GET
List products
ENDPOINT/v1/programs/{program_id}/products
Returns products defined on the program, newest first. Each product is the
template for cards issued on that program, including the network program it
is issued under, its network product identifier, form factors, default
credit configuration, and card art. Filter by network_program_id to list
the products on one network.
Authentication & Headers
| Header | Type | Requirement | Description |
|---|---|---|---|
| Authorization | string | REQUIRED | API key passed as an HTTP Bearer token: Bearer rk_live_... |
| X-Program-ID | UUID | PROGRAM-SCOPED | Program boundary UUID that scopes the issuing card, wallet, or transfer. |
Path Parameters
| Parameter | Type | Requirement | Description |
|---|---|---|---|
| program_id | string | REQUIRED | Unique identifier of the program. |
Query Parameters
| Parameter | Type | Requirement | Description |
|---|---|---|---|
| network_program_id | string(uuid) | OPTIONAL | Return only products issued under this network program.
|
| page | integer | OPTIONAL | 1-based page index. Default 1. Values below 1 are treated as 1.
|
| page_size | integer | OPTIONAL | Number of objects to return in the page. Minimum 1, maximum 100, default
10. Also accepted as `page-size`. Values below 1 fall back to the default;
values above 100 are capped at 100.
|
| order_by | string | OPTIONAL | Field to sort by. When omitted, the endpoint uses its default order.
Also accepted as `order-by`. Valid fields are endpoint-specific
(`created_at`, `updated_at`, …).
|
| ascending | boolean | OPTIONAL | Sort direction. Default true (ascending). Pass `false` for descending.
Invalid values are ignored and the default is used.
|
Response Codes & Schemas
200A page of products for the program.
application/json{
"data": [
{
"id": "3f0c7a12-5d8e-4a91-b6c2-9e1f0a4d7c33",
"object": "product",
"program_id": "7c9e6679-7425-40de-944b-e07fc1f90ae7",
"name": "Consumer Rewards",
"network_program_id": "550e8400-e29b-41d4-a716-446655440000",
"network_product_id": "F",
"network": "VISA",
"capabilities": [
{
"id": "8d1f4b60-7c29-4e53-a6b8-2e5c9d0f7a14",
"object": "product_capability",
"product_id": "3f0c7a12-5d8e-4a91-b6c2-9e1f0a4d7c33",
"capability_id": "cap-inst-virtual-card",
"category": "INSTRUMENT",
"jurisdictions": [
"US"
],
"reserve_requirement_bps": null,
"enabled": true,
"created_at": "2026-08-10T14:24:00Z",
"updated_at": "2026-08-10T14:24:00Z"
},
{
"id": "5a8c2e71-3d94-4f06-b1e7-9c0d4a6f2b58",
"object": "product_capability",
"product_id": "3f0c7a12-5d8e-4a91-b6c2-9e1f0a4d7c33",
"capability_id": "cap-payin-ach",
"category": "PAYIN",
"jurisdictions": [
"US"
],
"reserve_requirement_bps": 250,
"enabled": true,
"created_at": "2026-08-10T14:25:00Z",
"updated_at": "2026-08-10T14:25:00Z"
}
],
"form_factors": [
"VIRTUAL",
"PHYSICAL"
],
"default_credit_configuration": {
"credit_limit": {
"amount": 500000,
"currency": "USD"
},
"overlimit_enabled": false,
"billing_cycle_day": 15
},
"card_art": {
"card_art_id": "8f2b1c40-0c1a-4b7e-9a3d-6d5f2e1a7b90",
"name": "Midnight Steel",
"front_image_url": "https://assets.rookpayments.com/card-art/8f2b1c40-0c1a-4b7e-9a3d-6d5f2e1a7b90/front.png",
"back_image_url": "https://assets.rookpayments.com/card-art/8f2b1c40-0c1a-4b7e-9a3d-6d5f2e1a7b90/back.png"
},
"created_at": "2026-08-10T14:22:00Z",
"updated_at": "2026-08-27T15:04:05Z"
}
],
"total_count": 1
}400Bad Request: malformed JSON, failed schema validation, or conflicting parameters.
application/json{
"error": {
"type": "invalid_request_error",
"code": "invalid_request",
"message": "invalid order by: foo. Valid options are: [created_at updated_at]",
"param": "order_by",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/invalid_request"
}
}401Unauthorized: missing, malformed, or unknown API key.
application/json{
"error": {
"type": "authentication_error",
"code": "authentication_error",
"message": "A valid API key is required.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/authentication_error"
}
}403Forbidden: the API key is denied by RBAC, or it cannot access this
program. A resource that exists on another program or organization
returns `404 not_found`, not `403`.
application/json{
"error": {
"type": "permission_error",
"code": "permission_denied",
"message": "The API key cannot access this program.",
"param": "X-Program-ID",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/permission_denied"
}
}404Not Found: unknown id, or the resource is not visible to this API key.
application/json{
"error": {
"type": "not_found_error",
"code": "not_found",
"message": "No card found for the given id.",
"param": "card_id",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/not_found"
}
}429Too Many Requests: the API key exceeded its rate limit.
application/json{
"error": {
"type": "rate_limit_error",
"code": "rate_limited",
"message": "Rate limit exceeded. Retry after the number of seconds in Retry-After.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/rate_limited"
}
}500Internal Server Error: unexpected failure. Retry with the same Idempotency-Key.
application/json{
"error": {
"type": "api_error",
"code": "internal_error",
"message": "An unexpected error occurred. Retry with the same Idempotency-Key.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/internal_error"
}
}