---
title: "Update Card"
method: PATCH
path: "/cards/{id}"
tags: ["Cards"]
---

# Update Card

`PATCH /cards/{id}`

Update, freeze, or cancel a card. Updating the card's name, billing address, or limits requires both `payout:account:update` and `company:balance:read`; a card's assigned holder may update their own card's pin and frozen state with any user token.

## Request body

- object
  - `account_id` string — The owning account ID (a biz_ identifier). Provide this or user_id.
  - `billing` object — The billing address. On an issued card this replaces the card's billing address and region is also required. On an invited card, sending it as the invited user completes onboarding and starts card provisioning.
    - `city` string, required — Billing city.
    - `country_code` string, required — Billing country code, ISO 3166-1 alpha-2.
    - `line1` string, required — Street address line 1.
    - `line2` string — Street address line 2.
    - `postal_code` string, required — Billing postal code.
    - `region` string — Billing region or state. Required when updating an issued card's billing address.
  - `canceled` boolean — Pass `true` to permanently cancel the card. A canceled card cannot be uncanceled. Cannot be combined with other fields.
  - `cardholder` object — Details for the invited cardholder, accepted only while completing onboarding on an invited card. The legal name comes from an approved identity verification when the invited user has one, and from these fields when they do not.
    - `email` string — Email address for the invited cardholder.
    - `first_name` string — Legal first name of the invited cardholder.
    - `last_name` string — Legal last name of the invited cardholder.
    - `phone` string — Phone number for the invited cardholder.
  - `frozen` boolean — Pass `true` to freeze the card, `false` to unfreeze it. The assigned cardholder may freeze their own card without the payout:account:update scope.
  - `name` string — A display name for the card.
  - `pin` string — New 4-digit PIN. Can only be set on a card assigned to the acting user, who may set it without the payout:account:update scope.
  - `remove_limit` boolean — Pass `true` to remove the spending limit (make the card unlimited).
  - `spend_limit` number — Spending limit amount, in dollars.
  - `spend_limit_frequency` 'daily' | 'weekly' | 'monthly' | 'one_time' — The window the spend limit applies to.
  - `transaction_limit` number — Per-transaction limit amount, in dollars.
  - `user_id` string — The owning user ID (a user_ identifier). Provide this or account_id.

## Response `200`

invited card onboarding completed: card provisioning started

- object
  - `billing` object, nullable, required — The billing address.
    - `city` string, nullable, required — Billing city.
    - `country_code` string, nullable, required — Billing country code.
    - `line1` string, nullable, required — Street address line 1.
    - `line2` string, nullable, required — Street address line 2.
    - `postal_code` string, nullable, required — Billing postal code.
    - `region` string, nullable, required — Billing region or state.
  - `canceled_at` string, date-time, nullable, required — When the card was canceled.
  - `created_at` string, date-time, nullable, required — When the card was created.
  - `expiration_month` string, nullable, required — Card expiration month.
  - `expiration_year` string, nullable, required — Card expiration year.
  - `id` string, required — Card ID, prefixed `icrd_`.
  - `last4` string, nullable, required — Last four digits of the card number. `null` for pending invitation cards.
  - `limit` object, nullable, required — The spending limit configuration.
    - `amount` number, required — The limit amount in dollars.
    - `frequency` 'daily' | 'weekly' | 'monthly' | 'one_time' | 'per_transaction', required — The window the limit amount applies to. `per_transaction` caps each individual authorization and is what a limit set with `transaction_limit` reports.
  - `name` string, nullable, required — Card display name.
  - `object` 'card', required
  - `secrets` object, nullable — Sensitive card details. Present only on `GET /cards/:id` for active cards; `null` when the card is inactive or details cannot be retrieved.
    - `card_number` string, required — Full card number.
    - `cvc` string, required — Card verification code.
    - `name_on_card` string, nullable, required — Cardholder name printed on the card.
    - `pin` string, nullable, required — The card PIN. Only returned when the request is authenticated as the user the card is assigned to; `null` for all other callers, including account API keys.
  - `spent_last_month` integer, nullable, required — Total spend in the last 30 days, in cents.
  - `status` 'null' | 'active' | 'frozen' | 'canceled' | 'invited' | 'denied', nullable, required — The card status. `denied` means the issuer declined the cardholder, so the card will never be issued.
  - `type` 'null' | 'virtual' | 'physical', nullable, required — The card type.
  - `user_id` string, nullable, required — Cardholder user ID, prefixed `user_`, when assigned.

## Other responses

- `400` — Invalid Parameters
- `403` — Forbidden
- `404` — Resource not found
- `409` — Conflict

## Changes

> 64 revisions in range; 1 not diffed.

- **2026-09-19** `d629b0d5d839` — 1 info
  - the security scope `payout:account:update` was added to the endpoint's security scheme `bearerAuth`
- **2026-09-18** `355991ab86d5` — 1 info
  - the security scope `payout:account:update` was added to the endpoint's security scheme `bearerAuth`
- **2026-09-17** `076176906e3f` — 1 info
  - the security scope `payout:account:update` was added to the endpoint's security scheme `bearerAuth`
- **2026-09-17** `ef86d14ef691` — 1 info
  - the security scope `payout:account:update` was added to the endpoint's security scheme `bearerAuth`
- **2026-09-16** `ff3a76573563` — 1 info
  - the security scope `payout:account:update` was added to the endpoint's security scheme `bearerAuth`

[Full history](https://skmtc.dev/whop/apis/whop-api/changes/cards/:id/patch.md)

---

[API](https://skmtc.dev/whop/apis/whop-api.md) · [All operations](https://skmtc.dev/whop/apis/whop-api/llms.txt) · [OpenAPI document](https://skmtc.dev/whop/apis/whop-api/revisions/d629b0d5d839?raw)
