> ## Documentation Index
> Fetch the complete documentation index at: https://docs.incard.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Issue virtual card

> Issues a virtual card to the member who owns the API key. The card is `active` immediately.
Retrying with the same `Idempotency-Key` returns the original card. Requires permission `issue_cards`.




## OpenAPI

````yaml /specs/company.openapi.yaml post /developer/cards/virtual
openapi: 3.1.0
info:
  title: Incard Developer API
  version: 0.1.0
  description: OpenAPI definition for the Incard Developer API.
servers:
  - url: https://api.incard.com
    description: Developer Gateway
security:
  - BearerAuth: []
tags:
  - name: ACCOUNTS
    description: Currency accounts and their available balances.
  - name: TRANSACTIONS
    description: Transaction history with filters, pagination, and running balances.
  - name: CARDS
    description: Issue, list, freeze, replace, and set spending limits on cards.
  - name: INVOICES
  - name: webhooks
paths:
  /developer/cards/virtual:
    post:
      tags:
        - CARDS
      summary: Issue virtual card
      description: >
        Issues a virtual card to the member who owns the API key. The card is
        `active` immediately.

        Retrying with the same `Idempotency-Key` returns the original card.
        Requires permission `issue_cards`.
      operationId: create_virtual_card
      parameters:
        - $ref: '#/components/parameters/IdempotencyKey'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - account_id
                - design_id
              properties:
                account_id:
                  type: string
                  format: uuid
                  description: Account the card spends from.
                design_id:
                  type: string
                  format: uuid
                  description: >-
                    Virtual card design. See the Cards guide for the list of
                    designs.
                name:
                  type: string
                  description: Card name. Defaults to `Virtual <last four>`.
                auto_convert:
                  type: boolean
                spending_limit:
                  $ref: '#/components/schemas/SpendingLimitInput'
            example:
              account_id: 0d6c0a2a-2b08-49bc-89a9-eb936c9ff28c
              design_id: c6d5ea1a-80f8-49ab-9fee-250d368b3915
              name: Marketing spend
              spending_limit:
                period: monthly
                amount: '5000.00'
      responses:
        '201':
          $ref: '#/components/responses/CardCreated'
        '400':
          $ref: '#/components/responses/CardBadRequest'
        '401':
          description: Unauthorized
        '403':
          $ref: '#/components/responses/CardForbidden'
        '404':
          $ref: '#/components/responses/CardAccountNotFound'
        '409':
          $ref: '#/components/responses/CardConflict'
        '422':
          $ref: '#/components/responses/CardNotIssuable'
        '502':
          $ref: '#/components/responses/CardIssuerUnavailable'
        '503':
          $ref: '#/components/responses/CardIssuerUnavailable'
components:
  parameters:
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      required: true
      description: >-
        A UUID you generate per order. Retrying with the same key returns the
        original result.
      schema:
        type: string
        format: uuid
  schemas:
    SpendingLimitInput:
      type: object
      title: SpendingLimitInput
      description: >
        Periods follow the UK calendar; weeks start on Monday. `amount` must be
        more than 0 and have at most two decimal places.

        A `daily` limit can be at most `card_limits.daily.amount`, and a
        `weekly` or `monthly` limit at most

        `card_limits.rolling_32_days.amount`, compared as-is without converting
        from EUR. `lifetime` limits have no cap.
      properties:
        period:
          type: string
          enum:
            - daily
            - weekly
            - monthly
            - lifetime
        amount:
          type: string
          description: >-
            Decimal amount in the card's account currency. A JSON number is also
            accepted.
      required:
        - period
        - amount
    Card:
      type: object
      title: Card
      description: A company card. Card numbers, CVVs, and PINs are never returned.
      properties:
        id:
          type: string
          format: uuid
        token:
          type: string
          description: Card token, a string of digits. Usable in the `tokens` list filter.
        company_id:
          type: string
          format: uuid
        account_id:
          type: string
          format: uuid
          description: Account the card spends from.
        user_id:
          type: string
          format: uuid
          description: Cardholder.
        type:
          type: string
          enum:
            - virtual
            - physical
        design_id:
          type: string
          format: uuid
        status:
          type: string
          enum:
            - inactive
            - active
            - frozen
            - suspended
            - locked
            - blocked
            - expired
            - terminated
          description: >
            `inactive` cards are issued but not yet activated. `suspended`,
            `locked`, and `blocked` are set by Incard.

            `expired` and `terminated` cards have ended.
        name:
          type: string
        last_four:
          type: string
        expiry_date:
          type: string
          format: date
        auto_convert:
          type: boolean
        three_ds_biometric:
          type: boolean
        spending_limit:
          oneOf:
            - $ref: '#/components/schemas/CardSpendingLimit'
            - type: 'null'
          description: The card's spending limit, or `null` for none.
        card_limits:
          $ref: '#/components/schemas/CardLimits'
        created_at:
          type: string
          format: date-time
      required:
        - id
        - token
        - company_id
        - account_id
        - user_id
        - type
        - design_id
        - status
        - name
        - last_four
        - expiry_date
        - auto_convert
        - three_ds_biometric
        - spending_limit
        - card_limits
        - created_at
    CardError:
      type: object
      title: CardError
      properties:
        error:
          type: string
      required:
        - error
    CardSpendingLimit:
      type: object
      title: CardSpendingLimit
      properties:
        period:
          type: string
          enum:
            - daily
            - weekly
            - monthly
            - lifetime
        amount:
          type: string
          description: Decimal amount with two places.
        currency:
          type: string
          description: The card's account currency.
        used:
          type: string
          description: >-
            Spent in the current period. Omitted if it can't be read, or if the
            card has ended.
      required:
        - period
        - amount
        - currency
    CardLimits:
      type: object
      title: CardLimits
      description: >-
        Fixed limits on the card, in EUR. `used` is only included in list
        responses.
      properties:
        currency:
          type: string
          example: EUR
        max_per_purchase:
          $ref: '#/components/schemas/CardLimit'
        daily:
          $ref: '#/components/schemas/CardLimit'
        rolling_32_days:
          $ref: '#/components/schemas/CardLimit'
    CardLimit:
      type: object
      title: CardLimit
      properties:
        amount:
          type: string
        used:
          type: string
  responses:
    CardCreated:
      description: The new card.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Card'
          example:
            id: 3f8b2c1d-9e4a-4b7c-8d2e-1f3a5b7c9d0e
            token: '104857321'
            company_id: bebb185d-8210-4e66-ac63-397b49a1e09f
            account_id: 0d6c0a2a-2b08-49bc-89a9-eb936c9ff28c
            user_id: 29b297ca-c617-437e-9c1d-32f494fbf44d
            type: virtual
            design_id: c6d5ea1a-80f8-49ab-9fee-250d368b3915
            status: active
            name: Marketing spend
            last_four: '4242'
            expiry_date: '2029-07-31'
            auto_convert: false
            three_ds_biometric: false
            spending_limit:
              period: monthly
              amount: '5000.00'
              currency: GBP
              used: '0.00'
            card_limits:
              currency: EUR
              max_per_purchase:
                amount: '250000.00'
              daily:
                amount: '500000.00'
              rolling_32_days:
                amount: '2500000.00'
            created_at: '2026-10-07T09:12:44Z'
    CardBadRequest:
      description: Invalid request.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/CardError'
          example:
            error: 'invalid spending limit: amount has more than 2 decimal places'
    CardForbidden:
      description: The member lacks the required permission.
      content:
        application/json:
          schema:
            type: object
            properties:
              success:
                type: boolean
              error:
                type: object
                properties:
                  code:
                    type: string
                  message:
                    type: string
          example:
            success: false
            error:
              code: forbidden
              message: access denied
    CardAccountNotFound:
      description: Account not found in this company.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/CardError'
          example:
            error: account not found
    CardConflict:
      description: >-
        The card can't make this change in its current state, or another change
        to it is in progress.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/CardError'
          example:
            error: card is being changed; try again
    CardNotIssuable:
      description: >
        The card can't be issued (card quota reached, company not active,
        account closed, missing company or cardholder

        details, or an undeliverable country), or the card issuer rejected the
        request.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/CardError'
          example:
            error: >-
              card quota reached: the company holds 30 live cards and its quota
              is 30; contact support to raise it
    CardIssuerUnavailable:
      description: The card issuer is unavailable. Retry later.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/CardError'
          example:
            error: card issuer unavailable
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: access_token
      description: Short-lived access token. Obtain with your api_key.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.