curl --request POST \
--url https://platform.spritz.finance/v1/debit-cards/ \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"encryptedCardNumber": "ev:SWFSS:...",
"expiryMonth": "09",
"expiryYear": "29",
"cardLastFour": "4321",
"cardBin": "411111",
"cardholderFirstName": "John",
"cardholderLastName": "Doe",
"billingAddress": {
"line1": "123 Main St",
"city": "New York",
"state": "NY",
"postalCode": "10001",
"country": "US",
"line2": "Apt 4"
},
"label": "My Visa Debit"
}
'import requests
url = "https://platform.spritz.finance/v1/debit-cards/"
payload = {
"encryptedCardNumber": "ev:SWFSS:...",
"expiryMonth": "09",
"expiryYear": "29",
"cardLastFour": "4321",
"cardBin": "411111",
"cardholderFirstName": "John",
"cardholderLastName": "Doe",
"billingAddress": {
"line1": "123 Main St",
"city": "New York",
"state": "NY",
"postalCode": "10001",
"country": "US",
"line2": "Apt 4"
},
"label": "My Visa Debit"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
encryptedCardNumber: 'ev:SWFSS:...',
expiryMonth: '09',
expiryYear: '29',
cardLastFour: '4321',
cardBin: '411111',
cardholderFirstName: 'John',
cardholderLastName: 'Doe',
billingAddress: {
line1: '123 Main St',
city: 'New York',
state: 'NY',
postalCode: '10001',
country: 'US',
line2: 'Apt 4'
},
label: 'My Visa Debit'
})
};
fetch('https://platform.spritz.finance/v1/debit-cards/', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://platform.spritz.finance/v1/debit-cards/",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'encryptedCardNumber' => 'ev:SWFSS:...',
'expiryMonth' => '09',
'expiryYear' => '29',
'cardLastFour' => '4321',
'cardBin' => '411111',
'cardholderFirstName' => 'John',
'cardholderLastName' => 'Doe',
'billingAddress' => [
'line1' => '123 Main St',
'city' => 'New York',
'state' => 'NY',
'postalCode' => '10001',
'country' => 'US',
'line2' => 'Apt 4'
],
'label' => 'My Visa Debit'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://platform.spritz.finance/v1/debit-cards/"
payload := strings.NewReader("{\n \"encryptedCardNumber\": \"ev:SWFSS:...\",\n \"expiryMonth\": \"09\",\n \"expiryYear\": \"29\",\n \"cardLastFour\": \"4321\",\n \"cardBin\": \"411111\",\n \"cardholderFirstName\": \"John\",\n \"cardholderLastName\": \"Doe\",\n \"billingAddress\": {\n \"line1\": \"123 Main St\",\n \"city\": \"New York\",\n \"state\": \"NY\",\n \"postalCode\": \"10001\",\n \"country\": \"US\",\n \"line2\": \"Apt 4\"\n },\n \"label\": \"My Visa Debit\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://platform.spritz.finance/v1/debit-cards/")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"encryptedCardNumber\": \"ev:SWFSS:...\",\n \"expiryMonth\": \"09\",\n \"expiryYear\": \"29\",\n \"cardLastFour\": \"4321\",\n \"cardBin\": \"411111\",\n \"cardholderFirstName\": \"John\",\n \"cardholderLastName\": \"Doe\",\n \"billingAddress\": {\n \"line1\": \"123 Main St\",\n \"city\": \"New York\",\n \"state\": \"NY\",\n \"postalCode\": \"10001\",\n \"country\": \"US\",\n \"line2\": \"Apt 4\"\n },\n \"label\": \"My Visa Debit\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://platform.spritz.finance/v1/debit-cards/")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"encryptedCardNumber\": \"ev:SWFSS:...\",\n \"expiryMonth\": \"09\",\n \"expiryYear\": \"29\",\n \"cardLastFour\": \"4321\",\n \"cardBin\": \"411111\",\n \"cardholderFirstName\": \"John\",\n \"cardholderLastName\": \"Doe\",\n \"billingAddress\": {\n \"line1\": \"123 Main St\",\n \"city\": \"New York\",\n \"state\": \"NY\",\n \"postalCode\": \"10001\",\n \"country\": \"US\",\n \"line2\": \"Apt 4\"\n },\n \"label\": \"My Visa Debit\"\n}"
response = http.request(request)
puts response.read_body{
"id": "6ab3aa90aacef26176c97a29",
"status": "active",
"network": "visa",
"cardNumberLast4": "1111",
"expiryMonth": 12,
"expiryYear": 2027,
"currency": "USD",
"isTokenized": true,
"createdAt": "2023-11-07T05:31:56Z",
"label": "<string>",
"requirements": [
{
"type": "card_details",
"fields": [
"cardholder_name",
"billing_address"
],
"reason": "Cardholder name and billing address are required to enable payouts."
}
]
}{
"title": "Unauthorized",
"status": 401,
"type": "urn:problem-type:auth:unauthorized",
"detail": "Bearer token required",
"instance": "<string>",
"realm": "API",
"scope": "read:users"
}{
"title": "<string>",
"status": 404,
"resourceType": "user",
"resourceId": "<string>",
"type": "about:blank",
"detail": "<string>",
"instance": "<string>"
}{
"title": "Unauthorized",
"status": 400,
"type": "urn:problem-type:auth:unauthorized",
"detail": "<string>",
"instance": "/errors/1234567890",
"code": "transaction_limit",
"field": "amountUsd",
"retryable": true,
"retryAfter": 5,
"suggestedAction": "auto_ramp",
"clearsAt": "2023-11-07T05:31:56Z",
"availableAt": "2023-11-07T05:31:56Z",
"permanent": true
}Add a debit card
Adds a debit card as a push-to-card payout destination. Never send a raw card number: collect it with the Evervault Card component in the user’s browser (initialised with the Evervault team ID and per-environment app ID that Spritz provides during onboarding) and forward the encrypted card.number token together with the plaintext expiry, last four, BIN and brand it returns. Requires an active crypto_to_fiat / push_to_card capability. See the Push to debit card guide.
curl --request POST \
--url https://platform.spritz.finance/v1/debit-cards/ \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"encryptedCardNumber": "ev:SWFSS:...",
"expiryMonth": "09",
"expiryYear": "29",
"cardLastFour": "4321",
"cardBin": "411111",
"cardholderFirstName": "John",
"cardholderLastName": "Doe",
"billingAddress": {
"line1": "123 Main St",
"city": "New York",
"state": "NY",
"postalCode": "10001",
"country": "US",
"line2": "Apt 4"
},
"label": "My Visa Debit"
}
'import requests
url = "https://platform.spritz.finance/v1/debit-cards/"
payload = {
"encryptedCardNumber": "ev:SWFSS:...",
"expiryMonth": "09",
"expiryYear": "29",
"cardLastFour": "4321",
"cardBin": "411111",
"cardholderFirstName": "John",
"cardholderLastName": "Doe",
"billingAddress": {
"line1": "123 Main St",
"city": "New York",
"state": "NY",
"postalCode": "10001",
"country": "US",
"line2": "Apt 4"
},
"label": "My Visa Debit"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
encryptedCardNumber: 'ev:SWFSS:...',
expiryMonth: '09',
expiryYear: '29',
cardLastFour: '4321',
cardBin: '411111',
cardholderFirstName: 'John',
cardholderLastName: 'Doe',
billingAddress: {
line1: '123 Main St',
city: 'New York',
state: 'NY',
postalCode: '10001',
country: 'US',
line2: 'Apt 4'
},
label: 'My Visa Debit'
})
};
fetch('https://platform.spritz.finance/v1/debit-cards/', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://platform.spritz.finance/v1/debit-cards/",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'encryptedCardNumber' => 'ev:SWFSS:...',
'expiryMonth' => '09',
'expiryYear' => '29',
'cardLastFour' => '4321',
'cardBin' => '411111',
'cardholderFirstName' => 'John',
'cardholderLastName' => 'Doe',
'billingAddress' => [
'line1' => '123 Main St',
'city' => 'New York',
'state' => 'NY',
'postalCode' => '10001',
'country' => 'US',
'line2' => 'Apt 4'
],
'label' => 'My Visa Debit'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://platform.spritz.finance/v1/debit-cards/"
payload := strings.NewReader("{\n \"encryptedCardNumber\": \"ev:SWFSS:...\",\n \"expiryMonth\": \"09\",\n \"expiryYear\": \"29\",\n \"cardLastFour\": \"4321\",\n \"cardBin\": \"411111\",\n \"cardholderFirstName\": \"John\",\n \"cardholderLastName\": \"Doe\",\n \"billingAddress\": {\n \"line1\": \"123 Main St\",\n \"city\": \"New York\",\n \"state\": \"NY\",\n \"postalCode\": \"10001\",\n \"country\": \"US\",\n \"line2\": \"Apt 4\"\n },\n \"label\": \"My Visa Debit\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://platform.spritz.finance/v1/debit-cards/")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"encryptedCardNumber\": \"ev:SWFSS:...\",\n \"expiryMonth\": \"09\",\n \"expiryYear\": \"29\",\n \"cardLastFour\": \"4321\",\n \"cardBin\": \"411111\",\n \"cardholderFirstName\": \"John\",\n \"cardholderLastName\": \"Doe\",\n \"billingAddress\": {\n \"line1\": \"123 Main St\",\n \"city\": \"New York\",\n \"state\": \"NY\",\n \"postalCode\": \"10001\",\n \"country\": \"US\",\n \"line2\": \"Apt 4\"\n },\n \"label\": \"My Visa Debit\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://platform.spritz.finance/v1/debit-cards/")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"encryptedCardNumber\": \"ev:SWFSS:...\",\n \"expiryMonth\": \"09\",\n \"expiryYear\": \"29\",\n \"cardLastFour\": \"4321\",\n \"cardBin\": \"411111\",\n \"cardholderFirstName\": \"John\",\n \"cardholderLastName\": \"Doe\",\n \"billingAddress\": {\n \"line1\": \"123 Main St\",\n \"city\": \"New York\",\n \"state\": \"NY\",\n \"postalCode\": \"10001\",\n \"country\": \"US\",\n \"line2\": \"Apt 4\"\n },\n \"label\": \"My Visa Debit\"\n}"
response = http.request(request)
puts response.read_body{
"id": "6ab3aa90aacef26176c97a29",
"status": "active",
"network": "visa",
"cardNumberLast4": "1111",
"expiryMonth": 12,
"expiryYear": 2027,
"currency": "USD",
"isTokenized": true,
"createdAt": "2023-11-07T05:31:56Z",
"label": "<string>",
"requirements": [
{
"type": "card_details",
"fields": [
"cardholder_name",
"billing_address"
],
"reason": "Cardholder name and billing address are required to enable payouts."
}
]
}{
"title": "Unauthorized",
"status": 401,
"type": "urn:problem-type:auth:unauthorized",
"detail": "Bearer token required",
"instance": "<string>",
"realm": "API",
"scope": "read:users"
}{
"title": "<string>",
"status": 404,
"resourceType": "user",
"resourceId": "<string>",
"type": "about:blank",
"detail": "<string>",
"instance": "<string>"
}{
"title": "Unauthorized",
"status": 400,
"type": "urn:problem-type:auth:unauthorized",
"detail": "<string>",
"instance": "/errors/1234567890",
"code": "transaction_limit",
"field": "amountUsd",
"retryable": true,
"retryAfter": 5,
"suggestedAction": "auto_ramp",
"clearsAt": "2023-11-07T05:31:56Z",
"availableAt": "2023-11-07T05:31:56Z",
"permanent": true
}Authorizations
User bearer credential: either a Cognito JWT or an ak_ user API key. Backend integrators using HMAC must include the user API key alongside the three HMAC headers on user-scoped endpoints.
Body
Card number as encrypted by the Evervault Card component (card.number in its change payload). An opaque ev: token — never a raw PAN. Initialise the component with the Evervault team ID and the per-environment app ID that Spritz provides during onboarding.
"ev:SWFSS:..."
Expiry month exactly as the Evervault Card component returns it (card.expiry.month). This value is plaintext, not encrypted; one or two digits are accepted.
^(0?[1-9]|1[0-2])$"09"
Expiry year exactly as the Evervault Card component returns it (card.expiry.year). This value is plaintext, not encrypted; a two-digit year is accepted.
^[0-9]{2}$|^20[0-9]{2}$"29"
Last 4 digits of the card number (plaintext from iframe)
^[0-9]{4}$"4321"
Card BIN / first 6-8 digits (plaintext from iframe)
^[0-9]{6,8}$"411111"
visa, mastercard Cardholder's first name
1"John"
Cardholder's last name
1"Doe"
Show child attributes
Show child attributes
Friendly name for the card
"My Visa Debit"
Response
Response for status 201
Unique identifier for the debit card
"6ab3aa90aacef26176c97a29"
active, pending, inactive, rejected, action_required visa, mastercard Last 4 digits of card number
"1111"
12
2027
USD, CAD, EUR, GBP Whether this card has been tokenized via Evervault for secure storage
true
Actions the user must complete before the card can be used for payouts. Present (non-empty) when status is action_required.
Show child attributes
Show child attributes