Developers · REST API v1

Issue cards from your own code

Create, fund, freeze and close virtual Visa and Mastercard cards over HTTPS. Requests are JSON, authenticated with a secret key, and draw on the same USDT balance you top up with crypto.

Base URLhttps://usdtcryptocard.com/api/v1
Authentication
Bearer sk_live_…
Format
JSON over HTTPS
Endpoints
15
Webhooks
Signed with HMAC-SHA256

Introduction

The API does what the dashboard does, from your server. Every card you issue and every load you make is paid from your account balance, which you fund with crypto deposits and which is always held in USDT.

Amounts are in US dollars with two decimals. Timestamps are ISO 8601 in UTC. List endpoints are paginated with page and per_page.

  1. Create a keyOpen API access in your dashboard and generate a key.
  2. Get it switched onConfirm your email, make a first deposit, then ask support to enable the API.
  3. Make a callCheck your balance with the request on the right, then issue your first card.
First call
Request
curl https://usdtcryptocard.com/api/v1/wallet/balance \
  -H "Authorization: Bearer sk_live_..."
Response200
{
  "balance": 1312.5,
  "currency": "USDT",
  "pending_deposits": 500,
  "cards_active": 8,
  "cards_total_balance": 2450
}

Authentication

Send your secret key as a Bearer token in the Authorization header of every request. Keys start with sk_live_ and are generated in your dashboard, under API access.

Keep the key on your server

Anyone holding the key can move money on your account. Load it from an environment variable and never put it in browser or mobile code.

Before your first request

A new key answers 403 until the account is ready. You get onboarding_incomplete until you confirm your email and make a first deposit, then api_not_enabled until support switches API access on. Write to us and we'll enable it.

Headers
Request
Authorization: Bearer sk_live_your_api_key
Content-Type: application/json
X-Idempotency-Key: 7c1e2f0a-retry-safe

Errors

Anything other than a 2xx comes with a JSON body: a stable error code you can branch on, and a message written for humans.

200
Request succeeded
201
Resource created
400
Invalid request parameters
401
Missing or invalid API key
403
The key is valid, but API access isn't on for this account yet
404
Resource not found
429
Rate limit exceeded
error.json
Response403
{
  "error": "api_not_enabled",
  "message": "Open a support ticket from your dashboard to enable API access."
}

Rate limits

Limits are counted per API key. Go over one and you get a 429: wait a moment and retry with backoff.

Requests / Minute
1,000
Card Creates / Minute
50
Requests / Hour
10,000
Cards

Card Management

Each card has its own balance, limits and lifecycle, so one campaign, client or subscription never touches another.

POST/cards

Issue a new virtual card

Issues a card on the BIN you pick and loads it from your balance in the same call.

Request Body

bin_idstringrequired
BIN identifier (e.g. 491653). Use GET /bins to list available BINs.
amountnumberrequired
Initial load in USD, taken from your balance. Minimum $50; the $1 issuance fee is charged on top.
labelstringoptional
Custom label for the card (max 64 chars)
spending_limitnumberoptional
Monthly spending limit in USD. Defaults to BIN maximum.
allowed_categoriesstring[]optional
Merchant categories the card may be used for, such as advertising or software. Anything else is declined.
auto_freeze_atnumberoptional
Auto-freeze when balance drops below this amount
metadataobjectoptional
Key-value pairs for your internal tracking (max 20 keys)
POST /v1/cards
Request
curl -X POST https://usdtcryptocard.com/api/v1/cards \
  -H "Authorization: Bearer sk_live_..." \
  -H "Content-Type: application/json" \
  -d '{
    "bin_id": "491653",
    "amount": 500,
    "label": "Meta Ads — Campaign 12",
    "spending_limit": 2000,
    "allowed_categories": [
      "advertising"
    ],
    "metadata": {
      "campaign": "fall_2026"
    }
  }'
Response201
{
  "id": "card_8xK2m9Lp4q",
  "bin_id": "491653",
  "network": "visa",
  "last4": "2039",
  "status": "active",
  "balance": 500,
  "spending_limit": 2000,
  "label": "Meta Ads — Campaign 12",
  "allowed_categories": [
    "advertising"
  ],
  "auto_freeze_at": null,
  "metadata": {
    "campaign": "fall_2026"
  },
  "created_at": "2026-09-30T12:00:00Z",
  "expires_at": "2030-10-31"
}
GET/cards

List all cards with filters & pagination

Your cards, newest first.

Query Parameters

statusstringoptional
Filter by statusactivefrozenterminated
bin_idstringoptional
Filter by BIN
pageintegeroptional
Page number. Default: 1
per_pageintegeroptional
Items per page (1-100). Default: 25
GET /v1/cards
Request
curl https://usdtcryptocard.com/api/v1/cards?status=active&per_page=25 \
  -H "Authorization: Bearer sk_live_..."
Response200
{
  "data": [
    {
      "id": "card_8xK2m9Lp4q",
      "bin_id": "491653",
      "network": "visa",
      "last4": "2039",
      "status": "active",
      "balance": 500,
      "spending_limit": 2000,
      "label": "Meta Ads — Campaign 12"
    }
  ],
  "page": 1,
  "per_page": 25,
  "total": 1
}
GET/cards/{card_id}

Get card summary (no sensitive data)

The card without its number or CVV. Use the details endpoint when you need those.

Path parameters

card_idstringrequired
The card's id, as returned when you created it.
GET /v1/cards/{card_id}
Request
curl https://usdtcryptocard.com/api/v1/cards/card_8xK2m9Lp4q \
  -H "Authorization: Bearer sk_live_..."
Response200
{
  "id": "card_8xK2m9Lp4q",
  "bin_id": "491653",
  "network": "visa",
  "last4": "2039",
  "status": "active",
  "balance": 500,
  "spending_limit": 2000,
  "label": "Meta Ads — Campaign 12",
  "created_at": "2026-09-30T12:00:00Z"
}
GET/cards/{card_id}/details

Get full PAN, CVV & expiry

Sensitive Endpoint

Returns full card PAN, CVV, and expiry. PCI-sensitive — never log or store unencrypted. Rate limited to 30 req/min.

Path parameters

card_idstringrequired
The card's id, as returned when you created it.
GET /v1/cards/{card_id}/details
Request
curl https://usdtcryptocard.com/api/v1/cards/card_8xK2m9Lp4q/details \
  -H "Authorization: Bearer sk_live_..."
Response200
{
  "id": "card_8xK2m9Lp4q",
  "pan": "4916530000002039",
  "cvv": "123",
  "exp_month": 10,
  "exp_year": 2030
}
POST/cards/{card_id}/freeze

Temporarily suspend a card

Suspends all transactions. Balance is preserved. Card can be unfrozen later.

Path parameters

card_idstringrequired
The card's id, as returned when you created it.
POST /v1/cards/{card_id}/freeze
Request
curl -X POST https://usdtcryptocard.com/api/v1/cards/card_8xK2m9Lp4q/freeze \
  -H "Authorization: Bearer sk_live_..."
Response200
{
  "id": "card_8xK2m9Lp4q",
  "status": "frozen",
  "balance": 500
}
POST/cards/{card_id}/unfreeze

Re-enable a frozen card

Re-enables transactions on a frozen card. Returns the card object with status: "active".

Path parameters

card_idstringrequired
The card's id, as returned when you created it.
POST /v1/cards/{card_id}/unfreeze
Request
curl -X POST https://usdtcryptocard.com/api/v1/cards/card_8xK2m9Lp4q/unfreeze \
  -H "Authorization: Bearer sk_live_..."
Response200
{
  "id": "card_8xK2m9Lp4q",
  "status": "active",
  "balance": 500
}
DELETE/cards/{card_id}

Permanently terminate a card

Irreversible Action

Terminating a card is permanent. Remaining balance is returned to your wallet instantly.

Path parameters

card_idstringrequired
The card's id, as returned when you created it.
DELETE /v1/cards/{card_id}
Request
curl -X DELETE https://usdtcryptocard.com/api/v1/cards/card_8xK2m9Lp4q \
  -H "Authorization: Bearer sk_live_..."
Response200
{
  "id": "card_8xK2m9Lp4q",
  "status": "terminated",
  "returned_to_wallet": 500
}
Funding

Card Funding

Add or withdraw funds from individual cards. Funds come from your wallet balance.

POST/cards/{card_id}/fund

Add funds to a card

Moves money from your balance onto the card. It's spendable right away.

Path parameters

card_idstringrequired
The card's id, as returned when you created it.

Request Body

amountnumberrequired
Amount in USD to move from your balance onto the card.
POST /v1/cards/{card_id}/fund
Request
curl -X POST https://usdtcryptocard.com/api/v1/cards/card_8xK2m9Lp4q/fund \
  -H "Authorization: Bearer sk_live_..." \
  -H "Content-Type: application/json" \
  -d '{
    "amount": 200
  }'
Response200
{
  "card_id": "card_8xK2m9Lp4q",
  "card_balance": 700,
  "wallet_balance": 612.5
}
POST/cards/{card_id}/withdraw

Withdraw funds back to wallet

Returns updated card and wallet balances.

Path parameters

card_idstringrequired
The card's id, as returned when you created it.
POST /v1/cards/{card_id}/withdraw
Request
curl -X POST https://usdtcryptocard.com/api/v1/cards/card_8xK2m9Lp4q/withdraw \
  -H "Authorization: Bearer sk_live_..."
Response200
{
  "card_id": "card_8xK2m9Lp4q",
  "card_balance": 0,
  "wallet_balance": 1312.5
}
Transactions

Transaction History

View all transactions across your cards. Includes authorizations, settlements, refunds, and declines.

GET/transactions

List all transactions with filters

Authorizations, settlements, refunds and declines across all your cards, newest first.

Query Parameters

card_idstringoptional
Filter by card
typestringoptional
Only return transactions of this type.authorizationsettlementrefunddecline
fromstringoptional
Start date (ISO 8601)
tostringoptional
End date (ISO 8601)
pageintegeroptional
Page number. Default: 1
GET /v1/transactions
Request
curl https://usdtcryptocard.com/api/v1/transactions?card_id=card_8xK2m9Lp4q \
  -H "Authorization: Bearer sk_live_..."
Response200
{
  "data": [
    {
      "id": "txn_3fQ9w1Zk",
      "card_id": "card_8xK2m9Lp4q",
      "type": "settlement",
      "amount": 42.9,
      "currency": "USD",
      "fee": 0.3,
      "merchant": {
        "name": "SPOTIFY",
        "mcc": "4899"
      },
      "created_at": "2026-09-30T14:02:11Z"
    }
  ],
  "page": 1
}
Wallet

Wallet & Deposits

Manage your account wallet. Deposit crypto, check balances, and track incoming deposits.

GET/wallet/balance

Get wallet balance & stats

Your balance, held in USDT, plus what's sitting on your cards.

GET /v1/wallet/balance
Request
curl https://usdtcryptocard.com/api/v1/wallet/balance \
  -H "Authorization: Bearer sk_live_..."
Response200
{
  "balance": 1312.5,
  "currency": "USDT",
  "pending_deposits": 500,
  "cards_active": 8,
  "cards_total_balance": 2450
}
GET/wallet/deposit-address

Get crypto deposit addresses

Where to send crypto. Deposits are converted to USDT once the network confirms them.

Query Parameters

currencystringoptional
Only return the address for this coin. Leave it out to get all of them.btcethsolusdtbnbtrxpolltcavaxarb
GET /v1/wallet/deposit-address
Request
curl https://usdtcryptocard.com/api/v1/wallet/deposit-address?currency=usdt \
  -H "Authorization: Bearer sk_live_..."
Response200
{
  "data": [
    {
      "currency": "usdt",
      "network": "ERC-20 (Ethereum)",
      "address": "0x9c4e…b71a"
    }
  ]
}
BINs

BIN Selection

The 9 BINs you can issue on, with their network and wallet support.

GET/bins

List all available BINs

The BIN catalog, with network, category and Apple Pay / Google Pay support.

GET /v1/bins
Request
curl https://usdtcryptocard.com/api/v1/bins \
  -H "Authorization: Bearer sk_live_..."
Response200
{
  "data": [
    {
      "id": "471938",
      "network": "visa",
      "category": "ads",
      "3ds": true,
      "apple_pay": true,
      "google_pay": true
    },
    {
      "id": "553184",
      "network": "mastercard",
      "category": "ads",
      "3ds": true,
      "apple_pay": true,
      "google_pay": true
    }
  ],
  "total": 9
}
3D Secure

3D Secure Authentication

Retrieve 3DS challenges and OTP codes. All cards are enrolled in 3DS 2.0 automatically.

GET/3ds

List pending 3DS challenges

Pending 3D Secure challenges with their one-time codes, so you can finish a checkout without a phone.

GET /v1/3ds
Request
curl https://usdtcryptocard.com/api/v1/3ds?status=pending \
  -H "Authorization: Bearer sk_live_..."
Response200
{
  "data": [
    {
      "id": "3ds_m4n5o6p7",
      "card_id": "card_8xK2m9Lp4q",
      "merchant": "SPOTIFY",
      "amount": 9.99,
      "otp": "847291",
      "status": "pending",
      "expires_at": "2026-09-30T15:05:00Z"
    }
  ]
}
Webhooks

Webhooks & Events

Receive real-time notifications when events occur. Payloads are signed with HMAC-SHA256.

Available Events

card.created
A new card was issued
card.frozen
A card was frozen
card.unfrozen
A card was unfrozen
card.terminated
A card was terminated
card.funded
Funds added to a card
transaction.authorized
Transaction authorized
transaction.settled
Transaction settled
transaction.declined
Transaction declined
transaction.refunded
Refund processed
3ds.challenge
3DS verification required
deposit.pending
Crypto deposit detected
deposit.confirmed
Crypto deposit confirmed

Signature Verification

Every delivery is signed with HMAC-SHA256 using your endpoint's secret. Recompute the signature over the raw body and compare in constant time before you trust the payload.

verify
Code
# Recompute the signature of a raw payload
echo -n "$RAW_BODY" | openssl dgst -sha256 -hmac "$WEBHOOK_SECRET"
POST/webhooks

Register a webhook endpoint

Registers an HTTPS endpoint and the events it should receive.

Request Body

urlstringrequired
HTTPS endpoint URL to receive events
eventsstring[]required
Event names to subscribe to. Use ["*"] for everything.
secretstringoptional
Custom signing secret. Auto-generated if omitted.
POST /v1/webhooks
Request
curl -X POST https://usdtcryptocard.com/api/v1/webhooks \
  -H "Authorization: Bearer sk_live_..." \
  -H "Content-Type: application/json" \
  -d '{
    "url": "https://example.com/hooks/cards",
    "events": [
      "transaction.authorized",
      "3ds.challenge"
    ]
  }'
Response201
{
  "id": "wh_5tLr8QaZ",
  "url": "https://example.com/hooks/cards",
  "events": [
    "transaction.authorized",
    "3ds.challenge"
  ],
  "secret": "whsec_…",
  "created_at": "2026-09-30T12:00:00Z"
}
Virtual Card Issuing API Reference | USDT Crypto Card