Create a card
Issues a virtual or physical card onto a wallet. Virtual cards are available immediately. Physical cards require shipping address and method. The response never includes PAN or CVV. Send Idempotency-Key so retries return the original card instead of issuing a second one.
Authentication & Headers
| Header | Type | Requirement | Description |
|---|---|---|---|
| Authorization | string | REQUIRED | API key passed as an HTTP Bearer token: Bearer rk_live_... |
| X-Program-ID | UUID | PROGRAM-SCOPED | Program boundary UUID that scopes the issuing card, wallet, or transfer. |
| Content-Type | string | REQUIRED | Must be application/json. |
| Idempotency-Key | string | OPTIONAL | Unique UUID to prevent duplicate execution of financial creations or mutations. |
Request Body Schema
application/jsonIssuing wallet the card spends against.
Physical form of a card issued from a product. `VIRTUAL` cards are available immediately for digital wallets and online spend. `PHYSICAL` cards are manufactured and shipped to the cardholder.
VIRTUALPHYSICALProduct to issue from. Omit to use the wallet's product. Must belong to the same program and allow `form_factor`.
Card-art asset to apply. Omit to use the product default.
Destination and carrier service for a physical card. Required when issuing, reissuing, converting, or bulk-ordering a physical card.
Card-level spend cap. Omit to inherit wallet spend limits. `amount` is a non-negative integer of minor units.
Integrator label stored on the card.
Four-digit PIN. Write-only; never returned on the card or in logs.
Response Codes & Schemas
{
"id": "0c4e8f16-2a7b-4d93-b5e1-8f3a6c9d0142",
"object": "card",
"wallet_id": "4d8f2a10-6c3e-4b91-9e5a-2f7c8d1e0b44",
"wallet_entity_id": "2e9c4b71-8a5d-4f03-b6e2-1c7d9a0f3e58",
"program_id": "7c9e6679-7425-40de-944b-e07fc1f90ae7",
"product_id": "3f0c7a12-5d8e-4a91-b6c2-9e1f0a4d7c33",
"card_art_id": "8f2b1c40-0c1a-4b7e-9a3d-6d5f2e1a7b90",
"state": "OPEN",
"form_factor": "VIRTUAL",
"last_four": "4242",
"exp_month": 8,
"exp_year": 2029,
"network": "VISA",
"spend_limit": {
"amount": 250000,
"currency": "USD"
},
"memo": "Primary virtual",
"shipping": null,
"replacement_for_card_id": null,
"digital_wallet_tokens": 1,
"created_at": "2026-08-12T10:30:00Z",
"updated_at": "2026-08-12T10:30:00Z"
}{
"error": {
"type": "invalid_request_error",
"code": "invalid_request",
"message": "invalid order by: foo. Valid options are: [created_at updated_at]",
"param": "order_by",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/invalid_request"
}
}{
"error": {
"type": "authentication_error",
"code": "authentication_error",
"message": "A valid API key is required.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/authentication_error"
}
}{
"error": {
"type": "permission_error",
"code": "permission_denied",
"message": "The API key cannot access this program.",
"param": "X-Program-ID",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/permission_denied"
}
}{
"error": {
"type": "not_found_error",
"code": "not_found",
"message": "No card found for the given id.",
"param": "card_id",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/not_found"
}
}{
"error": {
"type": "conflict_error",
"code": "conflict",
"message": "The card cannot be reissued from its current state.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/conflict"
}
}{
"error": {
"type": "invalid_request_error",
"code": "insufficient_funds",
"message": "The source financial account does not have enough available balance.",
"param": "amount",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/insufficient_funds"
}
}{
"error": {
"type": "rate_limit_error",
"code": "rate_limited",
"message": "Rate limit exceeded. Retry after the number of seconds in Retry-After.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/rate_limited"
}
}{
"error": {
"type": "api_error",
"code": "internal_error",
"message": "An unexpected error occurred. Retry with the same Idempotency-Key.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/internal_error"
}
}