---
title: "Get All External Cards"
method: GET
path: "/programs/{programCode}/accounts/{accountIdentifier}/externalcards"
tags: ["Account"]
---

# Get All External Cards

`GET /programs/{programCode}/accounts/{accountIdentifier}/externalcards`

Retrieves all external debit or credit cards linked to the specified account. Returns card details and status for each linked card.

## Path parameters

- `programCode` string, required
- `accountIdentifier` string, required

## Headers

- `X-GD-RequestId` string, required

## Response `200`

OK

- GetAllExternalCardsResponse — Get All External Cards Response – Represents the response containing a list of external payment cards associated with a customer account. Provides the maximum number of cards allowed and a collection of external card details, including identifiers, cardholder information, eligibility, and masked card data. Inherits standard response metadata from Gd.Bos.DataTransfer.Response.ResponseBase, including response details and status.
  - `externalCards` ExternalCard[], nullable — The list of external cards associated with the account. Each Gd.Bos.DataTransfer.ExternalCard contains details such as identifiers, expiration, network, cardholder, address, eligibility, and masked PAN.
    - `accountExternalPaymentIdentifier` string, uuid — The unique identifier for the external payment card.
    - `expirationDate` EncryptedData — Represents a container for encrypted data used in secure data transfer operations. Contains the encrypted payload and associated cryptographic metadata, including encryption version, ephemeral public key, and public key hash. Used to securely transmit sensitive information such as user data, ensuring confidentiality and integrity during transport.
      - `version` string, nullable — The version of the encryption algorithm used to encrypt the data (e.g., "v1", "v2").
      - `ephemeralPublicKey` string, nullable — The ephemeral public key used in the encryption process, typically for key exchange or session establishment.
      - `publicKeyHash` string, nullable — The hash of the public key used to verify the integrity and authenticity of the encryption key.
      - `data` string, nullable — The encrypted data payload, typically base64-encoded, containing the sensitive information.
    - `network` string, nullable — The card network (e.g., "Visa", "Mastercard", "Amex").
    - `bankName` string, nullable — The name of the issuing bank.
    - `nickName` string, nullable — The nickname assigned to the card by the user.
    - `firstName` string, nullable — The first name of the cardholder.
    - `lastName` string, nullable — The last name of the cardholder.
    - `address` string, nullable — The billing address associated with the card.
    - `city` string, nullable — The city of the billing address.
    - `state` string, nullable — The state or province of the billing address.
    - `zip` string, nullable — The ZIP or postal code of the billing address.
    - `fundingEligible` boolean — Indicates whether the card is eligible for funding operations (can receive deposits).
    - `withdrawalEligible` boolean — Indicates whether the card is eligible for withdrawal operations.
    - `last4PAN` string, nullable — The last four digits of the card's primary account number (PAN).
  - `maxCardsAllowed` integer — The maximum number of external cards allowed for the account.
  - `responseDetails` ResponseDetail[], nullable — Required: A list of response details providing status codes, descriptions, and additional information about the result of the operation.
    - `code` integer — The primary status or error code for the response (e.g., 200 for success, 400 for validation error).
    - `subCode` integer, nullable — An optional subcode providing more granular detail about the response or error.
    - `description` string, nullable — A human-readable description of the response, error, or status.
    - `url` string, nullable — A URL linking to documentation or a web page with more information about the response code.

## Other responses

- `401` — Unauthorized
- `403` — Forbidden
- `500` — Internal Server Error
- `503` — Service Unavailable

---

[API](https://skmtc.net/greendot/apis/baas-apis.md) · [All operations](https://skmtc.net/greendot/apis/baas-apis/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/greendot/baas-apis/versions/666553766b78/schema)
