Create a payment card

Create the durable Pending PaymentCard owned by the effective Account. Use the returned id with the link endpoint to launch Footprint; raw card numbers and CVC are never accepted. Idempotent via Idempotency-Key.

If externalId is supplied and already used by another resource of this type for the owning Account, the request returns 409 ResourceConflict; create is not an upsert. Use filter[externalId][eq] on the list endpoint to retrieve the existing resource.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params

Creates a Pending Account-owned PaymentCard for the hosted Footprint linking flow. Use the returned id with the link and activate actions; raw PAN, CVC, and provider tokens are never accepted.

string
length ≤ 200
^(?!.*(?:^|[^0-9])(?:[0-9][^A-Za-z0-9]*){12,18}[0-9](?:$|[^0-9])).*$

Customer reconciliation identifier. Obvious PAN-shaped values, including punctuation- or whitespace-separated values, are rejected; submit all sensitive card data only through the hosted Footprint frame. Ordinary business identifiers remain valid.

metadata
object

Free-form key-value pairs. Max 50 keys; key length at most 40 characters; value length at most 500 characters. Where a list endpoint declares metadata filtering, it uses the QueryQL namespace via filter[metadata.{key}][eq]=value or filter[metadata.{key}][in][]=value. Endpoints that do not declare the dynamic Metadata filter do not support Metadata filtering.

Headers
string
required
length between 1 and 255
^[\x21-\x7e]{1,255}$

REQUIRED idempotency token for money-moving requests (e.g. transfers). The token is used by the API so a retry after a 5xx/timeout replays the original result instead of moving funds twice. Reuse the same key to retry safely; use a NEW key to issue a genuinely new transfer. Use 1-255 printable ASCII characters.

string
^(?:[A-Za-z0-9_.]{22}|[a-f0-9]{24})$

Select the Account for an Account-scoped operation. A direct ServiceAccount API key MUST supply this header, and the target must be within the ServiceAccount owner's or Authorization grant's Account boundary. A Person bearer may select an Account on which it has an active Stakeholder, and an Account session may select its bound Account (or a descendant only when the session explicitly includes descendants).

string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json