifier for the card that was replaced.

cardholder_currency

string

3-character alphabetic ISO 4217 code for the currency of the cardholder.

created

date-time

required

An RFC 3339 timestamp for when the card was created. UTC time zone.

digital_card_art_token

string | null

Specifies the digital card art to be displayed in the user's digital wallet after tokenization. This artwork must be approved by Mastercard and configured by Lithic to use.

exp_month

string

length between 2 and 2

Two digit (MM) expiry month.

exp_year

string

length between 4 and 4

Four digit (yyyy) expiry year.

funding

null

funding_account

required

Deprecated: Funding account for the card.

hostname

string

Hostname of card's locked merchant (will be empty if not applicable).

last_four

string

required

length between 4 and 4

Last four digits of the card number.

memo

string

Friendly name to identify the card.

network_program_token

string | null

Globally unique identifier for the card's network program. Null if the card is not associated with a network program. Currently applicable to Visa cards participating in Account Level Management only

pending_commands

array of strings

Indicates if there are offline PIN changes pending card interaction with an offline PIN terminal. Possible commands are: CHANGE_PIN, UNBLOCK_PIN. Applicable only to cards issued in markets supporting offline PINs.

pin_status

string

enum

required

Indicates if a card is blocked due a PIN status issue (e.g. excessive incorrect attempts).

product_id

string | null

Only applicable to cards of type PHYSICAL. This must be configured with Lithic before use. Specifies the configuration (i.e., physical card art) that the card should be manufactured with.

spend_limit

integer

required

Amount (in cents) to limit approved authorizations (e.g. 100000 would be a $1,000 limit). Transaction requests above the spend limit will be declined.

spend_limit_duration

string

enum

required

Spend limit duration values:

state

string

enum

required

Card state values:

substatus

string | null

enum

Card state substatus values:

comment

string

Additional context or information related to the card.

token

string

required

Globally unique identifier.

type

string

enum

required

Card types:

pan

string

length between 16 and 16

Primary Account Number (PAN) (i.e. the card number). Customers must be PCI compliant to have PAN returned as a field in production. Please contact https://support.lithic.com/ for questions.

cvv

string

length between 3 and 3

Three digit cvv printed on the back of the card.

`400 A parameter in the query given in the request does not match the valid queries for the endpoint.

`401 | | | | --- | --- | | User has not been authenticated | Invalid or missing API key | | API key is not active | The API key used is no longer active | | Could not find API key | The API key provided is not associated with any user | | Please provide API key in Authorization header | The Authorization header is not in the request | | Please provide API key in the form Authorization: [api-key] | The Authorization header is not formatted properly | | Insufficient privileges. Issuing API key required | Write access requires an Issuing API key. Reach out at lithic.com/contact | | Insufficient privileges to create virtual cards. | Creating virtual cards requires an additional privilege |

`404 The specified resource was not found.

`422 Unprocessable entity.

`429 Client has exceeded the number of allowed requests in a given time period. | | | | --- | --- | | Rate limited, too many requests per second | User has exceeded their per second rate limit | | Rate limited, reached daily limit | User has exceeded their daily rate limit | | Rate limited, too many keys tried | One IP has queried too many different API keys |


Example Request:

curl --request POST \
     --url https://sandbox.lithic.com/v1/cards/search_by_pan \
     --header 'accept: application/json' \
     --header 'content-type: application/json' \
     --data '
{
  "pan": "4111111289144142"
}
'\n```

## Example Response:

```json
{
  "account_token": "f3f4918c-dee9-464d-a819-4aa42901d624",
  "card_program_token": "5e9483eb-8103-4e16-9794-2106111b2eca",
  "bulk_order_token": "5e9483eb-8103-4e16-9794-2106111b2eca",
  "replacement_for": "5e9483eb-8103-4e16-9794-2106111b2eca",
  "cardholder_currency": "USD",
  "created": "2021-06-28T22:53:15Z",
  "digital_card_art_token": "5e9483eb-8103-4e16-9794-2106111b2eca",
  "exp_month": "06",
  "exp_year": "2027",
  "funding": {
    "account_name": "string",
    "created": "2026-07-18T00:25:14.908Z",
    "last_four": "string",
    "nickname": "string",
    "state": "DELETED",
    "token": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
    "type": "DEPOSITORY_CHECKING"
  },
  "hostname": "string",
  "last_four": "string",
  "memo": "New Card",
  "network_program_token": "5e9483eb-8103-4e16-9794-2106111b2eca",
  "pending_commands": [
    "string"
  ],
  "pin_status": "OK",
  "product_id": "1",
  "spend_limit": 1000,
  "spend_limit_duration": "ANNUALLY",
  "state": "CLOSED",
  "substatus": "LOST",
  "comment": "string",
  "token": "7ef7d65c-9023-4da3-b113-3b8583fd7951",
  "type": "MERCHANT_LOCKED",
  "pan": "4111111289144142",
  "cvv": "776"
}