Skip to main content
PATCH
Update a cardholder
Sandbox only. This endpoint is available in sandbox only while we finish development. It is not available in production yet, and its request and response shapes may change before release.

Authorizations

x-api-key
string
header
required

Headers

x-idempotency-key
string<uuid>
required

Unique key to ensure request idempotency. If the same key is used within a certain time window, the original response will be returned instead of executing the request again.

Path Parameters

cardholder_id
string
required

KSUID is a 27-character globally unique ID that combines a timestamp with a random component. Used for all entity identifiers in the Dakota platform.

Required string length: 27
Pattern: ^[0-9A-Za-z]{27}$
Example:

"1NFHrqBHb3cTfLVkFSGmHZqdDPi"

Body

application/json

Cardholder fields to update

Mutable cardholder contact details. All fields are optional; only supplied fields are changed.

first_name
string
last_name
string
email
string<email>
Maximum string length: 254
phone
string

Response

Cardholder updated successfully

Response containing cardholder details.

id
string
required

KSUID is a 27-character globally unique ID that combines a timestamp with a random component. Used for all entity identifiers in the Dakota platform.

Required string length: 27
Pattern: ^[0-9A-Za-z]{27}$
Example:

"1NFHrqBHb3cTfLVkFSGmHZqdDPi"

customer_id
string
required

KSUID is a 27-character globally unique ID that combines a timestamp with a random component. Used for all entity identifiers in the Dakota platform.

Required string length: 27
Pattern: ^[0-9A-Za-z]{27}$
Example:

"1NFHrqBHb3cTfLVkFSGmHZqdDPi"

first_name
string
required
last_name
string
required
email
string
required
phone
string
required
status
enum<string>
required

Current status of the cardholder. Returns pending on create; on the clean path it flips to active within seconds via a cardholder.updated webhook.

An enrollment flagged during screening takes a longer route: pending → under_review (a reviewer holds it) → request_for_information (the reviewer needs something from you) → active or declined. You answer information requests through the API; there is never a cardholder-facing link. Every transition emits cardholder.updated, and opening a request also emits cardholder.information_requested.

suspended and closed are lifecycle rather than review states. closed is terminal and appears only in the cardholder.updated webhook emitted when a cardholder is deleted — deleted cardholders are not returned by the REST endpoints.

Available options:
pending,
under_review,
request_for_information,
active,
declined,
suspended,
closed
Example:

"pending"

created_at
integer
required

Unix timestamp (seconds) of creation.

updated_at
integer
required

Unix timestamp (seconds) of last update.

open_requirements
Cardholder Open Requirements Ā· object

Summary of what a reviewer is currently waiting on for this cardholder. count is 0 and types is empty unless the cardholder is in request_for_information.

This is a summary only. Read the individual items, with their descriptions, from GET /cardholders/{cardholder_id}/application.

external_id
string | null