Get card CVV
GET /api/partner/cards/:id/card-cvv
Returns the CVV2 for the card. Sensitive — never log this
response. Requires expDate and securityKey (RSA-OAEP, base64).
Request
Unauthorized — missing or invalid JWT
Forbidden — resource not owned by the calling partner