> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://beta-docs.payabli.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://beta-docs.payabli.com/_mcp/server.

# List vcards by org

GET https://api-sandbox.payabli.com/api/Query/vcards/org/{orgId}

Retrieve a list of vcards (virtual credit cards) issued for an organization. Use filters to limit results.

Reference: https://beta-docs.payabli.com/api-reference/query/get-list-of-virtual-cards-for-organization

## Authentication

- `requestToken` header (required) — API Key authentication via header

## Servers

- `https://api-sandbox.payabli.com/api` (Sandbox, default)
- `https://api.payabli.com/api` (Production)

## Request

### Path parameters

- `orgId` (integer, required) — The numeric identifier for organization, assigned by Payabli.

### Query parameters

- `fromRecord` (integer, optional, default: 0) — The number of records to skip before starting to collect the result set.
- `limitRecord` (integer, optional, default: 20) — Max number of records to return for the query. Use `0` or negative value to return all records.
- `parameters` (map from string to string, optional) — Collection of field names, conditions, and values used to filter the query. **You must remove `parameters=` from the request before you send it, otherwise Payabli will ignore the filters.** Because of a technical limitation, you can't make a request that includes filters from the API console on this page. The response won't be filtered. Instead, copy the request, remove `parameters=` and run the request in a different client. For example: \--url [https://api-sandbox.payabli.com/api/Query/transactions/org/236?parameters=totalAmount(gt)=1000\&limitRecord=20](https://api-sandbox.payabli.com/api/Query/transactions/org/236?parameters=totalAmount\(gt\)=1000\&limitRecord=20) should become: \--url [https://api-sandbox.payabli.com/api/Query/transactions/org/236?totalAmount(gt)=1000\&limitRecord=20](https://api-sandbox.payabli.com/api/Query/transactions/org/236?totalAmount\(gt\)=1000\&limitRecord=20) List of field names accepted: * status (in, nin, eq, ne) * createdAt (gt, ge, lt, le, eq, ne) * cardToken (ct, nct, eq, ne) * lastFour (ct, nct, eq, ne) * expirationDate (ct, nct, eq, ne) * mcc (ct, nct, eq, ne) * payoutId (ct, nct, eq, ne, in, nin) * customerId (ct, nct, eq, ne, in, nin) * vendorId (ct, nct, eq, ne, in, nin) * miscData1 (ct, nct, eq, ne) * miscData2 (ct, nct, eq, ne) * currentUses (gt, ge, lt, le, eq, ne) * amount (gt, ge, lt, le, eq, ne) * balance (gt, ge, lt, le, eq, ne) * paypointLegal (ne, eq, ct, nct) * paypointDba (ne, eq, ct, nct) * orgName (ne, eq, ct, nct) * externalPaypointId (ct, nct, eq, ne) * paypointId (in, nin, eq, ne) List of comparison accepted - enclosed between parentheses: * eq or empty => equal * gt => greater than * ge => greater or equal * lt => less than * le => less or equal * ne => not equal * ct => contains * nct => not contains * in => inside array separated by "|" * nin => not inside array separated by "|"
- `sortBy` (string, optional) — The field name to use for sorting results. Use `desc(field_name)` to sort descending by `field_name`, and use `asc(field_name)` to sort ascending by `field_name`.

## Response

### 200

Success

- `Summary` (VCardSummary, optional)
- `Records` (list of VCardRecord, optional)

## Errors

### 400 Bad Request Error

Bad request/ invalid data

- `any`

### 401 Unauthorized Error

Unauthorized request.

- `any`

### 500 Internal Server Error

Internal API Error

- `any`

### 503 Service Unavailable Error

Database connection error

- `isSuccess` (boolean, optional) — Boolean indicating whether the operation was successful. A `true` value indicates success. A `false` value indicates failure.
- `responseData` (map from string to any, optional) — The object containing the response data.
- `responseText` (string, optional) — Response text for operation: 'Success' or 'Declined'.

## Types

### VCardSummary

- `totalPages` (integer, required) — Total number of pages in response.
- `totalRecords` (integer, required) — Total number of records in response.
- `totalAmount` (double, required) — Total amount for the records.
- `totalactive` (integer, required) — Total number of active vCards.
- `totalamounteactive` (double, required) — Total amount of active vCards.
- `totalbalanceactive` (double, required) — Total balance of active vCards.
- `pageIdentifier` (string, optional) — Auxiliary validation used internally by payment pages and components.
- `pageSize` (integer, optional) — Number of records on each response page.

### VCardRecord

- `vcardSent` (boolean, optional) — When `true`, the vCard has been sent.
- `cardToken` (string, optional)
- `cardNumber` (string, optional) — The vCard number.
- `cvc` (string, optional) — The vCard CVC number.
- `expirationDate` (string, optional) — Expiration date in format YYYY-MM-DD. The minimum time to expire is 3 months, maximum is 3 years. If not provided, the default is 6 months.
- `status` (string, optional)
- `amount` (double, optional) — The vCard amount.
- `currentBalance` (double, optional) — The vCard's current balance.
- `expenseLimit` (double, optional)
- `expenseLimitPeriod` (string, optional)
- `maxNumberOfUses` (integer, optional)
- `currentNumberOfUses` (integer, optional)
- `exactAmount` (boolean, optional)
- `mcc` (string, optional) — MCC assigned to vCard.
- `tcc` (string, optional) — TCC assigned to vCard.
- `misc1` (string, optional) — Custom field 1.
- `misc2` (string, optional) — Custom field 2.
- `dateCreated` (datetime, optional) — Timestamp of when record was created, in UTC.
- `dateModified` (datetime, optional) — Timestamp of when record was last updated, in UTC.
- `associatedVendor` (AssociatedVendor, optional)
- `associatedCustomer` (CustomerData, optional) — Data pertaining to single customer. See [customerData Object Model](/api-reference/schemas/customerdata) for a complete reference.
- `ParentOrgName` (string, optional) — The name of the parent organization.
- `PaypointDbaname` (string, optional) — The paypoint's DBA name.
- `PaypointLegalname` (string, optional) — The paypoint's legal name.
- `PaypointEntryname` (string, optional) — The paypoint's entry name (entrypoint).
- `externalPaypointID` (string, optional) — A custom identifier for the paypoint, if applicable. Like `entrypoint` is the Payabli identifier for the merchant, `externalPaypointId` is a custom field you can use to include the merchant's ID from your own systems.

### AssociatedVendor

- `VendorNumber` (string, optional) — Custom number identifying the vendor. Must be unique in paypoint.
- `Name1` (string, optional) — Primary name for vendor.
- `Name2` (string, optional) — Secondary name for vendor.
- `EIN` (string, optional) — Business EIN or tax ID. This value is masked in API responses, for example `XXXX6789`.
- `Phone` (string, optional) — Vendor's phone number.
- `Email` (string, optional) — Vendor's email address.
- `Address1` (string, optional) — Vendor's address.
- `Address2` (string, optional) — Additional line for vendor's address.
- `City` (string, optional) — Vendor's city.
- `State` (string, optional) — Vendor's state.
- `Zip` (string, optional) — Vendor's zip code.
- `Country` (string, optional) — Vendor's country.
- `Mcc` (string, optional) — Business Merchant Category Code (MCC). [This resource](https://github.com/greggles/mcc-codes/blob/main/mcc_codes.csv) lists MCC codes.
- `LocationCode` (string, optional) — Additional location code used to identify the vendor.
- `Contacts` (list of Contacts, optional) — Array of objects describing the vendor's contacts.
- `BillingData` (BillingDataResponse, optional)
- `PaymentMethod` (string, optional)
- `VendorStatus` (integer, optional) — Vendor's status. Allowed status: - 0 Inactive - 1 Active
- `VendorId` (integer, optional)
- `EnrollmentStatus` (string, optional) — Enrollment status of vendor in payables program.
- `Summary` (VendorSummary, optional)
- `PaypointLegalname` (string, optional) — The paypoint's legal name.
- `PaypointDbaname` (string, optional) — The paypoint's DBA name.
- `PaypointEntryname` (string, optional) — Paypoint's entryname.
- `ParentOrgName` (string, optional) — The name of the parent organization.
- `CreatedDate` (datetime, optional) — Timestamp of when record was created, in UTC.
- `LastUpdated` (datetime, optional) — Timestamp of when record was last updated, in UTC.
- `remitAddress1` (string, optional) — Remittance address. Used for mailing paper checks.
- `remitAddress2` (string, optional) — Remittance address additional line. Used for mailing paper checks.
- `remitCity` (string, optional) — Remittance address city. Used for mailing paper checks.
- `remitState` (string, optional) — Remittance address state. Used for mailing paper checks.
- `remitZip` (string, optional) — Remittance address ZIP code. Used for mailing paper checks.
- `remitCountry` (string, optional) — Remittance address country. Used for mailing paper checks.
- `payeeName1` (string, optional) — Alternative name used to receive paper check.
- `payeeName2` (string, optional) — Alternative name used to receive paper check.
- `customField1` (string, optional)
- `customField2` (string, optional)
- `customerVendorAccount` (string, optional)
- `InternalReferenceId` (long, optional) — Internal identifier for global vendor account.
- `additionalData` (map from string to map from string to any, optional) — Custom dictionary of key:value pairs. You can use this field to store any data related to the object or for your system. If you are using [custom identifiers](/developer-guides/entities-custom-identifiers), pass those in this object. Example usage: ```json { "additionalData": { "key1": "value1", "key2": "value2", "key3": "value3" } } ```
- `externalPaypointID` (string, optional)

### CustomerData

Data pertaining to single customer. See [customerData Object Model](/api-reference/schemas/customerdata) for a complete reference.

- `additionalFields` (map from string to string, optional) — Additional Custom fields in format "key":"value".
- `address` (string, optional) — Customer address
- `address1` (string, optional) — Additional customer address
- `balance` (double, optional) — Customer balance.
- `city` (string, optional) — Customer city
- `company` (string, optional) — Company name
- `country` (string, optional) — Customer country in ISO-3166-1 alpha 2 format See https://en.wikipedia.org/wiki/ISO_3166-1 for reference.
- `createdAt` (datetime, optional) — Timestamp of when record was created, in UTC.
- `customerNumber` (string, optional) — User-provided unique identifier for the customer. This is typically the customer ID from your own system.
- `customerPsw` (string, optional) — Customer password for customer portal
- `customerStatus` (integer, optional) — Customer Status. Possible values: - `-99` Deleted - `0` Inactive - `1` Active - `85` Locked (typically due to multiple failed login attempts)
- `customerUsername` (string, optional) — Customer username for customer portal
- `email` (string, optional) — Customer email address.
- `firstname` (string, optional) — Customer first name
- `identifierFields` (list of string, optional) — List of fields acting as customer identifiers, to be used instead of CustomerNumber.
- `lastname` (string, optional) — Customer last name
- `phone` (string, optional) — Customer phone number
- `shippingAddress` (string, optional) — The shipping address.
- `shippingAddress1` (string, optional) — Additional line for shipping address.
- `shippingCity` (string, optional) — Shipping city.
- `shippingCountry` (string, optional) — Shipping address country.
- `shippingState` (string, optional) — Shipping state or province.
- `shippingZip` (string, optional) — Shipping ZIP code. For Pay In functions, this field supports 5-digit and 9-digit ZIP codes and alphanumeric Canadian postal codes. For example: "37615-1234" or "37615".
- `state` (string, optional) — Customer State
- `timeZone` (integer, optional) — Timezone, in UTC offset. For example, -5 is Eastern time.
- `zip` (string, optional) — Customer zip code

### Contacts

- `contactEmail` (string, optional) — Contact email address.
- `contactName` (string, optional) — Contact name.
- `contactPhone` (string, optional) — Contact phone number.
- `contactTitle` (string, optional) — Contact title.

### BillingDataResponse

- `accountNumber` (string, optional) — Masked account number for bank account.
- `bankAccountFunction` (integer, optional) — Describes whether the bank account is used for deposits or withdrawals in Payabli: - `0`: Deposit - `1`: Withdrawal - `2`: Deposit and withdrawal
- `bankAccountHolderName` (string, optional) — The accountholder's name.
- `bankAccountHolderType` (enum, optional) — Describes whether the bank is a personal or business account.
  - Allowed values: `Personal`, `Business`
- `bankName` (string, optional) — Name of bank for account.
- `id` (integer, optional) — The bank's ID in Payabli.
- `routingAccount` (string, optional) — Routing number of bank account.
- `typeAccount` (enum, optional) — Type of bank account: Checking or Savings.
  - Allowed values: `Checking`, `Savings`

### VendorSummary

- `inTransitBills` (integer, optional)
- `inTransitBillsAmount` (double, optional)
- `overdueBills` (integer, optional)
- `overdueBillsAmount` (double, optional)
- `paidBills` (integer, optional)
- `paidBillsAmount` (double, optional)
- `pendingBills` (integer, optional)
- `pendingBillsAmount` (double, optional)
- `totalBills` (integer, optional)
- `totalBillsAmount` (double, optional)

## Examples

**Response**

```json
{
  "Summary": {
    "totalPages": 1,
    "totalRecords": 5,
    "totalAmount": 2500,
    "totalactive": 5,
    "totalamounteactive": 2500,
    "totalbalanceactive": 1875.25,
    "pageIdentifier": "XXXXXXXXXXXXXX",
    "pageSize": 20
  },
  "Records": [
    {
      "vcardSent": true,
      "cardToken": "vcrd_5Ty8NrBzXjKuqHm9DwElfP",
      "cardNumber": "44XX XXXX XXXX 1234",
      "cvc": "XXX",
      "expirationDate": "2025-12",
      "status": "Active",
      "amount": 500,
      "currentBalance": 375.25,
      "expenseLimit": 100,
      "expenseLimitPeriod": "monthly",
      "maxNumberOfUses": 10,
      "currentNumberOfUses": 3,
      "exactAmount": false,
      "mcc": "5812",
      "tcc": "T01",
      "misc1": "Invoice #12345",
      "misc2": "Project: Office Supplies",
      "dateCreated": "2023-01-15T09:30:00Z",
      "dateModified": "2023-02-20T14:15:22Z",
      "associatedVendor": {
        "VendorNumber": "V-12345",
        "Name1": "Office Supply Co.",
        "EIN": "XXXXX6789",
        "Email": "billing@officesupply.example.com",
        "VendorId": 1542
      },
      "associatedCustomer": {
        "firstname": "Acme",
        "lastname": "Corporation"
      },
      "ParentOrgName": "SupplyPro",
      "PaypointDbaname": "Global Factory LLC",
      "PaypointLegalname": "Global Factory LLC",
      "PaypointEntryname": "4872acb376a",
      "externalPaypointID": "pay-10"
    }
  ]
}
```

**SDK Code**

```python ListVCardsOrg
import requests

url = "https://api-sandbox.payabli.com/api/Query/vcards/org/123"

querystring = {"fromRecord":"251","limitRecord":"0","sortBy":"desc(field_name)"}

headers = {"requestToken": "<apiKey>"}

response = requests.get(url, headers=headers, params=querystring)

print(response.json())
```

```javascript ListVCardsOrg
const url = 'https://api-sandbox.payabli.com/api/Query/vcards/org/123?fromRecord=251&limitRecord=0&sortBy=desc%28field_name%29';
const options = {method: 'GET', headers: {requestToken: '<apiKey>'}};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go ListVCardsOrg
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://api-sandbox.payabli.com/api/Query/vcards/org/123?fromRecord=251&limitRecord=0&sortBy=desc%28field_name%29"

	req, _ := http.NewRequest("GET", url, nil)

	req.Header.Add("requestToken", "<apiKey>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby ListVCardsOrg
require 'uri'
require 'net/http'

url = URI("https://api-sandbox.payabli.com/api/Query/vcards/org/123?fromRecord=251&limitRecord=0&sortBy=desc%28field_name%29")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)
request["requestToken"] = '<apiKey>'

response = http.request(request)
puts response.read_body
```

```java ListVCardsOrg
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.get("https://api-sandbox.payabli.com/api/Query/vcards/org/123?fromRecord=251&limitRecord=0&sortBy=desc%28field_name%29")
  .header("requestToken", "<apiKey>")
  .asString();
```

```php ListVCardsOrg
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api-sandbox.payabli.com/api/Query/vcards/org/123?fromRecord=251&limitRecord=0&sortBy=desc%28field_name%29', [
  'headers' => [
    'requestToken' => '<apiKey>',
  ],
]);

echo $response->getBody();
```

```csharp ListVCardsOrg
using RestSharp;

var client = new RestClient("https://api-sandbox.payabli.com/api/Query/vcards/org/123?fromRecord=251&limitRecord=0&sortBy=desc%28field_name%29");
var request = new RestRequest(Method.GET);
request.AddHeader("requestToken", "<apiKey>");
IRestResponse response = client.Execute(request);
```

```swift ListVCardsOrg
import Foundation

let headers = ["requestToken": "<apiKey>"]

let request = NSMutableURLRequest(url: NSURL(string: "https://api-sandbox.payabli.com/api/Query/vcards/org/123?fromRecord=251&limitRecord=0&sortBy=desc%28field_name%29")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "GET"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```