Update Card
curl --request PUT \
--url https://api.sandbox.sudo.cards/cards/{id} \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"status": "active",
"fundingSourceId": "<string>",
"metadata": "<string>",
"spendingControls": {
"allowedCategories": [],
"blockedCategories": [],
"channels": {
"atm": true,
"pos": true,
"web": true,
"mobile": true
},
"spendingLimits": [
{
"amount": 123,
"interval": "daily"
}
]
},
"creditAccountId": "<string>"
}
'import requests
url = "https://api.sandbox.sudo.cards/cards/{id}"
payload = {
"status": "active",
"fundingSourceId": "<string>",
"metadata": "<string>",
"spendingControls": {
"allowedCategories": [],
"blockedCategories": [],
"channels": {
"atm": True,
"pos": True,
"web": True,
"mobile": True
},
"spendingLimits": [
{
"amount": 123,
"interval": "daily"
}
]
},
"creditAccountId": "<string>"
}
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
status: 'active',
fundingSourceId: '<string>',
metadata: '<string>',
spendingControls: {
allowedCategories: [],
blockedCategories: [],
channels: {atm: true, pos: true, web: true, mobile: true},
spendingLimits: [{amount: 123, interval: 'daily'}]
},
creditAccountId: '<string>'
})
};
fetch('https://api.sandbox.sudo.cards/cards/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.sudo.cards/cards/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'status' => 'active',
'fundingSourceId' => '<string>',
'metadata' => '<string>',
'spendingControls' => [
'allowedCategories' => [
],
'blockedCategories' => [
],
'channels' => [
'atm' => true,
'pos' => true,
'web' => true,
'mobile' => true
],
'spendingLimits' => [
[
'amount' => 123,
'interval' => 'daily'
]
]
],
'creditAccountId' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.sandbox.sudo.cards/cards/{id}"
payload := strings.NewReader("{\n \"status\": \"active\",\n \"fundingSourceId\": \"<string>\",\n \"metadata\": \"<string>\",\n \"spendingControls\": {\n \"allowedCategories\": [],\n \"blockedCategories\": [],\n \"channels\": {\n \"atm\": true,\n \"pos\": true,\n \"web\": true,\n \"mobile\": true\n },\n \"spendingLimits\": [\n {\n \"amount\": 123,\n \"interval\": \"daily\"\n }\n ]\n },\n \"creditAccountId\": \"<string>\"\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://api.sandbox.sudo.cards/cards/{id}")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"status\": \"active\",\n \"fundingSourceId\": \"<string>\",\n \"metadata\": \"<string>\",\n \"spendingControls\": {\n \"allowedCategories\": [],\n \"blockedCategories\": [],\n \"channels\": {\n \"atm\": true,\n \"pos\": true,\n \"web\": true,\n \"mobile\": true\n },\n \"spendingLimits\": [\n {\n \"amount\": 123,\n \"interval\": \"daily\"\n }\n ]\n },\n \"creditAccountId\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.sandbox.sudo.cards/cards/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"status\": \"active\",\n \"fundingSourceId\": \"<string>\",\n \"metadata\": \"<string>\",\n \"spendingControls\": {\n \"allowedCategories\": [],\n \"blockedCategories\": [],\n \"channels\": {\n \"atm\": true,\n \"pos\": true,\n \"web\": true,\n \"mobile\": true\n },\n \"spendingLimits\": [\n {\n \"amount\": 123,\n \"interval\": \"daily\"\n }\n ]\n },\n \"creditAccountId\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"statusCode": 200,
"message": "Card updated successfully.",
"data": {
"business": "670cec9d25852ba485d74273",
"customer": "64a1b2c3d4e5f6a7b8c9d0e1",
"account": "67974b365c184d20fc340889",
"fundingSource": "670cec9d25852ba485d74286",
"type": "virtual",
"brand": "Verve",
"currency": "NGN",
"maskedPan": "506110******1234",
"expiryMonth": "09",
"expiryYear": "2028",
"metadata": {
"createdBy": "api",
"purpose": "general"
},
"status": "inactive",
"spendingControls": {
"channels": {
"atm": true,
"pos": true,
"web": true,
"mobile": true,
"_id": "6840b5161443c90831ba07b1"
},
"allowedCategories": [],
"blockedCategories": [],
"spendingLimits": [
{
"amount": 1500000,
"interval": "daily",
"categories": [],
"_id": "6840b5161443c90831ba07b2"
}
],
"_id": "6840b5161443c90831ba07b0"
},
"is2FAEnrolled": false,
"isDefaultPINChanged": false,
"disposable": false,
"refundAccount": null,
"isDeleted": false,
"createdAt": "2025-06-04T21:05:26.115Z",
"updatedAt": "2025-06-05T09:15:00.000Z",
"_id": "6418eb71a37e405064694518",
"__v": 0
}
}{
"statusCode": 400,
"message": "\"status\" must be one of [active, inactive, canceled]",
"data": null
}{
"statusCode": 401,
"message": "Unauthorized. Provide a valid API key in the Authorization header.",
"data": null
}{
"statusCode": 404,
"message": "Card not found.",
"data": null
}Cards
Update Card
Update details for a specific card.
PUT
/
cards
/
{id}
Update Card
curl --request PUT \
--url https://api.sandbox.sudo.cards/cards/{id} \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"status": "active",
"fundingSourceId": "<string>",
"metadata": "<string>",
"spendingControls": {
"allowedCategories": [],
"blockedCategories": [],
"channels": {
"atm": true,
"pos": true,
"web": true,
"mobile": true
},
"spendingLimits": [
{
"amount": 123,
"interval": "daily"
}
]
},
"creditAccountId": "<string>"
}
'import requests
url = "https://api.sandbox.sudo.cards/cards/{id}"
payload = {
"status": "active",
"fundingSourceId": "<string>",
"metadata": "<string>",
"spendingControls": {
"allowedCategories": [],
"blockedCategories": [],
"channels": {
"atm": True,
"pos": True,
"web": True,
"mobile": True
},
"spendingLimits": [
{
"amount": 123,
"interval": "daily"
}
]
},
"creditAccountId": "<string>"
}
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
status: 'active',
fundingSourceId: '<string>',
metadata: '<string>',
spendingControls: {
allowedCategories: [],
blockedCategories: [],
channels: {atm: true, pos: true, web: true, mobile: true},
spendingLimits: [{amount: 123, interval: 'daily'}]
},
creditAccountId: '<string>'
})
};
fetch('https://api.sandbox.sudo.cards/cards/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sandbox.sudo.cards/cards/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'status' => 'active',
'fundingSourceId' => '<string>',
'metadata' => '<string>',
'spendingControls' => [
'allowedCategories' => [
],
'blockedCategories' => [
],
'channels' => [
'atm' => true,
'pos' => true,
'web' => true,
'mobile' => true
],
'spendingLimits' => [
[
'amount' => 123,
'interval' => 'daily'
]
]
],
'creditAccountId' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.sandbox.sudo.cards/cards/{id}"
payload := strings.NewReader("{\n \"status\": \"active\",\n \"fundingSourceId\": \"<string>\",\n \"metadata\": \"<string>\",\n \"spendingControls\": {\n \"allowedCategories\": [],\n \"blockedCategories\": [],\n \"channels\": {\n \"atm\": true,\n \"pos\": true,\n \"web\": true,\n \"mobile\": true\n },\n \"spendingLimits\": [\n {\n \"amount\": 123,\n \"interval\": \"daily\"\n }\n ]\n },\n \"creditAccountId\": \"<string>\"\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://api.sandbox.sudo.cards/cards/{id}")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"status\": \"active\",\n \"fundingSourceId\": \"<string>\",\n \"metadata\": \"<string>\",\n \"spendingControls\": {\n \"allowedCategories\": [],\n \"blockedCategories\": [],\n \"channels\": {\n \"atm\": true,\n \"pos\": true,\n \"web\": true,\n \"mobile\": true\n },\n \"spendingLimits\": [\n {\n \"amount\": 123,\n \"interval\": \"daily\"\n }\n ]\n },\n \"creditAccountId\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.sandbox.sudo.cards/cards/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"status\": \"active\",\n \"fundingSourceId\": \"<string>\",\n \"metadata\": \"<string>\",\n \"spendingControls\": {\n \"allowedCategories\": [],\n \"blockedCategories\": [],\n \"channels\": {\n \"atm\": true,\n \"pos\": true,\n \"web\": true,\n \"mobile\": true\n },\n \"spendingLimits\": [\n {\n \"amount\": 123,\n \"interval\": \"daily\"\n }\n ]\n },\n \"creditAccountId\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"statusCode": 200,
"message": "Card updated successfully.",
"data": {
"business": "670cec9d25852ba485d74273",
"customer": "64a1b2c3d4e5f6a7b8c9d0e1",
"account": "67974b365c184d20fc340889",
"fundingSource": "670cec9d25852ba485d74286",
"type": "virtual",
"brand": "Verve",
"currency": "NGN",
"maskedPan": "506110******1234",
"expiryMonth": "09",
"expiryYear": "2028",
"metadata": {
"createdBy": "api",
"purpose": "general"
},
"status": "inactive",
"spendingControls": {
"channels": {
"atm": true,
"pos": true,
"web": true,
"mobile": true,
"_id": "6840b5161443c90831ba07b1"
},
"allowedCategories": [],
"blockedCategories": [],
"spendingLimits": [
{
"amount": 1500000,
"interval": "daily",
"categories": [],
"_id": "6840b5161443c90831ba07b2"
}
],
"_id": "6840b5161443c90831ba07b0"
},
"is2FAEnrolled": false,
"isDefaultPINChanged": false,
"disposable": false,
"refundAccount": null,
"isDeleted": false,
"createdAt": "2025-06-04T21:05:26.115Z",
"updatedAt": "2025-06-05T09:15:00.000Z",
"_id": "6418eb71a37e405064694518",
"__v": 0
}
}{
"statusCode": 400,
"message": "\"status\" must be one of [active, inactive, canceled]",
"data": null
}{
"statusCode": 401,
"message": "Unauthorized. Provide a valid API key in the Authorization header.",
"data": null
}{
"statusCode": 404,
"message": "Card not found.",
"data": null
}Authorizations
Path Parameters
The _id of the card to update.
Body
application/json
The card status.
Available options:
active, inactive, canceled The funding source _id. Required if you wish to map card to an existing funding source.
The metadata object to attach to the card. Stored in key-value pair
Card spending controls. Default usage limits will be applied if non is provided.
Show child attributes
Show child attributes
Required if status is set to canceled
Available options:
lost, stolen The credit account _id. Required for canceled status only.
⌘I
