> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hifi.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Retrieve an external card session

> Retrieve the status of an external card session. Restricted to HIFI's
hosted session UI; not callable with a client API key.




## OpenAPI

````yaml https://production.hifi.com/api/v3/openapi.json get /v3/users/{userId}/external-card-sessions/{cardSessionId}
openapi: 3.0.0
info:
  title: Hifi API
  version: 3.0.0
  description: API documentation for HIFI
servers:
  - url: https://production.hifi.com
    description: Production server
  - url: https://sandbox.hifi.com
    description: Sandbox server
security:
  - bearerAuth: []
tags:
  - name: Common
    description: Common endpoints
  - name: User
    description: User endpoints
  - name: Counter Party
    description: Counter party endpoints
  - name: Crypto Transfer
    description: Crypto transfer and batch transfer endpoints
  - name: Wallet
    description: Wallet and wallet offer endpoints
  - name: External Account
    description: External bank account endpoints (under a counter party)
  - name: External Wallet
    description: External wallet endpoints (under a counter party)
  - name: External Card
    description: External card endpoints (under a counter party)
  - name: Token Swap
    description: Token swap endpoints
  - name: Bridge
    description: Bridge endpoints
  - name: Virtual Account
    description: Virtual account endpoints
  - name: Compliance
    description: Compliance and compliance link endpoints
  - name: Webhook Endpoint
    description: Webhook endpoint endpoints
  - name: File
    description: File upload endpoints
  - name: Onramp
    description: Onramp (fiat to crypto) endpoints
  - name: Offramp
    description: Offramp (crypto to fiat) endpoints
  - name: Orchestration Address
    description: Orchestration (liquidation) address endpoints
  - name: KYC Link
    description: Hosted and custom KYC/KYB link endpoints
  - name: Transfer Approval
    description: Transfer approval endpoints
  - name: Corridor
    description: Supported fiat/crypto transfer corridor endpoints
  - name: Migration
    description: v2-to-v3 ID mapping endpoints
paths:
  /v3/users/{userId}/external-card-sessions/{cardSessionId}:
    get:
      tags:
        - External Card
      summary: Retrieve an external card session
      description: |
        Retrieve the status of an external card session. Restricted to HIFI's
        hosted session UI; not callable with a client API key.
      operationId: v3GetExternalCardSession
      parameters:
        - $ref: '#/components/parameters/UserIdPathParameter'
        - $ref: '#/components/parameters/CardSessionIdPathParameter'
      responses:
        '200':
          $ref: '#/components/responses/GetExternalCardSessionResponse'
        '401':
          $ref: '#/components/responses/UnauthorizedResponse'
        '403':
          $ref: '#/components/responses/UnauthorizedResponse'
        '404':
          $ref: '#/components/responses/NotFoundResponse'
        '500':
          $ref: '#/components/responses/InternalServerErrorResponse'
components:
  parameters:
    UserIdPathParameter:
      name: userId
      in: path
      schema:
        type: string
        pattern: ^user_[A-Za-z0-9]+$
      description: ID of the user.
      required: true
    CardSessionIdPathParameter:
      name: cardSessionId
      in: path
      required: true
      schema:
        type: string
      description: Public ID of the external card session (prefixed with `ecs_`)
      example: ecs_2mNpXwZ7bV1aLcs3Kf9dQ
  responses:
    GetExternalCardSessionResponse:
      description: External card session retrieved successfully.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ExternalCardSessionObject'
          example:
            id: ecs_2mNpXwZ7bV1aLcs3Kf9dQ
            userId: usr_3Kf9dQ2mNpXwZ7bV1aLcs
            counterPartyId: null
            url: null
            recipientEmail: jane.doe@example.com
            redirectUrl: https://example.com/card-onboarding/complete
            status: PENDING
            expiredAt: '2026-07-01T11:30:00.000Z'
            createdAt: '2026-07-01T10:30:00.000Z'
            updatedAt: '2026-07-01T10:30:00.000Z'
    UnauthorizedResponse:
      description: Unauthorized
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Unauthorized'
    NotFoundResponse:
      description: Not Found
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/NotFound'
    InternalServerErrorResponse:
      description: Internal Server Error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/InternalServerError'
  schemas:
    ExternalCardSessionObject:
      type: object
      description: A hosted external card collection session.
      properties:
        id:
          type: string
          description: Public ID of the card session (prefixed with `ecs_`).
          example: ecs_2mNpXwZ7bV1aLcs3Kf9dQ
        userId:
          type: string
          description: >-
            Public ID of the user this session belongs to (prefixed with
            `usr_`).
          example: usr_3Kf9dQ2mNpXwZ7bV1aLcs
        counterPartyId:
          type: string
          nullable: true
          description: >-
            Public ID of the associated counter party, if one was supplied or
            has since been created.
          example: cpty_7bV1aLcs3Kf9dQ2mNpXwZ
        url:
          type: string
          nullable: true
          description: >-
            Hosted session URL, including a fragment-embedded session token.
            Only present on creation.
          example: >-
            https://dashboard.hifi.com/sandbox/external-card-sessions/ecs_2mNpXwZ7bV1aLcs3Kf9dQ?userId=usr_3Kf9dQ2mNpXwZ7bV1aLcs#sessionToken=...
        recipientEmail:
          type: string
          nullable: true
          example: jane.doe@example.com
        redirectUrl:
          type: string
          nullable: true
          example: https://example.com/card-onboarding/complete
        status:
          type: string
          enum:
            - PENDING
            - PROCESSING
            - COMPLETED
            - EXPIRED
          example: PENDING
        expiredAt:
          type: string
          format: date-time
          nullable: true
          example: '2026-07-01T11:30:00.000Z'
        createdAt:
          type: string
          format: date-time
          example: '2026-07-01T10:30:00.000Z'
        updatedAt:
          type: string
          format: date-time
          example: '2026-07-01T10:30:00.000Z'
    Unauthorized:
      type: object
      properties:
        type:
          type: string
          description: Unauthorized enum
          example: UNAUTHORIZED
        message:
          type: string
          description: Unauthorized message
          example: Authentication required
    NotFound:
      type: object
      properties:
        type:
          type: string
          example: RESOURCE_NOT_FOUND
          description: The error type, e.g., RESOURCE_NOT_FOUND
        message:
          type: string
          description: A descriptive error message
        fields:
          type: array
          description: List of specific field errors
          items:
            type: object
            properties:
              code:
                type: string
                description: Error code related to the field issue
              message:
                type: string
                description: Error message for the specific issue
              field:
                type: string
                description: The name of the field that has an issue
    InternalServerError:
      type: object
      properties:
        type:
          type: string
          example: INTERNAL_SERVER_ERROR
          description: Internal server error enum
        message:
          type: string
          example: An internal server error occurred
          description: Internal server error message
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT

````