List card holders
curl --request GET \
--url https://api.opencard.io/api/v1/application/accounts/{accountId}/organizations/{organizationId}/cardholders \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.opencard.io/api/v1/application/accounts/{accountId}/organizations/{organizationId}/cardholders', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.opencard.io/api/v1/application/accounts/{accountId}/organizations/{organizationId}/cardholders"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.opencard.io/api/v1/application/accounts/{accountId}/organizations/{organizationId}/cardholders",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"current_page": 1,
"data": [
{
"id": 15,
"reference_id": "employee_john_42",
"organization_id": 3,
"identity_id": 123,
"email": "john@acme.se",
"created_at": "2026-06-08T10:00:00.000000Z",
"updated_at": "2026-06-08T10:30:00.000000Z",
"meta": {
"ssn": true,
"signed": true,
"signed_at": "2026-06-08T10:30:00.000000Z",
"email_status": "delivered",
"pdpc_url": "https://sandbox-api.opencard.io/accounts/1/pdpcs/8/sign/abc...",
"system": "Acme EMS",
"organization_number": "5561234567"
},
"identity": {
"name": "Anna Andersson",
"employee_id": "001"
}
}
],
"per_page": 15,
"total": 1,
"last_page": 1
}Card Holders
List card holders
Paginated list. Each item includes identity (name, employee_id) when linked — no separate identities call needed for display.
GET
/
accounts
/
{accountId}
/
organizations
/
{organizationId}
/
cardholders
List card holders
curl --request GET \
--url https://api.opencard.io/api/v1/application/accounts/{accountId}/organizations/{organizationId}/cardholders \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.opencard.io/api/v1/application/accounts/{accountId}/organizations/{organizationId}/cardholders', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.opencard.io/api/v1/application/accounts/{accountId}/organizations/{organizationId}/cardholders"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.opencard.io/api/v1/application/accounts/{accountId}/organizations/{organizationId}/cardholders",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"current_page": 1,
"data": [
{
"id": 15,
"reference_id": "employee_john_42",
"organization_id": 3,
"identity_id": 123,
"email": "john@acme.se",
"created_at": "2026-06-08T10:00:00.000000Z",
"updated_at": "2026-06-08T10:30:00.000000Z",
"meta": {
"ssn": true,
"signed": true,
"signed_at": "2026-06-08T10:30:00.000000Z",
"email_status": "delivered",
"pdpc_url": "https://sandbox-api.opencard.io/accounts/1/pdpcs/8/sign/abc...",
"system": "Acme EMS",
"organization_number": "5561234567"
},
"identity": {
"name": "Anna Andersson",
"employee_id": "001"
}
}
],
"per_page": 15,
"total": 1,
"last_page": 1
}Authorizations
The access token received from the authorization server in the OAuth 2.0 flow.
Path Parameters
Your account ID
Organization ID
⌘I

