Create a card
Creates a payment card for the current user. The card carries only its last four digits and expiry; no full card number is ever stored.
Authorizations
PINT (Purchase Intent) token — a JWT issued via POST /v0/sis/token/pint that encodes user-level consent for a specific scope. Sent in the x-sumvin-pint-token header alongside or instead of an x-juno-jwt JWT, depending on the integration surface (Platform vs SIS).
Headers
Tenant org ID for multi-tenant auth
Controls how timestamp fields are serialized in JSON response bodies.
Default (header omitted or any other value): epoch milliseconds as integers.
iso8601: UTC ISO 8601 strings of the form YYYY-MM-DDTHH:MM:SSZ.
Example: with X-Timestamp-Format: iso8601, the field value 1704067200000 becomes "2024-01-01T00:00:00Z".
Affected fields (recursively, in dicts and arrays): any field whose name ends in _at, plus the literal field names timestamp, period_start, and period_end. All other fields are passed through unchanged.
Only iso8601 is recognized. Any other value (or omitting the header) yields the default epoch-ms representation; the server does not reject unknown values, so this is documented as an example rather than an enum to keep generated clients permissive.
"iso8601"
Response
Card created
HAL-style hypermedia links for navigation and available actions.
A card's progress toward being usable by an agent for payments.
not_enrolled means enablement has never begun; the remaining values mirror
the underlying enrollment lifecycle. Kept separate from VisaEnrollmentStatus
deliberately (enums can't subclass with new members); the correspondence is
pinned by tests/unit/test_visa_enums.py — extend both together.
not_enrolled, pending, tokenized, enrolled, failed