> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pointzero.io/llms.txt
> Use this file to discover all available pages before exploring further.

# API reference

> Base URLs, authentication, request format, object IDs and conventions shared by every endpoint of the PointZero Card Issuing API, version 2026-10.

The PointZero API is organised around REST. It accepts JSON request bodies, returns JSON responses and uses standard HTTP methods and status codes. Current version: `2026-10`.

## Base URLs

| Environment | Base URL |
| - | - |
| Production | `https://api.pointzero.io/v1` |
| Sandbox | `https://sandbox.api.pointzero.io/v1` |

Use `sk_live_` keys with production and `sk_test_` keys with the sandbox. See [Environments](/guides/environments).

## Authentication

Send your secret API key as a bearer token on every request.

```bash theme={null}
curl https://api.pointzero.io/v1/cards \
  -H "Authorization: Bearer sk_live_..."
```

More in [Authentication](/guides/authentication).

## Requests and responses

Send `Content-Type: application/json` with every `POST`, `PUT` and `PATCH` request. Each object in a response has an `object` field with its type and an `id` with a type-specific prefix.

| Prefix | Object |
| - | - |
| `prog_` | Program |
| `cus_` | Customer |
| `card_` | Card |
| `txn_` | Transaction |
| `dsp_` | Dispute |
| `wlt_` | Wallet token |
| `ord_` | Physical card order |

`PATCH` updates only the fields you send. `PUT` replaces the whole object, so include every value you want to keep.

## Conventions

<CardGroup cols={2}>
  <Card title="Amounts and currencies" icon="coins" href="/guides/amounts-and-currencies">
    Integers in minor units, ISO currency and country codes, UTC timestamps.
  </Card>

  <Card title="Pagination" icon="list" href="/guides/pagination">
    Cursor pagination with `limit` and `starting_after`.
  </Card>

  <Card title="Idempotency" icon="repeat" href="/guides/idempotency">
    Retry create requests safely with `Idempotency-Key`.
  </Card>

  <Card title="Errors" icon="triangle-exclamation" href="/guides/errors">
    Status codes, error types and the `request_id`.
  </Card>
</CardGroup>

## Resources

| Resource | What it covers |
| - | - |
| [Programs](/api-reference/programs/list-programs) | Card programs configured for your account. |
| [Customers](/api-reference/customers/create-a-customer) | Individuals and businesses that hold cards. |
| [Cards](/api-reference/cards/create-a-card) | Issue cards and manage their lifecycle and limits. |
| [Authorization controls](/api-reference/authorization-controls/retrieve-authorization-controls) | Merchant, country and channel rules. |
| [3D Secure](/api-reference/3d-secure/retrieve-3ds-settings) | 3DS settings for online payments. |
| [Wallets](/api-reference/wallets/list-wallet-tokens) | Apple Pay and Google Pay tokens. |
| [Physical cards](/api-reference/physical-cards/order-a-physical-card) | Production and delivery of plastic cards. |
| [PIN](/api-reference/pin/retrieve-pin-status) | PIN management for physical cards. |
| [Transactions](/api-reference/transactions/list-transactions) | Authorizations, refunds and settlements. |
| [Disputes](/api-reference/disputes/create-a-dispute) | Chargebacks on card transactions. |

## OpenAPI specification

The reference is generated from our OpenAPI 3.0 spec. Download [openapi.json](/api-reference/openapi.json) to generate a client or import it into Postman or Insomnia.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.