> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agentcard.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# List a user's vaulted cards

> Display fields for the cards a user has stored. Never card data.

Use it to skip enrollment for a returning user, and to pick the `id` to pass as `card_id` on a checkout authorization.

<ParamField query="user_id" type="string" required>The user whose cards to list.</ParamField>

<RequestExample>
  ```bash cURL theme={null}
  curl "https://api.agentcard.sh/api/v2/vault_cards?user_id=usr_8f3k2m" \
    -H "Authorization: Bearer $ORG_TOKEN"
  ```
</RequestExample>

<ResponseExample>
  ```json 200 theme={null}
  {
    "object": "list",
    "data": [
      {
        "object": "vault_card", "id": "vc_7f3a9c2e1b4d6f8a0c2e4b6d", "brand": "visa", "last4": "4832", "expiry_month": 12, "expiry_year": 2029, "created_at": "2026-09-02T18:41:07Z",
        "payment_permission": { "card_id": "vc_7f3a9c2e1b4d6f8a0c2e4b6d", "grant_id": null, "revision": null, "status": "pending", "ready": false }
      }
    ]
  }
  ```
</ResponseExample>

<ResponseField name="payment_permission" type="object">Whether your app can pay with this card without an approval link: `card_id`, `grant_id`, `revision`, `status`, and `ready`, as on [Get a vault session](/api-reference/vault/sessions-get). A card the user never gave your app reads `pending`, with `ready` false. `unavailable` means Agentcard couldn't read the permission: read again. See [Enable auto-approval](/vault/app-auto-approval).</ResponseField>

The response never includes a card number or anything that could decrypt one.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.