This v2 API is used to delete an existing card stored on PayU Vault.
HTTP Method: DELETE
Environment
Request parameters
| Parameter | Description |
|---|---|
| date | The current date and time. Use the date format only after the Authentication contract has been confirmed; the value here is an illustrative format. |
| authorization | Authorization value. The format and algorithm are pending engineering confirmation. For more information, refer to authorization fields description table below. |
authorization fields description
| Parameter | Description |
|---|---|
| username | Represents the username or identifier for the client or merchant, in this case, it's "<Your_TEST_KEY>". |
| algorithm | Use SHA512 algorithm for hashing and send this as header value. |
| headers | Specifies which headers have been used in generating the hash. In this case, only the "date" header is used. |
| signature | Authorization value. The format and algorithm are pending engineering confirmation. For more information, refer to hashing algorithm. |
hashing algorithm
The following formula appears in the current source but is disputed by the audit. Do not use it until the API team confirms it:
sha512(<Body data> + '|' + date + '|' + merchant_secret}Where, <Body data> contains the request Body posted with the request.
Sample authorization header code
var merchant_key = pm.environment.get('merchantKey') || '<YOUR_TEST_KEY>';
var merchant_secret = pm.environment.get('merchantSalt') || '<YOUR_TEST_SALT>';
// Generate current date in RFC 1123 format
var date = new Date().toUTCString();
// Get request body data (empty for GET/DELETE)
var data = "";
if (pm.request.method === "POST" && pm.request.body && pm.request.body.raw) {
data = pm.request.body.raw;
}
// Generate authorization header
var hash_string = data + '|' + date + '|' + merchant_secret;
var hash = CryptoJS.SHA512(hash_string).toString(CryptoJS.enc.Hex);
var authorization = 'hmac username="' + merchant_key + '", algorithm="sha512", headers="date", signature="' + hash + '"';
// Set environment variables
pm.environment.set('date', date);
pm.environment.set('authorization', authorization);Query parameters
Mandatory
| Parameter | Description | Example |
|---|---|---|
userCredentialmandatory | String User authentication credential in the format username:userid. | testuser:testuser123 |
cardTokenmandatory | String Card token of the saved card. | |
| Optional |
| Parameter | Description | Example |
|---|---|---|
networkTokenoptional | String Network issuer token. | |
issuerToken optional | String Issuer token. | |
bankType optional | String The bank type of card. It can be any of the following: Credit, Debit, or Prepaid. | Credit |
Sample Request
curl --location --request DELETE '<redacted URL>' \
--header 'Date: Mon, 05 Oct 2026 08:30:00 GMT' \
--header 'Authorization: hmac username="merchant_key", algorithm="sha512", headers="date", signature="<SIGNATURE>"'import requests
url = "<redacted URL>"
params = {
"userCredential": "sms:user12345",
"cardToken": "29850879bf39848ca078727b8e1a95165a41cea1"
}
headers = {
"Date": "Mon, 05 Oct 2026 08:30:00 GMT",
"Authorization": 'hmac username="merchant_key", algorithm="sha512", headers="date", signature="<SIGNATURE>"'
}
response = requests.delete(url, headers=headers, params=params)
print(response.json())<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => '<redacted URL>',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_CUSTOMREQUEST => 'DELETE',
CURLOPT_HTTPHEADER => [
'Date: Mon, 05 Oct 2026 08:30:00 GMT',
'Authorization: hmac username="merchant_key", algorithm="sha512", headers="date", signature="<SIGNATURE>"'
],
]);
$response = curl_exec($curl);
curl_close($curl);
echo $response;import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;
public class DeleteCard {
public static void main(String[] args) throws Exception {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("<redacted URL>"))
.header("Date", "Mon, 05 Oct 2026 08:30:00 GMT")
.header("Authorization", "hmac username=\"merchant_key\", algorithm=\"sha512\", headers=\"date\", signature=\"<SIGNATURE>\"")
.DELETE()
.build();
HttpClient client = HttpClient.newHttpClient();
HttpResponse<String> response = client.send(request, HttpResponse.BodyHandlers.ofString());
System.out.println(response.body());
}
}const axios = require('axios');
const config = {
method: 'delete',
url: '<redacted URL>',
headers: {
'Date': 'Mon, 05 Oct 2026 08:30:00 GMT',
'Authorization': 'hmac username="merchant_key", algorithm="sha512", headers="date", signature="<SIGNATURE>"'
}
};
axios(config)
.then(response => console.log(JSON.stringify(response.data)))
.catch(error => console.error(error));Response Parameters
| Parameter | Type | Description |
|---|---|---|
| status | Integer | Status flag: 1 (Success) or 0 (Failure). |
| message | String | Descriptive outcome message (e.g. "Card deleted successfully"). |
Sample Response (Success)
{
"status": 1,
"message": "Card deleted successfully"
}Sample Response (Failure)
{
"status": 0,
"message": "cardToken is invalid"
}Next Steps
- Update Local Customer Profile:
- On receiving
status: 1, remove the corresponding card token and masked PAN reference from your customer database.
- On receiving
- Refresh Stored Payment Instruments UI:
- Refresh the customer's payment options using the Get User Cards API or Get Payment Instrument API.
- Handle Edge Cases:
- If the API returns
status: 0(cardToken is invalid), ensure that the card is marked deleted or purged locally.
- If the API returns
