Build With MyBundlePay

One integration for payments, cards, bills and payouts.

MyBundlePay gives developers a clean payment gateway, virtual account funding, payout rails, card issuing tools, bill payments, webhooks and merchant-ready checkout experiences.

REST APIs JSON based
Webhooks Real time events
Sandbox Test first

API Test Console

Test the current endpoint directly from the documentation. Secret keys stay inside this browser session.

Enter your test key, review the sample body for this page, then send a request.

GET https://mybundlepay.com/ng/api/v2/virtual-card/list

KEY USAGE POLICY

Important: Use your test_secret_key for sandbox testing. Switch to live_secret_key only when you are ready to go live.

  • Test calls return mock data.
  • Live calls fetch actual cards created under your business.
  • Ensure your server IP is whitelisted before calling live endpoints.

⚠️ Do not use live keys for testing — unauthorized IPs will be blocked.

HEADERS

Authorization * string

Send your {secret_key} as a Bearer token in the header.

Content-Type * application/json

All requests must use JSON body format.

IP WHITELISTING

Only authorized server IPs can access this endpoint. Whitelist your IP in MyBundlePay Dashboard.

BODY PARAMS

Parameter Required Description
page Page number to fetch cards (default: 1).
per_page Number of cards per page (default: 10).

<?php

$curl = curl_init();

curl_setopt_array($curl, array(
  CURLOPT_URL => 'https://mybundlepay.com/ng/api/v2/virtual-card/list',
  CURLOPT_RETURNTRANSFER => true,
  CURLOPT_ENCODING => '',
  CURLOPT_MAXREDIRS => 10,
  CURLOPT_TIMEOUT => 0,
  CURLOPT_FOLLOWLOCATION => true,
  CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
  CURLOPT_CUSTOMREQUEST => 'GET',
  CURLOPT_POSTFIELDS =>'{
    "page": "1",
    "per_page": "2"
}',
  CURLOPT_HTTPHEADER => array(
    'Content-Type: application/json',
    'Authorization: Bearer {secret_key}'
  ),
));

$response = curl_exec($curl);
curl_close($curl);
echo $response;
?>

const axios = require('axios');

const data = {
  page: "1",
  per_page: "2"
};

axios.get("https://mybundlepay.com/ng/api/v2/virtual-card/list", {
  headers: {
    "Content-Type": "application/json",
    "Authorization": "Bearer {secret_key}"
  },
  data: data
})
.then(res => console.log(res.data))
.catch(err => console.error(err.response ? err.response.data : err.message));
✅ Success Response

{
  "status": "success",
  "message": "Cards fetched successfully.",
  "data": [
    {
      "card_account_id": "Test",
      "card_Id": "xxxxxxx-6a21-4dcb-9c65-xxxxxxx",
      "card_balance": "12.50",
      "cardNumber": "5311 40XX XXXX 3456",
      "cardName": "MyBundlePay Business",
      "cardType": "virtual",
      "cardBrand": "MasterCard",
      "cvv2": "921",
      "card_expiry": "12/28",
      "card_status": "ACTIVE",
      "valid": "true",
      "card_reference": "MBP-VCC-REF001",
      "card_city": "Lagos",
      "card_street": "13B Example Ave",
      "card_country": "Nigeria",
      "card_zipCode": "100001",
      "card_countryCode": "NG"
    }
  ],
  "pagination": {
    "current_page": 1,
    "per_page": 2,
    "total": 8
  },
  "mode": "test"
}
❌ Error Response (Invalid Token)

{
  "status": "failed",
  "code": "INVALID_TOKEN",
  "message": "Invalid secret key provided.",
  "mode": "test"
}
❌ Error Response (IP Not Authorized)

{
  "status": "failed",
  "code": "IP_NOT_AUTHORIZED",
  "message": "Your IP is not authorized for API access.",
  "ip": "54.86.50.139",
  "mode": "live"
}