ROOKDocs
POST

Simulate card shipping progression

ENDPOINT/v1/simulate/cards/{card_id}/shipping

Advances fulfillment status for a sandbox physical card along ORDEREDEMBOSSEDSHIPPEDDELIVERED. Send tracking when status is SHIPPED or DELIVERED. Served only on the sandbox host.

Authentication & Headers

HeaderTypeRequirementDescription
AuthorizationstringREQUIREDAPI key passed as an HTTP Bearer token: Bearer rk_live_...
X-Program-IDUUIDPROGRAM-SCOPEDProgram boundary UUID that scopes the issuing card, wallet, or transfer.
Content-TypestringREQUIREDMust be application/json.
Idempotency-KeystringOPTIONALUnique UUID to prevent duplicate execution of financial creations or mutations.

Path Parameters

ParameterTypeRequirementDescription
card_idstringREQUIREDUnique identifier of the card.

Request Body Schema

application/json
statusstring
REQUIRED

Fulfillment of a physical card. `ORDERED` is accepted for manufacturing. `EMBOSSED` is produced. `SHIPPED` has a carrier scan. `DELIVERED` is confirmed at the shipping address.

Enum values:ORDEREDEMBOSSEDSHIPPEDDELIVERED
trackingstringnull
optional

Carrier tracking number. Required when `status` is `SHIPPED` or `DELIVERED`. Null for `ORDERED` and `EMBOSSED`.

Response Codes & Schemas

200The card after the fulfillment update.
application/json
{
  "id": "1d5f9a27-3b8c-4e04-c6f2-9e4b7d0e1253",
  "object": "card",
  "wallet_id": "4d8f2a10-6c3e-4b91-9e5a-2f7c8d1e0b44",
  "wallet_entity_id": "2e9c4b71-8a5d-4f03-b6e2-1c7d9a0f3e58",
  "program_id": "7c9e6679-7425-40de-944b-e07fc1f90ae7",
  "product_id": "3f0c7a12-5d8e-4a91-b6c2-9e1f0a4d7c33",
  "card_art_id": "8f2b1c40-0c1a-4b7e-9a3d-6d5f2e1a7b90",
  "state": "OPEN",
  "form_factor": "PHYSICAL",
  "last_four": "4444",
  "exp_month": 8,
  "exp_year": 2029,
  "network": "VISA",
  "spend_limit": null,
  "memo": "Backup physical",
  "shipping": {
    "status": "SHIPPED",
    "tracking": "1Z999AA10123456784",
    "method": "STANDARD"
  },
  "replacement_for_card_id": null,
  "digital_wallet_tokens": 0,
  "created_at": "2026-08-20T09:05:00Z",
  "updated_at": "2026-08-21T16:40:00Z"
}
400Bad Request: malformed JSON, failed schema validation, or conflicting parameters.
application/json
{
  "error": {
    "type": "invalid_request_error",
    "code": "invalid_request",
    "message": "invalid order by: foo. Valid options are: [created_at updated_at]",
    "param": "order_by",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/invalid_request"
  }
}
401Unauthorized: missing, malformed, or unknown API key.
application/json
{
  "error": {
    "type": "authentication_error",
    "code": "authentication_error",
    "message": "A valid API key is required.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/authentication_error"
  }
}
403Forbidden: the API key is denied by RBAC, or it cannot access this program. A resource that exists on another program or organization returns `404 not_found`, not `403`.
application/json
{
  "error": {
    "type": "permission_error",
    "code": "permission_denied",
    "message": "The API key cannot access this program.",
    "param": "X-Program-ID",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/permission_denied"
  }
}
404Not Found: unknown id, or the resource is not visible to this API key.
application/json
{
  "error": {
    "type": "not_found_error",
    "code": "not_found",
    "message": "No card found for the given id.",
    "param": "card_id",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/not_found"
  }
}
409Conflict: incompatible state, or Idempotency-Key reused with a different body.
application/json
{
  "error": {
    "type": "conflict_error",
    "code": "conflict",
    "message": "The card cannot be reissued from its current state.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/conflict"
  }
}
422Unprocessable Entity: the document is valid JSON but violates a business rule.
application/json
{
  "error": {
    "type": "invalid_request_error",
    "code": "insufficient_funds",
    "message": "The source financial account does not have enough available balance.",
    "param": "amount",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/insufficient_funds"
  }
}
429Too Many Requests: the API key exceeded its rate limit.
application/json
{
  "error": {
    "type": "rate_limit_error",
    "code": "rate_limited",
    "message": "Rate limit exceeded. Retry after the number of seconds in Retry-After.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/rate_limited"
  }
}
500Internal Server Error: unexpected failure. Retry with the same Idempotency-Key.
application/json
{
  "error": {
    "type": "api_error",
    "code": "internal_error",
    "message": "An unexpected error occurred. Retry with the same Idempotency-Key.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/internal_error"
  }
}