How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Toqio Card actions API

The Card actions API from Toqio — 7 operation(s) for card actions.

Toqio Card actions API is one of 49 APIs that Toqio publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Card actions. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 8 operations across 7 paths, and defines 12 schemas. It is described by OpenAPI 3.2.0, at version 100.

Requests are made against 2 base URLs: https://api.sandbox.toq.io/wallet, https://api.toq.io/wallet.

8 operations 7 paths 12 schemas 1 DELETE2 GET1 POST4 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
100
Base URL
https://api.toq.io/wallet/api
Authentication
OAuth 2.0, OAuth 2.0
Resource Areas
1

Authentication & Security 2

Toqio Card actions API declares 2 security schemes for authenticating requests. It supports OAuth 2.0 (bearer-jwt) using the password flow. It supports OAuth 2.0 (clientCredentials) using the clientCredentials flow. By default, every request must be authenticated.

Paths & Operations 8

Across 7 paths, the API surfaces 8 operations — 1 DELETE, 2 GET, 1 POST, 4 PUT. Each is listed below with its method, path, parameters, and response codes.

Card actions 8
PUT
/api/customers/{customerId}/cards/{cardId}/activate
Activate card
activateCard 2 params body → 200401403404
DELETE
/api/customers/{customerId}/cards/{cardId}
Cancel card
cancelCard 2 params → 200401403404
GET
/api/customers/{customerId}/cards/{cardId}
Get card
getCard 2 params → 200401403404
GET
/api/customers/{customerId}/clients/{clientId}/cards
Get cards by client
getCardsByClient 14 params → 200201401403404
POST
/api/customers/{customerId}/cards
Issue card
issueCardUsingPOST 1 param body → 200201401403404
PUT
/api/customers/{customerId}/cards/{cardId}/suspend
Suspend card
suspendCard 2 params body → 200201401403404
PUT
/api/customers/{customerId}/clients/{clientId}/card/{cardId}
Update card
updateCard 3 params body → 200401403404
PUT
/api/customers/{customerId}/clients/{clientId}/card/{cardId}/updateAlias
Update card alias
updateCardAliasUsingPUT 3 params body → 200201401403404

Schemas 12

The contract defines 12 schemas that model the data the API accepts and returns. The most detailed are ViewCardDTO (30 properties), IssueCardViaAPIDTO (26 properties), ApiCardDTO (26 properties), AccountSummaryDTO (11 properties). Each schema is shown below with its type and property counts.

CardAddress
object
Required for physical cards. Physical card will be shipped to this address.
7 properties
AuthenticationResponse
object
Only available for Modulr users.
2 properties
UpdateCardDTO
object
10 properties
IssueCardViaAPIDTO
object
26 properties 4 required
CardMask
object
4 properties
ViewCardDTO
object
30 properties
ApiCardDTO
object
26 properties
FreezeReasonDTO
object
1 property 1 required
CardDesignDTO
object
7 properties
SecurityQuestionDTO
object
Users must answer at least one question. Answers are case sensitive
5 properties
CardTokenDTO
object
2 properties
AccountSummaryDTO
object
11 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

toqio-card-actions-api-openapi.yml Raw ↑

Other APIs Toqio publishes across the network.

Toqio Account API
Toqio Account information API
Toqio API Endpoints API
Toqio Beneficiary actions API
Toqio Beneficiary API
Toqio Card Details API
Toqio Card Lifecycle API
Toqio Card Limits API
Toqio Client accounts information API
Toqio Client actions API
Toqio Client information API
Toqio Compliance API
Where this information came from

This is an independent, third-party profile of Toqio Card actions API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.