Register for card status updates
curl --request POST \
--url https://apigwuat.corpay.com/cards/statusUpdate \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"cardIdentifier": 123,
"target_url": "<string>",
"hmac_enabled": true,
"hmac_secret": "<string>",
"max_retries": 123
}
'import requests
url = "https://apigwuat.corpay.com/cards/statusUpdate"
payload = {
"cardIdentifier": 123,
"target_url": "<string>",
"hmac_enabled": True,
"hmac_secret": "<string>",
"max_retries": 123
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
cardIdentifier: 123,
target_url: '<string>',
hmac_enabled: true,
hmac_secret: '<string>',
max_retries: 123
})
};
fetch('https://apigwuat.corpay.com/cards/statusUpdate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://apigwuat.corpay.com/cards/statusUpdate",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'cardIdentifier' => 123,
'target_url' => '<string>',
'hmac_enabled' => true,
'hmac_secret' => '<string>',
'max_retries' => 123
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://apigwuat.corpay.com/cards/statusUpdate"
payload := strings.NewReader("{\n \"cardIdentifier\": 123,\n \"target_url\": \"<string>\",\n \"hmac_enabled\": true,\n \"hmac_secret\": \"<string>\",\n \"max_retries\": 123\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://apigwuat.corpay.com/cards/statusUpdate")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"cardIdentifier\": 123,\n \"target_url\": \"<string>\",\n \"hmac_enabled\": true,\n \"hmac_secret\": \"<string>\",\n \"max_retries\": 123\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://apigwuat.corpay.com/cards/statusUpdate")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"cardIdentifier\": 123,\n \"target_url\": \"<string>\",\n \"hmac_enabled\": true,\n \"hmac_secret\": \"<string>\",\n \"max_retries\": 123\n}"
response = http.request(request)
puts response.read_body{
"status": "created",
"integration_key": "corpay.gfn.cards.statusUpdate.cardIdentifier.123426",
"webhook_id": "744317f9-ca90-4388-bb00-f2a10f1db627"
}{
"errorCode": "ER-001",
"errorDescription": "Invalid request parameters"
}{
"error": "Integration key already registered",
"integration_key": "corpay.gfn.cards.statusUpdate.cardIdentifier.123426"
}{
"errorCode": "ER-012",
"errorDescription": "The server encountered an unexpected condition and could not complete the request. Please contact Corpay Support."
}Webhooks
Register for card status updates
To get card status updates from Corpay system, register for webhook using Card Identifier. for each card the registration needs to be done separately. if hmac_enabled is set true then hmac_secret is needed. max_retries value by default it set to 1. Upon updates on card status, the data that is shared on registered target URL would contain following properties: example: cardIdentifier: 1234 previousStatus: Active newStatus: Blocked changedAt: ‘2026-01-17T10:30:00Z’
POST
/
cards
/
statusUpdate
Register for card status updates
curl --request POST \
--url https://apigwuat.corpay.com/cards/statusUpdate \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"cardIdentifier": 123,
"target_url": "<string>",
"hmac_enabled": true,
"hmac_secret": "<string>",
"max_retries": 123
}
'import requests
url = "https://apigwuat.corpay.com/cards/statusUpdate"
payload = {
"cardIdentifier": 123,
"target_url": "<string>",
"hmac_enabled": True,
"hmac_secret": "<string>",
"max_retries": 123
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
cardIdentifier: 123,
target_url: '<string>',
hmac_enabled: true,
hmac_secret: '<string>',
max_retries: 123
})
};
fetch('https://apigwuat.corpay.com/cards/statusUpdate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://apigwuat.corpay.com/cards/statusUpdate",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'cardIdentifier' => 123,
'target_url' => '<string>',
'hmac_enabled' => true,
'hmac_secret' => '<string>',
'max_retries' => 123
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://apigwuat.corpay.com/cards/statusUpdate"
payload := strings.NewReader("{\n \"cardIdentifier\": 123,\n \"target_url\": \"<string>\",\n \"hmac_enabled\": true,\n \"hmac_secret\": \"<string>\",\n \"max_retries\": 123\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://apigwuat.corpay.com/cards/statusUpdate")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"cardIdentifier\": 123,\n \"target_url\": \"<string>\",\n \"hmac_enabled\": true,\n \"hmac_secret\": \"<string>\",\n \"max_retries\": 123\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://apigwuat.corpay.com/cards/statusUpdate")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"cardIdentifier\": 123,\n \"target_url\": \"<string>\",\n \"hmac_enabled\": true,\n \"hmac_secret\": \"<string>\",\n \"max_retries\": 123\n}"
response = http.request(request)
puts response.read_body{
"status": "created",
"integration_key": "corpay.gfn.cards.statusUpdate.cardIdentifier.123426",
"webhook_id": "744317f9-ca90-4388-bb00-f2a10f1db627"
}{
"errorCode": "ER-001",
"errorDescription": "Invalid request parameters"
}{
"error": "Integration key already registered",
"integration_key": "corpay.gfn.cards.statusUpdate.cardIdentifier.123426"
}{
"errorCode": "ER-012",
"errorDescription": "The server encountered an unexpected condition and could not complete the request. Please contact Corpay Support."
}Authorizations
Use OAuth2 client credentials to obtain a bearer token.
Token endpoint:
POST <BASE_URL>/keycloak/realms/longship/protocol/openid-connect/token
Use the same base URL as the selected API server:
- Test environment:
https://apigwuat.corpay.com - Production environment:
https://apigw.corpay.com
Example:
curl --location '<BASE_URL>/keycloak/realms/longship/protocol/openid-connect/token' \
--header 'accept: application/json' \
--data-urlencode 'grant_type=client_credentials' \
--data-urlencode 'client_id=.......' \
--data-urlencode 'client_secret=......'
Body
application/json
⌘I