Kardlane
Cards

E-codes & PINs

Digital cards: send the code (and PIN) instead of photos.

POST /v1/trades
{
  "externalRef": "sale_9001",
  "cardType": "RAZER_GOLD",
  "country": "USD",
  "value": 100,
  "customerRate": 1050,
  "code": "X7KQ9PLM2RTV8WZN",
  "pin": "4821"
}

What vendors see#

Vendors price e-codes differently from physical cards, so the rate request says so — USD 100 RAZER GOLD ECODE — and the winning vendor receives the code with the PIN on the next line:

Card message
USD 100 RAZER GOLD ECODE
X7KQ9PLM2RTV8WZN
PIN: 4821

How the PIN is handled#

  • Stored encrypted, and decrypted only at the moment it’s sent to the chosen vendor.
  • Never returned by the API, and never included in webhooks, alerts, logs or the AI’s prompts — the agent only knows the card has one, so it understands a “wrong PIN” reply.
  • A physical card with a separate PIN can send assets and pin together.
Note: The same code sent twice — or a code already seen in a vendor group — is held for a person before any vendor sees it.