Fake cards API
505 cards from the Bank API, a fake banking API. Debit and credit cards on an account. Numbers are masked; the last four are real digits of the seed.
Reads with filters, sorting, search and relations; writes that answer like a real server and stay in your session token. Same ids on every build. Free, no key, CORS open.
Connect
- List
- https://api.sondahub.com/v1/bank/cards
- One record
- https://api.sondahub.com/v1/bank/cards/{id}
- OpenAPI 3
- https://api.sondahub.com/v1/bank/openapi.json
- GraphQL
- https://api.sondahub.com/v1/bank/graphql
- JSON file
- https://api.sondahub.com/data/bank/cards.json
- MCP
- https://api.sondahub.com/mcp · list_records
curl "https://api.sondahub.com/v1/bank/cards?limit=3"
Sample records
Records 1 to 3 of 505, exactly as GET /v1/bank/cards/{id} answers them. The data file holds all of them.
[
{
"id": 1,
"created_at": "2026-04-09T16:36:38Z",
"updated_at": "2026-04-09T16:36:38Z",
"account_id": 1,
"customer_id": 1,
"brand": "mastercard",
"type": "debit",
"masked_number": "•••• •••• •••• 3806",
"last4": "3806",
"holder_name": "OMAR GARCIA",
"expires": "05/29",
"status": "active",
"contactless": true,
"daily_limit": 500
},
{
"id": 2,
"created_at": "2026-04-30T13:53:14Z",
"updated_at": "2026-04-30T13:53:14Z",
"account_id": 2,
"customer_id": 2,
"brand": "visa",
"type": "debit",
"masked_number": "•••• •••• •••• 3492",
"last4": "3492",
"holder_name": "MAX JONES",
"expires": "07/27",
"status": "active",
"contactless": true,
"daily_limit": 1000
},
{
"id": 3,
"created_at": "2025-07-05T03:23:52Z",
"updated_at": "2025-07-05T03:23:52Z",
"account_id": 3,
"customer_id": 3,
"brand": "mastercard",
"type": "debit",
"masked_number": "•••• •••• •••• 7590",
"last4": "7590",
"holder_name": "CLARA ROMERO",
"expires": "11/28",
"status": "active",
"contactless": true,
"daily_limit": 500
}
]
Fields
| Field | Type | Notes |
|---|---|---|
idread-only | int | Assigned by the server. Seed records keep their ids across restarts; records you create continue after the seed. |
created_atread-only | datetime | When the record was created (ISO 8601, UTC). |
updated_atread-only | datetime | When the record last changed. |
account_idrequired | int → accounts | |
customer_idrequired | int → customers | |
brand | enum | visa mastercard amex |
type | enum | debit credit virtual |
masked_numberread-only | string | |
last4read-only | string | |
holder_name | string | |
expires | string | |
status | enum | active blocked expired lost |
contactless | bool | |
daily_limit | float | min 0 |
Relations: account → one account through account_id; customer → one customer through customer_id. Use ?expand=account,customer to embed them, or the nested routes.
Endpoints
Try it
curl "https://api.sondahub.com/v1/bank/cards?brand=mastercard&daily_limit_gte=10&expand=account&limit=3"
curl https://api.sondahub.com/v1/bank/cards/1?expand=account
curl -i -X POST https://api.sondahub.com/v1/bank/cards \
-H "Content-Type: application/json" \
-d '{"account_id":1,"customer_id":1,"brand":"visa","type":"debit","expires":"09/28","status":"active"}'
curl "https://api.sondahub.com/v1/bank/cards?sort=-id&limit=3" \ -H "X-Sondahub-Session: THE_TOKEN_FROM_THE_CREATE"
curl -X PATCH https://api.sondahub.com/v1/bank/cards/1 \
-H "Content-Type: application/json" \
-d '{"brand":"mastercard"}'
curl -X DELETE https://api.sondahub.com/v1/bank/cards/506 \ -H "X-Sondahub-Session: THE_TOKEN_FROM_THE_CREATE"
Query recipes
Every list option works on cards; these are ready to paste. All the options.
| What | Request |
|---|---|
| Page 2, 50 at a time (of 505) | /v1/bank/cards?page=2&limit=50 |
| Only brand = visa | /v1/bank/cards?brand=visa |
| Daily limit between two values, largest first | /v1/bank/cards?daily_limit_gte=1&daily_limit_lte=500&sort=-daily_limit |
| Newest first by created at | /v1/bank/cards?sort=-created_at&limit=5 |
| Holder name contains “omar” | /v1/bank/cards?holder_name_like=omar |
| Full-text search | /v1/bank/cards?q=omar |
| Only some fields | /v1/bank/cards?fields=id,holder_name&limit=5 |
| Embed the account | /v1/bank/cards/1?expand=account |
| Just the count | /v1/bank/cards?limit=1&fields=id |
GraphQL
The same cards as the cards query on https://api.sondahub.com/v1/bank/graphql, and one card as card(id: 1). Introspection is on. More on the GraphQL API.
{
cards(limit: 3, sort: "-id", filter: { brand: visa }) {
total
data {
id account_id customer_id brand
account { number }
}
}
}
curl https://api.sondahub.com/v1/bank/graphql -H "Content-Type: application/json" -d '{"query": "{ cards(limit: 3, sort: \"-id\", filter: { brand: visa }) { total data { id account_id customer_id brand account { number } } } }"}'
From an AI agent (MCP)
The MCP server reaches the same rows with list_records, get_record, create_record, update_record and delete_record, and as the resource sondahub://bank/cards.
curl https://api.sondahub.com/mcp \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"list_records","arguments":{"api":"bank","collection":"cards","filters":{"brand":"visa"},"limit":3}}}'
More in the Bank API
customers (400) · accounts (640) · transactions (7,674) · transfers (800) · fx rates (28)
The live streams, and the whole API on one page: Bank API. Other worlds: fake e-commerce API, fake IoT API, fake social media API, fake helpdesk API, fake flight booking API, fake user directory API.