Skip to main content
POST
/
gateway
/
verify--card
Verify and tokenize a debit or credit card
curl --request POST \
  --url https://payapi-sandbox.ingo.money/gateway/verify--card \
  --header 'Authorization: <api-key>' \
  --header 'Content-Type: application/json' \
  --data '
{
  "participant_id": 12345,
  "account_type": "CA",
  "amount": 1010.5,
  "recipient_first_name": "Alex",
  "recipient_last_name": "Rivera",
  "account": "4111111111111111",
  "expiration_date": "2612",
  "cvv": "123",
  "recipient_address1": "100 Innovation Way",
  "recipient_address2": "Apt 2",
  "recipient_city": "Anytown",
  "recipient_state": "GA",
  "recipient_zip": "00000",
  "recipient_phone": "1231231234",
  "participant_unique_id1": "1f2739ed-3531-4af2-ae36-e6faf7936462",
  "participant_unique_id2": "90759390-01c7-47e7-8a90-6faa89b18ff6",
  "timestamp": 1576097158,
  "version": 11
}
'
import requests

url = "https://payapi-sandbox.ingo.money/gateway/verify--card"

payload = {
"participant_id": 12345,
"account_type": "CA",
"amount": 1010.5,
"recipient_first_name": "Alex",
"recipient_last_name": "Rivera",
"account": "4111111111111111",
"expiration_date": "2612",
"cvv": "123",
"recipient_address1": "100 Innovation Way",
"recipient_address2": "Apt 2",
"recipient_city": "Anytown",
"recipient_state": "GA",
"recipient_zip": "00000",
"recipient_phone": "1231231234",
"participant_unique_id1": "1f2739ed-3531-4af2-ae36-e6faf7936462",
"participant_unique_id2": "90759390-01c7-47e7-8a90-6faa89b18ff6",
"timestamp": 1576097158,
"version": 11
}
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.text)
const options = {
method: 'POST',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
participant_id: 12345,
account_type: 'CA',
amount: 1010.5,
recipient_first_name: 'Alex',
recipient_last_name: 'Rivera',
account: '4111111111111111',
expiration_date: '2612',
cvv: '123',
recipient_address1: '100 Innovation Way',
recipient_address2: 'Apt 2',
recipient_city: 'Anytown',
recipient_state: 'GA',
recipient_zip: '00000',
recipient_phone: '1231231234',
participant_unique_id1: '1f2739ed-3531-4af2-ae36-e6faf7936462',
participant_unique_id2: '90759390-01c7-47e7-8a90-6faa89b18ff6',
timestamp: 1576097158,
version: 11
})
};

fetch('https://payapi-sandbox.ingo.money/gateway/verify--card', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));
<?php

$curl = curl_init();

curl_setopt_array($curl, [
CURLOPT_URL => "https://payapi-sandbox.ingo.money/gateway/verify--card",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'participant_id' => 12345,
'account_type' => 'CA',
'amount' => 1010.5,
'recipient_first_name' => 'Alex',
'recipient_last_name' => 'Rivera',
'account' => '4111111111111111',
'expiration_date' => '2612',
'cvv' => '123',
'recipient_address1' => '100 Innovation Way',
'recipient_address2' => 'Apt 2',
'recipient_city' => 'Anytown',
'recipient_state' => 'GA',
'recipient_zip' => '00000',
'recipient_phone' => '1231231234',
'participant_unique_id1' => '1f2739ed-3531-4af2-ae36-e6faf7936462',
'participant_unique_id2' => '90759390-01c7-47e7-8a90-6faa89b18ff6',
'timestamp' => 1576097158,
'version' => 11
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);

$response = curl_exec($curl);
$err = curl_error($curl);

curl_close($curl);

if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}
package main

import (
"fmt"
"strings"
"net/http"
"io"
)

func main() {

url := "https://payapi-sandbox.ingo.money/gateway/verify--card"

payload := strings.NewReader("{\n \"participant_id\": 12345,\n \"account_type\": \"CA\",\n \"amount\": 1010.5,\n \"recipient_first_name\": \"Alex\",\n \"recipient_last_name\": \"Rivera\",\n \"account\": \"4111111111111111\",\n \"expiration_date\": \"2612\",\n \"cvv\": \"123\",\n \"recipient_address1\": \"100 Innovation Way\",\n \"recipient_address2\": \"Apt 2\",\n \"recipient_city\": \"Anytown\",\n \"recipient_state\": \"GA\",\n \"recipient_zip\": \"00000\",\n \"recipient_phone\": \"1231231234\",\n \"participant_unique_id1\": \"1f2739ed-3531-4af2-ae36-e6faf7936462\",\n \"participant_unique_id2\": \"90759390-01c7-47e7-8a90-6faa89b18ff6\",\n \"timestamp\": 1576097158,\n \"version\": 11\n}")

req, _ := http.NewRequest("POST", url, payload)

req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")

res, _ := http.DefaultClient.Do(req)

defer res.Body.Close()
body, _ := io.ReadAll(res.Body)

fmt.Println(string(body))

}
HttpResponse<String> response = Unirest.post("https://payapi-sandbox.ingo.money/gateway/verify--card")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"participant_id\": 12345,\n \"account_type\": \"CA\",\n \"amount\": 1010.5,\n \"recipient_first_name\": \"Alex\",\n \"recipient_last_name\": \"Rivera\",\n \"account\": \"4111111111111111\",\n \"expiration_date\": \"2612\",\n \"cvv\": \"123\",\n \"recipient_address1\": \"100 Innovation Way\",\n \"recipient_address2\": \"Apt 2\",\n \"recipient_city\": \"Anytown\",\n \"recipient_state\": \"GA\",\n \"recipient_zip\": \"00000\",\n \"recipient_phone\": \"1231231234\",\n \"participant_unique_id1\": \"1f2739ed-3531-4af2-ae36-e6faf7936462\",\n \"participant_unique_id2\": \"90759390-01c7-47e7-8a90-6faa89b18ff6\",\n \"timestamp\": 1576097158,\n \"version\": 11\n}")
.asString();
require 'uri'
require 'net/http'

url = URI("https://payapi-sandbox.ingo.money/gateway/verify--card")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"participant_id\": 12345,\n \"account_type\": \"CA\",\n \"amount\": 1010.5,\n \"recipient_first_name\": \"Alex\",\n \"recipient_last_name\": \"Rivera\",\n \"account\": \"4111111111111111\",\n \"expiration_date\": \"2612\",\n \"cvv\": \"123\",\n \"recipient_address1\": \"100 Innovation Way\",\n \"recipient_address2\": \"Apt 2\",\n \"recipient_city\": \"Anytown\",\n \"recipient_state\": \"GA\",\n \"recipient_zip\": \"00000\",\n \"recipient_phone\": \"1231231234\",\n \"participant_unique_id1\": \"1f2739ed-3531-4af2-ae36-e6faf7936462\",\n \"participant_unique_id2\": \"90759390-01c7-47e7-8a90-6faa89b18ff6\",\n \"timestamp\": 1576097158,\n \"version\": 11\n}"

response = http.request(request)
puts response.read_body
{
  "status": 100,
  "client_message": "Success",
  "data": {
    "customer_account_token": "ca875cce-58c0-46a0-8f14-676190cc7df6",
    "last_4": "1111",
    "request_timestamp": 1576097360,
    "issuers": [
      {
        "payee_id": "526263",
        "payee_name": "Bank of America - Platinum MasterCard and Visa",
        "payee_address": "PO Box 15019",
        "payee_city": "Wilmington",
        "payee_state": "DE",
        "payee_zip": "19850-5019",
        "credit_info": {
          "min": "0.05",
          "max": "1500.00",
          "card_type": "Debit",
          "estimated_posting_time": "Payment will post within 5 minutes.",
          "estimated_posting_date": "04/21/2026"
        },
        "issuing_network": "Visa",
        "credit_enabled": 1,
        "debit_enabled": 0
      }
    ],
    "participant_unique_id1": "1f2739ed-3531-4af2-ae36-e6faf7936462",
    "participant_unique_id2": "90759390-01c7-47e7-8a90-6faa89b18ff6",
    "expiration_date": "2612",
    "count": 1
  },
  "time": "2.4505"
}
{
"status": 700,
"client_message": "Account not currently available for payment",
"data": {
"request_timestamp": 1576097360
}
}

Authorizations

Authorization
string
header
required

HMAC-SHA512 signed Authorization header. See the Authentication page for the complete signing guide.

Body

application/json

Exactly one of the following groupings must be provided: (1) customer_account_token, (2) third_party_token, or (3) raw card fields — account, recipient_first_name, recipient_last_name, recipient_address1, recipient_city, recipient_state, recipient_zip.

participant_id
integer
required

Unique participant identifier assigned by Ingo.

Example:

12345

account_type
enum<string>
required

Always CA for card-based (debit or credit) transactions.

Available options:
CA
Minimum string length: 1
Example:

"CA"

participant_unique_id1
string
required

Participant assigned ID to be associated with customer_account_token creation. Should correlate to participant assigned values affiliated with future process requests for tracking purposes (e.g. CustomerID or AccountID). Must not contain NPI data.

Required string length: 1 - 255
Example:

"1f2739ed-3531-4af2-ae36-e6faf7936462"

timestamp
integer<int64>
required

Unix timestamp of the request.

Example:

1576097158

version
integer
required

API version of the request. Current version is 11.

Example:

11

customer_account_token
string

Alternative to raw card data when the account was previously tokenized. If provided, third_party_token and all raw card fields (account, expiration_date, recipient_first_name, recipient_last_name, recipient_address1, recipient_address2, recipient_city, recipient_state, recipient_zip) must be omitted.

Required string length: 1 - 255
Example:

"ca875cce-58c0-46a0-8f14-676190cc7df6"

third_party_token
object

Contains data about an optional third-party account token. If provided, customer_account_token and raw card fields (account, expiration_date, cvv) must be omitted. Only permitted if the client is configured for third-party token use.

amount
number<float> | null

Dollar amount of disbursement. Max value determined by participant velocity limits.

Required range: x >= 0.01
Example:

1010.5

recipient_first_name
string

Recipient first name. Required unless customer_account_token is provided. Must be omitted if customer_account_token is provided.

Required string length: 1 - 255
Example:

"Johnny"

recipient_last_name
string

Recipient last name. Required unless customer_account_token is provided. Must be omitted if customer_account_token is provided.

Required string length: 1 - 255
Example:

"Rockets"

recipient_business_name
string | null

Optional recipient business name.

Maximum string length: 150
Example:

"Rockets LLC"

account
string

Card account number. Required unless customer_account_token or third_party_token is provided. Must be omitted if either token is provided.

Required string length: 1 - 255
Example:

"4111111111111111"

expiration_date
string | null

Card expiration date in YYMM format. Conditionally required based on client configuration (expiration_date_enabled). Not required if customer_account_token or third_party_token is provided.

Maximum string length: 4
Pattern: ^[0-9]{2}(0[1-9]|1[0-2])$
Example:

"2612"

cvv
string | null

CVV value (3–4 digits depending on card type). Conditionally required based on client configuration (cvv_enabled). Never required if customer_account_token or third_party_token is provided.

Pattern: ^[0-9]{3,4}$
Example:

"123"

recipient_address1
string

Recipient billing address line 1. Required unless customer_account_token is provided.

Required string length: 1 - 255
Example:

"123 Main St"

recipient_address2
string | null

Recipient billing address line 2.

Maximum string length: 255
Example:

"Apt 2"

recipient_city
string

Recipient billing city. Required unless customer_account_token is provided.

Required string length: 1 - 255
Example:

"Atlanta"

recipient_state
string

Recipient billing state (standard US postal abbreviation). Required unless customer_account_token is provided.

Required string length: 2
Pattern: ^(?:A[LKSZRAEP]|C[AOT]|D[EC]|F[LM]|G[AU]|HI|I[ADLN]|K[SY]|LA|M[ADEHINOPST]|N[CDEHJMVY]|O[HKR]|P[ARW]|RI|S[CD]|T[NX]|UT|V[AIT]|W[AIVY])$
Example:

"GA"

recipient_zip
string

Recipient billing zip code. 5-digit zip or zip+4 in xxxxx-xxxx format. Required unless customer_account_token is provided.

Maximum string length: 10
Pattern: ^[0-9]{5}(?:-[0-9]{4})?$
Example:

"30313"

recipient_phone
string | null

10-digit recipient phone number.

Maximum string length: 10
Example:

"1231231234"

participant_unique_id2
string | null

Optional second participant assigned ID to be associated with customer_account_token creation. Should be carried forward to future process requests for tracking purposes. Must not contain NPI data.

Maximum string length: 255
Example:

"90759390-01c7-47e7-8a90-6faa89b18ff6"

store_id
string | null

Client assigned store ID. Required for Retail client participants.

Maximum string length: 255
Example:

"STORE-001"

terminal_id
string | null

Client assigned terminal ID. Required for Retail client participants.

Maximum string length: 255
Example:

"TERM-042"

clerk_id
string | null

Client assigned clerk ID. Required for Retail client participants.

Maximum string length: 255
Example:

"CLK-007"

Response

Verification successful — token returned

status
integer

Numeric code describing the status of the API request. 100 = Success.

Example:

100

client_message
string

Text description associated with the status code.

Example:

"Success"

data
object
time
string

Time in seconds to complete the request.

Example:

"2.4505"