---
title: "Create Card"
method: POST
path: "/cards"
tags: ["Cards"]
---

# Create Card

`POST /cards`

Issues a virtual card. For an individual (consumer) card issuing account, the card is issued to the account's own cardholder. For a company (business) card issuing account, pass assigned_user_id to issue the card to a company member; if that member is not yet an approved card-issuing user, the card is provisioned asynchronously or an onboarding invitation is sent (HTTP 202). Pass exactly one of account_id (a biz_ identifier) or user_id (a user_ identifier). Returns the newly created card resource.

## Headers

- `Idempotency-Key` string

## Request body

- object
  - `account_id` string — The owning account ID (a biz_ identifier). Provide this or user_id.
  - `assigned_user_id` string — The company member (a user_ identifier) to assign the card to. Required for company (business) card issuing accounts.
  - `name` string — A display name for the card.
  - `spend_limit` number — Spending limit amount, in dollars.
  - `spend_limit_frequency` 'daily' | 'weekly' | 'monthly' | 'one_time' — The spending limit window.
  - `transaction_limit` number — Per-transaction limit amount, in dollars.
  - `user_id` string — The owning user ID (a user_ identifier). Provide this or account_id.

## Response `201`

company card created for an assigned member

- object
  - `billing` object, nullable, required — The billing address.
    - `city` string, nullable, required — Billing city.
    - `country_code` string, nullable, required — Billing country code.
    - `line1` string, nullable, required — Street address line 1.
    - `line2` string, nullable, required — Street address line 2.
    - `postal_code` string, nullable, required — Billing postal code.
    - `region` string, nullable, required — Billing region or state.
  - `canceled_at` string, date-time, nullable, required — When the card was canceled.
  - `created_at` string, date-time, nullable, required — When the card was created.
  - `expiration_month` string, nullable, required — Card expiration month.
  - `expiration_year` string, nullable, required — Card expiration year.
  - `id` string, required — Card ID, prefixed `icrd_`.
  - `last4` string, nullable, required — Last four digits of the card number. `null` for pending invitation cards.
  - `limit` object, nullable, required — The spending limit configuration.
    - `amount` number, required — The limit amount in dollars.
    - `frequency` string, required — Limit window, for example `per24HourPeriod` or `perAuthorization`.
  - `name` string, nullable, required — Card display name.
  - `object` 'card', required
  - `secrets` object, nullable — Sensitive card details. Present only on `GET /cards/:card_id` for active cards; `null` when the card is inactive or details cannot be retrieved.
    - `card_number` string, required — Full card number.
    - `cvc` string, required — Card verification code.
    - `name_on_card` string, nullable, required — Cardholder name printed on the card.
    - `pin` string, nullable, required — The card PIN. Only returned when the request is authenticated as the user the card is assigned to; `null` for all other callers, including account API keys.
  - `spent_last_month` integer, nullable, required — Total spend in the last 30 days, in cents.
  - `status` 'null' | 'active' | 'frozen' | 'canceled' | 'invited', nullable, required — The card status.
  - `type` 'null' | 'virtual' | 'physical', nullable, required — The card type.
  - `user_id` string, nullable, required — Cardholder user ID, prefixed `user_`, when assigned.

## Other responses

- `202` — card not issued synchronously: provisioning started or onboarding invitation sent
- `400` — Invalid Parameters
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Resource not found

## Changes

- **2026-07-26** `60bbb4a6ffbc` — 2 info
  - added the new optional `header` request parameter `Idempotency-Key`
  - added the required property `secrets/pin` to the response with the `201` status

[Change history](https://skmtc.dev/whop/apis/whop-api/changes/cards/post.md)

---

[API](https://skmtc.dev/whop/apis/whop-api.md) · [All operations](https://skmtc.dev/whop/apis/whop-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/whop/whop-api/revisions/60bbb4a6ffbc/schema)
