---
updatedAt: 2026-10-05T10:02:59.000Z
agentTools:
  projectIndex: https://docs.payu.in/v2/llms.txt
---

# Delete a Saved Card API

***

title: Delete a Saved Card API
deprecated: false
hidden: false
metadata:
robots: index
-------------

This v2 API is used to delete an existing card stored on PayU Vault.

HTTP Method: **DELETE**

**Environment**

|            |                                             |
| :--------- | :------------------------------------------ |
| Test       | <https://apitest.payu.in/storecard/card/v1> |
| Production | <https://info.payu.in/storecard/card/v1>    |

## Request parameters

| Parameter     | Description                                                                                                                                                      |
| :------------ | :--------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| date          | The current date and time. Use the date format only after the Authentication contract has been confirmed; the value here is an illustrative format.              |
| authorization | Authorization value. The format and algorithm are pending engineering confirmation. For more information, refer to authorization fields description table below. |

<Accordion title="authorization fields description" icon="fa-table">
  | Parameter | Description                                                                                                                                                                      |
  | --------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
  | username  | Represents the username or identifier for the client or merchant, in this case, it's "<Your_TEST_KEY>".                                                                                  |
  | algorithm | Use SHA512 algorithm for hashing and send this as header value.                                                                                                                  |
  | headers   | Specifies which headers have been used in generating the hash. In this case, only the "date" header is used.                                                                     |
  | signature | Authorization value. The format and algorithm are pending engineering confirmation. For more information, refer to [hashing algorithm](#hashing-algorithm). |

  #### hashing algorithm

  The following formula appears in the current source but is disputed by the audit. Do not use it until the API team confirms it:

  ```
  sha512(<Body data> + '|' + date + '|' + merchant_secret}
  ```

  Where, \<Body data> contains the request Body posted with the request.
</Accordion>

<Accordion title="Sample authorization header code" icon="fa-info-circle">
```javascript
var merchant_key = pm.environment.get('merchantKey') || '<YOUR_TEST_KEY>';
var merchant_secret = pm.environment.get('merchantSalt') || '<YOUR_TEST_SALT>';

// Generate current date in RFC 1123 format
var date = new Date().toUTCString();

// Get request body data (empty for GET/DELETE)
var data = "";
if (pm.request.method === "POST" && pm.request.body && pm.request.body.raw) {
    data = pm.request.body.raw;
}

// Generate authorization header
var hash_string = data + '|' + date + '|' + merchant_secret;
var hash = CryptoJS.SHA512(hash_string).toString(CryptoJS.enc.Hex);
var authorization = 'hmac username="' + merchant_key + '", algorithm="sha512", headers="date", signature="' + hash + '"';

// Set environment variables
pm.environment.set('date', date);
pm.environment.set('authorization', authorization);
```
<br />
</Accordion>

### Query parameters

**Mandatory**

| Parameter                       | Description                                                              | Example              |
| ------------------------------- | ------------------------------------------------------------------------ | -------------------- |
| userCredential<br />`mandatory` | `String` User authentication credential in the format `username:userid`. | testuser:testuser123 |
| cardToken<br />`mandatory`      | `String` Card token of the saved card.                                   |                      |
| **Optional**                    |                                                                          |                      |

| Parameter                     | Description                                                                                | Example |
| ----------------------------- | ------------------------------------------------------------------------------------------ | ------- |
| networkToken<br />`optional`  | `String` Network issuer token.                                                             |         |
| issuerToken  <br />`optional` | `String` Issuer token.                                                                     |         |
| bankType <br />`optional`     | `String` The bank type of card. It can be any of the following: Credit, Debit, or Prepaid. | Credit  |

***

## Sample Request

```curl
curl --location --request DELETE '<redacted URL>' \
--header 'Date: Mon, 05 Oct 2026 08:30:00 GMT' \
--header 'Authorization: hmac username="merchant_key", algorithm="sha512", headers="date", signature="<SIGNATURE>"'
```
```python
import requests

url = "<redacted URL>"
params = {
    "userCredential": "sms:user12345",
    "cardToken": "29850879bf39848ca078727b8e1a95165a41cea1"
}
headers = {
    "Date": "Mon, 05 Oct 2026 08:30:00 GMT",
    "Authorization": 'hmac username="merchant_key", algorithm="sha512", headers="date", signature="<SIGNATURE>"'
}

response = requests.delete(url, headers=headers, params=params)
print(response.json())
```
```php
<?php
$curl = curl_init();

curl_setopt_array($curl, [
  CURLOPT_URL => '<redacted URL>',
  CURLOPT_RETURNTRANSFER => true,
  CURLOPT_CUSTOMREQUEST => 'DELETE',
  CURLOPT_HTTPHEADER => [
    'Date: Mon, 05 Oct 2026 08:30:00 GMT',
    'Authorization: hmac username="merchant_key", algorithm="sha512", headers="date", signature="<SIGNATURE>"'
  ],
]);

$response = curl_exec($curl);
curl_close($curl);
echo $response;
```
```java
import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;

public class DeleteCard {
    public static void main(String[] args) throws Exception {
        HttpRequest request = HttpRequest.newBuilder()
            .uri(URI.create("<redacted URL>"))
            .header("Date", "Mon, 05 Oct 2026 08:30:00 GMT")
            .header("Authorization", "hmac username=\"merchant_key\", algorithm=\"sha512\", headers=\"date\", signature=\"<SIGNATURE>\"")
            .DELETE()
            .build();

        HttpClient client = HttpClient.newHttpClient();
        HttpResponse<String> response = client.send(request, HttpResponse.BodyHandlers.ofString());
        System.out.println(response.body());
    }
}
```
```javascript
const axios = require('axios');

const config = {
  method: 'delete',
  url: '<redacted URL>',
  headers: { 
    'Date': 'Mon, 05 Oct 2026 08:30:00 GMT',
    'Authorization': 'hmac username="merchant_key", algorithm="sha512", headers="date", signature="<SIGNATURE>"'
  }
};

axios(config)
  .then(response => console.log(JSON.stringify(response.data)))
  .catch(error => console.error(error));
```

## Response Parameters

| Parameter   | Type    | Description                                                       |
| :---------- | :------ | :---------------------------------------------------------------- |
| **status**  | Integer | Status flag: `1` (Success) or `0` (Failure).                      |
| **message** | String  | Descriptive outcome message (e.g. `"Card deleted successfully"`). |

### Sample Response (Success)

```json
{
  "status": 1,
  "message": "Card deleted successfully"
}
```

### Sample Response (Failure)

```json
{
  "status": 0,
  "message": "cardToken is invalid"
}
```

***

## Next Steps

1. **Update Local Customer Profile**:
   * On receiving `status: 1`, remove the corresponding card token and masked PAN reference from your customer database.
2. **Refresh Stored Payment Instruments UI**:
   * Refresh the customer's payment options using the **[Get User Cards API](./v2_get_user_cards_api.md)** or **[Get Payment Instrument API](./v2-get-payment-instrument-api.md)**.
3. **Handle Edge Cases**:
   * If the API returns `status: 0` (`cardToken is invalid`), ensure that the card is marked deleted or purged locally.