Skip to main content
Cards is available in sandbox only while we finish development. Dakota enables Cards per account. The Cards endpoints are in the API reference, marked Sandbox only. Endpoints, fields, and flows can still change before release.
No Dakota endpoint or webhook returns the full card number (PAN), expiry, or CVV. The most any card object carries is last4. To show the details, your backend mints a short-lived reveal session, and Cards.js uses it to render the values in the cardholder’s browser, inside a frame served by the card-data processor. The values never pass through your backend or Dakota’s.

Mint a reveal session

Call POST /cards/{card_id}/reveal_session from your backend. Your frontend never holds a Dakota API key.
  • origin is the HTTPS origin of the page that shows the card: scheme and host only, with no path. The session only works on that origin. Plain http://localhost is rejected, including in development.
  • Cards.js sends sessionType and expects expiresAt. Your backend renames sessionType to session_type on the request to Dakota, and expires_at to expiresAt on the response it returns to Cards.js.
  • Do not send an X-Idempotency-Key. Every call mints a new session, including a retry.
  • Use the host that matches the environment you give Cards.js.
Rules to design around:
  1. One session per reveal. A session works once. To show the details again, mint a new one.
  2. Short-lived. A session expires within minutes.
  3. The card must be active. A pending, frozen, or closed card cannot mint a session.
  4. Rate limited. Any of your API keys can mint sessions, up to 60 per minute and 600 per hour for your account. Over that, the call returns 429.
Your backend is the access check. Dakota verifies that the card belongs to your account, but it cannot know which of your users is asking. Authenticate the user and confirm they own the card before every mint. Without that check, any signed-in user could reveal any of your cards.

Show it with Cards.js

Cards.js (@dakota-xyz/cards-js) renders a masked card, mints a session through your backend when the user asks, reveals the values, and masks them again when the session window ends. It has React bindings. Showing card details needs a browser application. A Dakota-hosted reveal page for integrations without a frontend is planned.