openapi: 3.0.3 info: title: Moov Accounts Card Issuing API description: The Moov API lets software platforms accept, store, send, and spend money through a single REST API. It is organized around Moov accounts, funding sources (bank accounts, cards, wallets, payment methods), and money movement (transfers, refunds, disputes, sweeps, card issuing). The API is based on REST principles, returns JSON, and uses standard HTTP response codes. Requests are authenticated with an OAuth 2.0 access token (Bearer). Event notifications are delivered via webhooks (HTTPS POST with an HMAC SHA-512 signature); Moov does not expose a public WebSocket API. This document models a representative subset of the commercial hosted API at api.moov.io - the canonical, machine-generated OpenAPI spec is published by Moov (see externalDocs). Separately, Moov maintains open-source Go libraries for banking file formats at github.com/moov-io, which are not part of this API. version: v2026.04.00 contact: name: Moov url: https://moov.io termsOfService: https://moov.io/legal/platform-agreement/ servers: - url: https://api.moov.io description: Moov production security: - bearerAuth: [] tags: - name: Card Issuing description: Virtual spending cards, authorizations, and card transactions. paths: /issuing/{accountID}/cards: parameters: - $ref: '#/components/parameters/accountID' post: operationId: createIssuedCard tags: - Card Issuing summary: Create a spending card. responses: '200': description: The created spending card. get: operationId: listIssuedCards tags: - Card Issuing summary: List spending cards. responses: '200': description: A list of spending cards. /issuing/{accountID}/cards/{issuedCardID}: parameters: - $ref: '#/components/parameters/accountID' - $ref: '#/components/parameters/issuedCardID' get: operationId: getIssuedCard tags: - Card Issuing summary: Retrieve a spending card. responses: '200': description: The spending card. patch: operationId: updateIssuedCard tags: - Card Issuing summary: Update a spending card. responses: '200': description: The updated spending card. /issuing/{accountID}/cards/{issuedCardID}/details: parameters: - $ref: '#/components/parameters/accountID' - $ref: '#/components/parameters/issuedCardID' get: operationId: getIssuedCardDetails tags: - Card Issuing summary: Get PCI details for a spending card. responses: '200': description: The full PCI card details. /issuing/{accountID}/authorizations: parameters: - $ref: '#/components/parameters/accountID' get: operationId: listAuthorizations tags: - Card Issuing summary: List authorizations. responses: '200': description: A list of authorizations. /issuing/{accountID}/authorizations/{authorizationID}: parameters: - $ref: '#/components/parameters/accountID' - name: authorizationID in: path required: true schema: type: string get: operationId: getAuthorization tags: - Card Issuing summary: Retrieve an authorization. responses: '200': description: The authorization. /issuing/{accountID}/authorizations/{authorizationID}/events: parameters: - $ref: '#/components/parameters/accountID' - name: authorizationID in: path required: true schema: type: string get: operationId: listAuthorizationEvents tags: - Card Issuing summary: List authorization events. responses: '200': description: A list of authorization events. /issuing/{accountID}/card-transactions: parameters: - $ref: '#/components/parameters/accountID' get: operationId: listCardTransactions tags: - Card Issuing summary: List card transactions. responses: '200': description: A list of card transactions. /issuing/{accountID}/card-transactions/{cardTransactionID}: parameters: - $ref: '#/components/parameters/accountID' - name: cardTransactionID in: path required: true schema: type: string get: operationId: getCardTransaction tags: - Card Issuing summary: Retrieve a card transaction. responses: '200': description: The card transaction. components: parameters: accountID: name: accountID in: path required: true schema: type: string format: uuid description: The Moov account identifier. issuedCardID: name: issuedCardID in: path required: true schema: type: string format: uuid securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: JWT description: OAuth 2.0 access token passed as a Bearer token. externalDocs: description: Moov API reference and canonical OpenAPI spec url: https://docs.moov.io/api/