Record verified cardholder consent for a configured token requestor
/cards/wallets/tokensOnly an explicitly bank-bound customer with customer scope, the card's exact holder ID, verified session/device and authentication within five minutes may consent. The card must be active and holder authority current. Requestor and exact terms version/SHA256 must match CARD_WALLET_CONFIG. An empty configuration disables enrollment. Consent identities, session/device hashes and source terms remain immutable; processor activation is separate.
Headers
Idempotency-KeystringRequiredSend on every write that creates or changes money or state; a replay with the same key returns the original result with 200.
Body parameters
card_idstringRequiredExample card_2tVh8nqLxq4GbDe0K1F6S9zRcWm
device_sha256stringRequiredOpaque device binding digest, not raw device identifiers
requestor_idstringRequiredterms_sha256stringRequiredterms_versionstringRequiredReturns
200 OK
consent_device_sha256stringRequiredconsent_session_sha256stringRequiredconsent_step_up_atstring · date-timeRequiredconsented_atstring · date-timeRequiredconsented_bystringRequiredeffective_statusstringRequiredenrollmentobjectRequired5 child attributes
card_idstringRequiredExample card_2tVh8nqLxq4GbDe0K1F6S9zRcWm
device_sha256stringRequiredOpaque device binding digest, not raw device identifiers
requestor_idstringRequiredterms_sha256stringRequiredterms_versionstringRequiredholder_customer_idstringRequiredExample cust_2tVh8nqLxq4GbDe0K1F6S9zRcWm
idstringRequiredlocal_sequenceintegerRequiredlocal_statusstringRequirednetworkstringRequirednetwork_sequenceintegerRequirednetwork_statusstringRequirednetwork_token_referencestringOptionalErrors
Every error is a problem document with a stable code. See Errors.
400401403404409412413422424429500503