Skip to main content
Three endpoints: register a cardholder under a business, list them, and issue a single-use card. Card details are returned once, encrypted to your own RSA public key.

Before you can call these

Two things have to be in place, and neither is self-service:
  1. Your API key needs the cards permission. Ask your Endl contact to enable it.
  2. You must register an RSA public key, or issuing fails with 400 ERRCRD_1004. See Card details encryption.
The business customer must also be enabled for cards — otherwise every call returns 400 ERRCRD_1001.

Headers

Response shape

Success returns the object directly — 200 or 201, no envelope. Every error returns this envelope, with the stable code in errors[].code:
This differs from the rest of /api/v0, where a success body is unwrapped and errors vary by the layer that raised them. On Cards the split is simple: success bare, every error enveloped.

Error codes