# Get Account & Routing Numbers (masked)

**GET** `/users/{user_id}/accounts/{account_id}/numbers`

Base URL: `https://live.savewithsail.com/api/v1`

Deposit routing details with the account number **masked**. Safe for display and polling. The full account number requires an explicit `POST …/numbers/reveal`. Requires the `account_numbers` key scope, connection product, and a user token.

## Authorization

- PartnerKey (http, bearer)
- x-sail-user-token (apiKey in header)

## Path parameters

- `user_id` (string, required)
  The Sail user id.
- `account_id` (string, required)
  The Sail account id.

## Responses

### 200

Masked deposit numbers.

- `account_id` (string)
  The Sail account id.
- `account_number_mask` (string)
  The account number with all but the last digits masked.
- `routing_number` (string)
  Routing numbers are public per-institution; returned unmasked.
- `last_revealed_at` (string<date-time>)
  When this partner last performed a full reveal, if ever.

Example:

```json
{
  "account_id": "string",
  "account_number_mask": "••••3388",
  "routing_number": "string",
  "last_revealed_at": "1970-01-01T00:00:00.000Z"
}
```

### 401

`user_token_required` / `invalid_user_token`.

### 403

`insufficient_key_scope` or `product_not_enabled`.

### default

Standard error envelope covering 400, 401, 403, 404, 429, and 500.

- `error` (object)
  The error detail.
  - `code` (string)
    Machine-readable code, e.g. `not_found`, `token_scope_mismatch`, `product_not_enabled`, `insufficient_key_scope`, `insufficient_token_scope`, `user_token_required`, `user_token_expired`, `invalid_user_token`, `invalid_key_configuration`, `connection_not_reconnectable`, `rate_limited`.
  - `message` (string)
    Human-readable error message. May change, so match on `error.code` instead.
  - `param` (string)
    The request field that caused the error, when applicable. Null otherwise.

Example:

```json
{
  "error": {
    "code": "string",
    "message": "string",
    "param": "string"
  }
}
```