Enrôler une carte bancaire
curl --request POST \
--url https://egimgarsud.gimpayapp.com/api/v1/wallets/card \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"refContributeurDemandeur": "<string>",
"refContributeurEmetteur": "<string>",
"refUsager": "<string>",
"codeClient": "<string>",
"pan": "<string>",
"cvv": "<string>",
"dateExpiration": "<string>"
}
'import requests
url = "https://egimgarsud.gimpayapp.com/api/v1/wallets/card"
payload = {
"refContributeurDemandeur": "<string>",
"refContributeurEmetteur": "<string>",
"refUsager": "<string>",
"codeClient": "<string>",
"pan": "<string>",
"cvv": "<string>",
"dateExpiration": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
refContributeurDemandeur: '<string>',
refContributeurEmetteur: '<string>',
refUsager: '<string>',
codeClient: '<string>',
pan: '<string>',
cvv: '<string>',
dateExpiration: '<string>'
})
};
fetch('https://egimgarsud.gimpayapp.com/api/v1/wallets/card', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://egimgarsud.gimpayapp.com/api/v1/wallets/card",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'refContributeurDemandeur' => '<string>',
'refContributeurEmetteur' => '<string>',
'refUsager' => '<string>',
'codeClient' => '<string>',
'pan' => '<string>',
'cvv' => '<string>',
'dateExpiration' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://egimgarsud.gimpayapp.com/api/v1/wallets/card"
payload := strings.NewReader("{\n \"refContributeurDemandeur\": \"<string>\",\n \"refContributeurEmetteur\": \"<string>\",\n \"refUsager\": \"<string>\",\n \"codeClient\": \"<string>\",\n \"pan\": \"<string>\",\n \"cvv\": \"<string>\",\n \"dateExpiration\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://egimgarsud.gimpayapp.com/api/v1/wallets/card")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"refContributeurDemandeur\": \"<string>\",\n \"refContributeurEmetteur\": \"<string>\",\n \"refUsager\": \"<string>\",\n \"codeClient\": \"<string>\",\n \"pan\": \"<string>\",\n \"cvv\": \"<string>\",\n \"dateExpiration\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://egimgarsud.gimpayapp.com/api/v1/wallets/card")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"refContributeurDemandeur\": \"<string>\",\n \"refContributeurEmetteur\": \"<string>\",\n \"refUsager\": \"<string>\",\n \"codeClient\": \"<string>\",\n \"pan\": \"<string>\",\n \"cvv\": \"<string>\",\n \"dateExpiration\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"message": "<string>",
"status": 123,
"timestamp": "2023-11-07T05:31:56Z",
"body": {
"refUsager": "<string>",
"libelle": "<string>",
"pan": "<string>",
"typeCarteBancaire": "DEBIT",
"reference": "<string>"
}
}{
"message": "<string>",
"status": 123,
"timestamp": "2023-11-07T05:31:56Z",
"body": null
}{
"message": "<string>",
"status": 123,
"timestamp": "2023-11-07T05:31:56Z",
"body": null
}{
"message": "<string>",
"status": 123,
"timestamp": "2023-11-07T05:31:56Z",
"body": null
}Instruments de paiement
Enrôler une carte bancaire
Rattacher une carte bancaire de type débit, crédit ou prépayée à un usager déjà enrôlé dans GIMpay.
POST
/
api
/
v1
/
wallets
/
card
Enrôler une carte bancaire
curl --request POST \
--url https://egimgarsud.gimpayapp.com/api/v1/wallets/card \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"refContributeurDemandeur": "<string>",
"refContributeurEmetteur": "<string>",
"refUsager": "<string>",
"codeClient": "<string>",
"pan": "<string>",
"cvv": "<string>",
"dateExpiration": "<string>"
}
'import requests
url = "https://egimgarsud.gimpayapp.com/api/v1/wallets/card"
payload = {
"refContributeurDemandeur": "<string>",
"refContributeurEmetteur": "<string>",
"refUsager": "<string>",
"codeClient": "<string>",
"pan": "<string>",
"cvv": "<string>",
"dateExpiration": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
refContributeurDemandeur: '<string>',
refContributeurEmetteur: '<string>',
refUsager: '<string>',
codeClient: '<string>',
pan: '<string>',
cvv: '<string>',
dateExpiration: '<string>'
})
};
fetch('https://egimgarsud.gimpayapp.com/api/v1/wallets/card', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://egimgarsud.gimpayapp.com/api/v1/wallets/card",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'refContributeurDemandeur' => '<string>',
'refContributeurEmetteur' => '<string>',
'refUsager' => '<string>',
'codeClient' => '<string>',
'pan' => '<string>',
'cvv' => '<string>',
'dateExpiration' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://egimgarsud.gimpayapp.com/api/v1/wallets/card"
payload := strings.NewReader("{\n \"refContributeurDemandeur\": \"<string>\",\n \"refContributeurEmetteur\": \"<string>\",\n \"refUsager\": \"<string>\",\n \"codeClient\": \"<string>\",\n \"pan\": \"<string>\",\n \"cvv\": \"<string>\",\n \"dateExpiration\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://egimgarsud.gimpayapp.com/api/v1/wallets/card")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"refContributeurDemandeur\": \"<string>\",\n \"refContributeurEmetteur\": \"<string>\",\n \"refUsager\": \"<string>\",\n \"codeClient\": \"<string>\",\n \"pan\": \"<string>\",\n \"cvv\": \"<string>\",\n \"dateExpiration\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://egimgarsud.gimpayapp.com/api/v1/wallets/card")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"refContributeurDemandeur\": \"<string>\",\n \"refContributeurEmetteur\": \"<string>\",\n \"refUsager\": \"<string>\",\n \"codeClient\": \"<string>\",\n \"pan\": \"<string>\",\n \"cvv\": \"<string>\",\n \"dateExpiration\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"message": "<string>",
"status": 123,
"timestamp": "2023-11-07T05:31:56Z",
"body": {
"refUsager": "<string>",
"libelle": "<string>",
"pan": "<string>",
"typeCarteBancaire": "DEBIT",
"reference": "<string>"
}
}{
"message": "<string>",
"status": 123,
"timestamp": "2023-11-07T05:31:56Z",
"body": null
}{
"message": "<string>",
"status": 123,
"timestamp": "2023-11-07T05:31:56Z",
"body": null
}{
"message": "<string>",
"status": 123,
"timestamp": "2023-11-07T05:31:56Z",
"body": null
}Cet appel rattache une carte bancaire supplémentaire à un usager existant. Pour le premier instrument d’un nouvel usager, utilisez plutôt l’enrôlement d’usager.
Champs requis selon le type de carte
Quatre champs sont exigés dans tous les cas —refUsager, refContributeurDemandeur, refContributeurEmetteur et typeCarteBancaire. Les autres dépendent du type de carte :
typeCarteBancaire | Champs à fournir en plus |
|---|---|
DEBIT | pan, cvv, dateExpiration |
CREDIT | pan, cvv, dateExpiration |
PREPAYEE | codeClient |
Le schéma OpenAPI marque
codeClient, pan, cvv et dateExpiration comme facultatifs, car aucun n’est requis pour tous les types. La combinaison réellement attendue est celle du tableau ci-dessus.Format des données de carte
| Champ | Format attendu |
|---|---|
pan | Les quatre derniers chiffres de la carte, pas le numéro complet |
cvv | Le code à 3 chiffres au dos de la carte |
dateExpiration | MM/yyyy — par exemple 05/2028 |
Ne journalisez jamais le
pan complet ni le cvv, que ce soit côté serveur ou dans les traces de votre application. GIMpay ne retourne d’ailleurs qu’un PAN masqué en lecture, et le cvv est systématiquement nul dans les réponses.Points de vigilance
typeCarteBancaire accepte DEBIT, CREDIT ou PREPAYEE
typeCarteBancaire accepte DEBIT, CREDIT ou PREPAYEE
CREDIT était un écart non arbitré (absent de la spécification technique v1.1) ; l’équipe SDK Flutter le confirme désormais comme valeur valide (suivi d’implémentation du 2026-07-31), et le schéma OpenAPI servant le playground ci-dessous la documente aussi. Voir le glossaire.Aucune valeur de réseau de carte n'est définie
Aucune valeur de réseau de carte n'est définie
Le contrat ne prévoit pas de champ pour le réseau (schema) :
typeCarteBancaire porte le mode de fonctionnement de la carte, pas son réseau d’acceptation.Réponses
Le corps utile arrive dansbody, à l’intérieur de l’enveloppe commune { message, status, body, timestamp }, et contient refInstrumentPaiement ainsi que le PAN sous forme masquée.
Et ensuite ?
Vérifier les droits de la carte
GET /wallets/{referenceWallet}/authorizationExécuter une opération
Utilisez cette carte comme instrument initiateur.
Authorizations
Jeton émis par POST /api/v1/auth/token.
Body
application/json
Champs conditionnels selon typeCarteBancaire : PREPAYEE → seul codeClient est requis (pan, cvv, dateExpiration interdits) ; DEBIT/CREDIT → pan, cvv et dateExpiration sont requis (codeClient interdit).
La référence du contributeur demandeur qui demande l'enrôlement de l'instrument de paiement
La référence du contributeur émetteur de l'instrument de paiement à enrôler
La reference de l'usager
Available options:
DEBIT, CREDIT, PREPAYEE Requis pour PREPAYEE.
13 à 19 chiffres. Requis pour DEBIT/CREDIT.
Requis pour DEBIT/CREDIT.
Requis pour DEBIT/CREDIT.
Pattern:
MM/yyyy