---
title: "Validate Card CVV"
method: POST
path: "/programs/{programCode}/validateCard"
tags: ["PaymentInstrument"]
---

# Validate Card CVV

`POST /programs/{programCode}/validateCard`

Validate Card CVV

## Path parameters

- `programCode` string, required

## Headers

- `X-GD-RequestId` string, required

## Request body

- ValidateCardRequestEncrypted — Represents a request to validate a payment instrument using encrypted card data.
  - `encryptedPrivatePaymentInstrumentData` EncryptedData — Represents a container for encrypted data used in secure data transfer operations. Contains the encrypted payload and associated cryptographic metadata, including encryption version, ephemeral public key, and public key hash. Used to securely transmit sensitive information such as user data, ensuring confidentiality and integrity during transport.
    - `version` string, nullable — The version of the encryption algorithm used to encrypt the data (e.g., "v1", "v2").
    - `ephemeralPublicKey` string, nullable — The ephemeral public key used in the encryption process, typically for key exchange or session establishment.
    - `publicKeyHash` string, nullable — The hash of the public key used to verify the integrity and authenticity of the encryption key.
    - `data` string, nullable — The encrypted data payload, typically base64-encoded, containing the sensitive information.
  - `paymentInstrumentIdentifier` string, nullable — The unique identifier for the payment instrument (e.g., card) to be validated.
  - `last4Ssn` string, nullable — The last four digits of the Social Security Number (SSN) for identity verification.
  - `isExpirationDateOptional` boolean, nullable — Indicates whether the expiration date is optional for this validation request.
  - `includeClosedAccountAndCard` boolean — Indicates whether to include closed accounts and cards in the validation process.

## Response `200`

OK

- ValidateCardResponse — Represents the response for a card validation operation.
  - `accountIdentifier` string, nullable — Unique identifier for the account associated with the card being validated.
  - `paymentInstrumentIdentifier` string, nullable — Unique identifier for the payment instrument being validated.
  - `activationStatus` string, nullable — The activation status of the payment instrument.
  - `identityTypes` IdentityTypes[], nullable — The list of identity types associated with the cardholder.
    - `createdDateTime` string, date-time — The date and time when this identity type record was created.
    - `identityType` 'SSN' | 'DrivingLicense' | 'Passport' | 'MatriculaId' | 'ITIN' | 'EIN' | 'NationalIdCard' | 'ConsulateId' — The type of identity associated with this record (e.g., SSN, passport, driver's license).
    - `countryCode` string, nullable — The Country Code for given identity type associated with this record (e.g., USA, MEX).
  - `isDOBMatched` boolean, nullable — Indicates whether the date of birth (DOB) provided matches the record.
  - `isDOBVerified` boolean, nullable — Indicates whether the date of birth (DOB) has been verified.
  - `isProspect` boolean, nullable — Indicates whether the user is considered a prospect (not yet a full customer).
  - `prospectType` string, nullable — The type of prospect, if the user is a prospect.
  - `prospectIdentifier` string, nullable — Unique identifier for the prospect, if applicable.
  - `prospectStatus` integer, nullable — The status code of the prospect, if applicable.
  - `retailCardIdentifier` string, nullable — Unique identifier for the retail card, if applicable.
  - `isRetailCard` boolean, nullable — Indicates whether the card is a retail card.
  - `retailCardStatus` integer, nullable — The status code of the retail card, if applicable.
  - `productCode` string, nullable — The product code associated with the card.
  - `isExpired` boolean, nullable — Indicates whether the card is expired.
  - `isInvalidCvv` boolean, nullable — Indicates whether the provided CVV is invalid.
  - `isDirectSignUp` boolean, nullable — Indicates whether the cardholder is eligible for direct sign-up.
  - `responseDetails` ResponseDetail[], nullable — Required: A list of response details providing status codes, descriptions, and additional information about the result of the operation.
    - `code` integer — The primary status or error code for the response (e.g., 200 for success, 400 for validation error).
    - `subCode` integer, nullable — An optional subcode providing more granular detail about the response or error.
    - `description` string, nullable — A human-readable description of the response, error, or status.
    - `url` string, nullable — A URL linking to documentation or a web page with more information about the response code.

## Other responses

- `401` — Unauthorized
- `403` — Forbidden
- `500` — Internal Server Error
- `503` — Service Unavailable

---

[API](https://skmtc.net/greendot/apis/baas-apis.md) · [All operations](https://skmtc.net/greendot/apis/baas-apis/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/greendot/baas-apis/revisions/666553766b78/schema)
