Card issuing request

List card issuing requests

Returns a paginated list of card issuing requests for the company. A card issuing request is what the dashboard creates when a user asks for a card: it captures the requested budget, interval, and (for physical cards) the shipping details, and is later approved by Cardda — producing the actual VendorCard and setting vendor_card_id.

Authorization is index? = admin? || in_company?. A non-admin caller must therefore resolve a company they belong to — supplied via the company-id header (or a company_id query param). With neither present the caller has no company membership, fails the gate, and the request returns 401. Admins bypass the gate.

Once authorized, the result is scoped per-caller via policy_scope. That scope is not limited to the resolved company: it spans every company where the caller holds the card_issuing_requests_manage permission, plus the caller's own requests. Roles within that scope:

  • Admins see every request.
  • Managers (card_issuing_requests_manage permission) see every request of the companies they manage.
  • Regular users see only their own requests (user_id matches their Firebase user id).

Each row includes the computed fields kyc_completed (whether the company finished KYC) and shipping_municipality_name (municipality resolved from the shipping address).

All operators in Filters are supported on the columns below.

get/v1/card_issuing_requests

Query parameters

company_idstring uuid

Company-context fallback used when the company-id header is absent. A non-admin caller must resolve a company they belong to (header or this query param) to pass the in_company? gate; admins may omit both.

idstring

Filter by request id. Use id={"$in":[...]} for batch lookups.

user_idstring

Firebase user id of the requesting cardholder.

status'pending' | 'accepted' | 'declined' | 'printing' | 'printed' | 'sent' | 'delivered'
Example:pending

Lifecycle status. Use $or/$in to paint a dashboard, e.g. hide finished requests with status={"$nin":["accepted","declined"]}.

physicalboolean

Whether the request is for a physical card.

vendor_idstring

Issuing partner selected at approval time (e.g. plh, pomelo, slash).

typestring

STI subclass derived from vendor_id.

created_atstring

Creation timestamp. Accepts a single ISO-8601 date-time string or a JSON-encoded operator object ({"$gte":"...","$lt":"..."}). Schema is type: string (no format) so both forms validate.

$orstring

Logical OR across sub-conditions, e.g. $or=[{"status":"pending"},{"status":"printing"}].

Parameters

#/paths/~1v1~1merchants/get/parameters/0 — unresolved $ref
#/paths/~1v1~1merchants/get/parameters/2 — unresolved $ref
#/paths/~1v1~1merchants/get/parameters/3 — unresolved $ref
#/paths/~1v1~1merchants/get/parameters/4 — unresolved $ref
#/paths/~1v1~1merchants/get/parameters/5 — unresolved $ref

Response

Paginated list of card issuing requests. Headers include X-Total-Count and Content-Range for offset pagination — see Pagination.

idstring uuid
namestring nullable

Display name requested for the card.

user_idstring

Firebase user id of the future cardholder (not a UUID).

company_idstring uuid
status'pending' | 'accepted' | 'declined' | 'printing' | 'printed' | 'sent' | 'delivered'

Lifecycle of the request.

  • pending — created, awaiting approval / issuing.
  • accepted — a card was issued and linked (vendor_card_id is set).
  • declined — rejected.
  • printing / printed — physical card in production.
  • sent — dispatched to the cardholder (admin marks this).
  • delivered — cardholder self-confirmed receipt (see confirm_delivery).
budget_centsinteger

Requested spending budget in cents, in budget_currency.

budget_currencystring

ISO-4217 code of the requested budget currency.

interval'monthly' | 'daily'

Budget renewal interval for the resulting card.

physicalboolean

Whether a physical (plastic) card is requested. false for virtual-only.

purchase'national' | 'international' | 'both' nullable

Allowed purchase geography for the card.

vendor_idstring nullable

Issuing partner selected at approval time (e.g. plh, pomelo, slash).

vendor_card_idstring nullable

Id of the issued VendorCard once the request is accepted (vendor-prefixed string, not a UUID).

typestring nullable

STI subclass derived from vendor_id (e.g. Cards::Plh::Request).

recipient_namestring nullable

Recipient full name for physical shipments. Required for physical CLP requests.

contact_phonestring nullable

Contact phone for the physical shipment.

shipping_municipality_namestring nullable

Resolved municipality name for the shipping address (computed field).

kyc_completedboolean

Whether the owning company has completed KYC. Computed field. Serialized as the JSON key kyc_completed (the ? Ruby predicate suffix is stripped).

tracking_numberstring nullable

Carrier tracking number (staff-set). Only present for dispatched physical cards.

tracking_urlstring nullable

Carrier tracking URL (staff-set).

estimated_delivery_datestring date nullable

Estimated delivery date (staff-set).

shipment_idstring nullable

Vendor shipment identifier for physical cards.

printing_atstring date-time nullable

When the request entered the printing milestone.

sent_atstring date-time nullable

When the physical card was dispatched.

delivered_atstring date-time nullable

When the cardholder confirmed delivery.

created_atstring date-time
updated_atstring date-time

Example response

[
  {
    "id": "9f8b2c1d-4e5a-6b7c-8d9e-0f1a2b3c4d5e",
    "name": "Marketing — María Pérez",
    "user_id": "U2MGkNZT6zNPKtB85OpJi9SjFvG2",
    "company_id": "550e8400-e29b-41d4-a716-446655440000",
    "status": "pending",
    "budget_cents": 500000,
    "budget_currency": "CLP",
    "interval": "monthly",
    "purchase": "both",
    "vendor_id": "plh",
    "vendor_card_id": "Q2FyZDoxMDIwNjQ5Mw==",
    "type": "Cards::Plh::Request",
    "recipient_name": "María Pérez",
    "contact_phone": "+56912345678",
    "shipping_address": {
      "street": "Av. Apoquindo",
      "number": "4700",
      "municipality_id": 13114,
      "municipality_name": "Las Condes",
      "complement": "Oficina 501"
    },
    "shipping_municipality_name": "Las Condes",
    "kyc_completed": true,
    "tracking_number": "CL123456789",
    "tracking_url": "https://tracking.example.com/CL123456789",
    "estimated_delivery_date": "2026-08-01"
  }
]

Changes