> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.americanexpress.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.americanexpress.ferndocs.com/_mcp/server.

# Assign an existing Card User to an existing Card

PATCH https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/cards/{cardId}
Content-Type: application/json

Assign an existing Card User to an existing Card. The Card must be in an ACTIVE or PREACTIVE status and the Card User must be in an ACTIVATED status. Once a Card is assigned to a Card User it cannot be reassigned and the digitialWalletProvisionable field cannot be modified.

Reference: https://developer.americanexpress.ferndocs.com/payment-services/card-on-demand/api-reference/patch-card

## Authentication

- `Authorization` header (bearer token, required) — OAuth 2.0 client credentials. Exchange your API key and secret for a bearer token, then send it as `Authorization: Bearer <token>`.

## Servers

- `https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand` (Sandbox, default)
- `https://api.americanexpress.com/commercial/v1/card_on_demand` (Production)

## Request

### Path parameters

- `cardId` (string, required) — A unique ID that is created for the Card.

### Body (application/json)

This endpoint expects an object.

- `cardUserId` (string, required) — A unique ID that is created for the Card User.
- `digitalWalletProvisionable` (boolean, required) — This field captures the User's preference for whether the Card can be added to a digital wallet. This field is required when a Partner has signed up for the mobile wallet provisioning and the Card is being created for a Card User. If one or both of these conditions are not met, the field must be NULL.

## Response

### 200

Successful operation

- `cardId` (string, required) — A unique ID that is created for the Card.
- `cardUserId` (string, required) — A unique ID that is created for the Card User.
- `digitalWalletProvisionable` (boolean, required) — This field captures the User's preference for whether the Card can be added to a digital wallet. This field is required when a Partner has signed up for the mobile wallet provisioning and the Card is being created for a Card User. If one or both of these conditions are not met, the field must be NULL.

## Errors

### 400 Bad Request Error

Bad Request

- `errors` (list of 400ErrorItems, required)

### 401 Unauthorized Error

Unauthorized

- `errorCode` (string, required) — A machine-readable field indicating the type of error.
- `errorDescription` (string, optional) — Provides a short description of the error.

### 404 Not Found Error

Resource not found

- `errorCode` (string, required) — A machine-readable field indicating the type of error.
- `errorDescription` (string, optional) — Provides a short description of the error.

### 500 Internal Server Error

Service error

- `errorCode` (string, required) — A machine-readable field indicating the type of error.
- `errorDescription` (string, optional) — Provides a short description of the error.

### 504 Gateway Timeout Error

Service unavailable

- `errorCode` (string, required) — A machine-readable field indicating the type of error.
- `errorDescription` (string, optional) — Provides a short description of the error.

## Types

### 400ErrorItems

- `code` (string, required) — A machine-readable field indicating the type of error.
- `message` (string, required) — Provides a short description of the error.
- `detail` (string, optional) — Provides a detailed description of the error.
- `link` (string, optional) — The link to documentation that explains the error.

## Examples

**Request**

```json
{
  "cardUserId": "123456",
  "digitalWalletProvisionable": true
}
```

**Response**

```json
{
  "cardId": "CAEQd4zBEYrPi56",
  "cardUserId": "123456",
  "digitalWalletProvisionable": true
}
```

**SDK Code**

```python patchCard_example
import requests

url = "https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/cards/CAEQd4zBEYrPi56"

payload = {
    "cardUserId": "123456",
    "digitalWalletProvisionable": True
}
headers = {
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.patch(url, json=payload, headers=headers)

print(response.json())
```

```javascript patchCard_example
const url = 'https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/cards/CAEQd4zBEYrPi56';
const options = {
  method: 'PATCH',
  headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
  body: '{"cardUserId":"123456","digitalWalletProvisionable":true}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go patchCard_example
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/cards/CAEQd4zBEYrPi56"

	payload := strings.NewReader("{\n  \"cardUserId\": \"123456\",\n  \"digitalWalletProvisionable\": true\n}")

	req, _ := http.NewRequest("PATCH", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby patchCard_example
require 'uri'
require 'net/http'

url = URI("https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/cards/CAEQd4zBEYrPi56")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Patch.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"cardUserId\": \"123456\",\n  \"digitalWalletProvisionable\": true\n}"

response = http.request(request)
puts response.read_body
```

```java patchCard_example
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.patch("https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/cards/CAEQd4zBEYrPi56")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("{\n  \"cardUserId\": \"123456\",\n  \"digitalWalletProvisionable\": true\n}")
  .asString();
```

```php patchCard_example
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/cards/CAEQd4zBEYrPi56', [
  'body' => '{
  "cardUserId": "123456",
  "digitalWalletProvisionable": true
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

```csharp patchCard_example
using RestSharp;

var client = new RestClient("https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/cards/CAEQd4zBEYrPi56");
var request = new RestRequest(Method.PATCH);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"cardUserId\": \"123456\",\n  \"digitalWalletProvisionable\": true\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift patchCard_example
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = [
  "cardUserId": "123456",
  "digitalWalletProvisionable": true
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.qasb2s.americanexpress.com/commercial/v1/card_on_demand/cards/CAEQd4zBEYrPi56")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "PATCH"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```