---
title: "List payment methods"
method: GET
path: "/api/space/payment_methods"
tags: ["Space Billing"]
---

# List payment methods

`GET /api/space/payment_methods`

Lists the cards on file for the space as a bare array, not a paged envelope. Use a
card's `id` as `payment_method_id` in
[Top up the balance](/docs/apis/rest/space/balance/create-top-up) or as
`topup_payment_method_id` in
[Update low balance settings](/docs/apis/rest/space/balance/update-low-balance-setting).

Adding a card is not part of this API. Cards are added in the Dashboard.

#### Permissions

Authenticate with a [Personal access token](/docs/apis/authorization#personal-access-tokens) whose holder is an owner or admin of the space. A project API token is not accepted on this endpoint, and a Personal access token has no scopes: the holder's role in the space is the whole authorization decision.

## Response `200`

The request has succeeded.

- SpacePaymentMethod[]
  - `type` 'payment_method', required — The object type. Always `payment_method`.
  - `id` string, uuid, required — Universal Unique Identifier.
  - `brand` string, required — The card brand.
  - `last4` string, required — The last four digits of the card number.
  - `expires_month` integer, required — The month the card expires, from 1 to 12.
  - `expires_year` integer, required — The four-digit year the card expires.
  - `country` string, required — The ISO 3166-1 alpha-2 country code of the card.
  - `auto_topup_source` boolean, required — Whether this card is the one auto top-up charges. The active auto top-up source cannot be deleted.

## Other responses

- `401` — The credential is missing, unknown, or revoked; its holder is not a member of the space in the subdomain; the member is not an owner or admin; or billing for this space is not managed in the space itself, which is the case for a space purchased through a cloud marketplace and for a suspended or deactivated space. A space deactivated for nonpayment keeps the billing endpoints so that its outstanding balance can be settled. The body is the plain text `Unauthorized`. An unverified space instead receives the JSON body `{"message": "Please validate a phone number to access your account."}` on every endpoint under `/api/space`.
- `500` — An internal server error occurred.

## Changes

> 161 revisions in range; 3 could not be searched.

- **2026-09-15** `45bac4fd93ab` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/signalwire/apis/signalwire-rest-api/changes/api/space/payment_methods/get.md)

---

[API](https://skmtc.dev/signalwire/apis/signalwire-rest-api.md) · [All operations](https://skmtc.dev/signalwire/apis/signalwire-rest-api/llms.txt) · [OpenAPI document](https://skmtc.dev/signalwire/apis/signalwire-rest-api/revisions/20ee0f568ece?raw)
