A card's image and its provider's logo as public URLs.
Reference
Exchange rates
Market
Calculators
Assistant
Only Enterprise gets these inside other responses. No image or logo is a free 404.
Cost
5 DS Credits
per request
Scope
cards:read
Same data as
—
the DepositScout website
403 endpoint_restricted and is not charged. When it opens it will cost 5 DS Credits per request. Early access: [email protected].GET https://depositscout.com/api/developer/v1/assets/cards/{sourceKey}
Stable card id from /cards/rewards or /cards/travel.
| Parameter | In | Type | Example | Description |
|---|---|---|---|---|
| sourceKey* | path | string | — | Stable card id from /cards/rewards or /cards/travel. |
curl "https://depositscout.com/api/developer/v1/assets/cards/sourceKey" \
-H "Authorization: Bearer $DS_API_KEY"Runs against this site. A ds_test_ key is free and returns sample data in the real shape; a live key returns real data and spends credits. The key is kept in this tab only.
curl "/api/developer/v1/assets/cards/sourceKey" \
-H "Authorization: Bearer ds_test_…"data is a single object. Every 2xx also sets X-DS-Request-Id, X-DS-Credits-Charged, X-DS-Credits-Balance, the X-RateLimit-* trio and an ETag.
{
"data": {
"…": "the item"
},
"meta": {
"requestId": "req_7f3a9c2d1b4e5a6f7c8d",
"generatedAt": "2026-09-21T09:00:00.000Z",
"creditsCharged": 5,
"creditsBalance": 199,
"attribution": "Rates powered by DepositScout — depositscout.com"
}
}Logos and images: imageUrl, logoUrl. An absolute, public HTTPS URL for the provider's logo (or, for imageUrl, the card's image) that you can load directly (usually SVG; PNG or JPG for a few), or null when we have none.
What this endpoint can return instead of data. Every error has the same shape: error (a stable code to branch on), message (what to do next), requestId and a docs link, plus the extra fields shown. None of them is charged.
missing_api_key— No Authorization header, or it isn't a Bearer token.{
"error": "missing_api_key",
"message": "Send your key as 'Authorization: Bearer ds_live_…'. Create one at https://depositscout.com/developer.",
"requestId": "req_7f3a9c2d1b4e5a6f7c8d",
"docs": "https://depositscout.com/developers/docs#missing_api_key"
}insufficient_scope— The key doesn't carry the scope the endpoint needs.{
"error": "insufficient_scope",
"message": "This key doesn't have the 'cards:read' scope.",
"requestId": "req_7f3a9c2d1b4e5a6f7c8d",
"docs": "https://depositscout.com/developers/docs#insufficient_scope",
"required": "cards:read"
}endpoint_restricted— A live key was used on an endpoint that is test-only for now. See the open list on the endpoints table.{
"error": "endpoint_restricted",
"message": "This endpoint isn't open to live keys yet. Test keys get sample data; the open list is at https://depositscout.com/developers/docs#endpoints. Ask [email protected] for early access.",
"requestId": "req_7f3a9c2d1b4e5a6f7c8d",
"docs": "https://depositscout.com/developers/docs#endpoint_restricted"
}insufficient_credits— Balance is lower than the call's cost. A list whose page you can't fully afford is cut to the rows your balance covers instead (meta.limit and X-DS-Limit-Reduced say so), so this only happens below one row's price. Body has required, balance and topUp.{
"error": "insufficient_credits",
"message": "Not enough DS Credits for this request. Top up at https://depositscout.com/developer/credits.",
"requestId": "req_7f3a9c2d1b4e5a6f7c8d",
"docs": "https://depositscout.com/developers/docs#insufficient_credits",
"required": 5,
"balance": 0,
"topUp": "https://depositscout.com/developer/credits"
}not_found— Unknown route, unknown sourceKey or slug, or an endpoint that hasn't launched yet.{
"error": "not_found",
"message": "Nothing at that address.",
"requestId": "req_7f3a9c2d1b4e5a6f7c8d",
"docs": "https://depositscout.com/developers/docs#not_found"
}rate_limited— Burst or daily limit hit. Retry-After tells you when.{
"error": "rate_limited",
"message": "Too many requests. Retry after 12s.",
"requestId": "req_7f3a9c2d1b4e5a6f7c8d",
"docs": "https://depositscout.com/developers/docs#rate_limited",
"retryAfter": 12
}Every code is listed in the shared error contract. Back to all endpoints.