ROOKDocs
PATCH

Update a product

ENDPOINT/v1/programs/{program_id}/products/{product_id}

Applies a partial update to a product's name, form factors, default credit configuration, or card art. Omitted fields are left unchanged. Cards already issued from the product keep the values they inherited at issuance.

Authentication & Headers

HeaderTypeRequirementDescription
AuthorizationstringREQUIREDAPI key passed as an HTTP Bearer token: Bearer rk_live_...
X-Program-IDUUIDPROGRAM-SCOPEDProgram boundary UUID that scopes the issuing card, wallet, or transfer.
Content-TypestringREQUIREDMust be application/json.
Idempotency-KeystringOPTIONALUnique UUID to prevent duplicate execution of financial creations or mutations.

Path Parameters

ParameterTypeRequirementDescription
program_idstringREQUIREDUnique identifier of the program.
product_idstringREQUIREDUnique identifier of the product.

Request Body Schema

application/json
namestring
optional

Display name of the product.

network_program_idstringuuid
optional

Network program (the program's registration with a card network) this product is issued under. Determines the network and BIN ranges of cards issued from the product. Must belong to the same program.

network_product_idstring
optional

Product identifier assigned by the card network for this product (for example a Visa product ID or a Mastercard product code). Sent to the network at authorization and settlement.

form_factorsarray
optional

Card form factors this product may issue. At least one of `VIRTUAL` or `PHYSICAL`.

default_credit_configurationobject
optional

Default credit terms copied onto cards issued from this product. A card may override these values after issuance.

Properties of default_credit_configuration
credit_limitobjectrequired
Default credit limit for a new card. `amount` is a non-negative integer of minor units; `125000` with `USD` is $1,250.00.
overlimit_enabledbooleanrequired
When true, authorizations may exceed `credit_limit` up to program policy. When false, authorizations that would exceed `credit_limit` are declined.
billing_cycle_dayintegerrequired
Day of the month on which the billing cycle closes. Capped at 28 so every month has that day. Evaluated in the program's `timezone`.
card_artobject
optional

Write-only reference to card artwork. Send `card_art_id` on product create or update. The read model is `CardArt`, which includes the display name and image URLs.

Properties of card_art
card_art_idstringrequired
Identifier of the card-art asset to apply to this product.

Response Codes & Schemas

200The product after the update.
application/json
{
  "id": "3f0c7a12-5d8e-4a91-b6c2-9e1f0a4d7c33",
  "object": "product",
  "program_id": "7c9e6679-7425-40de-944b-e07fc1f90ae7",
  "name": "Consumer Rewards",
  "network_program_id": "550e8400-e29b-41d4-a716-446655440000",
  "network_product_id": "F",
  "network": "VISA",
  "capabilities": [
    {
      "id": "8d1f4b60-7c29-4e53-a6b8-2e5c9d0f7a14",
      "object": "product_capability",
      "product_id": "3f0c7a12-5d8e-4a91-b6c2-9e1f0a4d7c33",
      "capability_id": "cap-inst-virtual-card",
      "category": "INSTRUMENT",
      "jurisdictions": [
        "US"
      ],
      "reserve_requirement_bps": null,
      "enabled": true,
      "created_at": "2026-08-10T14:24:00Z",
      "updated_at": "2026-08-10T14:24:00Z"
    },
    {
      "id": "5a8c2e71-3d94-4f06-b1e7-9c0d4a6f2b58",
      "object": "product_capability",
      "product_id": "3f0c7a12-5d8e-4a91-b6c2-9e1f0a4d7c33",
      "capability_id": "cap-payin-ach",
      "category": "PAYIN",
      "jurisdictions": [
        "US"
      ],
      "reserve_requirement_bps": 250,
      "enabled": true,
      "created_at": "2026-08-10T14:25:00Z",
      "updated_at": "2026-08-10T14:25:00Z"
    }
  ],
  "form_factors": [
    "VIRTUAL"
  ],
  "default_credit_configuration": {
    "credit_limit": {
      "amount": 500000,
      "currency": "USD"
    },
    "overlimit_enabled": false,
    "billing_cycle_day": 15
  },
  "card_art": {
    "card_art_id": "8f2b1c40-0c1a-4b7e-9a3d-6d5f2e1a7b90",
    "name": "Midnight Steel",
    "front_image_url": "https://assets.rookpayments.com/card-art/8f2b1c40-0c1a-4b7e-9a3d-6d5f2e1a7b90/front.png",
    "back_image_url": "https://assets.rookpayments.com/card-art/8f2b1c40-0c1a-4b7e-9a3d-6d5f2e1a7b90/back.png"
  },
  "created_at": "2026-08-10T14:22:00Z",
  "updated_at": "2026-08-27T16:20:00Z"
}
400Bad Request: malformed JSON, failed schema validation, or conflicting parameters.
application/json
{
  "error": {
    "type": "invalid_request_error",
    "code": "invalid_request",
    "message": "invalid order by: foo. Valid options are: [created_at updated_at]",
    "param": "order_by",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/invalid_request"
  }
}
401Unauthorized: missing, malformed, or unknown API key.
application/json
{
  "error": {
    "type": "authentication_error",
    "code": "authentication_error",
    "message": "A valid API key is required.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/authentication_error"
  }
}
403Forbidden: the API key is denied by RBAC, or it cannot access this program. A resource that exists on another program or organization returns `404 not_found`, not `403`.
application/json
{
  "error": {
    "type": "permission_error",
    "code": "permission_denied",
    "message": "The API key cannot access this program.",
    "param": "X-Program-ID",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/permission_denied"
  }
}
404Not Found: unknown id, or the resource is not visible to this API key.
application/json
{
  "error": {
    "type": "not_found_error",
    "code": "not_found",
    "message": "No card found for the given id.",
    "param": "card_id",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/not_found"
  }
}
409Conflict: incompatible state, or Idempotency-Key reused with a different body.
application/json
{
  "error": {
    "type": "conflict_error",
    "code": "conflict",
    "message": "The card cannot be reissued from its current state.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/conflict"
  }
}
429Too Many Requests: the API key exceeded its rate limit.
application/json
{
  "error": {
    "type": "rate_limit_error",
    "code": "rate_limited",
    "message": "Rate limit exceeded. Retry after the number of seconds in Retry-After.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/rate_limited"
  }
}
500Internal Server Error: unexpected failure. Retry with the same Idempotency-Key.
application/json
{
  "error": {
    "type": "api_error",
    "code": "internal_error",
    "message": "An unexpected error occurred. Retry with the same Idempotency-Key.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/internal_error"
  }
}