How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Lithic Card API

Virtual and physical card issuance, lifecycle, and digital wallet provisioning.

Lithic Card API is one of 31 APIs that Lithic publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Card. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 18 operations across 16 paths, and defines 1 schema. It is described by OpenAPI 3.2.0, at version 1.0.0.

Requests are made against 2 base URLs: https://api.lithic.com, https://sandbox.lithic.com.

18 operations 16 paths 1 schemas 10 GET1 PATCH7 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0.0
Base URL
https://api.lithic.com/v1
Authentication
API Key
Contact
License
Resource Areas
1

Authentication & Security 1

Lithic Card API declares 1 security scheme for authenticating requests. An API key is passed in the header as Authorization (ApiKeyAuth). By default, every request must be authenticated.

  • ApiKeyAuth — Raw API secret key value (not prefixed with "Bearer").

Paths & Operations 18

Across 16 paths, the API surfaces 18 operations — 10 GET, 1 PATCH, 7 POST. Each is listed below with its method, path, parameters, and response codes.

Card 18

Virtual and physical card issuance, lifecycle, and digital wallet provisioning.

GET
/v1/cards/{card_token}/signals
Fetch card signals
getCardSignals 1 param → 200401422
GET
/v1/card_programs
List card programs
getCardPrograms → 200401422
GET
/v1/card_programs/{card_program_token}
Get card program
getCardProgram → 200401422
GET
/v1/cards
List cards
getCards → 200401422
POST
/v1/cards
Create card
postCards body → 200401422
POST
/v1/cards/search_by_pan
Search for card by PAN
searchCardByPan body → 200401422
GET
/v1/cards/{card_token}
Get card
getCardByToken → 200401422
PATCH
/v1/cards/{card_token}
Update card
patchCardByToken body → 200401422
GET
/v1/cards/{card_token}/balances
Get card balances
getCardBalance → 200401422
GET
/v1/cards/{card_token}/financial_transactions
List card financial transactions
getCardFinancialTransactions → 200401422
GET
/v1/cards/{card_token}/financial_transactions/{financial_transaction_token}
Get card financial transaction
getCardFinancialTransactionByToken → 200401422
POST
/v1/cards/{card_token}/provision
Provision card (Digital Wallet)
postCardProvision body → 200401422
POST
/v1/cards/{card_token}/web_provision
Web Push Provision card (Digital Wallet)
postCardWebProvision body → 200401422
POST
/v1/cards/{card_token}/reissue
Reissue physical card
postCardReissue body → 200401422
POST
/v1/cards/{card_token}/renew
Renew a card
postCardRenew body → 200401422
POST
/v1/cards/{card_token}/convert_physical
Convert virtual to physical card
postConvertPhysical body → 200401422
GET
/v1/cards/{card_token}/spend_limits
Get card's available spend limit
getCardSpendLimits → 200401422
GET
/v1/embed/card
Embedded card UI
getEmbedCard → 200401422

Schemas 1

The contract defines 1 schema that model the data the API accepts and returns. The most detailed is Card (2 properties). Each schema is shown below with its type and property counts.

Card
object
Virtual and physical card issuance, lifecycle, and digital wallet provisioning.
2 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

lithic-com-card-api-openapi.yml Raw ↑

Other APIs Lithic publishes across the network.

Lithic 3DS API
Lithic Account API
Lithic Account Holder API
Lithic Auth Rules API
Lithic Auth Stream Access (ASA) API
Lithic Balance API
Lithic Book Transfer API
Lithic Card Authorizations API
Lithic Card Bulk Orders API
Lithic Chargeback API
Lithic Credit Product API
Lithic Event API
Where this information came from

This is an independent, third-party profile of Lithic Card API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.