Card
A debit card on the bank's BIN linked to an account: lifecycle, controls, and the PAN behind a token.
OBJECTThe Card objectA debit card on the bank's BIN linked to an account: lifecycle, controls, and the PAN behind a token.POSTCreate a card
/cards · Issue a cardGETList all cards/cards · List cardsGETClearings posted against an account or facility that could not carry them/cards/clearing-exceptionsPOSTSettle a business date's cleared purchases with the network/cards/settlementsGETRead payment descriptions for customer statements/cards/statement-detailsGETGet a card by ID/cards/{id} · Read a cardPOSTAnswer a directory server's 3-D Secure authentication request (AReq) with an ARes or Erro message/cards/3ds/areqPOSTAnswer a 3-D Secure challenge message (CReq) with a CRes or Erro message/cards/3ds/creqPOSTIndex card numbers, end expired challenges and deliver due challenge results now/cards/3ds/maintenance-runsGETList the clearing file exception queue/cards/clearing/exceptions · Verified staff on the card clearing desk's narrow scopes only: cards:clearing:read for reads, cards:clearing:write with a step-up within five minutes for writes; cards:write does not reach these routes and no service token or API key doesPOSTFetch a processing date's clearing files from the configured source/cards/clearing/fetches · Verified staff on the card clearing desk's narrow scopes only: cards:clearing:read for reads, cards:clearing:write with a step-up within five minutes for writes; cards:write does not reach these routes and no service token or API key doesPOSTDeliver a network clearing and settlement file by upload/cards/clearing/files · Verified staff on the card clearing desk's narrow scopes only: cards:clearing:read for reads, cards:clearing:write with a step-up within five minutes for writes; cards:write does not reach these routes and no service token or API key doesGETList retained clearing files/cards/clearing/files · Verified staff on the card clearing desk's narrow scopes only: cards:clearing:read for reads, cards:clearing:write with a step-up within five minutes for writes; cards:write does not reach these routes and no service token or API key doesPOSTPropose independently reviewed fuel driver and vehicle authority/cards/fleet/authorities · Verified cards staff and fresh step-up for authority changes; independent operations:approve reviewGETObserve retained actual fuel obligations awaiting accounting/cards/fleet/close-readiness · Svc_operations with cards:read or verified cards staff may observe retained uncompleted presentments through date=YYYY-MM-DDGETPage immutable fleet authority versions for one card/cards/fleet/history · Verified cards staff and fresh step-up for authority changes; independent operations:approve reviewPOSTRetain signed measured fuel presentment and policy exceptions/cards/fleet/presentments · Verified cards staff and fresh step-up for authority changes; independent operations:approve reviewPOSTDecide a token service's token authorization request: approve, decline or require identification and verification (token service connector only)/cards/network-tokens/authorization-requests · Only the network's own token service connector (svc_vts for visa, svc_mdes for mastercard, svc_ddx for discover) holding cards:tokens:network and no API key; cards:write and staff are refusedPOSTDeliver pending token service commands now (staff)/cards/network-tokens/command-deliveries · Staff with cards:tokens:write and a fresh step-up run a delivery pass now (the service also delivers every CARD_NETWORK_TOKEN_DELIVERY_INTERVAL)POSTApply a token lifecycle notification from the token service (token service connector only)/cards/network-tokens/notifications · Only the network's own token service connector (svc_vts for visa, svc_mdes for mastercard, svc_ddx for discover) holding cards:tokens:network and no API key; cards:write and staff are refusedPOSTPropose a resume, a controls change or a card replacement for independent review (staff)/cards/network-tokens/proposals · Staff with cards:tokens:write and a fresh step-up propose resuming a bank suspension, replacing a token's controls (both at the token's current sequence) or moving a card's tokens to a replacement card with the same holder, account, facility, network and kindGETList network token proposals, newest first (staff)/cards/network-tokens/proposals · Staff with cards:tokens:read; newest first, pending=true leaves out reviewed proposals; limit and starting_after pageGETList a card's network tokens for its holder or network token staff/cards/network-tokens/tokens · The card's bound holder (verified customer identity) or staff with cards:tokens:readPOSTCheck the one-time code the cardholder entered in the wallet (token service connector only)/cards/network-tokens/verification-attempts · Only the network's own token service connector (svc_vts for visa, svc_mdes for mastercard, svc_ddx for discover) holding cards:tokens:network and no API key; cards:write and staff are refusedPOSTSend the cardholder a one-time code by the method they chose in the wallet (token service connector only)/cards/network-tokens/verification-codes · Only the network's own token service connector (svc_vts for visa, svc_mdes for mastercard, svc_ddx for discover) holding cards:tokens:network and no API key; cards:write and staff are refusedPOSTFetch and record the card bureau's acknowledgment and status files/cards/production/bureau-fetchesPOSTDeliver a card bureau acknowledgment or status file/cards/production/bureau-filesPOSTBuild a production file from the pending orders/cards/production/filesPOSTOrder a new, reissued or replacement physical card from the card bureau/cards/production/ordersPOSTRecord the PIN service's outcome for a PIN-set session/cards/production/pin-eventsPOSTOpen a session to set a card's PIN with the PIN service/cards/production/pin-set-sessionsPOSTPropose a bulk expiry renewal or reissue run for independent approval/cards/production/runsPOSTSend the production files due for submission to the card bureau/cards/production/submissionsPOSTPropose a source-bound card scheme dispute with signed eligibility evidence/cards/schemes/cases · Verified cards staff, fresh step-up on writes and independent operations:approve reviewGETList the latest 200 retained scheme cases/cards/schemes/cases · Verified cards staff, fresh step-up on writes and independent operations:approve reviewGETObserve retained signed scheme financial facts and unfinished accounting for bank close/cards/schemes/close-readiness · Required date=YYYY-MM-DD is a nonfuture bank posting datePOSTCapture source-bound interchange, network fees or actual external cash reconciliation/cards/settlements/network-finance · Verified staff cards authority; fresh step-up for writes and independent operations:approve reviewGETList the latest 200 retained network finance records/cards/settlements/network-finance · Verified staff cards authority; fresh step-up for writes and independent operations:approve reviewPOSTPropose explicit historical card settlement membership/cards/settlements/reconciliationsGETList historical card settlement reconciliations/cards/settlements/reconciliationsPOSTRetain customer receipt allocations against actual posted card sources/cards/spend/expenses · Verified bank-bound customer PERSON identity with customer scope, session/device and online account organization membership requiredGETPage expense evidence for the current authorized business organization/cards/spend/expenses · Verified bank-bound customer PERSON identity with customer scope, session/device and online account organization membership requiredPOSTPrepare one immutable customer accounting artifact from reviewed actual card expenses/cards/spend/exports · Verified bank-bound customer PERSON identity with customer scope, session/device and online account organization membership requiredGETStand-in decisions and network advices the switch posts after answering (cards:read; status=pending, posted, matched, recorded, reversed, held or refused)/cards/switch/advicesGETMessages the card networks sent the switch and the answers, redacted (cards:read; network and network_ref filter)/cards/switch/exchangesGETCard network links: adapter (simulator), profile, connection, sign-on and last echo (cards:read)/cards/switch/linksPOSTPropose the next version of the stand-in parameters (cards:switch:write, fresh step-up); in force only once a different member of staff approves/cards/switch/stand-in-parametersGETEvery version of the bank's stand-in parameters and its decision (cards:read)/cards/switch/stand-in-parametersPOSTAuthorize using an active token and exact signed cryptogram verification/cards/wallets/authorizations · Requires the same verified processor identity and signing keyPOSTApply a signed issuer-processor token lifecycle receipt/cards/wallets/events · Requires svc_issuerproc service JWT with cards:write and an Ed25519 signature from the configured current network/requestor keyPOSTRecord verified cardholder consent for a configured token requestor/cards/wallets/tokens · Only an explicitly bank-bound customer with customer scope, the card's exact holder ID, verified session/device and authentication within five minutes may consentGETList card token lifecycle state for its holder or bank authority/cards/wallets/tokens · Card_id is requiredPOSTActivate a card/cards/{id}/activatePOSTClose a card/cards/{id}/closePUTReplace the card's controls/cards/{id}/controlsGETReveal the card number (step-up required)/cards/{id}/panPOSTPause a card/cards/{id}/pausePOSTBind a card to its verification and issuer master keys and return its codes once/cards/{id}/personalization · Verified bank staff with cards:read observe the registry; opening a ceremony, entering a component, personalising a card and unlocking a PIN take the narrow cards:security:write and a step-up in the last five minutes, never cards:writePOSTSet or change a card's PIN from a PIN-pad block/cards/{id}/pin · Verified bank staff with cards:read observe the registry; opening a ceremony, entering a component, personalising a card and unlocking a PIN take the narrow cards:security:write and a step-up in the last five minutes, never cards:writeGETA card's PIN verification record without the value/cards/{id}/pin · Verified bank staff with cards:read observe the registry; opening a ceremony, entering a component, personalising a card and unlocking a PIN take the narrow cards:security:write and a step-up in the last five minutes, never cards:writeGETList the production orders that produce or replace a card/cards/{id}/production-ordersPOSTReport a card lost or stolen (optional Idempotency-Key records the report and replays its outcome; the operations service reports on cards:report under its command key, relaying the request id, maker and checker)/cards/{id}/reportPOSTResume a paused card/cards/{id}/resumeGETThe keys personalisation fixed for a card/cards/{id}/security-binding · Verified bank staff with cards:read observe the registry; opening a ceremony, entering a component, personalising a card and unlocking a PIN take the narrow cards:security:write and a step-up in the last five minutes, never cards:writeGETRead a 3-D Secure authentication with its challenge messages and value uses/cards/3ds/authentications/{id}GETRead a 3-D Secure enrollment proposal and its decision/cards/3ds/enrollment-proposals/{id}GETRead a clearing file exception and its resolutions/cards/clearing/exceptions/{id} · Verified staff on the card clearing desk's narrow scopes only: cards:clearing:read for reads, cards:clearing:write with a step-up within five minutes for writes; cards:write does not reach these routes and no service token or API key doesGETRead a retained clearing file/cards/clearing/files/{id} · Verified staff on the card clearing desk's narrow scopes only: cards:clearing:read for reads, cards:clearing:write with a step-up within five minutes for writes; cards:write does not reach these routes and no service token or API key doesGETRead a clearing exception resolution/cards/clearing/resolutions/{id} · Verified staff on the card clearing desk's narrow scopes only: cards:clearing:read for reads, cards:clearing:write with a step-up within five minutes for writes; cards:write does not reach these routes and no service token or API key doesGETRead a clearing file settlement reconciliation/cards/clearing/settlements/{id} · Verified staff on the card clearing desk's narrow scopes only: cards:clearing:read for reads, cards:clearing:write with a step-up within five minutes for writes; cards:write does not reach these routes and no service token or API key doesGETRead retained driver and vehicle fuel authority/cards/fleet/authorities/{id} · Verified cards staff and fresh step-up for authority changes; independent operations:approve reviewGETRead retained fuel lines and actual clearing result/cards/fleet/presentments/{id} · Verified cards staff and fresh step-up for authority changes; independent operations:approve reviewGETRead a network token proposal and its review (staff)/cards/network-tokens/proposals/{id} · Staff with cards:tokens:readGETRead a network token's network, issuer and effective status/cards/network-tokens/tokens/{id} · The card's bound holder (verified customer identity) or staff with cards:tokens:readGETRead a received bureau file and what each record did/cards/production/bureau-files/{id}GETRead a production file and its submission attempts/cards/production/files/{id}GETRead a card production order and its events/cards/production/orders/{id}GETRead a PIN-set session/cards/production/pin-set-sessions/{id}GETRead a production run and what it did with each candidate/cards/production/runs/{id}GETRead exact retained action and posting evidence/cards/schemes/actions/{id} · Verified cards staff, fresh step-up on writes and independent operations:approve reviewGETRead actual scheme state and bank recovery balances/cards/schemes/cases/{id} · Verified cards staff, fresh step-up on writes and independent operations:approve reviewGETRead retained network finance sources and posting evidence/cards/settlements/network-finance/{id} · Verified staff cards authority; fresh step-up for writes and independent operations:approve reviewGETRead historical card settlement evidence/cards/settlements/reconciliations/{id}GETRead retained receipt coding review and export membership/cards/spend/expenses/{id} · Verified bank-bound customer PERSON identity with customer scope, session/device and online account organization membership requiredGETRead exact retained accounting artifact without asserting external import/cards/spend/exports/{id} · Verified bank-bound customer PERSON identity with customer scope, session/device and online account organization membership requiredPOSTPost pending switch advices now (cards:switch:write, fresh step-up)/cards/switch/advices/runsGETRead one switch advice and its resolutions (cards:read)/cards/switch/advices/{id}GETRead one switch exchange (cards:read)/cards/switch/exchanges/{id}GETThe stand-in parameters in force (cards:read, or svc_cardnet with cards:switch:network)/cards/switch/stand-in-parameters/activeGETRead retained wallet lifecycle and effective status/cards/wallets/tokens/{id} · Card_id is requiredGETList a card's 3-D Secure authentications, newest first/cards/{id}/3ds/authenticationsGETRead a card's 3-D Secure enrollment, its changes and proposals/cards/{id}/3ds/enrollmentPOSTReset a locked PIN's try counter/cards/{id}/pin/unlock · Verified bank staff with cards:read observe the registry; opening a ceremony, entering a component, personalising a card and unlocking a PIN take the narrow cards:security:write and a step-up in the last five minutes, never cards:writePOSTApprove, reject or withdraw a 3-D Secure enrollment proposal/cards/3ds/enrollment-proposals/{id}/decisionsPOSTPropose posting, returning or writing off a clearing file exception/cards/clearing/exceptions/{id}/resolutions · Verified staff on the card clearing desk's narrow scopes only: cards:clearing:read for reads, cards:clearing:write with a step-up within five minutes for writes; cards:write does not reach these routes and no service token or API key doesPOSTMatch and post a clearing file's records/cards/clearing/files/{id}/processing · Verified staff on the card clearing desk's narrow scopes only: cards:clearing:read for reads, cards:clearing:write with a step-up within five minutes for writes; cards:write does not reach these routes and no service token or API key doesGETList a clearing file's records with their dispositions/cards/clearing/files/{id}/records · Verified staff on the card clearing desk's narrow scopes only: cards:clearing:read for reads, cards:clearing:write with a step-up within five minutes for writes; cards:write does not reach these routes and no service token or API key doesPOSTPropose a clearing file's settlement reconciliation to the master account movement/cards/clearing/files/{id}/settlements · Verified staff on the card clearing desk's narrow scopes only: cards:clearing:read for reads, cards:clearing:write with a step-up within five minutes for writes; cards:write does not reach these routes and no service token or API key doesPOSTApply an approved clearing exception resolution/cards/clearing/resolutions/{id}/applications · Verified staff on the card clearing desk's narrow scopes only: cards:clearing:read for reads, cards:clearing:write with a step-up within five minutes for writes; cards:write does not reach these routes and no service token or API key doesPOSTIndependently review a clearing exception resolution/cards/clearing/resolutions/{id}/reviews · Verified staff on the card clearing desk's narrow scopes only: cards:clearing:read for reads, cards:clearing:write with a step-up within five minutes for writes; cards:write does not reach these routes and no service token or API key doesPOSTPost an approved clearing file settlement reconciliation/cards/clearing/settlements/{id}/applications · Verified staff on the card clearing desk's narrow scopes only: cards:clearing:read for reads, cards:clearing:write with a step-up within five minutes for writes; cards:write does not reach these routes and no service token or API key doesPOSTIndependently review a clearing file settlement reconciliation/cards/clearing/settlements/{id}/reviews · Verified staff on the card clearing desk's narrow scopes only: cards:clearing:read for reads, cards:clearing:write with a step-up within five minutes for writes; cards:write does not reach these routes and no service token or API key doesPOSTIndependently review exact fleet driver vehicle and policy evidence/cards/fleet/authorities/{id}/reviews · Verified cards staff and fresh step-up for authority changes; independent operations:approve reviewPOSTImmediately revoke fleet authority for new spending/cards/fleet/authorities/{id}/revocations · Verified cards staff and fresh step-up for authority changes; independent operations:approve reviewPOSTPost or recover actual fuel clearing under retained final details/cards/fleet/presentments/{id}/applications · Verified cards staff and fresh step-up for authority changes; independent operations:approve reviewPOSTIndependently approve an exact evidenced fuel posting exception/cards/fleet/presentments/{id}/reviews · Verified cards staff and fresh step-up for authority changes; independent operations:approve reviewPOSTApprove or reject another staff member's network token proposal (staff)/cards/network-tokens/proposals/{id}/reviews · Staff with cards:tokens:approve, a fresh step-up and a subject different from the maker (403 otherwise) approve or reject against the proposal's content_sha256GETRead the commands sent to the token service for a token and every delivery attempt (staff)/cards/network-tokens/tokens/{id}/commands · Staff with cards:tokens:readPOSTReplace a token's own controls as its holder/cards/network-tokens/tokens/{id}/controls · The bound holder with authentication within five minutes replaces the token's own controls at the current sequence: per transaction and daily limits in minor units, channels within the token domain, blocked MCCs and a valid-until timeGETRead a network token's immutable events by sequence/cards/network-tokens/tokens/{id}/history · The card's bound holder (verified customer identity) or staff with cards:tokens:readPOSTApprove a pending token in the bank app as its holder (issuer_app verification)/cards/network-tokens/tokens/{id}/holder-verifications · The bound holder with authentication within five minutes approves a pending_idv token offered issuer_app verification, at the current sequence; staff cannot verify for the holderPOSTSuspend, resume or delete a token as its holder, or suspend or delete it as staff/cards/network-tokens/tokens/{id}/lifecycle · The bound holder with authentication within five minutes may suspend, resume their own suspension or delete; staff with cards:tokens:write and a fresh step-up may suspend (taking over a holder suspension as a bank hold) or deletePOSTApprove, reject or withdraw a production run/cards/production/runs/{id}/decisionsPOSTOrder the cards of an approved production run/cards/production/runs/{id}/executionsPOSTApply or recover reviewed bank-only scheme accounting/cards/schemes/actions/{id}/applications · Verified cards staff, fresh step-up on writes and independent operations:approve reviewPOSTIndependently review source-bound scheme action and reserved capacity/cards/schemes/actions/{id}/reviews · Verified cards staff, fresh step-up on writes and independent operations:approve reviewPOSTRetain an outbound instruction, authenticated network fact, cash fact or exact loss allocation/cards/schemes/cases/{id}/actions · Verified cards staff, fresh step-up on writes and independent operations:approve reviewPOSTPin actual original clearing and queue a deadline-bound issuer instruction/cards/schemes/cases/{id}/applications · Verified cards staff, fresh step-up on writes and independent operations:approve reviewGETRead immutable case instructions, signed facts and accounting results/cards/schemes/cases/{id}/history · Verified cards staff, fresh step-up on writes and independent operations:approve reviewPOSTIndependently review exact original clearing and scheme eligibility/cards/schemes/cases/{id}/reviews · Verified cards staff, fresh step-up on writes and independent operations:approve reviewPOSTPost or recover exact independently reviewed network accounting/cards/settlements/network-finance/{id}/applications · Verified staff cards authority; fresh step-up for writes and independent operations:approve reviewPOSTIndependently review exact network finance sources/cards/settlements/network-finance/{id}/reviews · Verified staff cards authority; fresh step-up for writes and independent operations:approve reviewPOSTFence unposted legacy cash and apply reviewed membership/cards/settlements/reconciliations/{id}/applicationsPOSTIndependently review exact historical settlement evidence/cards/settlements/reconciliations/{id}/reviewsPOSTIndependently review exact receipt source and customer accounting classifications/cards/spend/expenses/{id}/reviews · Verified bank-bound customer PERSON identity with customer scope, session/device and online account organization membership requiredGETObserve whether an exported bank source was subsequently reversed or changed/cards/spend/exports/{id}/source-status · Verified bank-bound customer PERSON identity with customer scope, session/device and online account organization membership requiredPOSTPropose posting or refusing a held switch advice (cards:switch:write, fresh step-up)/cards/switch/advices/{id}/resolutionsPOSTApprove or reject another member of staff's resolution (cards:switch:write and cards:switch:approve, fresh step-up), or withdraw your own; an approved post is attempted at once/cards/switch/resolutions/{id}/decisionPOSTApprove or reject another member of staff's stand-in parameters (cards:switch:write and cards:switch:approve, fresh step-up), or withdraw your own/cards/switch/stand-in-parameters/{id}/decisionPOSTSuspend, resume or permanently disable a wallet token in core/cards/wallets/tokens/{id}/controls · Fresh verified holder may suspend, resume or delete using the exact current local sequenceGETRead immutable wallet network receipts and local controls by sequence/cards/wallets/tokens/{id}/history · Same holder or bank read authority as token readsPOSTChange a card's 3-D Secure enrollment as its cardholder/cards/{id}/3ds/enrollment/changesPOSTPropose a staff change to a card's 3-D Secure enrollment/cards/{id}/3ds/enrollment/proposals