Issue Business Card
Issue a physical or virtual routable card tied to a business cardholder.
Authentication: send the program API key either in the api_key HTTP header or as an api_key JSON body field.
curl --request POST \
--url https://api.sdev.banking.ingopayments.tech/api/v4/business/routable-cards/create \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'api_key: <api-key>' \
--data '
{
"api_key": "YOUR_API_KEY",
"business_id": "buss-2ef94c60-5a11-4d72-a3c1-5be7fab0123e",
"user_id": "user-8f3a2b1c-0e44-4f2d-9a11-7b23cc90d1ef",
"card_type": "virtual",
"idempotent_key": "idp-9f1a2b3c-4d5e-6f70-8192-a3b4c5d6e7f8"
}
'import requests
url = "https://api.sdev.banking.ingopayments.tech/api/v4/business/routable-cards/create"
payload = {
"api_key": "YOUR_API_KEY",
"business_id": "buss-2ef94c60-5a11-4d72-a3c1-5be7fab0123e",
"user_id": "user-8f3a2b1c-0e44-4f2d-9a11-7b23cc90d1ef",
"card_type": "virtual",
"idempotent_key": "idp-9f1a2b3c-4d5e-6f70-8192-a3b4c5d6e7f8"
}
headers = {
"Authorization": "Bearer <token>",
"api_key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
Authorization: 'Bearer <token>',
api_key: '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
api_key: 'YOUR_API_KEY',
business_id: 'buss-2ef94c60-5a11-4d72-a3c1-5be7fab0123e',
user_id: 'user-8f3a2b1c-0e44-4f2d-9a11-7b23cc90d1ef',
card_type: 'virtual',
idempotent_key: 'idp-9f1a2b3c-4d5e-6f70-8192-a3b4c5d6e7f8'
})
};
fetch('https://api.sdev.banking.ingopayments.tech/api/v4/business/routable-cards/create', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sdev.banking.ingopayments.tech/api/v4/business/routable-cards/create",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'api_key' => 'YOUR_API_KEY',
'business_id' => 'buss-2ef94c60-5a11-4d72-a3c1-5be7fab0123e',
'user_id' => 'user-8f3a2b1c-0e44-4f2d-9a11-7b23cc90d1ef',
'card_type' => 'virtual',
'idempotent_key' => 'idp-9f1a2b3c-4d5e-6f70-8192-a3b4c5d6e7f8'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"api_key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.sdev.banking.ingopayments.tech/api/v4/business/routable-cards/create"
payload := strings.NewReader("{\n \"api_key\": \"YOUR_API_KEY\",\n \"business_id\": \"buss-2ef94c60-5a11-4d72-a3c1-5be7fab0123e\",\n \"user_id\": \"user-8f3a2b1c-0e44-4f2d-9a11-7b23cc90d1ef\",\n \"card_type\": \"virtual\",\n \"idempotent_key\": \"idp-9f1a2b3c-4d5e-6f70-8192-a3b4c5d6e7f8\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("api_key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.sdev.banking.ingopayments.tech/api/v4/business/routable-cards/create")
.header("Authorization", "Bearer <token>")
.header("api_key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"api_key\": \"YOUR_API_KEY\",\n \"business_id\": \"buss-2ef94c60-5a11-4d72-a3c1-5be7fab0123e\",\n \"user_id\": \"user-8f3a2b1c-0e44-4f2d-9a11-7b23cc90d1ef\",\n \"card_type\": \"virtual\",\n \"idempotent_key\": \"idp-9f1a2b3c-4d5e-6f70-8192-a3b4c5d6e7f8\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.sdev.banking.ingopayments.tech/api/v4/business/routable-cards/create")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["api_key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"api_key\": \"YOUR_API_KEY\",\n \"business_id\": \"buss-2ef94c60-5a11-4d72-a3c1-5be7fab0123e\",\n \"user_id\": \"user-8f3a2b1c-0e44-4f2d-9a11-7b23cc90d1ef\",\n \"card_type\": \"virtual\",\n \"idempotent_key\": \"idp-9f1a2b3c-4d5e-6f70-8192-a3b4c5d6e7f8\"\n}"
response = http.request(request)
puts response.read_body{
"status": "success",
"message": "operation completed",
"data": {
"items": [
{
"id": "rcrd-9a117b23-cc90-d1ef-8f3a-2b1c0e444f2d",
"last_four": "4242",
"user_id": "user-8f3a2b1c-0e44-4f2d-9a11-7b23cc90d1ef",
"business_id": "buss-2ef94c60-5a11-4d72-a3c1-5be7fab0123e",
"created_at": "2026-04-16T12:34:56.000Z"
}
],
"pagination": {
"page": 1,
"per_page": 25,
"total": 100,
"sort": "created_at:desc",
"search": "jane"
}
}
}{
"status": "error",
"message": "Something went wrong",
"data": "<unknown>",
"status_code": {
"status_code": 1000,
"message": "Resource not found",
"description": "The requested resource does not exist"
}
}{
"status": "error",
"message": "Something went wrong",
"data": "<unknown>",
"status_code": {
"status_code": 1000,
"message": "Resource not found",
"description": "The requested resource does not exist"
}
}{
"status": "error",
"message": "Something went wrong",
"data": "<unknown>",
"status_code": {
"status_code": 1000,
"message": "Resource not found",
"description": "The requested resource does not exist"
}
}Authorizations
Program API key identifying your integration. Pass as the api_key HTTP header (preferred) or as an api_key field in the JSON request body. Required on every request in addition to the HMAC Authorization header.
Body
Identifier of the target user. Required when the endpoint operates on a specific user.
"user-8f3a2b1c-0e44-4f2d-9a11-7b23cc90d1ef"
Identifier of the target business. Required when the endpoint operates on a specific business.
"buss-2ef94c60-5a11-4d72-a3c1-5be7fab0123e"
Requested card form factor.
physical, virtual Program API key. Accepted either in the api_key HTTP header or as this body field.
Client-supplied idempotency token. Submitting the same key twice returns the first response rather than creating a duplicate transaction.
Shipping address object. Required for physical card issuance.
Show child attributes
Show child attributes
Existing virtual card id to materialise as the physical card (when issuing physical after virtual).
curl --request POST \
--url https://api.sdev.banking.ingopayments.tech/api/v4/business/routable-cards/create \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'api_key: <api-key>' \
--data '
{
"api_key": "YOUR_API_KEY",
"business_id": "buss-2ef94c60-5a11-4d72-a3c1-5be7fab0123e",
"user_id": "user-8f3a2b1c-0e44-4f2d-9a11-7b23cc90d1ef",
"card_type": "virtual",
"idempotent_key": "idp-9f1a2b3c-4d5e-6f70-8192-a3b4c5d6e7f8"
}
'import requests
url = "https://api.sdev.banking.ingopayments.tech/api/v4/business/routable-cards/create"
payload = {
"api_key": "YOUR_API_KEY",
"business_id": "buss-2ef94c60-5a11-4d72-a3c1-5be7fab0123e",
"user_id": "user-8f3a2b1c-0e44-4f2d-9a11-7b23cc90d1ef",
"card_type": "virtual",
"idempotent_key": "idp-9f1a2b3c-4d5e-6f70-8192-a3b4c5d6e7f8"
}
headers = {
"Authorization": "Bearer <token>",
"api_key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
Authorization: 'Bearer <token>',
api_key: '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
api_key: 'YOUR_API_KEY',
business_id: 'buss-2ef94c60-5a11-4d72-a3c1-5be7fab0123e',
user_id: 'user-8f3a2b1c-0e44-4f2d-9a11-7b23cc90d1ef',
card_type: 'virtual',
idempotent_key: 'idp-9f1a2b3c-4d5e-6f70-8192-a3b4c5d6e7f8'
})
};
fetch('https://api.sdev.banking.ingopayments.tech/api/v4/business/routable-cards/create', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sdev.banking.ingopayments.tech/api/v4/business/routable-cards/create",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'api_key' => 'YOUR_API_KEY',
'business_id' => 'buss-2ef94c60-5a11-4d72-a3c1-5be7fab0123e',
'user_id' => 'user-8f3a2b1c-0e44-4f2d-9a11-7b23cc90d1ef',
'card_type' => 'virtual',
'idempotent_key' => 'idp-9f1a2b3c-4d5e-6f70-8192-a3b4c5d6e7f8'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"api_key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.sdev.banking.ingopayments.tech/api/v4/business/routable-cards/create"
payload := strings.NewReader("{\n \"api_key\": \"YOUR_API_KEY\",\n \"business_id\": \"buss-2ef94c60-5a11-4d72-a3c1-5be7fab0123e\",\n \"user_id\": \"user-8f3a2b1c-0e44-4f2d-9a11-7b23cc90d1ef\",\n \"card_type\": \"virtual\",\n \"idempotent_key\": \"idp-9f1a2b3c-4d5e-6f70-8192-a3b4c5d6e7f8\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("api_key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.sdev.banking.ingopayments.tech/api/v4/business/routable-cards/create")
.header("Authorization", "Bearer <token>")
.header("api_key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"api_key\": \"YOUR_API_KEY\",\n \"business_id\": \"buss-2ef94c60-5a11-4d72-a3c1-5be7fab0123e\",\n \"user_id\": \"user-8f3a2b1c-0e44-4f2d-9a11-7b23cc90d1ef\",\n \"card_type\": \"virtual\",\n \"idempotent_key\": \"idp-9f1a2b3c-4d5e-6f70-8192-a3b4c5d6e7f8\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.sdev.banking.ingopayments.tech/api/v4/business/routable-cards/create")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["api_key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"api_key\": \"YOUR_API_KEY\",\n \"business_id\": \"buss-2ef94c60-5a11-4d72-a3c1-5be7fab0123e\",\n \"user_id\": \"user-8f3a2b1c-0e44-4f2d-9a11-7b23cc90d1ef\",\n \"card_type\": \"virtual\",\n \"idempotent_key\": \"idp-9f1a2b3c-4d5e-6f70-8192-a3b4c5d6e7f8\"\n}"
response = http.request(request)
puts response.read_body{
"status": "success",
"message": "operation completed",
"data": {
"items": [
{
"id": "rcrd-9a117b23-cc90-d1ef-8f3a-2b1c0e444f2d",
"last_four": "4242",
"user_id": "user-8f3a2b1c-0e44-4f2d-9a11-7b23cc90d1ef",
"business_id": "buss-2ef94c60-5a11-4d72-a3c1-5be7fab0123e",
"created_at": "2026-04-16T12:34:56.000Z"
}
],
"pagination": {
"page": 1,
"per_page": 25,
"total": 100,
"sort": "created_at:desc",
"search": "jane"
}
}
}{
"status": "error",
"message": "Something went wrong",
"data": "<unknown>",
"status_code": {
"status_code": 1000,
"message": "Resource not found",
"description": "The requested resource does not exist"
}
}{
"status": "error",
"message": "Something went wrong",
"data": "<unknown>",
"status_code": {
"status_code": 1000,
"message": "Resource not found",
"description": "The requested resource does not exist"
}
}{
"status": "error",
"message": "Something went wrong",
"data": "<unknown>",
"status_code": {
"status_code": 1000,
"message": "Resource not found",
"description": "The requested resource does not exist"
}
}