The card platform
you can build on.
One REST API for cards, controls, ledger and KYC. Plain HTTPS with bearer tokens and idempotency keys, an OpenAPI reference generated from the same contract the platform runs on, and a test mode that runs the real authorization pipeline, declines and all.
curl -X POST https://api.rigid.fi/v1/simulated-spends \ -H "Authorization: Bearer $RIGID_API_TOKEN" \ -H "Content-Type: application/json" \ -d '{ "card_id": "card_3fk1", "amount": { "amount": "42.50", "currency": "USD" }, "mcc": "5411", "merchant_name": "Corner Grocer", "channel": "ecommerce" }' // 202 Accepted · decided in 61ms · authorization.decided webhook
First card in four calls.
Everything below is plain REST over https://api.rigid.fi. No client library required, nothing to keep up to date.
Mint a token
POST /v1/oauth/tokenCreate a cardholder
POST /v1/cardholdersIssue a card
POST /v1/cardsSimulate a spend
POST /v1/simulated-spends{
"type": "authorization.decided",
"created_at": "2026-09-28T12:00:00Z",
"data": {
"authorization_id": "auth_88f2",
"card_id": "card_3fk1",
"amount": "42.50",
"currency": "USD",
"decision": "approved",
"risk": { "score": 0.03, "action": "approve" },
"hold_id": "hold_1c9a"
}
}Signed webhooks
HMAC-SHA256 signatures with secret rotation, retries at 1m, 5m, 30m, 2h and 24h, and one-click redelivery from the console. Delivery is at-least-once, so your handler is idempotent by design, and every event carries the ids to make it so.
OpenAPI, not SDKs
- REST + OpenAPI
- curl
- Bearer tokens
- Idempotency-Key
- JSON
No client library to fall behind. The reference at rigid.fi/docs/api and the machine-readable spec at /docs/openapi.json come from the contract the platform is built against, so the docs and the API can't disagree.
Sandbox access in a day.
Test mode is the full platform on simulated rails: unlimited test cards, real decisions, real webhooks. Tell us what you're building.