swagger: '2.0'
info:
description: 'The current set of APIs will be available in Q2 2026 on Worldline Global Issuing Platforms.
Additional APIs are under construction and planned to be available in 2026.'
version: 2.41.1
title: Worldline Card Issuing Account - AccountState Card - Order API
contact: {}
host: sbx-wlip.api1-eu2.psapigateway.preprod.giservices.io/card-issuing
basePath: /api/v2
schemes:
- https
tags:
- name: Card - Order
description: Card Order Api Controller
paths:
/issuers/{issuerId}/cards/external-cards/{issuerCardExternalReference}/orders/{orderReference}:
get:
tags:
- Card - Order
summary: Retrieve card order by external reference
description: 'The API enables the order information (card, PIN mailer or TAN mailer order) related to a given card to be retrieved. The order is identified with order reference.
The response can also be enriched (if specified as embedded fields in input) with additional data such as the orders status history of the card, the card information.'
operationId: retrieveOrderByCardIssuerExtRef
produces:
- application/json
parameters:
- name: WL-Correlation-ID
in: header
required: false
type: string
- name: WL-Origin
in: header
required: false
type: string
- name: WL-Username
in: header
required: false
type: string
- name: filter
in: query
description: Filtered Fields
required: false
type: array
items:
type: string
collectionFormat: multi
- name: issuerId
in: path
description: Issuer ID
required: true
type: string
- name: issuerCardExternalReference
in: path
description: Issuer Card External Reference
required: true
type: string
- name: orderReference
in: path
description: Order Reference
required: true
type: string
- name: embed
in: query
description: Embedded Fields
required: false
type: array
items:
type: string
enum:
- card
- statusHistory
collectionFormat: multi
responses:
'400':
description: Bad request
schema:
$ref: '#/definitions/BadRequestErrorApiResponse'
'401':
description: Unauthorized
schema:
$ref: '#/definitions/UnauthorizedErrorApiResponse'
'403':
description: Forbidden
schema:
$ref: '#/definitions/ForbiddenErrorApiResponse'
'404':
description: Not found
schema:
$ref: '#/definitions/NotFoundErrorApiResponse'
'500':
description: Internal server error
schema:
$ref: '#/definitions/InternalServerErrorErrorApiResponse'
'502':
description: Bad gateway
schema:
$ref: '#/definitions/BadGatewayErrorApiResponse'
'200':
description: OK
schema:
$ref: '#/definitions/ApiResponseEntityOrder'
security:
- basic: []
deprecated: false
/issuers/{issuerId}/cards/external-cards/{issuerCardExternalReference}/orders/{orderReference}/release:
post:
tags:
- Card - Order
summary: 'This API is deprecated.
The Release orders for a card API must be used to release all orders related to a card.'
operationId: releaseCardOrderByCardIssuerExtRef
consumes:
- application/json
produces:
- application/json
parameters:
- name: WL-Correlation-ID
in: header
required: false
type: string
- name: WL-Origin
in: header
required: false
type: string
- name: WL-Username
in: header
required: false
type: string
- name: filter
in: query
description: Filtered Fields
required: false
type: array
items:
type: string
collectionFormat: multi
- name: issuerId
in: path
description: Issuer ID
required: true
type: string
- name: issuerCardExternalReference
in: path
description: Issuer Card External Reference
required: true
type: string
- name: orderReference
in: path
description: Order Reference
required: true
type: string
responses:
'400':
description: Bad request
schema:
$ref: '#/definitions/BadRequestErrorApiResponse'
'401':
description: Unauthorized
schema:
$ref: '#/definitions/UnauthorizedErrorApiResponse'
'403':
description: Forbidden
schema:
$ref: '#/definitions/ForbiddenErrorApiResponse'
'404':
description: Not found
schema:
$ref: '#/definitions/NotFoundErrorApiResponse'
'500':
description: Internal server error
schema:
$ref: '#/definitions/InternalServerErrorErrorApiResponse'
'502':
description: Bad gateway
schema:
$ref: '#/definitions/BadGatewayErrorApiResponse'
'200':
description: OK
schema:
$ref: '#/definitions/ApiResponseEntityReleaseOrderResponse'
security:
- basic: []
deprecated: true
/issuers/{issuerId}/cards/{cardReference}/orders/{orderReference}:
get:
tags:
- Card - Order
summary: Retrieve card order
description: 'The API enables the order information (card, PIN mailer or TAN mailer order) related to a given card to be retrieved. The order is identified with order reference.
The response can also be enriched (if specified as embedded fields in input) with additional data such as the orders status history of the card, the card information.'
operationId: retrieveOrder
produces:
- application/json
parameters:
- name: WL-Correlation-ID
in: header
required: false
type: string
- name: WL-Origin
in: header
required: false
type: string
- name: WL-Username
in: header
required: false
type: string
- name: filter
in: query
description: Filtered Fields
required: false
type: array
items:
type: string
collectionFormat: multi
- name: issuerId
in: path
description: Issuer ID
required: true
type: string
- name: cardReference
in: path
description: Card Reference
required: true
type: string
- name: orderReference
in: path
description: Order Reference
required: true
type: string
- name: embed
in: query
description: Embedded Fields
required: false
type: array
items:
type: string
enum:
- card
- statusHistory
- card.cardContract
collectionFormat: multi
responses:
'400':
description: Bad request
schema:
$ref: '#/definitions/BadRequestErrorApiResponse'
'401':
description: Unauthorized
schema:
$ref: '#/definitions/UnauthorizedErrorApiResponse'
'403':
description: Forbidden
schema:
$ref: '#/definitions/ForbiddenErrorApiResponse'
'404':
description: Not found
schema:
$ref: '#/definitions/NotFoundErrorApiResponse'
'500':
description: Internal server error
schema:
$ref: '#/definitions/InternalServerErrorErrorApiResponse'
'502':
description: Bad gateway
schema:
$ref: '#/definitions/BadGatewayErrorApiResponse'
'200':
description: OK
schema:
$ref: '#/definitions/ApiResponseEntityOrder'
security:
- basic: []
deprecated: false
/issuers/{issuerId}/cards/{cardReference}/orders/{orderReference}/release:
post:
tags:
- Card - Order
summary: 'This API is deprecated.
The Release orders for a card API must be used to release all orders related to a card.'
operationId: releaseCardOrder
consumes:
- application/json
produces:
- application/json
parameters:
- name: WL-Correlation-ID
in: header
required: false
type: string
- name: WL-Origin
in: header
required: false
type: string
- name: WL-Username
in: header
required: false
type: string
- name: filter
in: query
description: Filtered Fields
required: false
type: array
items:
type: string
collectionFormat: multi
- name: issuerId
in: path
description: Issuer ID
required: true
type: string
- name: cardReference
in: path
description: Card Reference
required: true
type: string
- name: orderReference
in: path
description: Order Reference
required: true
type: string
responses:
'400':
description: Bad request
schema:
$ref: '#/definitions/BadRequestErrorApiResponse'
'401':
description: Unauthorized
schema:
$ref: '#/definitions/UnauthorizedErrorApiResponse'
'403':
description: Forbidden
schema:
$ref: '#/definitions/ForbiddenErrorApiResponse'
'404':
description: Not found
schema:
$ref: '#/definitions/NotFoundErrorApiResponse'
'500':
description: Internal server error
schema:
$ref: '#/definitions/InternalServerErrorErrorApiResponse'
'502':
description: Bad gateway
schema:
$ref: '#/definitions/BadGatewayErrorApiResponse'
'200':
description: OK
schema:
$ref: '#/definitions/ApiResponseEntityReleaseOrderResponse'
security:
- basic: []
deprecated: true
definitions:
CardContract:
type: object
properties:
issuerId:
type: string
description: Issuer identifier (unique per platform)
cardContractIdentifier:
description: Identification of the card contract either by Issuer card contract external reference or by card contract reference
allOf:
- $ref: '#/definitions/CardContractIdentifier'
cardTemplateReference:
type: string
description: Card template reference used for card contract creation
cardTypeCode:
type: string
description: Scheme card type from the card profile
cardTypeLabel:
type: string
description: Scheme card type label from the card profile
status:
type: string
description: 'Status of the card contract (mandatory)
The status of the card contract is changing during its life cycle according to business processes in the system.
Possible values are :
- CREATED : The first status when the card contract is created. Related card is not activated.
- ACTIVE : The card contract is active. Related card is activated as per product configuration
Examples of business processes triggering this status: contract creation request, contract creation after a product change request.
- CLOSED : The card contract is closed and the associated card is deactivated/cancelled (if not already permanently blocked). Card renewal and card replacement are not possible.
Examples of business processes triggering this status: contract closing request, card contract closing request, contract closure after a product change request.'
openingDate:
type: string
format: date-time
description: Creation date of the card contract (mandatory)
activationDate:
type: string
format: date-time
description: Date when the card contract becomes active in our system
closingDate:
type: string
format: date-time
description: Closing date of the card contract (present only in case of card contract is already closed or card contract closing is scheduled)
closingComment:
type: string
description: 'Comment associated with the card contract closing action (optional)
Free text'
closingReason:
type: string
description: Indicates the reason for closing the card contract (present only in case of card contract is already closed or card contract closing is scheduled) Free text
closingDelayType:
type: string
description: 'The closing type of the card contract (present only in case of card contract is already closed or card contract closing is scheduled)
The closing type can be:
IMMEDIATE (at current date)
SCHEDULED (at future date, greater than the current date)
SCHEDULED_EXP_DATE (at the expiration date of active card)'
trustedAuthenticationReference:
type: string
description: 'Unique reference generated by card management system used as trusted authentication credential
It is related to a card. Same reference is used in case of card renewal/replacement.
Used for ACS enrolment (3D Secure)'
newCardRenewalAllowed:
type: boolean
description: "Indicates if the renewal is allowed for a card (true) or not (false). \nDefault value is true."
blockingRenewalReasonCode:
type: string
description: 'Reason for blocking the renewal of a card (optional)
The list of renewal blocking reasons is configurable per issuer (For example : LOST, CREDIT_RISK, FRAUDULENT …)'
newCardReplacementAllowed:
type: boolean
description: 'Indicates if the replacement is allowed for a card (true) or not (false). Default value is false '
blockingReplacementReasonCode:
type: string
description: Reason for blocking the replacement of a card (optional) The list of replacement blocking reasons is configurable per issuer (For example, CONTRACT_SUSPENSION …)
blockingPinReorderReasonCode:
type: string
description: 'Mandatory reason to be set for blocking a pin reorder
The list of blocking reasons for pin reorder is configurable per issuer (For example, CONTRACT_SUSPENSION …)'
newPinReorderAllowed:
type: boolean
description: The pin reorder process can be blocked (blocking pin reorder reason code must be provided) or not.
blockingPinReminderReasonCode:
type: string
description: 'Mandatory reason to be set for blocking pin reminder
The list of blocking reasons for pin reminder is configurable per issuer (For example, CONTRACT_SUSPENSION …)'
newPinReminderAllowed:
type: boolean
description: The pin reminder process can be blocked (blocking pin reminder reason code must be provided) or not.
issuerBranchCode:
type: string
description: 'The Branch code (optional)
By default, the value is NO_BRANCH.'
artwork:
type: string
description: Artwork (card design) defined for the card contract (mandatory)
forcedEmbossingName:
type: string
description: First line of the name to be embossed on the next physical card if provided by the issuer (optional)
forcedEmbossingName2ndLine:
type: string
description: 'The second line of the name to be embossed on the physical card if provided by the issuer (optional)
Can be present (optional) only if first line of forced embossing name is present and if embossing name calculation algorithm accepts a second line.'
schemeDeclarationOptOut:
type: boolean
description: DEPRECATED
schemeReportDeclarationBehavior:
type: string
description: 'The issuer can indicate if the card events are reported to the scheme. Relevant only if the ABU-VAU program is enabled. If the ABU-VAU program is disabled, the use of this attribute generates an error. Possible values are: OPT_IN: the card events are reported to the scheme, OPT_OUT: the card events are not reported to the scheme. If the ABU-VAU program is enabled and the attribute is empty, the default value set on card product is applied.'
principalSupplementaryCardIndicator:
type: string
description: 'Indicates if it is a Principal card or an additional card (mandatory)
Possible values: PRINCIPAL, SUPPLEMENTARY'
productCategory:
type: string
description: 'Defines the category of the product (mandatory)
The list of product categories is configurable per issuer (e.g. CREDIT, DEBIT, PREPAID)'
productCategoryLabel:
type: string
description: 'Label of the product category (optional)
Example: IMMEDIATE_DEBIT_DEBIT, REVOLVING_CREDIT_CREDIT, DIFFERED_DEBIT_CREDIT'
specificFields:
type: object
description: 'List of external data {"label":"value"} separated by a "," related to a card contract that can be provided by e.g. the issuer for information or for usage by other systems. Example : {"label1":"value1","label2":"value2"} Those provided data have no impact on our system business processes.'
additionalProperties:
type: string
productIdentifier:
description: Identifier of the product used to create the contract to which the card contract is belonging. It corresponds also to the identifier of the product used to create the card contract if the card contract is created from the product directly.
allOf:
- $ref: '#/definitions/ProductIdentifier'
productExtensionIdentifier:
description: "Identifier of the product extension used to create the card contract. \n Relevant if the card contract is created from a product extension."
allOf:
- $ref: '#/definitions/ProductExtensionIdentifier'
selectedModels:
type: array
description: 'List of models linked to the card contract
_Embedded property, only filled when available for the endpoint and explicitly requested in the ''embed'' query parameter._'
items:
$ref: '#/definitions/CardContractModel'
cardClass:
type: string
description: 'Information provided by the issuer to categorize cards within a contract.
The list of allowed card classes is defined by the issuer at its convenience according to its own business rules (e.g special conditions on fees for example) and is configured at product level to be controlled at card creation.'
cardIdentifiers:
type: array
description: 'Card Identifiers
_Embedded property, only filled when available for the endpoint and explicitly requested in the ''embed'' query parameter._'
items:
$ref: '#/definitions/CardIdentifier'
cards:
type: array
description: 'List of cards linked to the card contract. See the Card''s datatype for the detail list of the attributes
_Embedded property, only filled when available for the endpoint and explicitly requested in the ''embed'' query parameter._'
items:
$ref: '#/definitions/Card'
cardHolderIdentifier:
description: Card Holder Identifier
allOf:
- $ref: '#/definitions/CustomerIdentifier'
vipFlag:
type: boolean
default: false
description: "Indicates if the holder of the priority pass is a VIP or not. This information is used to determine the priority pass fees to apply. \n if true, VIP fees are applied. \n If false, standard fees are applied. \n By default, the value is false."
contractIdentifier:
description: Contract Identifier
allOf:
- $ref: '#/definitions/ContractIdentifier'
relatedAccounts:
type: array
description: 'List of posting accounts linked to a card contract
_Embedded property, only filled when available for the endpoint and explicitly requested in the ''embed'' query parameter._'
items:
$ref: '#/definitions/AccountRelation'
cardProfileDescription:
type: string
description: Description of the card profile linked to a card
originalCardContractIdentifier:
description: CardContract Identifier of the original cardContract in case of ProductChange
allOf:
- $ref: '#/definitions/CardContractIdentifier'
changedCardContractIdentifier:
description: CardContract Identifier of the new cardContract in case of ProductChange
allOf:
- $ref: '#/definitions/CardContractIdentifier'
photoReference:
type: string
description: Reference of a cardholder photo used to personalise the card (free text), e.g. URL where object is stored, a reference (optional).
pictureReference:
type: string
description: Reference of an image used to personalise the card (free text), e.g. URL where object is stored, a reference (optional).
cardProfileReference:
type: string
description: Reference of the card profile.
mainCardIndicator:
type: boolean
description: Indicates whether the card is the main one or not for a mutli cards product
logoReference:
type: string
description: For a corporate card a logo reference can be provided (free text), e.g. alphanumeric value, numeric value, URL where the logo is stored. This logo reference is sent to the embosser with the card order data.
cardContractGroupReference:
type: string
description: Unique reference to group card contracts calculated by the system if required by the product configuration
contractType:
type: string
description: "Indicates if it is a consumer (private) or corporate card. \n Possible values: \n CORPORATE \n CONSUMER"
enum:
- CORPORATE
- CONSUMER
deviceTokensNumber:
type: integer
description: Indicates the number of device tokens on the card attached to the card contract
commercialProductReference:
type: string
description: Commercial reference of the card profile linked to a card
commercialProductDescription:
type: string
description: Commercial description of the card profile linked to a card
merchantTokensNumber:
type: integer
description: Indicates the number of merchant tokens on the card attached to the card contract
authorizationDataValidation:
description: Cardholder data defined at card contract level and used by the Front Office for verification (AVS/ANI)
allOf:
- $ref: '#/definitions/AuthorizationDataValidation'
contactCenters:
type: array
items:
$ref: '#/definitions/ContactCenter'
clickToPayEnrollment:
type: string
description: 'Indicates if the card enrollment in Click to Pay service is requested or not.
Possible values are :
- OPT_IN : enrollment of the card in Click to Pay service is requested.
- OPT_OUT : enrollment of the card in Click to Pay service is not requested.
Relevant only if the Click to Pay feature is enabled.'
title: CardContract
CustomerIdentifier:
type: object
description: Identification of the updated customer either by Issuer customer external reference or by customer reference
properties:
customerReference:
type: string
description: Reference computed internally by our system
issuerCustomerExternalReference:
type: string
description: Reference provided by the Issuer
title: CustomerIdentifier
CardIdentifier:
type: object
description: Identification of the card either by Issuer card external reference or by card reference
properties:
cardReference:
type: string
description: 'Reference of the card generated by our system, unique per platform.
This reference is calculated sequentially by an internal algorithm on 16 digits (e.g. 2000000000096013).'
issuerCardExternalReference:
type: string
description: 'External reference of the card provided by the issuer or calculated by the system if the external reference generation algorithm is configured for the issuer.
This reference is unique per issuer and may be used to carry out research and find information.'
title: CardIdentifier
MailAddress:
type: object
required:
- country
properties:
typeCode:
type: string
description: Deprecated field
line1:
type: string
description: Address line 1 (conditional). Free text. A specific issuer algorithm can be activated to e.g. build the line, apply controls (e.g. length restriction).
line2:
type: string
description: Address line 2 (optional). Free text. A specific issuer algorithm can be activated to e.g. build the line, apply controls (e.g. length restriction).
line3:
type: string
description: Address line 3 (optional). Free text. A specific issuer algorithm can be activated to e.g. build the line, apply controls (e.g. length restriction).
line4:
type: string
description: Address line 4 (optional). Free text. A specific issuer algorithm can be activated to e.g. build the line, apply controls (e.g. length restriction).
line5:
type: string
description: Address line 5 (optional). Free text. A specific issuer algorithm can be activated to e.g. build the line, apply controls (e.g. length restriction).
buildingNumber:
type: string
description: Building number of the address (optional)
boxNumber:
type: string
description: Box number of the address (optional)
streetName:
type: string
description: Street name of the address (optional)
postCode:
type: string
description: Zip Code of the address (optional)
townName:
type: string
description: 'City corresponding to the address '
countrySubdivision:
type: string
description: Subdivision of the country (optional)
country:
type: string
description: Code of the country (mandatory). Free text. The value can be subject to a validation process if a specific rule has been configured at issuer level. The value can be optional if a specific rule has been configured.
countryName:
type: string
description: Country Name of the address. Free text
courtesyTitle:
type: string
description: Courtesy title of the address. Free text
title: MailAddress
OrderIdentifier:
type: object
description: Order reference calculated by our system
properties:
orderReference:
type: string
description: 'The reference of the order in our system, unique per platform
This reference is calculated from an algorithm configurable per issuer (currently a unique algorithm is defined).
The reference is composed of the creation date of the order (YYYYMMDD) + a sequence number of 16 digits (e;g; 202203212000000000097002, where 20220321 is the date when the order is created)'
title: OrderIdentifier
NotFoundErrorApiResponse:
type: object
required:
- responseMetadata
properties:
responseMetadata:
allOf:
- $ref: '#/definitions/NotFoundResponseMetadata'
title: NotFoundErrorApiResponse
BadGatewayErrorApiResponse:
type: object
required:
- responseMetadata
properties:
responseMetadata:
allOf:
- $ref: '#/definitions/BadGatewayResponseMetadata'
title: BadGatewayErrorApiResponse
InternalServerErrorErrorApiResponse:
type: object
required:
- responseMetadata
properties:
responseMetadata:
allOf:
- $ref: '#/definitions/InternalServerErrorResponseMetadata'
title: InternalServerErrorErrorApiResponse
InternalServerErrorResponseMetadata:
type: object
required:
- correlationId
- responseDateTime
- statusCode
- statusMessage
properties:
correlationId:
type: string
description: Correlation Identifier
responseDateTime:
type: string
example: format:yyyy-MM-dd'T'HH:mm:ss.SSSZ
description: Timestamp when response date was generated
statusCode:
type: integer
format: int32
example: 500
description: HTTP status code
statusMessage:
type: string
example: Internal server error
description: Executed REST API status message
title: InternalServerErrorResponseMetadata
CardBlockingInformation:
type: object
required:
- cardBlockingDateTime
properties:
cardBlockingDateTime:
type: string
format: date-time
description: Date and time when the card has been blocked by our system
blockAgent:
type: string
description: Operator who blocked the card (mandatory only if the card is blocked). It corresponds to the name of the user, referenced in our system, mentioned at the card blocking time.
blockingReason:
type: string
description: 'Reason for blocking a card (mandatory only if the card is blocked)
The list of blocking reasons is configurable per issuer (For example, LOST, STOLEN, FRAUDULENT …)'
blockingReasonDetail:
type: string
description: 'Complementary information describing the defined blocking reason
Free text'
lostStolenDate:
type: string
format: date-time
description: 'Date when the card has been lost or stolen
This date is provided in addition to the blocking reason (required only if the card is blocked in a context of loss/theft)'
lossPlace:
type: string
description: 'Place where the card has been lost
Free text'
lossCountry:
type: string
description: 'Country of card loss or steal
Can be required in certain countries (e.g. french issuers with CB)
Free text (not check on the provided value)'
lastUsageDate:
type: string
format: date-time
description: ' Date of last use of the card
Example: for lost or stolen reason'
lastUsagePlace:
type: string
description: 'Last place where the card has been used
Example: for lost or stolen reason'
lossCircumstances:
type: string
description: 'Description of the circumstances of the card loss
Free text'
lossReportedBy:
type: string
description: 'Person who has reported the card loss
Free text'
lossReportedVia:
type: string
description: 'How was reported the loss (channel)
Free text'
fraudCode:
type: string
description: 'Fraud code can be used in the context of dispute management.
Fraud code (free text) is provided in case of Fraud for Fraud declaration to the schemes (VISA, MasterCard).
The value must be a value expected by the schemes.'
contactData:
type: string
description: 'Indicates contact data (usually phone number)
Free text'
pinCompromised:
type: boolean
description: 'Indicates if the PIN is compromised (true) or not (false) only in case of lost or stolen reason. Default value is false '
customerRequestingBlockDate:
type: string
format: date-time
description: 'Date when the customer has declared the blocking request.
For example, the cardholder calls the customer service at 4 pm to declare he lost his card and the card blocking request can only be sent at 5 pm to the system: then the customerRequestingBlockDateTime is 4 pm.'
transferEffectiveDate:
type: string
format: date-time
description: Transfer effecti
# --- truncated at 32 KB (73 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/wordline/refs/heads/main/openapi/wordline-card-order-api-openapi.yml