> ## Documentation Index
> Fetch the complete documentation index at: https://docs.dueflow.co/llms.txt
> Use this file to discover all available pages before exploring further.

# List cards

> > **Requires scope** `cards:read` · **Minimum role** editor

[Scopes and roles](https://docs.dueflow.co/api-reference/scopes)



## OpenAPI

````yaml /openapi.json get /v1/cards
openapi: 3.1.0
info:
  title: Dueflow API
  version: 1.0.0
  description: >-
    Read and write your organization's Dueflow data. Authenticate with a
    personal access token or an organization service token as a bearer
    credential; cookies are ignored.
  termsOfService: https://dueflow.co/terms
  contact:
    name: Dueflow support
    email: support@dueflow.co
    url: https://docs.dueflow.co
servers:
  - url: https://api.dueflow.co
    description: Production
security:
  - bearerAuth: []
paths:
  /v1/cards:
    get:
      tags:
        - Cards
      summary: List cards
      description: |-
        > **Requires scope** `cards:read` · **Minimum role** editor

        [Scopes and roles](https://docs.dueflow.co/api-reference/scopes)
      operationId: getCards
      parameters:
        - name: limit
          in: query
          required: false
          schema:
            default: 50
            type: integer
            minimum: 1
            maximum: 100
        - name: cursor
          in: query
          required: false
          schema:
            type: string
        - name: updatedSince
          in: query
          required: false
          schema:
            type: string
            format: date-time
        - name: status
          in: query
          required: false
          schema:
            type: string
            enum:
              - active
              - frozen
              - canceled
              - invited
              - denied
        - name: assignedMemberId
          in: query
          required: false
          schema:
            type: string
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                        name:
                          anyOf:
                            - type: string
                            - type: 'null'
                        status:
                          anyOf:
                            - type: string
                              enum:
                                - active
                                - frozen
                                - canceled
                                - invited
                                - denied
                            - type: 'null'
                        last4:
                          anyOf:
                            - type: string
                            - type: 'null'
                        spendLimit:
                          anyOf:
                            - type: string
                            - type: 'null'
                        spendLimitFrequency:
                          anyOf:
                            - type: string
                              enum:
                                - daily
                                - weekly
                                - monthly
                                - one_time
                            - type: 'null'
                        transactionLimit:
                          anyOf:
                            - type: string
                            - type: 'null'
                        assignedMemberId:
                          anyOf:
                            - type: string
                            - type: 'null'
                        invitedAt:
                          anyOf:
                            - type: string
                              format: date-time
                            - type: 'null'
                        activatedAt:
                          anyOf:
                            - type: string
                              format: date-time
                            - type: 'null'
                        canceledAt:
                          anyOf:
                            - type: string
                              format: date-time
                            - type: 'null'
                        createdAt:
                          type: string
                          format: date-time
                        updatedAt:
                          type: string
                          format: date-time
                      required:
                        - id
                        - name
                        - status
                        - last4
                        - spendLimit
                        - spendLimitFrequency
                        - transactionLimit
                        - assignedMemberId
                        - invitedAt
                        - activatedAt
                        - canceledAt
                        - createdAt
                        - updatedAt
                      additionalProperties: false
                  hasMore:
                    type: boolean
                  nextCursor:
                    anyOf:
                      - type: string
                      - type: 'null'
                required:
                  - data
                  - hasMore
                  - nextCursor
                additionalProperties: false
        '401':
          description: Missing, malformed, expired or revoked token.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: The token lacks a required scope.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: No such resource, or the token's organization can't see it.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: Rate limited; see the `Retry-After` header.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - bearerAuth:
            - cards:read
components:
  schemas:
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
            message:
              type: string
            param:
              type: string
            requiredScopes:
              type: array
              items:
                type: string
            requestId:
              type: string
            docsUrl:
              type: string
          required:
            - code
            - message
            - requestId
            - docsUrl
          additionalProperties: false
      required:
        - error
      additionalProperties: false
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        A Dueflow access token: `dfp_` (personal) or `dfs_` (service).
        Permissions are the token's scopes intersected with the role ceiling,
        re-evaluated per request.

````