# `200      OK

object

Card details without PCI information

## account_token

string

required

Globally unique identifier for the account to which the card belongs.

## auth_rule_tokens

array of strings

deprecated

List of identifiers for the Auth Rule(s) that are applied on the card. This field is deprecated and will no longer be populated in the `Card` object. The key will be removed from the schema in a future release. Use the `/auth_rules` endpoints to fetch Auth Rule information instead.

## card_program_token

string

required

Globally unique identifier for the card program on which the card exists.

## bulk_order_token

uuid | null

Globally unique identifier for the bulk order associated with this card. Only applicable to physical cards that are part of a bulk shipment

## replacement_for

string | null

If the card is a replacement for another card, the globally unique identifier for the card that was replaced.

## cardholder_currency

string

3-character alphabetic ISO 4217 code for the currency of the cardholder.

## created

date-time

required

An RFC 3339 timestamp for when the card was created. UTC time zone.

## digital_card_art_token

string | null

Specifies the digital card art to be displayed in the user's digital wallet after tokenization. This artwork must be approved by Mastercard and configured by Lithic to use.

## exp_month

string

length between 2 and 2

Two digit (MM) expiry month.

## exp_year

string

length between 4 and 4

Four digit (yyyy) expiry year.

## funding

null

funding_account

required

Deprecated: Funding account for the card.

## hostname

string

Hostname of card's locked merchant (will be empty if not applicable).

## last_four

string

required

length between 4 and 4

Last four digits of the card number.

## memo

string

Friendly name to identify the card.

## network_program_token

string | null

Globally unique identifier for the card's network program. Null if the card is not associated with a network program. Currently applicable to Visa cards participating in Account Level Management only

## pending_commands

array of strings

Indicates if there are offline PIN changes pending card interaction with an offline PIN terminal. Possible commands are: CHANGE_PIN, UNBLOCK_PIN. Applicable only to cards issued in markets supporting offline PINs.

## pin_status

string

enum

required

Indicates if a card is blocked due a PIN status issue (e.g. excessive incorrect attempts).

* `OK`
* `BLOCKED`
* `NOT_SET`

## product_id

string | null

Only applicable to cards of type `PHYSICAL`. This must be configured with Lithic before use. Specifies the configuration (i.e., physical card art) that the card should be manufactured with.

## spend_limit

integer

required

Amount (in cents) to limit approved authorizations (e.g. 100000 would be a $1,000 limit). Transaction requests above the spend limit will be declined.

## spend_limit_duration

string

enum

required

Spend limit duration values:

* `ANNUALLY` - Card will authorize transactions up to spend limit for the trailing year.
* `FOREVER` - Card will authorize only up to spend limit for the entire lifetime of the card.
* `MONTHLY` - Card will authorize transactions up to spend limit for the trailing month. To support recurring monthly payments, which can occur on different day every month, the time window we consider for monthly velocity starts 6 days after the current calendar date one month prior.
* `TRANSACTION` - Card will authorize multiple transactions if each individual transaction is under the spend limit.

* `ANNUALLY`
* `FOREVER`
* `MONTHLY`
* `TRANSACTION`

## state

string

enum

required

Card state values:

* `CLOSED` - Card will no longer approve authorizations. Closing a card cannot be undone.
* `OPEN` - Card will approve authorizations (if they match card and account parameters).
* `PAUSED` - Card will decline authorizations, but can be resumed at a later time.
* `PENDING_FULFILLMENT` - The initial state for cards of type `PHYSICAL`. The card is provisioned pending manufacturing and fulfillment. Cards in this state can accept authorizations for e-commerce purchases, but not for "Card Present" purchases where the physical card itself is present.
* `PENDING_ACTIVATION` - At regular intervals, cards of type `PHYSICAL` in state `PENDING_FULFILLMENT` are sent to the card production warehouse and updated to state `PENDING_ACTIVATION`. Similar to `PENDING_FULFILLMENT`, cards in this state can be used for e-commerce transactions or can be added to mobile wallets. API clients should update the card's state to `OPEN` only after the cardholder confirms receipt of the card. In sandbox, the same daily batch fulfillment occurs, but no cards are actually manufactured.

* `CLOSED`
* `OPEN`
* `PAUSED`
* `PENDING_ACTIVATION`
* `PENDING_FULFILLMENT`

## substatus

string | null

enum

Card state substatus values:

* `LOST` - The physical card is no longer in the cardholder's possession due to being lost or never received by the cardholder.
* `COMPROMISED` - Card information has been exposed, potentially leading to unauthorized access. This may involve physical card theft, cloning, or online data breaches.
* `DAMAGED` - The physical card is not functioning properly, such as having chip failures or a demagnetized magnetic stripe.
* `END_USER_REQUEST` - The cardholder requested the closure of the card for reasons unrelated to fraud or damage, such as switching to a different product or closing the account.
* `ISSUER_REQUEST` - The issuer closed the card for reasons unrelated to fraud or damage, such as account inactivity, product or policy changes, or technology upgrades.
* `NOT_ACTIVE` - The card hasn’t had any transaction activity for a specified period, applicable to statuses like `PAUSED` or `CLOSED`.
* `SUSPICIOUS_ACTIVITY` - The card has one or more suspicious transactions or activities that require review. This can involve prompting the cardholder to confirm legitimate use or report confirmed fraud.
* `INTERNAL_REVIEW` - The card is temporarily paused pending further internal review.
* `EXPIRED` - The card has expired and has been closed without being reissued.
* `UNDELIVERABLE` - The card cannot be delivered to the cardholder and has been returned.
* `OTHER` - The reason for the status does not fall into any of the above categories. A comment can be provided to specify the reason.

* `LOST`
* `COMPROMISED`
* `DAMAGED`
* `END_USER_REQUEST`
* `ISSUER_REQUEST`
* `NOT_ACTIVE`
* `SUSPICIOUS_ACTIVITY`
* `INTERNAL_REVIEW`
* `EXPIRED`
* `UNDELIVERABLE`
* `OTHER`

## comment

string

Additional context or information related to the card.

## token

string

required

Globally unique identifier.

## type

string

enum

required

Card types:

* `VIRTUAL` - Card will authorize at any merchant and can be added to a digital wallet like Apple Pay or Google Pay (if the card program is digital wallet-enabled).
* `PHYSICAL` - Manufactured and sent to the cardholder. We offer white label branding, credit, ATM, PIN debit, chip/EMV, NFC and magstripe functionality.
* `SINGLE_USE` - Card is closed upon first successful authorization.
* `MERCHANT_LOCKED` - Card is locked to the first merchant that successfully authorizes the card.
* `UNLOCKED` - _[Deprecated]_ Similar behavior to VIRTUAL cards, please use VIRTUAL instead.
* `DIGITAL_WALLET` - _[Deprecated]_ Similar behavior to VIRTUAL cards, please use VIRTUAL instead.

* `MERCHANT_LOCKED`
* `PHYSICAL`
* `SINGLE_USE`
* `VIRTUAL`
* `UNLOCKED`
* `DIGITAL_WALLET`

## pan

string

length between 16 and 16

Primary Account Number (PAN) (i.e. the card number). Customers must be PCI compliant to have PAN returned as a field in production. Please contact [https://support.lithic.com/](https://support.lithic.com/) for questions.

## cvv

string

length between 3 and 3

Three digit cvv printed on the back of the card.

# `400      A parameter in the query given in the request does not match the valid queries for the endpoint.

# `401           |  |  | | --- | --- | | User has not been authenticated | Invalid or missing API key | | API key is not active | The API key used is no longer active | | Could not find API key | The API key provided is not associated with any user | | Please provide API key in Authorization header | The Authorization header is not in the request | | Please provide API key in the form Authorization: [api-key] | The Authorization header is not formatted properly | | Insufficient privileges. Issuing API key required | Write access requires an Issuing API key. Reach out at [lithic.com/contact](/content/contact/index.html) | | Insufficient privileges to create virtual cards. | Creating virtual cards requires an additional privilege |

# `404      The specified resource was not found.

# `422      Unprocessable entity.

# `429      Client has exceeded the number of allowed requests in a given time period.         |  |  | | --- | --- | | Rate limited, too many requests per second | User has exceeded their per second rate limit | | Rate limited, reached daily limit | User has exceeded their daily rate limit | | Rate limited, too many keys tried | One IP has queried too many different API keys |

---

## Example Request:

```bash
curl --request POST \
     --url https://sandbox.lithic.com/v1/cards/search_by_pan \
     --header 'accept: application/json' \
     --header 'content-type: application/json' \
     --data '
{
  "pan": "4111111289144142"
}
'\n```

## Example Response:

```json
{
  "account_token": "f3f4918c-dee9-464d-a819-4aa42901d624",
  "card_program_token": "5e9483eb-8103-4e16-9794-2106111b2eca",
  "bulk_order_token": "5e9483eb-8103-4e16-9794-2106111b2eca",
  "replacement_for": "5e9483eb-8103-4e16-9794-2106111b2eca",
  "cardholder_currency": "USD",
  "created": "2021-06-28T22:53:15Z",
  "digital_card_art_token": "5e9483eb-8103-4e16-9794-2106111b2eca",
  "exp_month": "06",
  "exp_year": "2027",
  "funding": {
    "account_name": "string",
    "created": "2026-07-18T00:25:14.908Z",
    "last_four": "string",
    "nickname": "string",
    "state": "DELETED",
    "token": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
    "type": "DEPOSITORY_CHECKING"
  },
  "hostname": "string",
  "last_four": "string",
  "memo": "New Card",
  "network_program_token": "5e9483eb-8103-4e16-9794-2106111b2eca",
  "pending_commands": [
    "string"
  ],
  "pin_status": "OK",
  "product_id": "1",
  "spend_limit": 1000,
  "spend_limit_duration": "ANNUALLY",
  "state": "CLOSED",
  "substatus": "LOST",
  "comment": "string",
  "token": "7ef7d65c-9023-4da3-b113-3b8583fd7951",
  "type": "MERCHANT_LOCKED",
  "pan": "4111111289144142",
  "cvv": "776"
}
```
