> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.americanexpress.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.americanexpress.ferndocs.com/_mcp/server.

# Create a Card

POST https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/cards
Content-Type: application/json

An on-demand Card is generated from the funding Account enrolled in Card on-demand. A Card can be used by the Account owner of the funding Account, by a Card User, or sent to a supplier for a business payment. Each Card has an expiration date that is automatically set for five years from the date the Card is created. This expiration date is different from the validToDate that is defined in the spendControls object of a Card.

Reference: https://developer.americanexpress.ferndocs.com/payment-services/card-on-demand/api-reference/create-new-card

## Authentication

- `Authorization` header (bearer token, required) — OAuth 2.0 client credentials. Exchange your API key and secret for a bearer token, then send it as `Authorization: Bearer <token>`.

## Servers

- `https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand` (Sandbox, default)
- `https://api.americanexpress.com/commercial/v1/card_on_demand` (Production)

## Request

### Body (application/json)

This endpoint expects an object.

- `accountId` (string, required) — The ID of the Account being used to fund the Card.
- `spendControls` (spendControls, required) — The Spend Control object determines how, when, and where on-demand cards can be authorized. If OPTIONAL fields are unpopulated in a POST /cards call, their value will be defaulted to those defined during the initial configuration set up.
- `cardDetails` (cardDetailsCreate, required) — The details of the Card being created.
- `deliveryMethod` (enum, required) — The method of delivery that is used for the response.
  - Allowed values: `API_RESPONSE`
- `userDetails` (userDetails, required) — This object is for the details of the user who is logged into your app when the request for creating an on-demand Card is made. This information will support customer service and fraud mitigation by American Express.
- `cardUserId` (string, optional) — The ID of the Card User associated with the Card. The Card User must be in an ACTIVATED status.
- `reloadable` (boolean, optional) — Indicates whether the Card can be reloaded with a new Spend Control object after the original Spend Control either expires or is fully utilized.
- `reconciliationField` (reconciliationField, optional) — The information collected for reconciliation.

## Response

### 200

Successful operation

- `cardId` (string, required) — A unique ID that is created for the Card.
- `status` (enum, required) — The status of the Card. For all Card creation requests, this will always be IN_PROGRESS.
  - Allowed values: `IN_PROGRESS`
- `card` (CardsPostResponsesContentApplicationJsonSchemaCard, required) — The Card request being returned.

## Errors

### 400 Bad Request Error

Bad Request

- `errors` (list of 400ErrorItems, required)

### 401 Unauthorized Error

Unauthorized

- `errorCode` (string, required) — A machine-readable field indicating the type of error.
- `errorDescription` (string, optional) — Provides a short description of the error.

### 403 Forbidden Error

Unauthenticated

- `errorCode` (string, required) — A machine-readable field indicating the type of error.
- `errorDescription` (string, optional) — Provides a short description of the error.

### 404 Not Found Error

Resource not found

- `errorCode` (string, required) — A machine-readable field indicating the type of error.
- `errorDescription` (string, optional) — Provides a short description of the error.

### 500 Internal Server Error

Service error

- `errorCode` (string, required) — A machine-readable field indicating the type of error.
- `errorDescription` (string, optional) — Provides a short description of the error.

### 503 Service Unavailable Error

Service unavailable

- `errorCode` (string, required) — A machine-readable field indicating the type of error.
- `errorDescription` (string, optional) — Provides a short description of the error.

## Types

### spendControls

The Spend Control object determines how, when, and where on-demand cards can be authorized. If OPTIONAL fields are unpopulated in a POST /cards call, their value will be defaulted to those defined during the initial configuration set up.

- `currentAmount` (string, required) — The amount allocated to the Card. The amount must be a positive number, with a maximum length of eight, and an additional two decimal places if needed. The minimum amount is 1.00. The maximum amount is 99999999.99. This value is determine by the authorizationAmount.
- `validFromDate` (string, required) — The beginning date from when the Spend Control is valid. The time zone will be based on the time zone set up on the accountId (or set explicitly during the Card request). The format is: YYYY-MM-DD. This date cannot be in the past.
- `validToDate` (string, required) — The end date, after which the Spend Control is no longer valid. The time zone will be based on the time zone set up on the accountId (or set explicitly during the Card request). The format is: YYYY-MM-DD. The validToDate, along with the validFromDate, sets the validity period for the Card, and is different from the Card expiration date.
- `spendType` (enum, optional) — Determines whether a Card can be used a single time, or multiple times.
  - Allowed values: `SINGLE_USE`, `MULTI_USE`
- `timeZone` (enum, optional) — Please find the International Organization for Standardization (ISO) time zones in the [ISO Timezones Guide](iso-timezones.pdf). The column to reference is 'Time zone abbreviation - STD'. The currently supported timezones are: AEST, PST, EST, MST, GST, AST, GMT, CET.
  - Allowed values: `AEST`, `PST`, `EST`, `MST`, `GST`, `AST`, `GMT`, `CET`
- `allowedMerchantIndustries` (list of string, optional) — The codes specifying the types of Merchants for which the Card can be used, as selected from the list of Merchant's Category Codes (MCC). The maximum number of MCCs that can be used is 25 per Card.
- `allowedMerchant` (list of string, optional) — The codes specifying the Merchants for which the Card can be used. The codes representing each Merchant are known as Service Establishments (SEs).
- `chargeAmountVariance` (SpendControlsChargeAmountVariance, optional)

### cardDetailsCreate

The details of the Card being created.

- `formFactor` (enum, required) — Indicates the form of the Card provided, whether it is PLASTIC, VIRTUAL or BOTH. Only VIRTUAL is currently supported. PLASTIC is coming soon.
  - Allowed values: `PLASTIC`, `VIRTUAL`, `BOTH`
- `cardReferenceId` (string, required) — A unique ID that can be assigned by the Buyer resource to each of the Cards requested. For instance, some Buyers use invoice numbers or employee codes to help match Cards within their systems. This field only accepts alphanumeric characters and hyphens.
- `digitalWalletProvisionable` (boolean, optional) — This field captures the User's preference for whether the Card can be added to a digital wallet. This field is required when a Partner has signed up for the mobile wallet provisioning and the Card is being created for a Card User. If one or both of these conditions are not met, the field must be NULL.

### userDetails

This object is for the details of the user who is logged into your app when the request for creating an on-demand Card is made. This information will support customer service and fraud mitigation by American Express.

- `userId` (string, required) — The username or User ID of the logged-in user who made the request for a new on-demand Card.
- `name` (UserDetailsName, required) — The name of the user.
- `email` (string, required) — The email address of the logged-in user who made the request for a new on-demand Card.
- `phone` (UserDetailsPhone, required) — The phone contact of the logged-in user who made the request for a new on-demand Card.
- `ipAddress` (string, required) — The IP address of the logged-in User's machine from which the request for modifying an on-demand Card was made. The address must be in an IPv4 or IPv6 standard format.
- `deviceId` (string, required) — The device ID of the logged-in user's machine from which the request for creating an on-demand Card was made.
- `sessionId` (string, required) — The session ID of the session on the user's machine during which the request for creating an on-demand Card was made.
- `userAgent` (UserDetailsUserAgent, optional) — This object is for the details of the client application from which the request for a new on-demand Card was made.

### reconciliationField

The information collected for reconciliation.

- `userDefinedFields` (list of ReconciliationFieldUserDefinedFieldsItems, optional) — The reference values which the buyer wants to pass as part of the payment. The buyer can send any reference information about the payment as part of this block. These values can be optionally included in the reconciliation file. The maximum allowed fields are 12.
- `accountingFields` (list of ReconciliationFieldAccountingFieldsItems, optional) — The fields that allow the Card requester to pass data that can be used during reconciliation to identify the purpose of the Card. Examples are Project ID, Employee number, or cost center. The Card is tagged with the data entered here for its life cycle. The maximum allowed fields are eight.

### CardsPostResponsesContentApplicationJsonSchemaCard

The Card request being returned.

- `accountId` (string, required) — The ID of the Account being used to fund the Card.
- `spendControls` (spendControls, required) — The Spend Control object determines how, when, and where on-demand cards can be authorized. If OPTIONAL fields are unpopulated in a POST /cards call, their value will be defaulted to those defined during the initial configuration set up.
- `cardDetails` (cardDetailsCreate, required) — The details of the Card being created.
- `deliveryMethod` (enum, required) — The method of delivery that is used for the response.
  - Allowed values: `API_RESPONSE`
- `userDetails` (CardsPostResponsesContentApplicationJsonSchemaCardUserDetails, required) — This object is for the details of the user who is logged into your app when the request for creating an on-demand Card is made. This information will support customer service and fraud mitigation by American Express.
- `cardUserId` (string, optional) — The ID of the Card User associated with the Card.
- `reloadable` (boolean, optional) — Indicates whether the Card can be reloaded with a new Spend Control object after the original Spend Control either expires or is fully utilized.
- `reconciliationField` (reconciliationField, optional) — The information collected for reconciliation.

### 400ErrorItems

- `code` (string, required) — A machine-readable field indicating the type of error.
- `message` (string, required) — Provides a short description of the error.
- `detail` (string, optional) — Provides a detailed description of the error.
- `link` (string, optional) — The link to documentation that explains the error.

### SpendControlsChargeAmountVariance

- `varianceType` (enum, optional) — The Variance Type can be either a percentage or a dollar amount. This field is applied in conjunction with the varianceLowerBound and varianceUpperBound fields.
  - Allowed values: `PERCENTAGE`, `AMOUNT`
- `varianceLowerBound` (string, optional) — The amount lower than the Card balance that the Card can be charged for below which it will be rejected by American Express. The maximum value of this field is dependent on the varianceType field. If the varianceType is PERCENTAGE, the maximum value is 100. If the varianceType is AMOUNT, then the amount must be zero or greater, with a maximum length of eight, and an additional two decimal places if needed, with a minimum amount of 0.00 and a maximum amount of 99999999.99.
- `varianceUpperBound` (string, optional) — The amount greater than the remaining Card balance that the Card can be charged for above which the transactions will not be authorized by American Express. The maximum value of this field is dependent on the varianceType field. If the varianceType is PERCENTAGE, the maximum value is 100. If the varianceType is AMOUNT, then the amount must be zero or greater, with a maximum length of eight, and an additional two decimal places if needed, with a minimum amount of 0.00 and a maximum amount of 99999999.99.
- `minimumAuthorizationAmount` (string, optional) — This defines the minimum amount the Card can be charged without affecting the Card amount currently on the Card. Any authorization amount less than or equal to this threshold would be approved, but it is not deducted from the preset Card amount. The amount must be zero or greater, with a maximum length of eight, and an additional two decimal places if needed, with a minimum amount of 0.00 and a maximum amount of 99999999.99.
- `autoExpirePercent` (string, optional) — The percentage remaining of the Card's original balance, after which the Card will automatically be closed. When the Card reaches the percentage specified, it will not be able to be used for further transactions.
- `autoExpireAmount` (string, optional) — The amount remaining on the Card, after which the Card will automatically be closed. When the Card reaches the specified amount remaining, it will not be able to be used for further transactions. The amount must be zero or greater, with a maximum length of eight, and an additional two decimal places if needed, with a minimum amount of 0.00 and a maximum amount of 99999999.99.

### UserDetailsName

The name of the user.

- `first` (string, required) — The first name of the user.
- `last` (string, required) — The last name of the user.
- `prefix` (string, optional) — The prefix.
- `middle` (string, optional) — The middle name or initial of the user.

### UserDetailsPhone

The phone contact of the logged-in user who made the request for a new on-demand Card.

- `number` (string, required) — The phone number of the user. Only numeric values are accepted.
- `extension` (string, required) — The extension of the phone number. Only numeric values are accepted.
- `type` (enum, required) — The type of phone.
  - Allowed values: `WORK`, `MOBILE`, `HOME`

### UserDetailsUserAgent

This object is for the details of the client application from which the request for a new on-demand Card was made.

- `webActionPath` (string, optional) — The full web path from which the request for creating an on-demand Card was made.
- `browserType` (string, optional) — The browser type from which the request for creating an on-demand Card was made. e.g., Google Chrome
- `browserVersion` (string, optional) — The version of the browser from which the request for creating an on-demand Card was made. e.g., 112.0.5615.49, 2023-04-05

### ReconciliationFieldUserDefinedFieldsItems

- `index` (string, required) — Specifies the index of the User-defined Field.
- `value` (string, required) — Specifies the value of the User-defined Field. If a value is provided, an index becomes required.

### ReconciliationFieldAccountingFieldsItems

- `index` (string, required) — Specifies the index of the User-defined Field.
- `value` (string, required) — Specifies the value of the User-defined Field. If a value is provided, an index becomes required.

### CardsPostResponsesContentApplicationJsonSchemaCardUserDetails

This object is for the details of the user who is logged into your app when the request for creating an on-demand Card is made. This information will support customer service and fraud mitigation by American Express.

- `userId` (string, required) — The username or User ID of the logged-in user who made the request for a new on-demand Card.
- `name` (CardsPostResponsesContentApplicationJsonSchemaCardUserDetailsName, required) — The name of the user.
- `email` (string, required) — The email address of the logged-in user who made the request for a new on-demand Card.
- `phone` (CardsPostResponsesContentApplicationJsonSchemaCardUserDetailsPhone, required) — The phone contact of the logged-in user who made the request for a new on-demand Card.
- `ipAddress` (string, required) — The IP address of the logged-in User's machine from which the request for modifying an on-demand Card was made. The address must be in an IPv4 or IPv6 standard format.
- `deviceId` (string, required) — The device ID of the logged-in user's machine from which the request for creating an on-demand Card was made.
- `sessionId` (string, required) — The session ID of the session on the user's machine during which the request for creating an on-demand Card was made.
- `userAgent` (CardsPostResponsesContentApplicationJsonSchemaCardUserDetailsUserAgent, optional) — This object is for the details of the client application from which the request for a new on-demand Card was made.

### CardsPostResponsesContentApplicationJsonSchemaCardUserDetailsName

The name of the user.

- `first` (string, required) — The first name of the user.
- `last` (string, required) — The last name of the user.
- `prefix` (string, optional) — The prefix.
- `middle` (string, optional) — The middle name or initial of the user.

### CardsPostResponsesContentApplicationJsonSchemaCardUserDetailsPhone

The phone contact of the logged-in user who made the request for a new on-demand Card.

- `number` (string, required) — The phone number of the user. Only numeric values are accepted.
- `extension` (string, required) — The extension of the phone number. Only numeric values are accepted.
- `type` (enum, required) — The type of phone.
  - Allowed values: `WORK`, `MOBILE`, `HOME`

### CardsPostResponsesContentApplicationJsonSchemaCardUserDetailsUserAgent

This object is for the details of the client application from which the request for a new on-demand Card was made.

- `webActionPath` (string, optional) — The full web path from which the request for creating an on-demand Card was made.
- `browserType` (string, optional) — The browser type from which the request for creating an on-demand Card was made. e.g., Google Chrome
- `browserVersion` (string, optional) — The version of the browser from which the request for creating an on-demand Card was made. e.g., 112.0.5615.49, 2023-04-05

## Examples

**Request**

```json
{
  "accountId": "CR6gVOF5QgCqunZ",
  "spendControls": {
    "currentAmount": "200.00",
    "validFromDate": "2024-01-01",
    "validToDate": "2024-06-01",
    "spendType": "SINGLE_USE",
    "timeZone": "MST",
    "allowedMerchantIndustries": [
      "4121",
      "4722"
    ],
    "allowedMerchant": [
      "1042721514",
      "1043439983"
    ],
    "chargeAmountVariance": {
      "varianceType": "PERCENTAGE",
      "varianceLowerBound": "100",
      "varianceUpperBound": "100",
      "minimumAuthorizationAmount": "300.00",
      "autoExpirePercent": "20",
      "autoExpireAmount": "2.00"
    }
  },
  "cardDetails": {
    "formFactor": "VIRTUAL",
    "cardReferenceId": "PO12345-AB7890",
    "digitalWalletProvisionable": false
  },
  "deliveryMethod": "API_RESPONSE",
  "userDetails": {
    "userId": "12345",
    "name": {
      "first": "John",
      "last": "Smith",
      "prefix": "Mr",
      "middle": "M"
    },
    "email": "someone@example.com",
    "phone": {
      "number": "5555551111",
      "extension": "01",
      "type": "MOBILE"
    },
    "ipAddress": "10.235.11.11",
    "deviceId": "D23232323",
    "sessionId": "lit3py55t21z5v55vlm25s55",
    "userAgent": {
      "webActionPath": "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0",
      "browserType": "FireFox",
      "browserVersion": "112.0.5615.49"
    }
  },
  "cardUserId": "123456",
  "reloadable": false,
  "reconciliationField": {
    "userDefinedFields": [
      {
        "index": "1",
        "value": "test"
      }
    ],
    "accountingFields": [
      {
        "index": "1",
        "value": "test"
      }
    ]
  }
}
```

**Response**

```json
{
  "cardId": "CAEQd4zBEYrPi56",
  "status": "IN_PROGRESS",
  "card": {
    "accountId": "CR6gVOF5QgCqunZ",
    "spendControls": {
      "currentAmount": "200.00",
      "validFromDate": "2024-01-01",
      "validToDate": "2024-06-01",
      "spendType": "SINGLE_USE",
      "timeZone": "MST",
      "allowedMerchantIndustries": [
        "4121",
        "4722"
      ],
      "allowedMerchant": [
        "1042721514",
        "1043439983"
      ],
      "chargeAmountVariance": {
        "varianceType": "PERCENTAGE",
        "varianceLowerBound": "100",
        "varianceUpperBound": "100",
        "minimumAuthorizationAmount": "300.00",
        "autoExpirePercent": "20",
        "autoExpireAmount": "2.00"
      }
    },
    "cardDetails": {
      "formFactor": "VIRTUAL",
      "cardReferenceId": "PO12345-AB7890",
      "digitalWalletProvisionable": false
    },
    "deliveryMethod": "API_RESPONSE",
    "userDetails": {
      "userId": "12345",
      "name": {
        "first": "John",
        "last": "Smith",
        "prefix": "Mr",
        "middle": "M"
      },
      "email": "someone@example.com",
      "phone": {
        "number": "5555551111",
        "extension": "01",
        "type": "MOBILE"
      },
      "ipAddress": "10.235.11.11",
      "deviceId": "D23232323",
      "sessionId": "lit3py55t21z5v55vlm25s55",
      "userAgent": {
        "webActionPath": "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0",
        "browserType": "FireFox",
        "browserVersion": "112.0.5615.49"
      }
    },
    "cardUserId": "123456",
    "reloadable": false,
    "reconciliationField": {
      "userDefinedFields": [
        {
          "index": "1",
          "value": "test"
        }
      ],
      "accountingFields": [
        {
          "index": "1",
          "value": "test"
        }
      ]
    }
  }
}
```

**SDK Code**

```python createNewCard_example
import requests

url = "https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/cards"

payload = {
    "accountId": "CR6gVOF5QgCqunZ",
    "spendControls": {
        "currentAmount": "200.00",
        "validFromDate": "2024-01-01",
        "validToDate": "2024-06-01",
        "spendType": "SINGLE_USE",
        "timeZone": "MST",
        "allowedMerchantIndustries": ["4121", "4722"],
        "allowedMerchant": ["1042721514", "1043439983"],
        "chargeAmountVariance": {
            "varianceType": "PERCENTAGE",
            "varianceLowerBound": "100",
            "varianceUpperBound": "100",
            "minimumAuthorizationAmount": "300.00",
            "autoExpirePercent": "20",
            "autoExpireAmount": "2.00"
        }
    },
    "cardDetails": {
        "formFactor": "VIRTUAL",
        "cardReferenceId": "PO12345-AB7890",
        "digitalWalletProvisionable": False
    },
    "deliveryMethod": "API_RESPONSE",
    "userDetails": {
        "userId": "12345",
        "name": {
            "first": "John",
            "last": "Smith",
            "prefix": "Mr",
            "middle": "M"
        },
        "email": "someone@example.com",
        "phone": {
            "number": "5555551111",
            "extension": "01",
            "type": "MOBILE"
        },
        "ipAddress": "10.235.11.11",
        "deviceId": "D23232323",
        "sessionId": "lit3py55t21z5v55vlm25s55",
        "userAgent": {
            "webActionPath": "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0",
            "browserType": "FireFox",
            "browserVersion": "112.0.5615.49"
        }
    },
    "cardUserId": "123456",
    "reloadable": False,
    "reconciliationField": {
        "userDefinedFields": [
            {
                "index": "1",
                "value": "test"
            }
        ],
        "accountingFields": [
            {
                "index": "1",
                "value": "test"
            }
        ]
    }
}
headers = {
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript createNewCard_example
const url = 'https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/cards';
const options = {
  method: 'POST',
  headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
  body: '{"accountId":"CR6gVOF5QgCqunZ","spendControls":{"currentAmount":"200.00","validFromDate":"2024-01-01","validToDate":"2024-06-01","spendType":"SINGLE_USE","timeZone":"MST","allowedMerchantIndustries":["4121","4722"],"allowedMerchant":["1042721514","1043439983"],"chargeAmountVariance":{"varianceType":"PERCENTAGE","varianceLowerBound":"100","varianceUpperBound":"100","minimumAuthorizationAmount":"300.00","autoExpirePercent":"20","autoExpireAmount":"2.00"}},"cardDetails":{"formFactor":"VIRTUAL","cardReferenceId":"PO12345-AB7890","digitalWalletProvisionable":false},"deliveryMethod":"API_RESPONSE","userDetails":{"userId":"12345","name":{"first":"John","last":"Smith","prefix":"Mr","middle":"M"},"email":"someone@example.com","phone":{"number":"5555551111","extension":"01","type":"MOBILE"},"ipAddress":"10.235.11.11","deviceId":"D23232323","sessionId":"lit3py55t21z5v55vlm25s55","userAgent":{"webActionPath":"Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0","browserType":"FireFox","browserVersion":"112.0.5615.49"}},"cardUserId":"123456","reloadable":false,"reconciliationField":{"userDefinedFields":[{"index":"1","value":"test"}],"accountingFields":[{"index":"1","value":"test"}]}}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go createNewCard_example
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/cards"

	payload := strings.NewReader("{\n  \"accountId\": \"CR6gVOF5QgCqunZ\",\n  \"spendControls\": {\n    \"currentAmount\": \"200.00\",\n    \"validFromDate\": \"2024-01-01\",\n    \"validToDate\": \"2024-06-01\",\n    \"spendType\": \"SINGLE_USE\",\n    \"timeZone\": \"MST\",\n    \"allowedMerchantIndustries\": [\n      \"4121\",\n      \"4722\"\n    ],\n    \"allowedMerchant\": [\n      \"1042721514\",\n      \"1043439983\"\n    ],\n    \"chargeAmountVariance\": {\n      \"varianceType\": \"PERCENTAGE\",\n      \"varianceLowerBound\": \"100\",\n      \"varianceUpperBound\": \"100\",\n      \"minimumAuthorizationAmount\": \"300.00\",\n      \"autoExpirePercent\": \"20\",\n      \"autoExpireAmount\": \"2.00\"\n    }\n  },\n  \"cardDetails\": {\n    \"formFactor\": \"VIRTUAL\",\n    \"cardReferenceId\": \"PO12345-AB7890\",\n    \"digitalWalletProvisionable\": false\n  },\n  \"deliveryMethod\": \"API_RESPONSE\",\n  \"userDetails\": {\n    \"userId\": \"12345\",\n    \"name\": {\n      \"first\": \"John\",\n      \"last\": \"Smith\",\n      \"prefix\": \"Mr\",\n      \"middle\": \"M\"\n    },\n    \"email\": \"someone@example.com\",\n    \"phone\": {\n      \"number\": \"5555551111\",\n      \"extension\": \"01\",\n      \"type\": \"MOBILE\"\n    },\n    \"ipAddress\": \"10.235.11.11\",\n    \"deviceId\": \"D23232323\",\n    \"sessionId\": \"lit3py55t21z5v55vlm25s55\",\n    \"userAgent\": {\n      \"webActionPath\": \"Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0\",\n      \"browserType\": \"FireFox\",\n      \"browserVersion\": \"112.0.5615.49\"\n    }\n  },\n  \"cardUserId\": \"123456\",\n  \"reloadable\": false,\n  \"reconciliationField\": {\n    \"userDefinedFields\": [\n      {\n        \"index\": \"1\",\n        \"value\": \"test\"\n      }\n    ],\n    \"accountingFields\": [\n      {\n        \"index\": \"1\",\n        \"value\": \"test\"\n      }\n    ]\n  }\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby createNewCard_example
require 'uri'
require 'net/http'

url = URI("https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/cards")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"accountId\": \"CR6gVOF5QgCqunZ\",\n  \"spendControls\": {\n    \"currentAmount\": \"200.00\",\n    \"validFromDate\": \"2024-01-01\",\n    \"validToDate\": \"2024-06-01\",\n    \"spendType\": \"SINGLE_USE\",\n    \"timeZone\": \"MST\",\n    \"allowedMerchantIndustries\": [\n      \"4121\",\n      \"4722\"\n    ],\n    \"allowedMerchant\": [\n      \"1042721514\",\n      \"1043439983\"\n    ],\n    \"chargeAmountVariance\": {\n      \"varianceType\": \"PERCENTAGE\",\n      \"varianceLowerBound\": \"100\",\n      \"varianceUpperBound\": \"100\",\n      \"minimumAuthorizationAmount\": \"300.00\",\n      \"autoExpirePercent\": \"20\",\n      \"autoExpireAmount\": \"2.00\"\n    }\n  },\n  \"cardDetails\": {\n    \"formFactor\": \"VIRTUAL\",\n    \"cardReferenceId\": \"PO12345-AB7890\",\n    \"digitalWalletProvisionable\": false\n  },\n  \"deliveryMethod\": \"API_RESPONSE\",\n  \"userDetails\": {\n    \"userId\": \"12345\",\n    \"name\": {\n      \"first\": \"John\",\n      \"last\": \"Smith\",\n      \"prefix\": \"Mr\",\n      \"middle\": \"M\"\n    },\n    \"email\": \"someone@example.com\",\n    \"phone\": {\n      \"number\": \"5555551111\",\n      \"extension\": \"01\",\n      \"type\": \"MOBILE\"\n    },\n    \"ipAddress\": \"10.235.11.11\",\n    \"deviceId\": \"D23232323\",\n    \"sessionId\": \"lit3py55t21z5v55vlm25s55\",\n    \"userAgent\": {\n      \"webActionPath\": \"Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0\",\n      \"browserType\": \"FireFox\",\n      \"browserVersion\": \"112.0.5615.49\"\n    }\n  },\n  \"cardUserId\": \"123456\",\n  \"reloadable\": false,\n  \"reconciliationField\": {\n    \"userDefinedFields\": [\n      {\n        \"index\": \"1\",\n        \"value\": \"test\"\n      }\n    ],\n    \"accountingFields\": [\n      {\n        \"index\": \"1\",\n        \"value\": \"test\"\n      }\n    ]\n  }\n}"

response = http.request(request)
puts response.read_body
```

```java createNewCard_example
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/cards")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("{\n  \"accountId\": \"CR6gVOF5QgCqunZ\",\n  \"spendControls\": {\n    \"currentAmount\": \"200.00\",\n    \"validFromDate\": \"2024-01-01\",\n    \"validToDate\": \"2024-06-01\",\n    \"spendType\": \"SINGLE_USE\",\n    \"timeZone\": \"MST\",\n    \"allowedMerchantIndustries\": [\n      \"4121\",\n      \"4722\"\n    ],\n    \"allowedMerchant\": [\n      \"1042721514\",\n      \"1043439983\"\n    ],\n    \"chargeAmountVariance\": {\n      \"varianceType\": \"PERCENTAGE\",\n      \"varianceLowerBound\": \"100\",\n      \"varianceUpperBound\": \"100\",\n      \"minimumAuthorizationAmount\": \"300.00\",\n      \"autoExpirePercent\": \"20\",\n      \"autoExpireAmount\": \"2.00\"\n    }\n  },\n  \"cardDetails\": {\n    \"formFactor\": \"VIRTUAL\",\n    \"cardReferenceId\": \"PO12345-AB7890\",\n    \"digitalWalletProvisionable\": false\n  },\n  \"deliveryMethod\": \"API_RESPONSE\",\n  \"userDetails\": {\n    \"userId\": \"12345\",\n    \"name\": {\n      \"first\": \"John\",\n      \"last\": \"Smith\",\n      \"prefix\": \"Mr\",\n      \"middle\": \"M\"\n    },\n    \"email\": \"someone@example.com\",\n    \"phone\": {\n      \"number\": \"5555551111\",\n      \"extension\": \"01\",\n      \"type\": \"MOBILE\"\n    },\n    \"ipAddress\": \"10.235.11.11\",\n    \"deviceId\": \"D23232323\",\n    \"sessionId\": \"lit3py55t21z5v55vlm25s55\",\n    \"userAgent\": {\n      \"webActionPath\": \"Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0\",\n      \"browserType\": \"FireFox\",\n      \"browserVersion\": \"112.0.5615.49\"\n    }\n  },\n  \"cardUserId\": \"123456\",\n  \"reloadable\": false,\n  \"reconciliationField\": {\n    \"userDefinedFields\": [\n      {\n        \"index\": \"1\",\n        \"value\": \"test\"\n      }\n    ],\n    \"accountingFields\": [\n      {\n        \"index\": \"1\",\n        \"value\": \"test\"\n      }\n    ]\n  }\n}")
  .asString();
```

```php createNewCard_example
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/cards', [
  'body' => '{
  "accountId": "CR6gVOF5QgCqunZ",
  "spendControls": {
    "currentAmount": "200.00",
    "validFromDate": "2024-01-01",
    "validToDate": "2024-06-01",
    "spendType": "SINGLE_USE",
    "timeZone": "MST",
    "allowedMerchantIndustries": [
      "4121",
      "4722"
    ],
    "allowedMerchant": [
      "1042721514",
      "1043439983"
    ],
    "chargeAmountVariance": {
      "varianceType": "PERCENTAGE",
      "varianceLowerBound": "100",
      "varianceUpperBound": "100",
      "minimumAuthorizationAmount": "300.00",
      "autoExpirePercent": "20",
      "autoExpireAmount": "2.00"
    }
  },
  "cardDetails": {
    "formFactor": "VIRTUAL",
    "cardReferenceId": "PO12345-AB7890",
    "digitalWalletProvisionable": false
  },
  "deliveryMethod": "API_RESPONSE",
  "userDetails": {
    "userId": "12345",
    "name": {
      "first": "John",
      "last": "Smith",
      "prefix": "Mr",
      "middle": "M"
    },
    "email": "someone@example.com",
    "phone": {
      "number": "5555551111",
      "extension": "01",
      "type": "MOBILE"
    },
    "ipAddress": "10.235.11.11",
    "deviceId": "D23232323",
    "sessionId": "lit3py55t21z5v55vlm25s55",
    "userAgent": {
      "webActionPath": "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0",
      "browserType": "FireFox",
      "browserVersion": "112.0.5615.49"
    }
  },
  "cardUserId": "123456",
  "reloadable": false,
  "reconciliationField": {
    "userDefinedFields": [
      {
        "index": "1",
        "value": "test"
      }
    ],
    "accountingFields": [
      {
        "index": "1",
        "value": "test"
      }
    ]
  }
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

```csharp createNewCard_example
using RestSharp;

var client = new RestClient("https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/cards");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"accountId\": \"CR6gVOF5QgCqunZ\",\n  \"spendControls\": {\n    \"currentAmount\": \"200.00\",\n    \"validFromDate\": \"2024-01-01\",\n    \"validToDate\": \"2024-06-01\",\n    \"spendType\": \"SINGLE_USE\",\n    \"timeZone\": \"MST\",\n    \"allowedMerchantIndustries\": [\n      \"4121\",\n      \"4722\"\n    ],\n    \"allowedMerchant\": [\n      \"1042721514\",\n      \"1043439983\"\n    ],\n    \"chargeAmountVariance\": {\n      \"varianceType\": \"PERCENTAGE\",\n      \"varianceLowerBound\": \"100\",\n      \"varianceUpperBound\": \"100\",\n      \"minimumAuthorizationAmount\": \"300.00\",\n      \"autoExpirePercent\": \"20\",\n      \"autoExpireAmount\": \"2.00\"\n    }\n  },\n  \"cardDetails\": {\n    \"formFactor\": \"VIRTUAL\",\n    \"cardReferenceId\": \"PO12345-AB7890\",\n    \"digitalWalletProvisionable\": false\n  },\n  \"deliveryMethod\": \"API_RESPONSE\",\n  \"userDetails\": {\n    \"userId\": \"12345\",\n    \"name\": {\n      \"first\": \"John\",\n      \"last\": \"Smith\",\n      \"prefix\": \"Mr\",\n      \"middle\": \"M\"\n    },\n    \"email\": \"someone@example.com\",\n    \"phone\": {\n      \"number\": \"5555551111\",\n      \"extension\": \"01\",\n      \"type\": \"MOBILE\"\n    },\n    \"ipAddress\": \"10.235.11.11\",\n    \"deviceId\": \"D23232323\",\n    \"sessionId\": \"lit3py55t21z5v55vlm25s55\",\n    \"userAgent\": {\n      \"webActionPath\": \"Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0\",\n      \"browserType\": \"FireFox\",\n      \"browserVersion\": \"112.0.5615.49\"\n    }\n  },\n  \"cardUserId\": \"123456\",\n  \"reloadable\": false,\n  \"reconciliationField\": {\n    \"userDefinedFields\": [\n      {\n        \"index\": \"1\",\n        \"value\": \"test\"\n      }\n    ],\n    \"accountingFields\": [\n      {\n        \"index\": \"1\",\n        \"value\": \"test\"\n      }\n    ]\n  }\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift createNewCard_example
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = [
  "accountId": "CR6gVOF5QgCqunZ",
  "spendControls": [
    "currentAmount": "200.00",
    "validFromDate": "2024-01-01",
    "validToDate": "2024-06-01",
    "spendType": "SINGLE_USE",
    "timeZone": "MST",
    "allowedMerchantIndustries": ["4121", "4722"],
    "allowedMerchant": ["1042721514", "1043439983"],
    "chargeAmountVariance": [
      "varianceType": "PERCENTAGE",
      "varianceLowerBound": "100",
      "varianceUpperBound": "100",
      "minimumAuthorizationAmount": "300.00",
      "autoExpirePercent": "20",
      "autoExpireAmount": "2.00"
    ]
  ],
  "cardDetails": [
    "formFactor": "VIRTUAL",
    "cardReferenceId": "PO12345-AB7890",
    "digitalWalletProvisionable": false
  ],
  "deliveryMethod": "API_RESPONSE",
  "userDetails": [
    "userId": "12345",
    "name": [
      "first": "John",
      "last": "Smith",
      "prefix": "Mr",
      "middle": "M"
    ],
    "email": "someone@example.com",
    "phone": [
      "number": "5555551111",
      "extension": "01",
      "type": "MOBILE"
    ],
    "ipAddress": "10.235.11.11",
    "deviceId": "D23232323",
    "sessionId": "lit3py55t21z5v55vlm25s55",
    "userAgent": [
      "webActionPath": "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0",
      "browserType": "FireFox",
      "browserVersion": "112.0.5615.49"
    ]
  ],
  "cardUserId": "123456",
  "reloadable": false,
  "reconciliationField": [
    "userDefinedFields": [
      [
        "index": "1",
        "value": "test"
      ]
    ],
    "accountingFields": [
      [
        "index": "1",
        "value": "test"
      ]
    ]
  ]
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/cards")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```