OpenAPI specification
Release: ActiveSingle operation + dependencies. Includes the request, responses, and referenced schemas for this API—not the full product specification.
Retrieve card transactions.
/v1/party/{partyId}/baas/cards/{cardId}/transactions/inquiryUse this endpoint to retrieve transaction line items associated with the cardholder between specific dates. Note: At any given time, the maximum query range spanning from the from_datetime and the to_datetime is 30 days. Starting from the current day, up to a year's worth of transactions can be queried with the from_datetime and to_datetime split into <= 30 day intervals. If the from_datetime goes well beyond the year, it will be automatically capped. Please note, due to compliance and regulatory rules, the request to view this data must originate from the cardholder.
Showing 10 of 10 top-level parameters (10 total fields) for Card Transactions Inquiry
partyIdRequiredstringpathThe UUID of the Payfare (banking service) user.
cardIdRequiredstringpathThe UUID of the banking service card.
Api-KeyRequiredstringheaderCommerceHub API key. Use the same value as the first part of the HMAC signing input.
Auth-Token-TypeRequiredstringheaderIdentifies the CommerceHub HMAC authentication scheme.
Available enum values
Selecting a value updates the request header.
Client-Request-IdRequiredstringheaderFresh client request identifier included in the HMAC signing input. Generate a new identifier for every request, for example using String(Date.now()). Use exactly the same value in the header and signature; this does not establish an idempotency or retry guarantee.
TimestampRequiredstringheaderRequest time as a 13-digit Unix timestamp in milliseconds, generated using String(Date.now()). Use exactly this value in the HMAC signing input. Accepted clock skew awaits confirmation.
AuthorizationRequiredstringheaderBase64(HMAC-SHA-256(apiSecret, apiKey + clientRequestId + timestamp)), without a prefix. Use exactly the values sent in the corresponding headers.
statusstringqueryTransaction type that you wish to pull. Sending "all" returns posted and pending transactions. Likewise, sending "posted" or "pending" will return the corresponding transactions of that type.
Available enum values
Selecting a value updates the request body.
from_datetimestringqueryThe starting UTC datetime in ISO 8601 format from which the transactions will be filtered from.
to_datetimestringqueryThe ending UTC datetime in ISO 8601 format from which the transactions will be filtered from.
Request
Card Transactions InquiryResponse
Top-level fields returned in a successful (200) response.
statusstringThe status field.
messagestringThe message field.
dataobjectThe data field.
curl --request GET 'https://cert.api.fiservapps.com/ch/v1/party/{partyId}/baas/cards/{cardId}/transactions/inquiry?status=all&from_datetime=2023-05-01T08%3A00%3A00&to_datetime=2023-05-02T23%3A59%3A59' \
--header 'Api-Key: YOUR_API_KEY' \
--header 'Auth-Token-Type: HMAC' \
--header 'Client-Request-Id: YOUR_CLIENT_REQUEST_ID' \
--header 'Timestamp: YOUR_TIMESTAMP' \
--header 'Authorization: YOUR_BASE64_SIGNATURE' \
--header 'Accept: application/json'Standard HTTP error reference. Not every status applies to every operation.
| HTTP | Meaning | Guidance |
|---|---|---|
| 400 | Bad Request | Check the URL parameters, headers, and request payload. |
| 401 | Unauthorized | Verify the API key, HMAC signature, request ID, and timestamp. |
| 403 | Forbidden | Verify access to the requested service and resource. |
| 404 | Not Found | Check the endpoint and resource identifiers. |
| 409 | Conflict | Check the current resource state before repeating the operation. |
| 422 | Unprocessable Content | Review the returned validation details and correct the request. |
| 429 | Too Many Requests | Respect Retry-After when present; confirm retry safety before resending mutations. |
| 500 | Internal Server Error | Record the response and request identifier; confirm the outcome before retrying a mutation. |
| 502 | Bad Gateway | An upstream response failed. Confirm the outcome before retrying a mutation. |
| 503 | Service Unavailable | Respect Retry-After when present and confirm the outcome before retrying a mutation. |
| 504 | Gateway Timeout | The upstream response timed out. Check the operation outcome before resending. |
Single operation + dependencies. Includes the request, responses, and referenced schemas for this API—not the full product specification.
No Postman workflow is mapped to this operation. No product-wide collection is substituted.
QA collections: Configure your environment and credentials before running. Some requests create resources or move funds.