> ## Documentation Index
> Fetch the complete documentation index at: https://gnosispay-feat-v2-auth-module.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Get Card PIN

> Returns the card PIN encrypted under a client-provided AES session key. The
caller RSA-OAEP encrypts a one-time AES-256 session key with the PCI public
key and passes it as `encryptedKey`; the EIP-712 signature over a prior
`view-pin` challenge is passed via the `x-eip712-signature` /
`x-eip712-nonce` headers. Fetched from partner-api over HTTP.



## OpenAPI

````yaml https://core.prod.gnosispay.com/user-api/openapi.json get /pci/cards/{cardId}/pin
openapi: 3.1.0
info:
  title: User Service
  version: 0.0.0
servers: []
security: []
tags:
  - name: Health
  - name: Auth
  - name: User
  - name: Cards
  - name: Phone
  - name: PCI
  - name: Terms
  - name: Source of Funds
paths:
  /pci/cards/{cardId}/pin:
    get:
      tags:
        - PCI
      summary: Get Card PIN
      description: >-
        Returns the card PIN encrypted under a client-provided AES session key.
        The

        caller RSA-OAEP encrypts a one-time AES-256 session key with the PCI
        public

        key and passes it as `encryptedKey`; the EIP-712 signature over a prior

        `view-pin` challenge is passed via the `x-eip712-signature` /

        `x-eip712-nonce` headers. Fetched from partner-api over HTTP.
      operationId: PCI_getCardPin
      parameters:
        - name: cardId
          in: path
          required: true
          schema:
            $ref: '#/components/schemas/uuid'
        - name: encryptedKey
          in: query
          required: true
          description: Base64-encoded RSA-OAEP encrypted AES-256 session key.
          schema:
            type: string
          explode: false
        - name: x-eip712-signature
          in: header
          required: true
          description: EIP-712 signature over the `view-pin` challenge.
          schema:
            type: string
        - name: x-eip712-nonce
          in: header
          required: true
          description: Nonce of the challenge that was signed.
          schema:
            type: string
      responses:
        '200':
          description: The request has succeeded.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PciEncryptedPinResponse'
        '401':
          description: Access is unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Unauthorized'
        '404':
          description: The server cannot find the requested resource.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NotFound'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - BearerAuth: []
components:
  schemas:
    uuid:
      type: string
      format: uuid
    PciEncryptedPinResponse:
      type: object
      required:
        - encryptedPin
        - iv
      properties:
        encryptedPin:
          type: string
          description: AES-GCM encrypted PIN (PIN Block 2 format), Base64-encoded.
        iv:
          type: string
          description: Base64-encoded AES-GCM initialization vector.
    Unauthorized:
      type: object
      required:
        - success
        - error
      properties:
        success:
          type: boolean
          enum:
            - false
        error:
          type: string
    NotFound:
      type: object
      required:
        - success
        - error
      properties:
        success:
          type: boolean
          enum:
            - false
        error:
          type: string
    Error:
      type: object
      required:
        - success
        - error
      properties:
        success:
          type: boolean
          enum:
            - false
        error:
          type: string
  securitySchemes:
    BearerAuth:
      type: http
      scheme: Bearer

````