sondahub

sondahub / Bank API / Cards

Fake cards API

505 cards from the Bank API, a fake banking API. Debit and credit cards on an account. Numbers are masked; the last four are real digits of the seed.

Reads with filters, sorting, search and relations; writes that answer like a real server and stay in your session token. Same ids on every build. Free, no key, CORS open.

Connect

List
https://api.sondahub.com/v1/bank/cards
One record
https://api.sondahub.com/v1/bank/cards/{id}
OpenAPI 3
https://api.sondahub.com/v1/bank/openapi.json
GraphQL
https://api.sondahub.com/v1/bank/graphql
JSON file
https://api.sondahub.com/data/bank/cards.json
MCP
https://api.sondahub.com/mcp · list_records
The first three cards
curl "https://api.sondahub.com/v1/bank/cards?limit=3"

Sample records

Records 1 to 3 of 505, exactly as GET /v1/bank/cards/{id} answers them. The data file holds all of them.

[
  {
    "id": 1,
    "created_at": "2026-04-09T16:36:38Z",
    "updated_at": "2026-04-09T16:36:38Z",
    "account_id": 1,
    "customer_id": 1,
    "brand": "mastercard",
    "type": "debit",
    "masked_number": "•••• •••• •••• 3806",
    "last4": "3806",
    "holder_name": "OMAR GARCIA",
    "expires": "05/29",
    "status": "active",
    "contactless": true,
    "daily_limit": 500
  },
  {
    "id": 2,
    "created_at": "2026-04-30T13:53:14Z",
    "updated_at": "2026-04-30T13:53:14Z",
    "account_id": 2,
    "customer_id": 2,
    "brand": "visa",
    "type": "debit",
    "masked_number": "•••• •••• •••• 3492",
    "last4": "3492",
    "holder_name": "MAX JONES",
    "expires": "07/27",
    "status": "active",
    "contactless": true,
    "daily_limit": 1000
  },
  {
    "id": 3,
    "created_at": "2025-07-05T03:23:52Z",
    "updated_at": "2025-07-05T03:23:52Z",
    "account_id": 3,
    "customer_id": 3,
    "brand": "mastercard",
    "type": "debit",
    "masked_number": "•••• •••• •••• 7590",
    "last4": "7590",
    "holder_name": "CLARA ROMERO",
    "expires": "11/28",
    "status": "active",
    "contactless": true,
    "daily_limit": 500
  }
]

Fields

FieldTypeNotes
idread-onlyintAssigned by the server. Seed records keep their ids across restarts; records you create continue after the seed.
created_atread-onlydatetimeWhen the record was created (ISO 8601, UTC).
updated_atread-onlydatetimeWhen the record last changed.
account_idrequiredint → accounts
customer_idrequiredint → customers
brandenumvisa mastercard amex
typeenumdebit credit virtual
masked_numberread-onlystring
last4read-onlystring
holder_namestring
expiresstring
statusenumactive blocked expired lost
contactlessbool
daily_limitfloatmin 0

Relations: account → one account through account_id; customer → one customer through customer_id. Use ?expand=account,customer to embed them, or the nested routes.

Endpoints

GET/v1/bank/cardsA page, with every filter, sort, search, field and expand option.
POST/v1/bank/cardsCreate one: 201 with the record, its id, a Location header and the session token that keeps it; 422 names each field that is wrong.
GET/v1/bank/cards/{id}One record, with an ETag; If-None-Match earns a 304.
PATCH/v1/bank/cards/{id}Change the fields you send.
PUT/v1/bank/cards/{id}Replace the record; required fields must all be there.
DELETE/v1/bank/cards/{id}Answers 200 with what was removed (a real server’s 204 lives at /v1/utils/status/204); gone for the session.
GET/v1/bank/cards/{id}/accountThe account this record points at.
GET/v1/bank/cards/{id}/customerThe customer this record points at.

Try it

List with a filter
curl "https://api.sondahub.com/v1/bank/cards?brand=mastercard&daily_limit_gte=10&expand=account&limit=3"
One record
curl https://api.sondahub.com/v1/bank/cards/1?expand=account
Create
curl -i -X POST https://api.sondahub.com/v1/bank/cards \
  -H "Content-Type: application/json" \
  -d '{"account_id":1,"customer_id":1,"brand":"visa","type":"debit","expires":"09/28","status":"active"}'
Read it back: newest first (send the session token)
curl "https://api.sondahub.com/v1/bank/cards?sort=-id&limit=3" \
  -H "X-Sondahub-Session: THE_TOKEN_FROM_THE_CREATE"
Change one field
curl -X PATCH https://api.sondahub.com/v1/bank/cards/1 \
  -H "Content-Type: application/json" \
  -d '{"brand":"mastercard"}'
Delete the one you created
curl -X DELETE https://api.sondahub.com/v1/bank/cards/506 \
  -H "X-Sondahub-Session: THE_TOKEN_FROM_THE_CREATE"

Query recipes

Every list option works on cards; these are ready to paste. All the options.

WhatRequest
Page 2, 50 at a time (of 505)/v1/bank/cards?page=2&limit=50
Only brand = visa/v1/bank/cards?brand=visa
Daily limit between two values, largest first/v1/bank/cards?daily_limit_gte=1&daily_limit_lte=500&sort=-daily_limit
Newest first by created at/v1/bank/cards?sort=-created_at&limit=5
Holder name contains “omar”/v1/bank/cards?holder_name_like=omar
Full-text search/v1/bank/cards?q=omar
Only some fields/v1/bank/cards?fields=id,holder_name&limit=5
Embed the account/v1/bank/cards/1?expand=account
Just the count/v1/bank/cards?limit=1&fields=id

GraphQL

The same cards as the cards query on https://api.sondahub.com/v1/bank/graphql, and one card as card(id: 1). Introspection is on. More on the GraphQL API.

{
  cards(limit: 3, sort: "-id", filter: { brand: visa }) {
    total
    data {
      id account_id customer_id brand
      account { number }
    }
  }
}
Run it
curl https://api.sondahub.com/v1/bank/graphql -H "Content-Type: application/json" -d '{"query": "{ cards(limit: 3, sort: \"-id\", filter: { brand: visa }) { total data { id account_id customer_id brand account { number } } } }"}'

From an AI agent (MCP)

The MCP server reaches the same rows with list_records, get_record, create_record, update_record and delete_record, and as the resource sondahub://bank/cards.

tools/call
curl https://api.sondahub.com/mcp \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"list_records","arguments":{"api":"bank","collection":"cards","filters":{"brand":"visa"},"limit":3}}}'

More in the Bank API

customers (400) · accounts (640) · transactions (7,674) · transfers (800) · fx rates (28)

The live streams, and the whole API on one page: Bank API. Other worlds: fake e-commerce API, fake IoT API, fake social media API, fake helpdesk API, fake flight booking API, fake user directory API.