---
title: "Get all cards"
method: GET
path: "/cards"
tags: ["Cards"]
---

# Get all cards

`GET /cards`

Get a list of all customer cards. Cards are the primary customer identification mechanism in CareCloud. Each card carries a unique number regardless of its format - plastic, electronic, virtual, or membership. A customer can hold multiple cards of different types. Use filters such as `customer_id`, `card_type_id`, and `card_state` to narrow results. See [Cards](https://help.crmcarecloud.com/en/loyalty-engine/cards) for details.

## Query parameters

- `count` integer
- `offset` integer
- `sort_field` string
- `sort_direction` 'ASC' | 'DESC'
- `customer_id` string
- `card_number` string
- `card_type_id` string
- `state` 0 | 1
- `is_valid` true | false
- `card_number_list` string[]
- `search_secondary_card_number` true | false

## Headers

- `Accept-Language` string

## Response `200`

OK

- object
  - `data` object
    - `cards` Card[] — Collection of customer cards.
      - `card_id` string — The unique ID of the card.
      - `customer_id` string — The unique ID of the card holder. [GET /customers](https://carecloud.readme.io/reference/getcustomers)
      - `card_type_id` string, required — The unique ID of the card type. [GET /card-types](https://carecloud.readme.io/reference/getcardtypes)
      - `card_number` string, required — Card number.
      - `secondary_card_number` string — Alternative card number for this card.
      - `valid_from` string — Timestamp from which the card is valid. Accepts the format `YYYY-MM-DD HH:MM:SS` or ISO-8601 format (`YYYY-MM-DDTHH:MM:SS`). All times must be in the local timezone.
      - `valid_to` string — Timestamp until which the card is valid. Accepts the format `YYYY-MM-DD HH:MM:SS` or ISO-8601 format (`YYYY-MM-DDTHH:MM:SS`). All times must be in the local timezone.
      - `store_id` string — The unique ID of the store where the card was assigned to a customer. [GET /stores](https://carecloud.readme.io/reference/getstores)
      - `last_change` string — Date and time of the last change. *(YYYY-MM-DD HH:MM:SS)*
      - `state` 0 | 1, required — State of the card. *Possible values are: 0 - blocked / 1 - active*
    - `total_items` integer — The number of all found customer cards.

## Other responses

- `400` — Bad input parameter. The response body's `error.error_data.invalid_params[]` array lists the parameters that caused the failure, each carrying a `reason` code. See the `BadRequestErrorBody` schema for the generic reason taxonomy. Operations with domain-specific business rules document additional reasons at the operation level.
- `401` — The client has invalid credentials or auth token.
- `403` — The client does not exist or the client tried to access an unauthorized property or resource.
- `404` — The resource was not found.
- `405` — The resource does not support the specified HTTP method.
- `429` — Too many requests - more than the resource limit.
- `500` — Server is not working as expected.
- `503` — Temporary state when the service is temporarily unavailable, overloaded or there is a maintenance window.

---

[API](https://skmtc.net/crmcarecloud/apis/rest-api-reference.md) · [All operations](https://skmtc.net/crmcarecloud/apis/rest-api-reference/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/crmcarecloud/rest-api-reference/revisions/329c06dbf8d9/schema)
