Skip to main content
POST
JavaScript

Authorizations

Authorization
string
header
required

A company API key, company scoped JWT, app API key, or user OAuth token. You must prepend your key/token with the word 'Bearer', which will look like Bearer ***************************

Headers

Idempotency-Key
string

A unique key that makes this request safe to retry. See Idempotent requests.

Maximum string length: 255
Example:

"d9105228-4a08-46b1-8b91-42fed586d383"

Api-Version-Date
string

Pins the request to a dated API version.

Example:

"2026-07-25"

Body

application/json
account_id
string

The owning account ID (a biz_ identifier). Provide this or user_id.

assigned_user_id
string

The company member (a user_ identifier) to assign the card to. Required for company (business) card issuing accounts.

name
string

A display name for the card.

spend_limit
number

Spending limit amount, in dollars.

spend_limit_frequency
enum<string>

The spending limit window.

Available options:
daily,
weekly,
monthly,
one_time
transaction_limit
number

Per-transaction limit amount, in dollars.

user_id
string

The owning user ID (a user_ identifier). Provide this or account_id.

Response

company card created for an assigned member

billing
object | null
required

The billing address.

canceled_at
string<date-time> | null
required

When the card was canceled.

created_at
string<date-time> | null
required

When the card was created.

expiration_month
string | null
required

Card expiration month.

expiration_year
string | null
required

Card expiration year.

id
string
required

Card ID, prefixed icrd_.

last4
string | null
required

Last four digits of the card number. null for pending invitation cards.

limit
object | null
required

The spending limit configuration.

name
string | null
required

Card display name.

object
enum<string>
required
Available options:
card
spent_last_month
integer | null
required

Total spend in the last 30 days, in cents.

status
enum<string> | null
required

The card status.

Available options:
null,
active,
frozen,
canceled,
invited
type
enum<string> | null
required

The card type.

Available options:
null,
virtual,
physical
user_id
string | null
required

Cardholder user ID, prefixed user_, when assigned.

secrets
object | null

Sensitive card details. Present only on GET /cards/:card_id for active cards; null when the card is inactive or details cannot be retrieved.