---
updatedAt: 2026-09-30T17:50:34.235Z
---

Fetch the complete documentation index at: https://docs.avvio.xyz/llms.txt. Use this file to discover all available pages before exploring further. Append .md to any documentation page URL to get its markdown version.

# Get payment method details

`GET https://api.avvio.xyz/business/api/v1/recipients/{orgId}/{recipientId}/methods/{methodId}/details`

Returns the full account details behind one payment method. Lists
carry only `last4`. This returns what was actually registered, which is useful for showing a user the account on file before they authorize a
payout, and for confirming what you stored matches what we hold.

Fetch it on demand for one method. List payloads leave it out so bulk
reads do not move full account numbers around. A read-only key is
refused this read (`403 INSUFFICIENT_SCOPE`); lists carry `last4`,
which is what reconciliation needs.

## Parameters

- `orgId` (path, required) — The opaque organization id issued to you, normally CUID-shaped (for example `cmsx…`). It is not an `org_`-prefixed alias. Pass it unchanged in every organization-scoped path.
- `recipientId` (path, required) — Opaque recipient id returned by this API. Pass it unchanged.
- `methodId` (path, required) — From the recipient's `paymentMethods[].id`.

## Example

```bash
curl -s "$AVVIO_BASE_URL/recipients/$AVVIO_ORG_ID/$recipientId/methods/$methodId/details" \
  -H "x-api-key: $AVVIO_API_KEY"
```

## Responses

- `200` — The registered account details
- `401` — The key was refused. Nothing ran. - `UNAUTHORIZED`: missing, invalid or revoked, or a key on a route that does not accept one. - `KEY_EXPIRED`: the key passed the expiry it was issued with. Issue a new one; an expired key cannot be rotated. - `KEY_IP_NOT_ALLOWED`: the key is pinned to source addresses and this request came from another.
- `403` — `FORBIDDEN` (a key for a different organization), `ACCOUNT_BLOCKED` (API access suspended), or `INSUFFICIENT_SCOPE` (a read-only key: full account details need the `write` scope).
- `404` — Unknown recipient or method
- `429` — Too many requests. The default ceiling is **100 requests per minute per API credential** on a 60-second window. High-volume payout and reconciliation routes declare a 600/minute override, and batch submission a 30/minute ceiling. A separate 2,000/minute per-source-IP abuse ceiling always applies. Obey `Retry-After`; it is in seconds and is authoritative. A 429 means the request was refused before the handler ran. Retry reads normally; retry an idempotent mutation with its same `Idempotency-Key`.

Machine contract: [partner-payouts.openapi.yaml](/partner-payouts.openapi.yaml), operation `getBeneficiaryMethodDetails`.
