Skip to main content
Cards are funded from an entity account and can be issued as single-use disposable cards or reusable virtual cards. All cards are managed through the same lifecycle endpoints: freeze, unfreeze, reassign, and delete.

The Card object

string
Unique card identifier.
string
Card status. One of active, blocked, or fraud.
string
Display name assigned to the card. Submitted as card_name in the request.
string
Card type. One of disposable or virtual.
string
Full card number (PAN). Treat as sensitive; never log or store.
string
Card expiration month in MM format.
string
Card expiration year in YY format.
string
Card verification value. Treat as sensitive; never log or store.
string
Cardholder’s first name. Present on Get card details.
string
Cardholder’s last name. Present on Get card details.
number
A placeholder value in the smallest currency unit. Present on Get card details. Not the card’s spending limit: the amount a card can actually transact is the available balance on its linked account.
string
ISO 4217 currency code for the card. Present on Get card details.
object
Spending controls on this card.
array
Per-MCC spending controls. Returned as an empty array.
array
Spending controls for a named group of MCCs. Returned as an empty array.
object
Billing address on file for the card.
object
Shipping address. Always null.
number
Unix timestamp in milliseconds when the card was created. Present on card creation responses.

Create a disposable card

POST /disposable-cards Issues a single-use virtual card funded from the specified account. The card is automatically blocked after its first successful transaction.

Request parameters

string
required
The ID of the account to fund the card from. The account’s currency doesn’t need to match the card’s currency: FX conversion is applied automatically at the prevailing rate as the card is used.
string
required
Display name for the card. Used in listings and the dashboard. Returned as name in the response.
object
required
Identity details for the cardholder.
string
required
ISO 4217 currency code for the card. See Supported currencies.
string
required
Card expiration month in MM format. e.g. "12".
string
required
Card expiration year in YY format. e.g. "27". Must be no more than 2 years from the creation date. Requests for a later date are rejected.
string
The ID of the entity to issue this card for. Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.

Request

Response

Returns the created card object with status: "active". Card credentials (number, cvv) are included in the creation response only.

Errors


Create a virtual card

POST /virtual-cards Issues a reusable virtual card. Unlike disposable cards, virtual cards aren’t blocked after a single transaction and support a higher lifetime transaction count.

Request parameters

string
required
The ID of the account to fund the card from. The account’s currency doesn’t need to match the card’s currency: FX conversion is applied automatically at the prevailing rate as the card is used.
string
required
Display name for the card. Returned as name in the response.
string
required
ISO 4217 currency code for the card. See Supported currencies.
object
required
Identity details for the cardholder. Same shape as disposable card cardholder.
string
required
Card expiration month in MM format. e.g. "12".
string
required
Card expiration year in YY format. e.g. "27". Must be no more than 2 years from the creation date. Requests for a later date are rejected.
string
The ID of the entity to issue this card for. Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.

Request

Response

Returns the created card object. Card credentials (number, cvv) are included in the creation response only.

Errors


List cards

GET /cards Returns a paginated list of cards. Soft-deleted cards are excluded; frozen and blocked cards are included.

Query parameters

string
Filter by account. If omitted, returns all cards across all accounts for the entity.
string
Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.
integer
Number of results per page. Between 1 and 100. Defaults to 20.
string
Pagination cursor for the next page. Use next_cursor from the previous response.
string
Pagination cursor for the previous page. Use previous_cursor from the previous response.

Request

Response

array
Array of card summary objects.
object
Pagination metadata.

Errors


Get card details

GET /card-details/{card_id} Returns full details for a single card, including sensitive credentials.
This endpoint returns the card number and cvv. Ensure your server-side code never logs or stores these values.

Path parameters

string
required
The card ID.

Query parameters

string
Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.

Request

Response

Returns the full Card object, plus first_name, last_name, amount, and currency.

Errors


Get card transactions

GET /card-transactions/{card_id} Returns a paginated list of transactions made with a specific card.

Path parameters

string
required
The card ID.

Query parameters

integer
Number of results per page. Defaults to 20.
string
Cursor for the next page.
string
Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.

Request

Response

array
Array of card transaction objects.
object
Pagination metadata.

Errors


Freeze a card

PATCH /card-details/{card_id}/freeze Sets the card status to blocked. All authorization requests are declined while the card is frozen. The card record and spending history are preserved. Use Unfreeze to restore the card.

Path parameters

string
required
The card ID.

Request parameters

string
Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.

Request

Response

Errors


Unfreeze a card

PATCH /card-details/{card_id}/unfreeze Restores a frozen card to active status. Subsequent authorization requests are processed normally.

Path parameters

string
required
The card ID.

Request parameters

string
Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.

Request

Response

Errors


Reassign a card

PATCH /cards/{card_id}/account Moves the card to a different account owned by the same entity. If the target account’s currency differs from the card’s transaction currency, FX conversion is applied automatically at the prevailing rate.

Path parameters

string
required
The card ID.

Request parameters

string
required
The ID of the account to reassign the card to.
string
Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.

Request

Response

Errors


Delete a card

DELETE /card-details/{card_id} Soft-deletes the card. The card is immediately blocked and removed from all listings. The underlying record is retained for audit and transaction history purposes.
Deletion cannot be reversed. A deleted card cannot be reactivated; issue a new card if the cardholder needs continued access.

Path parameters

string
required
The card ID.

Request parameters

string
Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.

Request

Response

Errors