Skip to content
Disposable virtual cards · Virtual card API

A card for the purchase,
not for the wallet.

Single-use, merchant-locked and time-boxed virtual cards, issued in 240ms with the controls in the same call and tokenized to Apple Pay and Google Pay. Your customers get a card that cannot be misused; your finance team gets a ledger that already knows what every charge was for.

Card issued, controls applied
240ms
Card issued, controls applied
Virtual card volume by 2029 (Juniper)
$17.4T
Virtual card volume by 2029 (Juniper)
Of merchant fraud losses are card-not-present (Nilson)
68%
Of merchant fraud losses are card-not-present (Nilson)
Time-boxed

9999 ···· ···· 2210

valid 12 – 19 Oct · PT only

Trip · Lisbon 🇵🇹expires in 6 days
Merchant-locked

9999 ···· ···· 0417

locked on first use · cap €15.99

Streaming · monthlyrenews · frozen anytime
Single-use

9999 ···· ···· 7703

1 authorization · exactly €1,240.00

Invoice #8841used · closed
✓Issued in 240msPOST /v1/cards · controls in the same call
THE CONTROLS

Eight primitives. Every disposable card is a combination of them.

Set them in the issue call. They are enforced at authorization, not reported afterwards, and every decline carries the control that produced it.

issue-card.httpREST
POST /v1/cards
{
  "card_product_id": "cp_consumer_eur",
  "cardholder_id": "ch_8k2m",
  "form_factor": "virtual",
  "controls": {
    "single_use": true,
    "merchant_lock": "first_use",
    "per_transaction_max": { "amount": "15.99", "currency": "EUR" },
    "not_after": "2026-10-31T23:59:59Z",
    "auto_close_on_settlement": true
  },
  "tokenize": ["apple_pay", "google_pay"]
}
// 201 Created · 240ms · card_7q2e · wallet token provisioned
single_use / max_authorizations

Dies after one authorization, or after n.

merchant_lock: first_use | allow_list

Bound to the first acceptor that charges it, or to a list you name. Matched on acceptor ID, never on a merchant name.

mcc_allow / mcc_deny · country_allow

Airlines and hotels only. No gambling. Portugal only, this week.

per_transaction_max · total_budget

A cap per charge and a budget for the card's life, derived exactly from the authorizations it made.

not_before / not_after

A card that exists for the trip, the project or the invoice, and then does not.

auto_close_on_settlement

Closes itself the moment the first clearing arrives, so nothing can ride on it afterwards.

freeze · revoke · reissue

Instant, from the app or the API, with the replacement tokenized to the wallet in the same motion.

tokenize · apple_pay · google_pay

Provisioned to the customer's wallet at issue time, so a disposable card still taps.

USE CASES

What a neobank can offer once cards are cheap to create and easy to kill.

Every item below is something a static card cannot do, because the card would have to be created for the purpose rather than the purpose fitted to the card.

Consumer neobanks

What your customer gets

Subscription control

One card per subscription. Cancelling is freezing the card, not finding the merchant's cancellation page.

Free-trial protection

A €1-capped single-use card that closes itself before the renewal date.

Privacy and breach shielding

A merchant-locked number is worthless anywhere else. The real PAN never leaves the bank.

Travel cards

Time-boxed and country-limited for the trip, destroyed on return.

Marketplace safety

Pay an unknown seller with a one-shot card capped at the price.

Family and teen cards

Per-person virtual cards with MCC denies, amount caps and instant parental freeze.

Business and spend management

What the finance team gets

Vendor cards

One card per supplier, locked to that acceptor, capped at contract value.

SaaS sprawl control

Every tool on its own card. Renewals become visible line items; a tool dies when its card does.

AP automation

A single-use card per invoice, auto-closed after first settlement. Card equals invoice, so reconciliation is a join, not a job.

Per-employee and per-project budgets

Budgets that expire when the project does, with a decision trace behind every decline.

Travel and ad spend

Just-in-time cards for a booking window, MCC-limited, capped, auditable.

Contractors

Capped, time-boxed cards for people who are not employees, issued to their wallet.

Platforms and marketplaces

What the platform can offer

Instant payouts

Gig workers, claimants and expense recipients paid onto a virtual card pushed to their wallet. No bank details collected.

Buyer-of-record flows

The platform buys from third-party merchants with a per-order single-use card.

Insurance and warranty

A card locked to the repair shop's MCC and the claim amount.

Travel agencies and OTAs

One virtual card per hotel booking, the largest virtual-card vertical there is.

Embedded finance

Your customers' customers get cards with your controls, under your programme.

AI agents

A card per task, minted by the agent under a mandate a human set. See agentic commerce.

Cards for AI agents live under a mandate. Read how that works on the agentic commerce page.

RISK, CONTAINED AT AUTHORIZATION

Card testing hits a dead number

A card that works once, or at one merchant, gives an attacker nothing to enumerate.

A breach exposes one card, not the account

The blast radius of a merchant compromise is the merchant-locked card that was stored there.

Fewer chargebacks

Disputed subscriptions are prevented by freezing rather than fought after the fact.

Reconciliation by construction

One card per invoice, booking or task means the ledger already knows what each charge was for.

FAQ

Disposable virtual cards, answered

What is a disposable virtual card?

A card number issued for a narrow purpose and a short life: one purchase, one merchant, one trip or one invoice. It carries the controls that define it (single-use, merchant lock, caps, expiry) and closes itself when its job is done, so the customer's real card details never reach a merchant.

Can a disposable virtual card be added to Apple Pay or Google Pay?

Yes. Cards are tokenized to the customer's wallet at issue time, so a single-use or merchant-locked card still taps in store and pays in-app.

How fast can we issue one?

A card with its controls is issued in one API call in about 240 milliseconds, which is fast enough to mint it at the moment of checkout and hand the details or the wallet token straight to the customer or the agent.

Do the controls work for physical cards too?

The same control primitives apply to every card on the platform. Disposable virtual cards are where they shine, because the card can be created for the control rather than the control retrofitted to the card.

WHO BUILDS ON IT

Who Disposable cards is for, and what they get.

The same platform, used differently by different teams. Each card names the segment, the outcome, and the products that carry it.

Expense management & B2B spend

A card per vendor, per employee, per invoice

Virtual cards locked to a supplier, capped at the contract, expiring with the project, with KYB on the customer and a ledger that already knows what each charge was for.

Marketplaces & platforms

Instant payouts and buyer-of-record cards, embedded in your product

Pay gig workers, claimants and sellers onto virtual cards pushed to their wallets, buy from third-party merchants with a per-order single-use card, and offer cards to your own customers under your brand.

Travel & OTAs

One virtual card per booking, in the merchant's currency

Time-boxed, MCC-limited cards for every hotel and flight, FX applied once at authorization across 150+ currencies, and fraud scoring tuned to travel's spiky, cross-border traffic.

Neobanks & consumer fintechs

A branded card in weeks, with onboarding your compliance team runs

Virtual cards tokenized to Apple Pay and Google Pay on day one, KYC flows configured per programme, Fraud AI on every tap, and disposable cards for subscriptions and privacy.

Issue your first disposable card in the demo.

We mint a single-use, merchant-locked card live, charge it twice, and show you the decline and the ledger entry.