Listar cartões do cliente
curl --request GET \
--url https://api.sandbox.z2pay.com/v1/customers/{customerId}/cards \
--header 'x-api-key: <api-key>'const options = {method: 'GET', headers: {'x-api-key': '<api-key>'}};
fetch('https://api.sandbox.z2pay.com/v1/customers/{customerId}/cards', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.sandbox.z2pay.com/v1/customers/{customerId}/cards"
headers = {"x-api-key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text){
"data": [
{
"id": "crd_hqx4mkpi8dcxbrb2nzynxnjky",
"customerId": "cust_j43n74fbt2geb8c1y86ssf6iw",
"brand": "visa",
"firstDigits": "411111",
"lastDigits": "1111",
"holderName": "JOAO DA SILVA",
"expirationMonth": "12",
"expirationYear": "2030",
"status": "active",
"createdAt": "2026-07-02T19:26:17.000Z",
"updatedAt": "2026-07-02T19:26:17.000Z"
}
],
"pagination": {
"page": 1,
"limit": 10,
"total": 1,
"totalPages": 1
}
}{
"error": {
"code": "VALIDATION_ERROR",
"message": "Validation failed",
"issues": [
{
"path": "status",
"message": "Status inválido. Valores aceitos: pending, waiting_payment, paid, refused, canceled, refunded"
},
{
"path": "startDate",
"message": "Data deve ser ISO 8601 com timezone (ex.: 2026-06-24T00:00:00Z)"
}
]
}
}{
"error": {
"code": "UNAUTHORIZED",
"message": "Invalid API key"
}
}{
"error": {
"code": "NOT_FOUND",
"message": "Card not found"
}
}Cartões
Listar cartões do cliente
Lista paginada dos cartões salvos de um cliente, com os dados mascarados que a API guarda.
GET
/
customers
/
{customerId}
/
cards
Listar cartões do cliente
curl --request GET \
--url https://api.sandbox.z2pay.com/v1/customers/{customerId}/cards \
--header 'x-api-key: <api-key>'const options = {method: 'GET', headers: {'x-api-key': '<api-key>'}};
fetch('https://api.sandbox.z2pay.com/v1/customers/{customerId}/cards', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.sandbox.z2pay.com/v1/customers/{customerId}/cards"
headers = {"x-api-key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text){
"data": [
{
"id": "crd_hqx4mkpi8dcxbrb2nzynxnjky",
"customerId": "cust_j43n74fbt2geb8c1y86ssf6iw",
"brand": "visa",
"firstDigits": "411111",
"lastDigits": "1111",
"holderName": "JOAO DA SILVA",
"expirationMonth": "12",
"expirationYear": "2030",
"status": "active",
"createdAt": "2026-07-02T19:26:17.000Z",
"updatedAt": "2026-07-02T19:26:17.000Z"
}
],
"pagination": {
"page": 1,
"limit": 10,
"total": 1,
"totalPages": 1
}
}{
"error": {
"code": "VALIDATION_ERROR",
"message": "Validation failed",
"issues": [
{
"path": "status",
"message": "Status inválido. Valores aceitos: pending, waiting_payment, paid, refused, canceled, refunded"
},
{
"path": "startDate",
"message": "Data deve ser ISO 8601 com timezone (ex.: 2026-06-24T00:00:00Z)"
}
]
}
}{
"error": {
"code": "UNAUTHORIZED",
"message": "Invalid API key"
}
}{
"error": {
"code": "NOT_FOUND",
"message": "Card not found"
}
}GET /customers/{customerId}/cards
Faz parte do recurso Cartões — como um cartão é salvo e como cobrá-lo depois estão lá.
Retorna uma lista paginada dos cartões daquele cliente, do mais recente para o mais antigo. Não há
filtros: o cliente do caminho já é o recorte.
A resposta é paginada, e o padrão é 20 por página. Confira
pagination.totalPages antes de
concluir que a lista acabou — nada no corpo avisa que houve corte além do próprio pagination. O
limit aceita até 100.Cliente inexistente responde 404, não lista vazia. Uma lista vazia significa uma coisa só: o
cliente existe e ainda não tem cartão salvo.
Cartão desativado some. Depois do
DELETE ele sai da listagem e o
GET por ID passa a responder 404. A resposta do próprio DELETE, com status em disabled,
é a última vez que você o vê — se precisa registrar a desativação do seu lado, é dali que ela sai.Não existe listagem global de cartões. Para varrer a conta inteira, percorra os clientes e
liste os cartões de cada um.
Exemplo
curl -G https://api.sandbox.z2pay.com/v1/customers/cust_j43n74fbt2geb8c1y86ssf6iw/cards \
-H "x-api-key: SUA_CHAVE_DE_SANDBOX" \
--data-urlencode "limit=20"
{
"data": [
{
"id": "crd_f3r7noniu07ntvbxkcb6sa6x9",
"customerId": "cust_j43n74fbt2geb8c1y86ssf6iw",
"brand": "visa",
"firstDigits": "411111",
"lastDigits": "1111",
"holderName": "JOAO DA SILVA",
"expirationMonth": "12",
"expirationYear": "2030",
"status": "active",
"createdAt": "2026-07-02T19:26:17.000Z",
"updatedAt": "2026-07-02T19:26:17.000Z"
}
],
"pagination": {
"page": 1,
"limit": 20,
"total": 1,
"totalPages": 1
}
}
Authorizations
API Key da Credential (gerada no Backoffice)
Path Parameters
ID do cliente
Query Parameters
Página da listagem. Padrão: 1.
Required range:
x >= 1Itens por página. Padrão: 20. Máximo: 100.
Required range:
1 <= x <= 100