Paymob Card Tokens API

Tokenisation surface for the Paymob "Pay with saved card" flow. Lists and deletes tokenised cards and runs both customer-initiated (CIT) and merchant-initiated (MIT) transactions against saved tokens for recurring, on-demand, and one-click payments.

OpenAPI Specification

paymob-card-tokens-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Paymob Accept Legacy (v2) Accounts Card Tokens API
  version: '2.0'
  description: 'The legacy Paymob Accept API uses a three-step flow: authenticate to receive a bearer auth_token, register an order, then request a payment_key. The payment_key is used either with the iframe redirect or the headless /payments/pay endpoint. Refund, void, capture, transaction inquiry, and saved-card MOTO operations are exposed on this surface.'
  contact:
    name: Paymob Developers
    url: https://developers.paymob.com
servers:
- url: https://accept.paymob.com
  description: Egypt production
- url: https://ksa.paymob.com
  description: Saudi Arabia production
- url: https://uae.paymob.com
  description: UAE production
- url: https://oman.paymob.com
  description: Oman production
- url: https://pakistan.paymob.com
  description: Pakistan production
security:
- BearerAuth: []
tags:
- name: Card Tokens
paths:
  /api/acceptance/card_tokens:
    get:
      summary: List Card Tokens
      operationId: listCardTokens
      tags:
      - Card Tokens
      responses:
        '200':
          description: Card tokens
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/CardToken'
  /api/acceptance/card_tokens/{token_id}:
    delete:
      summary: Delete Card Token
      operationId: deleteCardToken
      tags:
      - Card Tokens
      parameters:
      - name: token_id
        in: path
        required: true
        schema:
          type: string
      responses:
        '204':
          description: Token deleted
components:
  schemas:
    CardToken:
      type: object
      properties:
        id:
          type: string
        token:
          type: string
        masked_pan:
          type: string
        card_subtype:
          type: string
        email:
          type: string
        order_id:
          type: integer
        created_at:
          type: string
          format: date-time
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: Bearer auth_token from /api/auth/tokens (60-minute TTL).