Retrieve sensitive card details (PAN, CVV) after policy evaluation. Requires intent if policy mandates it.
API key authentication. Include your API key in the Authorization header as Bearer <api_key>.
Unique key for idempotent requests (24-hour cache)
Card ID (e.g., card_...)