---
title: "List Cards"
method: GET
path: "/cards"
tags: ["Cards"]
---

# List Cards

`GET /cards`

Lists the Whop cards of an account or user, including ones still being set up. Team members only see the cards assigned to them.

## Query parameters

- `account_id` string
- `user_id` string

## Response `200`

cards listed for an assigned cardholder without the ledger scope

- object
  - `data` object[], required
    - `billing` object, nullable, required — The billing address.
      - `city` string, nullable, required — Billing city.
      - `country_code` string, nullable, required — Billing country code.
      - `line1` string, nullable, required — Street address line 1.
      - `line2` string, nullable, required — Street address line 2.
      - `postal_code` string, nullable, required — Billing postal code.
      - `region` string, nullable, required — Billing region or state.
    - `canceled_at` string, date-time, nullable, required — When the card was canceled.
    - `created_at` string, date-time, nullable, required — When the card was created.
    - `expiration_month` string, nullable, required — Card expiration month.
    - `expiration_year` string, nullable, required — Card expiration year.
    - `id` string, required — Card ID, prefixed `icrd_`.
    - `last4` string, nullable, required — Last four digits of the card number. `null` for pending invitation cards.
    - `limit` object, nullable, required — The spending limit configuration.
      - `amount` number, required — The limit amount in dollars.
      - `frequency` 'daily' | 'weekly' | 'monthly' | 'one_time' | 'per_transaction', required — The window the limit amount applies to. `per_transaction` caps each individual authorization and is what a limit set with `transaction_limit` reports.
    - `name` string, nullable, required — Card display name.
    - `object` 'card', required
    - `secrets` object, nullable — Sensitive card details. Present only on `GET /cards/:id` for active cards; `null` when the card is inactive or details cannot be retrieved.
      - `card_number` string, required — Full card number.
      - `cvc` string, required — Card verification code.
      - `name_on_card` string, nullable, required — Cardholder name printed on the card.
      - `pin` string, nullable, required — The card PIN. Only returned when the request is authenticated as the user the card is assigned to; `null` for all other callers, including account API keys.
    - `spent_last_month` integer, nullable, required — Total spend in the last 30 days, in cents.
    - `status` 'null' | 'active' | 'frozen' | 'canceled' | 'invited' | 'denied', nullable, required — The card status. `denied` means the issuer declined the cardholder, so the card will never be issued.
    - `type` 'null' | 'virtual' | 'physical', nullable, required — The card type.
    - `user_id` string, nullable, required — Cardholder user ID, prefixed `user_`, when assigned.

## Other responses

- `400` — Invalid Parameters
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Resource not found

## Changes

> 40 revisions in range; 6 could not be searched.

- **2026-08-07** `f1020c3ecda4` — 4 info
  - added the optional property `error/code` to the response with the `400` status
  - added the optional property `error/code` to the response with the `401` status
  - added the optional property `error/code` to the response with the `403` status
  - added the optional property `error/code` to the response with the `404` status
- **2026-08-05** `6c970f803b46` — 1 warning
  - added the new `denied` enum value to the `data/items/status` response property for the response status `200`
- **2026-07-31** `099fdc3be422` — 5 warning
  - added the new `daily` enum value to the `data/items/limit/frequency` response property for the response status `200`
  - added the new `monthly` enum value to the `data/items/limit/frequency` response property for the response status `200`
  - added the new `one_time` enum value to the `data/items/limit/frequency` response property for the response status `200`
  - added the new `per_transaction` enum value to the `data/items/limit/frequency` response property for the response status `200`
  - …1 more
- **2026-07-26** `60bbb4a6ffbc` — 1 info
  - added the required property `data/items/secrets/pin` to the response with the `200` status

[Change history](https://skmtc.dev/whop/apis/whop-api/changes/cards/get.md)

---

[API](https://skmtc.dev/whop/apis/whop-api.md) · [All operations](https://skmtc.dev/whop/apis/whop-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/whop/whop-api/revisions/1b5d50d09479/schema)
