Przelewy24 Card API

The Card API API from Przelewy24 — 5 operation(s) for card api.

Operations 5

GET /api/v1/card/info/{orderId} Card info #
POST /api/v1/card/chargeWith3ds Charge card with 3DS #
POST /api/v1/card/charge Charge card #
POST /api/v1/card/pay Card Payment #
PUT /api/v1/transaction/reject Reject transaction #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/przelewy24-card-api-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

przelewy24-card-api-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Przelewy24 Card API
  contact:
    name: Przelewy24 Support
    url: https://www.przelewy24.pl/support
  x-refined-note:
  - x-logo differs across the merged source definitions and was not carried
  version: '1.0'
  description: 'Operations tagged Card API across 2 of this provider''s published API definitions: openapi-extended.yml, openapi.yml. Each path carries the servers of the definition it was published in.'
servers:
- url: https://sandbox.przelewy24.pl
  description: Sandbox server (uses test data)
- url: https://secure.przelewy24.pl
  description: Production server (uses live data)
tags:
- name: Card API
paths:
  /api/v1/card/info/{orderId}:
    get:
      tags:
      - Card API
      summary: Card info
      parameters:
      - name: orderId
        in: path
        description: An unique order ID.
        required: true
        schema:
          type: integer
          format: int64
      description: The method generates information about specific payment card based on previous payment. Including reference number to charge card without CVV authorisation.
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/cardinfores'
        '400':
          description: Wrong input data
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorCodeResponse'
        '403':
          description: Not authorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnauthorizedResponse'
        '404':
          description: Transaction not exists
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorCodeResponse'
      security:
      - basicAuth: []
      operationId: getApiV1CardInfoByOrderId
      x-operation-id-source: derived
    servers:
    - url: https://sandbox.przelewy24.pl
      description: Sandbox server (uses test data)
    - url: https://secure.przelewy24.pl
      description: Production server (uses live data)
  /api/v1/card/chargeWith3ds:
    post:
      tags:
      - Card API
      summary: Charge card with 3DS
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CardChargeRequestBody'
      description: The method allows to charge a card based on the reference number.
      responses:
        '200':
          description: The charge card command has been accepted - notification will be send on success.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ChargeCard3dsSuccessResponse'
        '201':
          description: The card payment requires 3DS redirection
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ChargeCard3dsSuccessResponse'
        '400':
          description: Invalid input data
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InvalidInputData'
        '401':
          description: Not authorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnauthorizedResponse'
      security:
      - basicAuth: []
      operationId: postApiV1CardChargeWith3ds
      x-operation-id-source: derived
    servers:
    - url: https://sandbox.przelewy24.pl
      description: Sandbox server (uses test data)
    - url: https://secure.przelewy24.pl
      description: Production server (uses live data)
  /api/v1/card/charge:
    post:
      tags:
      - Card API
      summary: Charge card
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CardChargeRequestBody'
      description: The method allows to charge a card based on the reference number.
      responses:
        '200':
          description: The charge card command has been accepted - notification will be send on success.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ChargeCardSuccessResponse'
        '400':
          description: Invalid input data
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InvalidInputData'
        '401':
          description: Not authorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnauthorizedResponse'
      security:
      - basicAuth: []
      operationId: postApiV1CardCharge
      x-operation-id-source: derived
    servers:
    - url: https://sandbox.przelewy24.pl
      description: Sandbox server (uses test data)
    - url: https://secure.przelewy24.pl
      description: Production server (uses live data)
  /api/v1/card/pay:
    post:
      tags:
      - Card API
      summary: Card Payment
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CardRegisterRequestBody'
      description: Method is used for charging customer's card. Method directly sends card details. To use the method, the merchant must have PCI DSS certificate.
      responses:
        '200':
          description: The card payment has been succesed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CardPaySuccessResponse'
        '201':
          description: The card payment requires 3DS redirection.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CardPayThreeDSecureResponse'
        '400':
          description: Invalid input data
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InvalidInputData'
        '401':
          description: Not authorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnauthorizedResponse'
        '409':
          description: Conflict
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CardPayResponse409'
      security:
      - basicAuth: []
      operationId: postApiV1CardPay
      x-operation-id-source: derived
    servers:
    - url: https://sandbox.przelewy24.pl
      description: Sandbox server (uses test data)
    - url: https://secure.przelewy24.pl
      description: Production server (uses live data)
  /api/v1/transaction/reject:
    put:
      tags:
      - Card API
      summary: Reject transaction
      description: Method allows to reject an authorised transaction.
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/TransactionRejectJsonRequestBodyV11'
        description: null
        required: true
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TransactionReject200'
        '400':
          description: Invalid input data
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InvalidInputData'
        '401':
          description: Not authorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnauthorizedResponse'
        '500':
          description: Undefined error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorCodeResponse'
      operationId: putApiV1TransactionReject
      x-operation-id-source: derived
    servers:
    - url: https://sandbox.przelewy24.pl
      description: Sandbox server (uses test data)
    - url: https://secure.przelewy24.pl
      description: Production server (uses live data)
components:
  schemas:
    InvalidInputData:
      properties:
        error:
          type: string
          default: Invalid input data
          example: Invalid input data
        code:
          type: number
          default: 400
          example: 400
    cardinfores:
      properties:
        data:
          type: object
          properties:
            refId:
              type: string
              description: Unique card token (reference code)
            bin:
              type: integer
              description: Card’s BIN number
            mask:
              type: string
              description: Masked card number
            cardType:
              type: string
              description: Card type (VISA, ECMC)
            cardDate:
              type: string
              description: Expiry date in the following format MMYYYY
            hash:
              type: string
              description: Unique card hash – unique for each card
        responseCode:
          type: number
          default: 0
          example: 0
    CardPayThreeDSecureResponse:
      properties:
        data:
          properties:
            orderId:
              type: integer
              format: int64
            redirectUrl:
              type: string
          type: object
        responseCode:
          type: number
          example: 0
    CardPayResponse409:
      properties:
        error:
          type: string
          example: Unable to make payment.
        code:
          type: number
    ChargeCard3dsSuccessResponse:
      properties:
        data:
          properties:
            orderId:
              type: integer
              format: int64
            redirectUrl:
              type: string
          type: object
        responseCode:
          type: number
          example: 0
    CardPaySuccessResponse:
      properties:
        data:
          properties:
            orderId:
              type: integer
              format: int64
            redirectUrl:
              type: string
          type: object
        responseCode:
          type: number
          example: 0
    CardChargeRequestBody:
      properties:
        token:
          type: string
          description: Token registered by <a href="#tag/Transaction-service-API/paths/~1api~1v1~1transaction~1register/post"><b>transaction/register</b></a> method. Card reference number must be provided during transaction registration in <b>methodRefId</b> parameter.
    CardRegisterRequestBody:
      type: object
      properties:
        transactionToken:
          type: string
          description: Token obtained during registration
        cardNumber:
          type: string
          description: Card number
          maxLength: 16
        cardDate:
          type: string
          description: Card expiry date in format MMYYYY
        cvv:
          type: string
          description: Card CVV
        clientName:
          type: string
          description: First name and surname of cardholder
      required:
      - transactionToken
      - cardNumber
      - cardDate
      - cvv
      - clientName
    ChargeCardSuccessResponse:
      properties:
        data:
          properties:
            orderId:
              type: integer
              format: int64
              description: Registered transaction ID
          type: object
        responseCode:
          type: number
          default: 0
          example: 0
    TransactionReject200:
      properties:
        data:
          properties:
            status:
              type: string
              example: success
          type: object
        responseCode:
          type: string
          example: '0'
    TransactionRejectJsonRequestBodyV11:
      properties:
        orderId:
          type: integer
          format: int64
          description: Transaction ID assigned by Przelewy24
        sessionId:
          type: string
          description: Unique ID from Partner’s system
        sign:
          type: string
          description: <br>Checksum of parameters:<br> {<font color = "brown">"merchantId":</font>int,<font color = "brown">"orderId":</font>int,<font color = "brown">"sessionId":</font>"string",<font color = "brown">"crc":</font>"string"} <br><br>calculated with the use of sha384<br><br> <b><font color = "#DB2053">IMPORTANT!:</font></b><br>  in case json_encode function is used, the following attributes should be added <br> "JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES"
    ErrorCodeResponse:
      properties:
        error:
          type: string
          example: Undefined error
          default: Undefined error
        code:
          type: integer
          example: 500
          default: 500
      type: object
    UnauthorizedResponse:
      properties:
        error:
          type: string
          default: Incorrect authentication
          example: Incorrect authentication
        code:
          type: number
          default: 401
          example: 401
    cardinfores_2:
      properties:
        data:
          type: object
          properties:
            refId:
              type: string
              description: Unique card token (reference code)
            bin:
              type: integer
              description: Card’s BIN number
            mask:
              type: string
              description: Masked card number
            cardType:
              type: string
              description: Card type (VISA, ECMC)
            cardDate:
              type: string
              description: Expiry date in the following format MMYYYY
            hash:
              type: string
              description: Unique card hash – unique for each card
        responseCode:
          type: number
  securitySchemes:
    basicAuth:
      description: This is the default authentication method. User and secretId are available in P24 panel:<br/>- "User" it's the same value as posId,<br/>- secretId it's the samevalue as key for reports (API key).
      type: http
      scheme: basic
x-refined-from:
- openapi-extended.yml
- openapi.yml
x-tagGroups:
- name: Methods available in API
  tags:
  - Ekspres P24 API
- name: Sign parameter
  tags:
  - Calculation of sign parameter
- name: Transfer
  tags:
  - Notifications on transfer status
  - Table of transfer statuses
  - Transfer scenarios