Skip to content

Issue a card

POST/v1/cards

Requires an API client bearer token.

Issues a card for the given cardholder under the specified card product. Requires an Idempotency-Key header. Emits card.created.

Parameters

Header parameters

NameRequiredDescription
Idempotency-Keyrequired

Client-chosen. An identical retry with the same key returns the stored response; reusing the key with a different payload returns 409.

Request body

card_product_idstring (uuid)required
cardholder_idstring (uuid)required

Example

curl -X POST https://api.rigid.fi/v1/cards \
  -H "Authorization: Bearer $RIGID_API_TOKEN" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "card_product_id": "uuid",
  "cardholder_id": "uuid"
}'

Responses

201

Issued card.

idstring (uuid)required
programme_idstring (uuid)required
card_product_idstring (uuid)required
cardholder_idstring (uuid)required
pan_refstringrequired
last4stringrequired
iinstringrequired
exp_monthintegerrequired
exp_yearintegerrequired
state"unactivated" | "active" | "suspended" | "terminated" | "lost" | "stolen"required
controlsarray of one ofrequired
+ show properties

One of

mcc_allow

kind"mcc_allow"required
valuesarray of stringrequired

mcc_deny

kind"mcc_deny"required
valuesarray of stringrequired

country_allow

kind"country_allow"required
valuesarray of stringrequired

country_deny

kind"country_deny"required
valuesarray of stringrequired

channel_allow

kind"channel_allow"required
valuesarray of stringrequired

channel_deny

kind"channel_deny"required
valuesarray of stringrequired

per_txn_cap

kind"per_txn_cap"required
amountstringrequired

per_day_cap

kind"per_day_cap"required
countintegerrequired

per_day_amount_cap

kind"per_day_amount_cap"required
amountstringrequired
funding_account_idstring | nullrequired
cvk_generationstringrequired
created_atstringrequired
currency"EUR" | "GBP" | "USD"required
cardholder_namestringrequired
cardholder_emailstringrequired
400

Validation error — including kyc_required (KYC not complete), or a missing/blank Idempotency-Key header

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
401

Authentication required

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
403

Forbidden — the caller may not act on this programme, or (code `live_mode_card_read_only`) live mode refuses a new card issuance, pending scheme certification

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
404

Card product or cardholder not found

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
409

Idempotency-Key reused with a different payload

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
500

Internal server error

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring