curl --request PATCH \
--url https://api.platform.sandbox.dakota.xyz/cards/{card_id} \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--header 'x-idempotency-key: <x-idempotency-key>' \
--data '
{
"status": "frozen"
}
'const options = {
method: 'PATCH',
headers: {
'x-idempotency-key': '<x-idempotency-key>',
'x-api-key': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({status: 'frozen'})
};
fetch('https://api.platform.sandbox.dakota.xyz/cards/{card_id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.platform.sandbox.dakota.xyz/cards/{card_id}"
payload = { "status": "frozen" }
headers = {
"x-idempotency-key": "<x-idempotency-key>",
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.platform.sandbox.dakota.xyz/cards/{card_id}"
payload := strings.NewReader("{\n \"status\": \"frozen\"\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("x-idempotency-key", "<x-idempotency-key>")
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"id": "2tQRvvnYkN6edEJUTmF1LzTj2ug",
"cardholder_id": "31TgvufZK3gDXBcA3BnSeLWiSn7",
"customer_id": "2tQRvD3xFcJ7bKpW9qNsT4hZmYr",
"wallet_id": "2tQRvK9pRzM4nVbW8sHqL5jXmYt",
"status": "frozen",
"version": 3,
"last4": "4242",
"spend_limit": {
"interval": "monthly",
"amount": 250000
},
"external_id": "ads-card-01",
"nickname": "Ads card",
"freeze_sources": [
"manual"
],
"created_at": 1758211200,
"updated_at": 1758211860
}{
"type": "https://docs.dakota.xyz/api-reference/errors#not-found",
"title": "Customer Not Found",
"status": 404,
"detail": "Customer cst_2abc123 was not found in your organization.",
"instance": "https://api.platform.dakota.xyz/customers/cst_2abc123",
"request_id": "req_7f3a8b2c"
}{
"type": "https://docs.dakota.xyz/api-reference/errors#not-found",
"title": "Customer Not Found",
"status": 404,
"detail": "Customer cst_2abc123 was not found in your organization.",
"instance": "https://api.platform.dakota.xyz/customers/cst_2abc123",
"request_id": "req_7f3a8b2c"
}{
"type": "https://docs.dakota.xyz/api-reference/errors#cardholder-suspended",
"title": "Cardholder Suspended",
"status": 403,
"detail": "Card-level unfreeze is blocked because the cardholder for this card is suspended. A cardholder suspension is cleared by a compliance review, not through this API. Freezing and closing this card remain available."
}{
"type": "https://docs.dakota.xyz/api-reference/errors#not-found",
"title": "Customer Not Found",
"status": 404,
"detail": "Customer cst_2abc123 was not found in your organization.",
"instance": "https://api.platform.dakota.xyz/customers/cst_2abc123",
"request_id": "req_7f3a8b2c"
}{
"type": "https://docs.dakota.xyz/api-reference/errors#not-found",
"title": "Customer Not Found",
"status": 404,
"detail": "Customer cst_2abc123 was not found in your organization.",
"instance": "https://api.platform.dakota.xyz/customers/cst_2abc123",
"request_id": "req_7f3a8b2c"
}{
"type": "https://docs.dakota.xyz/api-reference/errors#not-found",
"title": "Customer Not Found",
"status": 404,
"detail": "Customer cst_2abc123 was not found in your organization.",
"instance": "https://api.platform.dakota.xyz/customers/cst_2abc123",
"request_id": "req_7f3a8b2c"
}Update a card
Update a card’s status (freeze, unfreeze or close) and/or its nickname. Closing is terminal. To change the spend limit, use PUT /cards/{card_id}/spend_limit.
Freezing always succeeds. Unfreezing — sending status: active — is rejected while the card carries a freeze this API cannot lift; see the card’s freeze_sources and the 403 below.
curl --request PATCH \
--url https://api.platform.sandbox.dakota.xyz/cards/{card_id} \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--header 'x-idempotency-key: <x-idempotency-key>' \
--data '
{
"status": "frozen"
}
'const options = {
method: 'PATCH',
headers: {
'x-idempotency-key': '<x-idempotency-key>',
'x-api-key': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({status: 'frozen'})
};
fetch('https://api.platform.sandbox.dakota.xyz/cards/{card_id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.platform.sandbox.dakota.xyz/cards/{card_id}"
payload = { "status": "frozen" }
headers = {
"x-idempotency-key": "<x-idempotency-key>",
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.platform.sandbox.dakota.xyz/cards/{card_id}"
payload := strings.NewReader("{\n \"status\": \"frozen\"\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("x-idempotency-key", "<x-idempotency-key>")
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"id": "2tQRvvnYkN6edEJUTmF1LzTj2ug",
"cardholder_id": "31TgvufZK3gDXBcA3BnSeLWiSn7",
"customer_id": "2tQRvD3xFcJ7bKpW9qNsT4hZmYr",
"wallet_id": "2tQRvK9pRzM4nVbW8sHqL5jXmYt",
"status": "frozen",
"version": 3,
"last4": "4242",
"spend_limit": {
"interval": "monthly",
"amount": 250000
},
"external_id": "ads-card-01",
"nickname": "Ads card",
"freeze_sources": [
"manual"
],
"created_at": 1758211200,
"updated_at": 1758211860
}{
"type": "https://docs.dakota.xyz/api-reference/errors#not-found",
"title": "Customer Not Found",
"status": 404,
"detail": "Customer cst_2abc123 was not found in your organization.",
"instance": "https://api.platform.dakota.xyz/customers/cst_2abc123",
"request_id": "req_7f3a8b2c"
}{
"type": "https://docs.dakota.xyz/api-reference/errors#not-found",
"title": "Customer Not Found",
"status": 404,
"detail": "Customer cst_2abc123 was not found in your organization.",
"instance": "https://api.platform.dakota.xyz/customers/cst_2abc123",
"request_id": "req_7f3a8b2c"
}{
"type": "https://docs.dakota.xyz/api-reference/errors#cardholder-suspended",
"title": "Cardholder Suspended",
"status": 403,
"detail": "Card-level unfreeze is blocked because the cardholder for this card is suspended. A cardholder suspension is cleared by a compliance review, not through this API. Freezing and closing this card remain available."
}{
"type": "https://docs.dakota.xyz/api-reference/errors#not-found",
"title": "Customer Not Found",
"status": 404,
"detail": "Customer cst_2abc123 was not found in your organization.",
"instance": "https://api.platform.dakota.xyz/customers/cst_2abc123",
"request_id": "req_7f3a8b2c"
}{
"type": "https://docs.dakota.xyz/api-reference/errors#not-found",
"title": "Customer Not Found",
"status": 404,
"detail": "Customer cst_2abc123 was not found in your organization.",
"instance": "https://api.platform.dakota.xyz/customers/cst_2abc123",
"request_id": "req_7f3a8b2c"
}{
"type": "https://docs.dakota.xyz/api-reference/errors#not-found",
"title": "Customer Not Found",
"status": 404,
"detail": "Customer cst_2abc123 was not found in your organization.",
"instance": "https://api.platform.dakota.xyz/customers/cst_2abc123",
"request_id": "req_7f3a8b2c"
}Authorizations
Headers
Unique key to ensure request idempotency. If the same key is used within a certain time window, the original response will be returned instead of executing the request again.
Path Parameters
KSUID is a 27-character globally unique ID that combines a timestamp with a random component. Used for all entity identifiers in the Dakota platform.
27^[0-9A-Za-z]{27}$"1NFHrqBHb3cTfLVkFSGmHZqdDPi"
Body
Card fields to update
A status change (freeze/unfreeze/close), a new nickname, or both. A
nickname sent alongside status: closed is ignored — the card is closed
and its label is no longer reachable. The spend limit changes through
PUT /cards/{card_id}/spend_limit.
The transition to apply. active unfreezes, frozen freezes, and
closed is terminal.
Cardholder state takes precedence over card state: while the owning
cardholder is suspended, active is refused with a
#cardholder-suspended 403 and the card stays frozen. frozen and
closed are unaffected — a suspension restricts what a client can
re-enable, never what it can shut down.
active, frozen, closed Replacement display name for the card. Omit the field, or send null,
to leave the current nickname unchanged; there is no way to clear one once set.
64"Travel card"
Response
Card updated successfully
Response containing card details.
KSUID is a 27-character globally unique ID that combines a timestamp with a random component. Used for all entity identifiers in the Dakota platform.
27^[0-9A-Za-z]{27}$"1NFHrqBHb3cTfLVkFSGmHZqdDPi"
KSUID is a 27-character globally unique ID that combines a timestamp with a random component. Used for all entity identifiers in the Dakota platform.
27^[0-9A-Za-z]{27}$"1NFHrqBHb3cTfLVkFSGmHZqdDPi"
KSUID is a 27-character globally unique ID that combines a timestamp with a random component. Used for all entity identifiers in the Dakota platform.
27^[0-9A-Za-z]{27}$"1NFHrqBHb3cTfLVkFSGmHZqdDPi"
KSUID is a 27-character globally unique ID that combines a timestamp with a random component. Used for all entity identifiers in the Dakota platform.
27^[0-9A-Za-z]{27}$"1NFHrqBHb3cTfLVkFSGmHZqdDPi"
The card's version, strictly increasing for this card. It is bumped by one on every change that emits a card.created or card.updated event, including a request that changes nothing, and the same value appears as version in that event's payload.
Webhook deliveries can arrive out of order, and updated_at has only one-second resolution, so neither orders them. Keep the highest version you have applied for each card and drop any event or response whose version is not greater than it.
x >= 17
Current status of the card. Returns pending on create; flips to active via a card.updated webhook.
pending, active, frozen, closed "pending"
Unix timestamp (seconds) of creation.
Unix timestamp (seconds) of last update.
Non-sensitive last four digits, populated from the card provider.
"4242"
A single cap on card spend, enforced when a purchase is authorized.
Show child attributes
Show child attributes
Client-supplied display name for the card. Null when none was set.
64"Ads card"
What is currently holding a freeze on this card, distinct and sorted. Empty when nothing is.
A card is frozen while any source holds it, and lifting one source does not lift another. Read this rather than inferring the cause from status: status reports the card's state at the issuer, so it says only that the card is frozen, never why.
manual is a freeze applied through this API and is the only source a client can lift, by sending status: active to this card's PATCH endpoint. While any other source is present that request is rejected with a card-freeze-held problem, because no card-level action will clear it.
What is holding a freeze on a card.
manual is a freeze applied deliberately through this API, and is the only source a client can lift. It is the only value this API emits today.
This enum grows as new freeze causes are built — a value is added when it can actually occur, never before. Treat any value other than manual, including one your client does not recognise, as a hold no card-level request will clear.
manual ["manual"]
The cardholder this card belongs to.
Show child attributes
Show child attributes
The wallet this card draws on. Populated on the single-card detail endpoint; omitted from list responses.
Show child attributes
Show child attributes
Was this page helpful?

