> ## Documentation Index
> Fetch the complete documentation index at: https://docs.endl.io/llms.txt
> Use this file to discover all available pages before exploring further.

# List cardholders

> Cardholders under a business, **20 per page**, each with their cards newest first.

Follow `nextCursor` until it is `null`; `hasMore` says whether another page exists.



## OpenAPI

````yaml api-reference/endl-cards-api.json GET /api/v0/customer/{businessId}/card-users
openapi: 3.1.0
info:
  title: Endl Cards API
  version: '0'
  description: >-
    Issue single-use virtual cards to cardholders under a business customer.


    Three endpoints under `/api/v0/customer`. The key must carry the **`cards`**
    permission, and the business customer must be enabled for cards.


    **Card details are returned once, encrypted to your own RSA public key** —
    see [Card details encryption](/api-reference/cards/encryption).
servers:
  - url: https://api-sandbox.endl.io
    description: Sandbox
security:
  - apiKey: []
paths:
  /api/v0/customer/{businessId}/card-users:
    get:
      tags:
        - Cards
      summary: List cardholders
      description: >-
        Cardholders under a business, **20 per page**, each with their cards
        newest first.


        Follow `nextCursor` until it is `null`; `hasMore` says whether another
        page exists.
      parameters:
        - $ref: '#/components/parameters/ApiVersion'
        - $ref: '#/components/parameters/BusinessId'
        - name: cursor
          in: query
          schema:
            type: string
          description: The `nextCursor` from the previous page. Omit for the first page.
      responses:
        '200':
          description: A page of cardholders.
          content:
            application/json:
              schema:
                type: object
                properties:
                  cardholders:
                    type: array
                    description: Cardholders on this page.
                    items:
                      type: object
                      properties:
                        cardholderId:
                          type: string
                          description: >-
                            `cus_…`. **Omitted** if the cardholder has no
                            reference id yet.
                        businessId:
                          type: string
                          description: The business.
                        firstName:
                          type: string
                          description: As created.
                        lastName:
                          type: string
                          description: As created.
                        email:
                          type: string
                          description: As created.
                        status:
                          type: string
                          enum:
                            - active
                            - pending
                            - rejected
                            - locked
                            - canceled
                          description: Cardholder state.
                        cards:
                          type: array
                          description: The cardholder's cards, newest first.
                          items:
                            type: object
                            properties:
                              cardId:
                                type: string
                                format: uuid
                                description: >-
                                  Card id, a UUID. Also the `aad` on
                                  `encryptedCard`.
                              kind:
                                type: string
                                enum:
                                  - scoped
                                  - standard
                                description: '`scoped` (single-use) or `standard`.'
                              status:
                                type: string
                                enum:
                                  - active
                                  - notActivated
                                  - locked
                                  - canceled
                                description: Card state.
                              last4:
                                type: string
                                description: Last four digits.
                              expiryMonth:
                                type: string
                                description: '`MM`.'
                              expiryYear:
                                type: string
                                description: '`YYYY`.'
                              displayName:
                                type: string
                                description: When set.
                              limitAmount:
                                type: integer
                                description: Limit in cents.
                              limitFrequency:
                                type: string
                                enum:
                                  - allTime
                                  - perAuthorization
                                  - per24HourPeriod
                                  - per7DayPeriod
                                  - per30DayPeriod
                                  - perYearPeriod
                                description: Limit window.
                              scope:
                                type: object
                                description: >-
                                  Single-use cards only. See [Issue single-use
                                  card](/api-reference/cards/issue-card).
                                properties:
                                  amountInUSDCents:
                                    type: integer
                                    description: As requested.
                                  lifetimeLimitCents:
                                    type: integer
                                    description: Amount plus buffer, rounded up.
                                  bufferPercentage:
                                    type: integer
                                    description: As requested, or 20.
                                  expiresAt:
                                    type: string
                                    nullable: true
                                    description: As requested.
                                  allowedMccs:
                                    type: array
                                    items:
                                      type: string
                                    description: As requested, or `[]`.
                                  allowedMerchants:
                                    type: array
                                    items:
                                      type: string
                                    description: As requested, or `[]`.
                                  cardType:
                                    type: string
                                    enum:
                                      - consumer
                                      - commercial
                                    description: '`consumer` or `commercial`.'
                                  purpose:
                                    type: string
                                    nullable: true
                                    description: As requested.
                                  spentAt:
                                    type: string
                                    nullable: true
                                    description: >-
                                      Set when the first approved purchase
                                      closes the card.
                  nextCursor:
                    type: string
                    nullable: true
                    description: Pass as `cursor`. `null` on the last page.
                  hasMore:
                    type: boolean
                    description: Whether another page exists.
              example:
                cardholders:
                  - cardholderId: cus_6OzDYZWl5Aim37RwvZfZ
                    businessId: cus_HUCgMg1iqWb379FMNvaJ
                    firstName: Ada
                    lastName: Lovelace
                    email: ada@example.com
                    status: active
                    cards:
                      - cardId: f92950fa-bc30-4aaa-bafc-995b454bf1e5
                        kind: scoped
                        status: canceled
                        last4: '8326'
                        expiryMonth: '05'
                        expiryYear: '2031'
                        displayName: Agent card
                        limitAmount: 120
                        limitFrequency: allTime
                        scope:
                          amountInUSDCents: 100
                          lifetimeLimitCents: 120
                          bufferPercentage: 20
                          expiresAt: null
                          allowedMccs: []
                          allowedMerchants: []
                          cardType: consumer
                          purpose: order 8841
                          spentAt: '2026-09-29T10:12:00Z'
                nextCursor: null
                hasMore: false
        '400':
          description: >-
            `ERRCRD_1000` not a business customer · `ERRCRD_1001` business not
            enabled for cards · `ERRCRD_1005` invalid cursor.
          content:
            application/json:
              example:
                code: 400
                message: amountInUSDCents must be an integer from 1 to 10000000
                status: ERROR
                data: null
                errors:
                  - code: ERRCRD_1005
                    message: amountInUSDCents must be an integer from 1 to 10000000
                    field: null
        '401':
          description: Missing or invalid `Api-Key`.
          content:
            application/json:
              example:
                code: 401
                message: Partner API key required
                status: ERROR
                data: null
                errors:
                  - code: ERRCORE_1004
                    message: Partner API key required
                    field: null
        '403':
          description: Another partner's business, or the key lacks `cards`.
          content:
            application/json:
              example:
                code: 403
                message: Access denied / missing cards permission
                status: ERROR
                data: null
                errors:
                  - code: ERRCORE_1005
                    message: Access denied / missing cards permission
                    field: null
        '404':
          description: Unknown `businessId`.
          content:
            application/json:
              example:
                code: 404
                message: Reference not found
                status: ERROR
                data: null
                errors:
                  - code: ERRREF_1001
                    message: Reference not found
                    field: userId
        '502':
          description: Card service unavailable.
          content:
            application/json:
              example:
                code: 502
                message: Card issuing temporarily unavailable
                status: ERROR
                data: null
                errors:
                  - code: ERRCRD_1009
                    message: Card issuing temporarily unavailable
                    field: null
components:
  parameters:
    ApiVersion:
      name: Api-Version
      in: header
      required: true
      description: >-
        The API version this request targets. `2026-09.1`. See
        [Versioning](/api-reference/versioning).
      schema:
        type: string
        pattern: ^\d{4}-\d{2}\.\d+$
        default: 2026-09.1
      example: 2026-09.1
    BusinessId:
      name: businessId
      in: path
      required: true
      schema:
        type: string
      description: Your **business** customer, `cus_…`, enabled for cards.
      example: cus_HUCgMg1iqWb379FMNvaJ
  securitySchemes:
    apiKey:
      type: apiKey
      in: header
      name: Api-Key
      description: Partner API key. Must carry the `cards` permission.

````