> ## Documentation Index
> Fetch the complete documentation index at: https://partner-docs.contro.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Reveal card data

> Choose the right method to access card PAN, CVV, and expiry for your integration

## Overview

Contro provides two methods to access sensitive card data (PAN, CVV, expiry date). The right choice depends on your PCI DSS compliance status and how you want to handle card data.

<Info>
  Card data is highly sensitive and regulated. Not every organization is permitted to store or process this information directly. Choose the method that matches your compliance posture.
</Info>

## Decision flowchart

```mermaid theme={null}
flowchart TD
    A[Need to reveal card data] --> B{Is your organization<br>PCI DSS compliant?}
    B -->|Yes| C{Do you need card data<br>on your servers?}
    B -->|No| D[Embedded widget]
    C -->|Yes - backend processing,<br>batch ops, custom UI| E[Direct API]
    C -->|No - just displaying<br>to end-users| F{Want full UI control?}
    F -->|Yes| E
    F -->|No - faster setup| D

    E --> G["fa:fa-lock Direct API method"]
    D --> H["fa:fa-window-maximize Embedded widget method"]

    style G fill:#1a1a2e,color:#fff
    style H fill:#1a1a2e,color:#fff
```

## Methods compared

| Aspect | [Direct API](/partner/direct-api-reveal) | [Embedded widget](/partner/embedded-widget-reveal) |
| - | - | - |
| **PCI DSS required** | Yes (SAQ-D) | No - reduced scope (SAQ-A) |
| **Card data touches your servers** | Yes (RSA-encrypted) | No |
| **UI customization** | Full control - you build the UI | CSS stylesheet on Contro-hosted widget |
| **Implementation effort** | Higher - key management + decryption | Lower - embed an iframe |
| **Best for** | Backend systems, batch operations, custom UIs | End-user card reveal UIs |
| **Endpoint** | `GET /partner/cards/{id}/reveal` | `POST /partner/cards/{id}/reveal-html` |

## Direct API

**Best for:** Organizations with PCI DSS compliance that need card data on their servers - backend processing, batch operations, or fully custom card display UIs.

**How it works:**

1. Upload your RSA public key to Contro
2. Call the reveal endpoint
3. Decrypt the RSA-encrypted response with your private key
4. Use the card data however you need

Card data is encrypted end-to-end with your RSA key. Contro never exposes plaintext card data in API responses.

<Card title="Direct API guide" icon="lock" href="/partner/direct-api-reveal">
  Full setup: key generation, upload, API call, and decryption examples
</Card>

## Embedded widget

**Best for:** Organizations that want to show card data to end-users without handling sensitive data on their servers. No PCI DSS certification needed.

**How it works:**

1. Configure allowed origins in your dashboard settings
2. Generate a short-lived, single-use signed URL via API
3. Embed the URL in an iframe - Contro renders the card data
4. Optionally apply custom CSS for branding

Sensitive data never touches your servers. The widget is hosted by Contro with strict CSP headers, single-use tokens, and 60-second expiry.

<Card title="Embedded widget guide" icon="window-maximize" href="/partner/embedded-widget-reveal">
  Full setup: origin configuration, URL generation, iframe embedding, and styling
</Card>

## Security

Both methods are designed with security as a default:

* **Direct API**: RSA-4096 encryption with OAEP-SHA256. Card data is encrypted before leaving Contro's servers.
* **Embedded widget**: Single-use tokens, 60-second expiry, `frame-ancestors` CSP restricted to your allowed origins.
* **Sandbox testing**: Both methods work with `sk_test_` keys using test card data - no real card data is exposed during development.

## Next steps

1. **Determine your PCI status** - if unsure, start with the [embedded widget](/partner/embedded-widget-reveal) for faster integration
2. **Set up sandbox testing** - both methods return test data with `sk_test_` API keys
3. **Configure settings** - upload your RSA key or set allowed origins in [https://partner.contro.me/settings](https://partner.contro.me/settings) <Icon icon="arrow-up-right-from-square" size={12} />
