Skip to main content
POST
Issue single-use card

Authorizations

Api-Key
string
header
required

Partner API key. Must carry the cards permission.

Headers

Api-Version
string
default:2026-09.1
required

The API version this request targets. 2026-09.1. See Versioning.

Pattern: ^\d{4}-\d{2}\.\d+$
Idempotency-Key
string

1–64 characters. A retry with the same key never creates a second card.

Required string length: 1 - 64

Path Parameters

businessId
string
required

Your business customer, cus_…, enabled for cards.

cardholderId
string
required

An active cardholder of that business, cus_….

Body

application/json
amountInUSDCents
integer
required

1 – 10,000,000. Whole numbers only.

bufferPercentage
integer

0 – 20. Defaults to 20.

expiresAt
string

ISO-8601 with offset. Must be in the future and no more than 365 days out.

allowedMccs
string[]

Non-empty, unique 4-digit codes.

allowedMerchants
string[]

Non-empty, at most 25 unique names, 1–64 characters each.

displayName
string

At most 26 characters — letters, digits, spaces, . and -, with at least one letter.

purpose
string

At most 255 characters.

Response

The card, with its details encrypted in encryptedCard.

cardId
string<uuid>

The card. Also encryptedCard.aad.

cardholderId
string

Echo of the path.

status
string

active.

last4
string

Last four digits.

expiryMonth
string

MM.

expiryYear
string

YYYY.

scope
object

The spend scope as applied.

encryptedCard
object

The card number, CVV and expiry — returned once, encrypted to your RSA public key.