ROOKDocs
POST

Simulate a digital-wallet tokenization

ENDPOINT/v1/simulate/tokenizations

Injects a network token on a sandbox card as if the cardholder added it to a wallet. Creates a Tokenization with wallet as token_requestor_name. decision APPROVED yields status ACTIVE with TOKEN_CREATED, DECISION, and ACTIVATED events. DECLINED yields DEACTIVATED with a declined DECISION. REQUIRE_ADDITIONAL_AUTHENTICATION yields PENDING_2FA. Platform events: tokenization.updated. The Tokenization never includes PAN or CVV. Served only on the sandbox host.

Authentication & Headers

HeaderTypeRequirementDescription
AuthorizationstringREQUIREDAPI key passed as an HTTP Bearer token: Bearer rk_live_...
X-Program-IDUUIDPROGRAM-SCOPEDProgram boundary UUID that scopes the issuing card, wallet, or transfer.
Content-TypestringREQUIREDMust be application/json.
Idempotency-KeystringOPTIONALUnique UUID to prevent duplicate execution of financial creations or mutations.

Request Body Schema

application/json
card_idstringuuid
REQUIRED

Card to tokenize. The card object never returns PAN or CVV.

walletany
optional

Digital wallet. Null for merchant or card-on-file tokenizations.

tokenization_sourcestring
REQUIRED

Channel that requested the network token. Wallet values match `wallet`. `MERCHANT` is card-on-file with a merchant token requestor. `CARD_ON_FILE` is a stored-credential request without a wallet.

Enum values:APPLE_PAYGOOGLE_PAYSAMSUNG_PAYMERCHANTCARD_ON_FILE
decisionstring
REQUIRED

Outcome of a tokenization decision. `APPROVED` continues provisioning. `DECLINED` rejects the wallet request. `REQUIRE_ADDITIONAL_AUTHENTICATION` asks the network to step up the cardholder.

Enum values:APPROVEDDECLINEDREQUIRE_ADDITIONAL_AUTHENTICATION

Response Codes & Schemas

201The Tokenization that was created.
application/json
{
  "id": "3a8c1e40-6b2d-4f15-9c7a-2e5d0b8f1734",
  "object": "tokenization",
  "card_id": "0c4e8f16-2a7b-4d93-b5e1-8f3a6c9d0142",
  "wallet_id": "4d8f2a10-6c3e-4b91-9e5a-2f7c8d1e0b44",
  "network": "VISA",
  "token_requestor_name": "APPLE_PAY",
  "status": "ACTIVE",
  "device": {
    "device_id": "device_iphone_14_jane",
    "device_name": "Jane's iPhone",
    "device_type": "MOBILE_PHONE"
  },
  "last_four": "9012",
  "dpan": {
    "last_four": "5510"
  },
  "digital_card_art_id": "5e7a3c19-8d4f-4b02-9a6e-1c8d0f5b3728",
  "events": [
    {
      "type": "TOKEN_CREATED",
      "channel": null,
      "result": null,
      "created_at": "2026-08-12T11:00:00Z"
    },
    {
      "type": "DECISION",
      "channel": null,
      "result": "APPROVED",
      "created_at": "2026-08-12T11:00:01Z"
    },
    {
      "type": "ACTIVATED",
      "channel": null,
      "result": null,
      "created_at": "2026-08-12T11:00:05Z"
    }
  ],
  "created_at": "2026-08-12T11:00:00Z",
  "updated_at": "2026-08-18T09:12:00Z"
}
400Bad Request: malformed JSON, failed schema validation, or conflicting parameters.
application/json
{
  "error": {
    "type": "invalid_request_error",
    "code": "invalid_request",
    "message": "invalid order by: foo. Valid options are: [created_at updated_at]",
    "param": "order_by",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/invalid_request"
  }
}
401Unauthorized: missing, malformed, or unknown API key.
application/json
{
  "error": {
    "type": "authentication_error",
    "code": "authentication_error",
    "message": "A valid API key is required.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/authentication_error"
  }
}
403Forbidden: the API key is denied by RBAC, or it cannot access this program. A resource that exists on another program or organization returns `404 not_found`, not `403`.
application/json
{
  "error": {
    "type": "permission_error",
    "code": "permission_denied",
    "message": "The API key cannot access this program.",
    "param": "X-Program-ID",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/permission_denied"
  }
}
404Not Found: unknown id, or the resource is not visible to this API key.
application/json
{
  "error": {
    "type": "not_found_error",
    "code": "not_found",
    "message": "No card found for the given id.",
    "param": "card_id",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/not_found"
  }
}
409Conflict: incompatible state, or Idempotency-Key reused with a different body.
application/json
{
  "error": {
    "type": "conflict_error",
    "code": "conflict",
    "message": "The card cannot be reissued from its current state.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/conflict"
  }
}
422Unprocessable Entity: the document is valid JSON but violates a business rule.
application/json
{
  "error": {
    "type": "invalid_request_error",
    "code": "insufficient_funds",
    "message": "The source financial account does not have enough available balance.",
    "param": "amount",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/insufficient_funds"
  }
}
429Too Many Requests: the API key exceeded its rate limit.
application/json
{
  "error": {
    "type": "rate_limit_error",
    "code": "rate_limited",
    "message": "Rate limit exceeded. Retry after the number of seconds in Retry-After.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/rate_limited"
  }
}
500Internal Server Error: unexpected failure. Retry with the same Idempotency-Key.
application/json
{
  "error": {
    "type": "api_error",
    "code": "internal_error",
    "message": "An unexpected error occurred. Retry with the same Idempotency-Key.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/internal_error"
  }
}