Cards

Add a card to a digital wallet

Changed on

Exchange the values your app received from Apple Pay, Google Pay, or Samsung Pay for the encrypted provisioning payload that completes adding the card to that wallet (in-app push provisioning). Call it from your backend inside the wallet SDK's credentials callback and hand the response straight back to the SDK.

The payload is encrypted to the wallet provider's keys, so neither your app nor your servers ever see card data. Do not store or log it; it is valid for one provisioning attempt.

Cardholders can always add a card to a wallet by typing its details in manually — that path needs nothing from you. This endpoint is for the in-app "Add to Wallet" button, which additionally requires approval from each wallet provider. See Digital wallet tokenization.

Only ACTIVE cards can be added. Every call is audit-logged with the requesting actor and the target wallet.

post/cards/{id}/tokenize

Request

  • Base URL: https://api.lightspark.com/grid/2025-10-13
  • URL: https://api.lightspark.com/grid/2025-10-13/cards/{id}/tokenize
  • Auth: HTTP basic

Request body

OR
OR

Example request

{
  "wallet": "APPLE_PAY",
  "certificate": "LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUM=",
  "nonce": "MTIzNDU2Nzg=",
  "nonceSignature": "c2lnbmF0dXJl"
}

Response

Provisioning payload minted.

OR
OR

Example response

{
  "wallet": "APPLE_PAY",
  "applePay": {
    "activationData": "YWN0aXZhdGlvbi1kYXRh",
    "encryptedPassData": "ZW5jcnlwdGVkLXBhc3MtZGF0YQ==",
    "ephemeralPublicKey": "ZXBoZW1lcmFsLXB1YmxpYy1rZXk="
  }
}

Changes