PATCH
Update an application
ENDPOINT/v1/applications/{application_id}
Withdraws an open application or supplies updated income and requested
credit limit. Set status to WITHDRAWN to stop review. Terminal
applications reject further updates.
Authentication & Headers
| Header | Type | Requirement | Description |
|---|---|---|---|
| Authorization | string | REQUIRED | API key passed as an HTTP Bearer token: Bearer rk_live_... |
| X-Program-ID | UUID | PROGRAM-SCOPED | Program boundary UUID that scopes the issuing card, wallet, or transfer. |
| Content-Type | string | REQUIRED | Must be application/json. |
| Idempotency-Key | string | OPTIONAL | Unique UUID to prevent duplicate execution of financial creations or mutations. |
Path Parameters
| Parameter | Type | Requirement | Description |
|---|---|---|---|
| application_id | string | REQUIRED | Unique identifier of the application. |
Request Body Schema
application/jsonstatusstring
optionalSend `WITHDRAWN` to withdraw. Other status values are set by the API.
Enum values:
WITHDRAWNrequested_credit_limitobject
optionalUpdated requested credit limit. `amount` is a non-negative integer of minor units.
Properties of requested_credit_limit
amountanyrequired
currencystringrequired
ISO 4217 alphabetic currency code.
incomeobject
optionalUpdated stated annual income. `amount` is a non-negative integer of minor units.
Properties of income
amountanyrequired
currencystringrequired
ISO 4217 alphabetic currency code.
Response Codes & Schemas
200The application after the update.
application/json{
"id": "6a0d5e28-1f4b-4c79-a3d6-8e2b9c7f0154",
"object": "application",
"status": "WITHDRAWN",
"wallet_entity_id": "2e9c4b71-8a5d-4f03-b6e2-1c7d9a0f3e58",
"program_id": "7c9e6679-7425-40de-944b-e07fc1f90ae7",
"product_id": "3f0c7a12-5d8e-4a91-b6c2-9e1f0a4d7c33",
"requested_credit_limit": {
"amount": 500000,
"currency": "USD"
},
"income": {
"amount": 8500000,
"currency": "USD"
},
"consents": {
"credit_check": true,
"electronic_communications": true,
"cardholder_agreement": true,
"privacy_policy": true
},
"decision": null,
"kyc": {
"status": "IN_REVIEW",
"checks": [
{
"name": "CIP",
"status": "PASSED"
},
{
"name": "OFAC",
"status": "PASSED"
},
{
"name": "KYC",
"status": "PENDING"
},
{
"name": "KYB",
"status": "NOT_APPLICABLE"
},
{
"name": "IDV",
"status": "PASSED"
},
{
"name": "CREDIT",
"status": "PENDING"
}
]
},
"created_at": "2026-08-12T10:25:00Z",
"updated_at": "2026-08-12T12:00:00Z"
}400Bad Request: malformed JSON, failed schema validation, or conflicting parameters.
application/json{
"error": {
"type": "invalid_request_error",
"code": "invalid_request",
"message": "invalid order by: foo. Valid options are: [created_at updated_at]",
"param": "order_by",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/invalid_request"
}
}401Unauthorized: missing, malformed, or unknown API key.
application/json{
"error": {
"type": "authentication_error",
"code": "authentication_error",
"message": "A valid API key is required.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/authentication_error"
}
}403Forbidden: the API key is denied by RBAC, or it cannot access this
program. A resource that exists on another program or organization
returns `404 not_found`, not `403`.
application/json{
"error": {
"type": "permission_error",
"code": "permission_denied",
"message": "The API key cannot access this program.",
"param": "X-Program-ID",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/permission_denied"
}
}404Not Found: unknown id, or the resource is not visible to this API key.
application/json{
"error": {
"type": "not_found_error",
"code": "not_found",
"message": "No card found for the given id.",
"param": "card_id",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/not_found"
}
}409Conflict: incompatible state, or Idempotency-Key reused with a different body.
application/json{
"error": {
"type": "conflict_error",
"code": "conflict",
"message": "The card cannot be reissued from its current state.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/conflict"
}
}422Unprocessable Entity: the document is valid JSON but violates a business rule.
application/json{
"error": {
"type": "invalid_request_error",
"code": "insufficient_funds",
"message": "The source financial account does not have enough available balance.",
"param": "amount",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/insufficient_funds"
}
}429Too Many Requests: the API key exceeded its rate limit.
application/json{
"error": {
"type": "rate_limit_error",
"code": "rate_limited",
"message": "Rate limit exceeded. Retry after the number of seconds in Retry-After.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/rate_limited"
}
}500Internal Server Error: unexpected failure. Retry with the same Idempotency-Key.
application/json{
"error": {
"type": "api_error",
"code": "internal_error",
"message": "An unexpected error occurred. Retry with the same Idempotency-Key.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/internal_error"
}
}