List Cards On File
GET/api/customers/:customer/payment-methods
List a customer's saved (tokenized) cards on file. Returns only safe display metadata — brand, last four, expiry, cardholder name, the default flag, and the consent timestamp. The processor-vaulted reusable token is NEVER serialized and does not appear in the response.
customers:readGrant this scope to your token under Settings → Developer → Personal Access Tokens.
Authentication: Requires Bearer token (PAT).
Returns 200 with { data: [ ... ] } — an array of card-on-file records (no token field).
Request
Responses
- 200
- 401
- 403
- 404
- 429
OK
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Not found — no record with the given identifier (or the route does not exist). Verify the ID before retrying.
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.