curl --request POST \
--url https://api-pacb-uat.eximpe.com/pg/tokens/delete/ \
--header 'Content-Type: application/json' \
--header 'X-API-Version: <api-key>' \
--header 'X-Client-ID: <api-key>' \
--header 'X-Client-Secret: <api-key>' \
--header 'X-Merchant-ID: <api-key>' \
--data '
{
"card_token": "c8a28bca2021ead49124",
"identifier": "USER_AS_002"
}
'import requests
url = "https://api-pacb-uat.eximpe.com/pg/tokens/delete/"
payload = {
"card_token": "c8a28bca2021ead49124",
"identifier": "USER_AS_002"
}
headers = {
"X-Client-ID": "<api-key>",
"X-Client-Secret": "<api-key>",
"X-Merchant-ID": "<api-key>",
"X-API-Version": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'X-Client-ID': '<api-key>',
'X-Client-Secret': '<api-key>',
'X-Merchant-ID': '<api-key>',
'X-API-Version': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({card_token: 'c8a28bca2021ead49124', identifier: 'USER_AS_002'})
};
fetch('https://api-pacb-uat.eximpe.com/pg/tokens/delete/', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api-pacb-uat.eximpe.com/pg/tokens/delete/",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'card_token' => 'c8a28bca2021ead49124',
'identifier' => 'USER_AS_002'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Version: <api-key>",
"X-Client-ID: <api-key>",
"X-Client-Secret: <api-key>",
"X-Merchant-ID: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api-pacb-uat.eximpe.com/pg/tokens/delete/"
payload := strings.NewReader("{\n \"card_token\": \"c8a28bca2021ead49124\",\n \"identifier\": \"USER_AS_002\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-Client-ID", "<api-key>")
req.Header.Add("X-Client-Secret", "<api-key>")
req.Header.Add("X-Merchant-ID", "<api-key>")
req.Header.Add("X-API-Version", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api-pacb-uat.eximpe.com/pg/tokens/delete/")
.header("X-Client-ID", "<api-key>")
.header("X-Client-Secret", "<api-key>")
.header("X-Merchant-ID", "<api-key>")
.header("X-API-Version", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"card_token\": \"c8a28bca2021ead49124\",\n \"identifier\": \"USER_AS_002\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api-pacb-uat.eximpe.com/pg/tokens/delete/")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-Client-ID"] = '<api-key>'
request["X-Client-Secret"] = '<api-key>'
request["X-Merchant-ID"] = '<api-key>'
request["X-API-Version"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"card_token\": \"c8a28bca2021ead49124\",\n \"identifier\": \"USER_AS_002\"\n}"
response = http.request(request)
puts response.read_body{
"success": true,
"message": "Card details deleted successfully",
"data": {}
}{
"success": false,
"error": {
"code": "ERR_AUTH_000",
"message": "Missing credentials",
"details": {
"authentication": "Missing credentials."
}
}
}{
"success": false,
"error": {
"code": "<string>",
"message": "<string>",
"details": {}
}
}Delete Saved Card
Delete a saved card token permanently. This action cannot be undone.
curl --request POST \
--url https://api-pacb-uat.eximpe.com/pg/tokens/delete/ \
--header 'Content-Type: application/json' \
--header 'X-API-Version: <api-key>' \
--header 'X-Client-ID: <api-key>' \
--header 'X-Client-Secret: <api-key>' \
--header 'X-Merchant-ID: <api-key>' \
--data '
{
"card_token": "c8a28bca2021ead49124",
"identifier": "USER_AS_002"
}
'import requests
url = "https://api-pacb-uat.eximpe.com/pg/tokens/delete/"
payload = {
"card_token": "c8a28bca2021ead49124",
"identifier": "USER_AS_002"
}
headers = {
"X-Client-ID": "<api-key>",
"X-Client-Secret": "<api-key>",
"X-Merchant-ID": "<api-key>",
"X-API-Version": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'X-Client-ID': '<api-key>',
'X-Client-Secret': '<api-key>',
'X-Merchant-ID': '<api-key>',
'X-API-Version': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({card_token: 'c8a28bca2021ead49124', identifier: 'USER_AS_002'})
};
fetch('https://api-pacb-uat.eximpe.com/pg/tokens/delete/', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api-pacb-uat.eximpe.com/pg/tokens/delete/",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'card_token' => 'c8a28bca2021ead49124',
'identifier' => 'USER_AS_002'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Version: <api-key>",
"X-Client-ID: <api-key>",
"X-Client-Secret: <api-key>",
"X-Merchant-ID: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api-pacb-uat.eximpe.com/pg/tokens/delete/"
payload := strings.NewReader("{\n \"card_token\": \"c8a28bca2021ead49124\",\n \"identifier\": \"USER_AS_002\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-Client-ID", "<api-key>")
req.Header.Add("X-Client-Secret", "<api-key>")
req.Header.Add("X-Merchant-ID", "<api-key>")
req.Header.Add("X-API-Version", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api-pacb-uat.eximpe.com/pg/tokens/delete/")
.header("X-Client-ID", "<api-key>")
.header("X-Client-Secret", "<api-key>")
.header("X-Merchant-ID", "<api-key>")
.header("X-API-Version", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"card_token\": \"c8a28bca2021ead49124\",\n \"identifier\": \"USER_AS_002\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api-pacb-uat.eximpe.com/pg/tokens/delete/")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-Client-ID"] = '<api-key>'
request["X-Client-Secret"] = '<api-key>'
request["X-Merchant-ID"] = '<api-key>'
request["X-API-Version"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"card_token\": \"c8a28bca2021ead49124\",\n \"identifier\": \"USER_AS_002\"\n}"
response = http.request(request)
puts response.read_body{
"success": true,
"message": "Card details deleted successfully",
"data": {}
}{
"success": false,
"error": {
"code": "ERR_AUTH_000",
"message": "Missing credentials",
"details": {
"authentication": "Missing credentials."
}
}
}{
"success": false,
"error": {
"code": "<string>",
"message": "<string>",
"details": {}
}
}Overview
The Delete Saved Card endpoint permanently removes a saved card token from the system. This action is irreversible and immediately invalidates the card token for all future transactions. Use this endpoint when customers want to remove payment methods from their account or when you need to clean up expired or invalid cards.Key Features
🗑️ Permanent Deletion
- Immediately removes card token from the system
- Action cannot be undone
- Token becomes invalid for all future transactions
🔒 Dual Verification
- Requires both
card_tokenandidentifierfor security - Prevents accidental or unauthorized deletions
- Ensures only the card owner can delete their cards
✅ Clean Removal
- Complete token invalidation
- No residual data retention
- Clean system state after deletion
Required Parameters
| Parameter | Type | Description |
|---|---|---|
card_token | string | Unique token of the card to delete |
identifier | string | Customer identifier that owns the card |
Security Requirements
Both parameters are required for enhanced security:card_token: Identifies the specific card to deleteidentifier: Verifies ownership of the card
- Accidental deletion of wrong cards
- Unauthorized deletion by malicious actors
- Cross-customer data access
Usage Examples
Basic Card Deletion
Request:{
"card_token": "c8a28bca2021ead49124",
"identifier": "customer_12345"
}
{
"success": true,
"message": "Card details deleted successfully",
"data": {}
}
Batch Card Cleanup
// Delete multiple expired cards
const deleteExpiredCards = async (customerId, expiredTokens) => {
const deletionPromises = expiredTokens.map(token =>
deleteCard(token, customerId)
);
try {
await Promise.all(deletionPromises);
console.log('All expired cards deleted successfully');
} catch (error) {
console.error('Error deleting some cards:', error);
}
};
const deleteCard = async (cardToken, identifier) => {
const response = await fetch('/pg/tokens/delete/', {
method: 'DELETE',
headers: {
'Content-Type': 'application/json',
'X-Client-ID': 'CLIENT_ID',
'X-Client-Secret': 'CLIENT_SECRET',
'X-Merchant-ID': 'MERCHANT_ID'
},
body: JSON.stringify({
card_token: cardToken,
identifier: identifier
})
});
return response.json();
};
Implementation Examples
Frontend Card Management
// Card deletion with user confirmation
const handleCardDeletion = async (card) => {
// Show confirmation dialog
const confirmed = await showConfirmDialog(
`Delete ${card.network} **** ${card.masked_pan.slice(-4)}?`,
'This action cannot be undone.'
);
if (!confirmed) return;
try {
// Show loading state
setDeletingCard(card.card_token);
const response = await fetch('/pg/tokens/delete/', {
method: 'DELETE',
headers: {
'Content-Type': 'application/json',
'X-Client-ID': 'CLIENT_ID',
'X-Client-Secret': 'CLIENT_SECRET',
'X-Merchant-ID': 'MERCHANT_ID'
},
body: JSON.stringify({
card_token: card.card_token,
identifier: card.identifier
})
});
const result = await response.json();
if (result.success) {
// Remove from UI
setCards(cards => cards.filter(c => c.card_token !== card.card_token));
showSuccessMessage('Card deleted successfully');
} else {
showErrorMessage('Failed to delete card');
}
} catch (error) {
showErrorMessage('Error deleting card');
} finally {
setDeletingCard(null);
}
};
Backend Integration
import requests
import logging
def delete_customer_card(card_token, customer_id, client_id, client_secret, merchant_id):
"""Delete a saved card for a customer"""
headers = {
'X-Client-ID': client_id,
'X-Client-Secret': client_secret,
'X-Merchant-ID': merchant_id,
'Content-Type': 'application/json'
}
payload = {
'card_token': card_token,
'identifier': customer_id
}
try:
response = requests.delete(
'https://api-pacb.eximpe.com/pg/tokens/delete/',
headers=headers,
json=payload
)
if response.status_code == 200:
result = response.json()
logging.info(f"Card {card_token} deleted successfully for customer {customer_id}")
return True
else:
logging.error(f"Failed to delete card: {response.status_code} - {response.text}")
return False
except requests.RequestException as e:
logging.error(f"Error deleting card: {str(e)}")
return False
# Usage in customer account management
def remove_expired_cards(customer_id):
"""Remove all expired cards for a customer"""
# First, get all saved cards
saved_cards = get_customer_cards(customer_id)
# Filter expired cards
current_date = datetime.now()
expired_cards = [
card for card in saved_cards
if datetime(card['expiry_year'], card['expiry_month'], 1) < current_date
]
# Delete expired cards
for card in expired_cards:
delete_customer_card(
card['card_token'],
customer_id,
CLIENT_ID,
CLIENT_SECRET,
MERCHANT_ID
)
Error Handling
| Status Code | Description | Possible Cause | Action |
|---|---|---|---|
200 | Success | Card deleted successfully | Update UI, show confirmation |
400 | Bad Request | Missing or invalid parameters | Validate request data |
401 | Unauthorized | Invalid credentials | Check authentication |
404 | Not Found | Card token not found or doesn’t belong to identifier | Verify token and identifier |
500 | Server Error | Internal system error | Retry request or contact support |
Common Error Scenarios
Invalid Card Token
{
"success": false,
"error": {
"code": "ERR_TOKEN_404",
"message": "Card token not found"
}
}
Mismatched Identifier
{
"success": false,
"error": {
"code": "ERR_TOKEN_ACCESS",
"message": "Card token does not belong to the specified identifier"
}
}
Best Practices
🚨 User Experience
- Always Confirm: Show confirmation dialogs before deletion
- Clear Messaging: Explain that deletion is permanent
- Loading States: Show progress during deletion
- Error Handling: Provide clear error messages
🔒 Security
- Validate Ownership: Always verify the customer owns the card
- Audit Logging: Log all deletion requests for compliance
- Rate Limiting: Implement rate limits to prevent abuse
- Authentication: Ensure proper authentication before deletion
💡 Business Logic
- Clean Up Expired Cards: Automatically remove expired cards
- User Notifications: Notify users when cards are deleted
- Backup Considerations: Consider if you need to retain deletion logs
- Transaction Checks: Ensure no pending transactions use the token
Use Cases
Customer Account Management
Allow customers to remove unwanted payment methods from their account.Card Expiry Cleanup
Automatically remove expired cards to keep the card list clean.Security Breach Response
Quickly remove compromised cards from the system.Account Closure
Remove all saved cards when a customer closes their account.After Deletion
Once a card is deleted:- Token Invalidation: The card token becomes immediately invalid
- Transaction Prevention: No future transactions can use this token
- UI Updates: Remove the card from all user interfaces
- Clean State: The system has no residual card data
Related Endpoints
- Save Card - Save new cards for customers
- List Saved Cards - View all saved cards
- Create Order - Use remaining saved cards for payments
Migration Notes
If you’re migrating from a different card storage system:- Map Tokens: Ensure proper mapping between old and new tokens
- Batch Operations: Use batch deletion for bulk migrations
- Customer Communication: Inform customers about card re-saving if needed
- Testing: Thoroughly test deletion flows before production
Authorizations
Client Application ID - Your unique application identifier used to authenticate API requests. You can find your Client ID in the Developer Settings section of the merchant dashboard.
Client Secret Key - Your secret key used alongside the Client ID for secure authentication. Keep this confidential and never expose it in client-side code. Available in the Developer Settings section of the merchant dashboard.
Merchant Identifier - The unique ID for the merchant account. This is required for PSP (Payment Service Provider) merchants who manage multiple merchant accounts. You can find merchant IDs in the Merchant Management section of the dashboard.
API Version - Specifies which version of the API to use (e.g., '1.X.X', '2.X.X', or '3.X.X'). This header allows you to control which API version your integration uses. Default version information is available in the Developer Settings.
Body
Card token details to delete