> This page is for Afterpay Online Developer, version Chinese.
> For other versions, use one of these documentation indexes:
> - Main (default): https://developers.afterpay.com/afterpay-online-developer/main/llms.txt
> - v1: https://developers.afterpay.com/afterpay-online-developer/v-1/llms.txt
> - Chinese: https://developers.afterpay.com/afterpay-online-developer/chinese/llms.txt

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developers.afterpay.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developers.afterpay.com/_mcp/server.

# Retrieve Cash App Pay Grant

POST https://global-api-sandbox.afterpay.com/v2/grants/retrieve
Content-Type: application/json

Retrieves a Cash App Pay customer grant by the ID of the customer that approved it and its own ID.

Reference: https://developers.afterpay.com/afterpay-online-developer/chinese/guides/cash-app-afterpay-us/add-cash-app-pay/retrieve-grant

## Authentication

- `Authorization` header (basic auth, required) — Basic authentication of the form `Basic <base64(username:password)>`.

## Servers

- `https://global-api-sandbox.afterpay.com` (Sandbox, default)
- `https://global-api.afterpay.com` (Production)

## Request

### Headers

- `Accept` (string, optional, default: application/json) — Accept

### Body (application/json)

This endpoint expects a RetrieveGrantRequest.

- `customerId` (string, required) — ID of the customer that approved the customer grant.
- `grantId` (string, required) — ID of the customer grant to retrieve.

## Response

### 200

OK

- `grant` (Grant, required) — Describes a grant provided by Cash App.

## Errors

### 401 Unauthorized Error

Unauthenticated

- `errorCode` (string, optional)
- `errorId` (string, optional)
- `message` (string, optional)
- `httpStatusCode` (integer, optional)

### 403 Forbidden Error

Unauthorized

- `errorCode` (string, optional)
- `errorId` (string, optional)
- `message` (string, optional)
- `httpStatusCode` (integer, optional)

## Types

### Grant

Describes a grant provided by Cash App.

- `id` (string, required) — Unique identifier for this grant issued by Cash App.
- `intent` (enum, required) — Either ON_FILE or ONE_TIME
  - Allowed values: `ON_FILE`, `ONE_TIME`
- `type` (enum, required) — CASHAPP for all Cash App Pay transactions
  - Allowed values: `CASHAPP`
- `details` (GrantDetails, required)

### GrantDetails

- `status` (enum, required) — Describes whether or not this grant can be used to perform the action associated with it. If `ACTIVE`, it can be used to perform the action. If `EXPIRED`, it may no longer be used to perform the action due to the current time being past the "expires_at" time. If `CONSUMED`, it was already redeemed to perform the action and cannot be used again. If `REVOKED`, the customer or merchant explicitly unauthorized the grant, preventing it from being used to perform the action.
  - Allowed values: `ACTIVE`, `EXPIRED`, `CONSUMED`, `REVOKED`
- `cashapp` (GrantDetailsCashapp, required)
- `createdAt` (string, required) — When this grant was created, in [RFC 3339](https://datatracker.ietf.org/doc/html/rfc3339) format (UTC).
- `updatedAt` (string, required) — When this grant was last updated, in [RFC 3339](https://datatracker.ietf.org/doc/html/rfc3339) format (UTC).
- `expiresAt` (string, required) — If present, indicates when the grant's status will become EXPIRED, preventing a client from using it to create payments or refunds. The timestamp is in the [RFC 3339](https://datatracker.ietf.org/doc/html/rfc3339) format (UTC).

### GrantDetailsCashapp

- `customerId` (string, required)
- `cashtag` (string, required) — A publicly-accessible, unique identifier (username) for individuals and businesses using Cash App.

## Examples

**Request**

```json
{
  "customerId": "CST_AQmxh4y_QGoNNIG5NUw0jttqyYedL1LklACQdyJ3H-Vs6WmLtP6A_C7XjQNohvY",
  "grantId": "GRG_221243dc6985a6819ff6950c1a21332f7bc4a46ebd49b5a7002908ab768e8e5ff7831e084d0d2c9d8d939793b55eff50"
}
```

**Response**

```json
{
  "grant": {
    "id": "GRG_221243dc6985a6819ff6950c1a21332f7bc4a46ebd49b5a7002908ab768e8e5ff7831e084d0d2c9d8d939793b55eff50",
    "intent": "ON_FILE",
    "type": "CASHAPP",
    "details": {
      "status": "ACTIVE",
      "cashapp": {
        "customerId": "CST_AQmxh4y_QGoNNIG5NUw0jttqyYedL1LklACQdyJ3H-Vs6WmLtP6A_C7XjQNohvY",
        "cashtag": "$someCashTag"
      },
      "createdAt": "2024-07-08T22:42:46.039Z",
      "updatedAt": "2024-07-08T22:42:46.039Z",
      "expiresAt": "2034-07-08T22:42:46.039Z"
    }
  }
}
```

**SDK Code**

```python
import requests

url = "https://global-api-sandbox.afterpay.com/v2/grants/retrieve"

payload = {
    "customerId": "CST_AQmxh4y_QGoNNIG5NUw0jttqyYedL1LklACQdyJ3H-Vs6WmLtP6A_C7XjQNohvY",
    "grantId": "GRG_221243dc6985a6819ff6950c1a21332f7bc4a46ebd49b5a7002908ab768e8e5ff7831e084d0d2c9d8d939793b55eff50"
}
headers = {
    "User-Agent": "User-Agent"
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers, auth=("<username>", "<password>"))

print(response.json())
```

```javascript
const url = 'https://global-api-sandbox.afterpay.com/v2/grants/retrieve';
const credentials = btoa("<username>:<password>");

const options = {
  method: 'POST',
  headers: {
    'User-Agent': 'User-Agent',
    Authorization: `Basic ${credentials}`,
    'Content-Type': 'application/json'
  },
  body: '{"customerId":"CST_AQmxh4y_QGoNNIG5NUw0jttqyYedL1LklACQdyJ3H-Vs6WmLtP6A_C7XjQNohvY","grantId":"GRG_221243dc6985a6819ff6950c1a21332f7bc4a46ebd49b5a7002908ab768e8e5ff7831e084d0d2c9d8d939793b55eff50"}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://global-api-sandbox.afterpay.com/v2/grants/retrieve"

	payload := strings.NewReader("{\n  \"customerId\": \"CST_AQmxh4y_QGoNNIG5NUw0jttqyYedL1LklACQdyJ3H-Vs6WmLtP6A_C7XjQNohvY\",\n  \"grantId\": \"GRG_221243dc6985a6819ff6950c1a21332f7bc4a46ebd49b5a7002908ab768e8e5ff7831e084d0d2c9d8d939793b55eff50\"\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("User-Agent", "User-Agent")
	req.SetBasicAuth("<username>", "<password>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://global-api-sandbox.afterpay.com/v2/grants/retrieve")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["User-Agent"] = 'User-Agent'
request.basic_auth("<username>", "<password>")
request["Content-Type"] = 'application/json'
request.body = "{\n  \"customerId\": \"CST_AQmxh4y_QGoNNIG5NUw0jttqyYedL1LklACQdyJ3H-Vs6WmLtP6A_C7XjQNohvY\",\n  \"grantId\": \"GRG_221243dc6985a6819ff6950c1a21332f7bc4a46ebd49b5a7002908ab768e8e5ff7831e084d0d2c9d8d939793b55eff50\"\n}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://global-api-sandbox.afterpay.com/v2/grants/retrieve")
  .header("User-Agent", "User-Agent")
  .basicAuth("<username>", "<password>")
  .header("Content-Type", "application/json")
  .body("{\n  \"customerId\": \"CST_AQmxh4y_QGoNNIG5NUw0jttqyYedL1LklACQdyJ3H-Vs6WmLtP6A_C7XjQNohvY\",\n  \"grantId\": \"GRG_221243dc6985a6819ff6950c1a21332f7bc4a46ebd49b5a7002908ab768e8e5ff7831e084d0d2c9d8d939793b55eff50\"\n}")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://global-api-sandbox.afterpay.com/v2/grants/retrieve', [
  'body' => '{
  "customerId": "CST_AQmxh4y_QGoNNIG5NUw0jttqyYedL1LklACQdyJ3H-Vs6WmLtP6A_C7XjQNohvY",
  "grantId": "GRG_221243dc6985a6819ff6950c1a21332f7bc4a46ebd49b5a7002908ab768e8e5ff7831e084d0d2c9d8d939793b55eff50"
}',
  'headers' => [
    'Content-Type' => 'application/json',
    'User-Agent' => 'User-Agent',
  ],
    'auth' => ['<username>', '<password>'],
]);

echo $response->getBody();
```

```csharp
using RestSharp;
using RestSharp.Authenticators;

var client = new RestClient("https://global-api-sandbox.afterpay.com/v2/grants/retrieve");
client.Authenticator = new HttpBasicAuthenticator("<username>", "<password>");
var request = new RestRequest(Method.POST);
request.AddHeader("User-Agent", "User-Agent");

request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"customerId\": \"CST_AQmxh4y_QGoNNIG5NUw0jttqyYedL1LklACQdyJ3H-Vs6WmLtP6A_C7XjQNohvY\",\n  \"grantId\": \"GRG_221243dc6985a6819ff6950c1a21332f7bc4a46ebd49b5a7002908ab768e8e5ff7831e084d0d2c9d8d939793b55eff50\"\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let credentials = Data("<username>:<password>".utf8).base64EncodedString()

let headers = [
  "User-Agent": "User-Agent",
  "Authorization": "Basic \(credentials)",
  "Content-Type": "application/json"
]
let parameters = [
  "customerId": "CST_AQmxh4y_QGoNNIG5NUw0jttqyYedL1LklACQdyJ3H-Vs6WmLtP6A_C7XjQNohvY",
  "grantId": "GRG_221243dc6985a6819ff6950c1a21332f7bc4a46ebd49b5a7002908ab768e8e5ff7831e084d0d2c9d8d939793b55eff50"
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://global-api-sandbox.afterpay.com/v2/grants/retrieve")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```