Skip to main content
PATCH
Tighten or freeze an agent card

Authorizations

Authorization
string
header
required

Bearer token authentication for agent-scoped endpoints. The token is the accessToken returned when redeeming a device code via POST /agents/device-codes/redeem. Agent credentials are user-scoped: all requests are automatically bound to the agent's associated customer and subject to the agent's policy.

Path Parameters

cardId
string
required

Unique identifier of the card

Body

application/json

Update request for PATCH /agents/me/cards/{cardId}. At least one field must be supplied. An agent may only tighten a card: a limit may be set or lowered but not raised or removed, blockedMccs must contain every code in the card's effectiveBlockedMccs, and allowedMccs may only lose codes once set. The only status an agent may set is FROZEN; unfreezing and loosening happen on the platform through PATCH /cards/{id}. A purchase card's spending limits are fixed at issuance: supplying maxSpendPerTransaction, maxSpendPerDay or maxTransactionsPerDay for one is a 400, while its merchant categories and status follow the rules above.

status
enum<string>

Freeze the card. New authorizations are declined.

Available options:
FROZEN
Example:

"FROZEN"

maxSpendPerTransaction
integer<int64>

A per-transaction limit at or below the current one, in the smallest unit of the card's currency.

Required range: 1 <= x <= 9007199254740991
Example:

5000

maxSpendPerDay
integer<int64>

A UTC-calendar-day spend cap at or below the current one.

Required range: 1 <= x <= 9007199254740991
Example:

20000

maxTransactionsPerDay
integer<int32>

A UTC-calendar-day transaction cap at or below the current one.

Required range: 1 <= x <= 2147483647
Example:

10

allowedMccs
string[]

Merchant category codes the card may spend at. Once set, a replacement must be a subset of the current list.

Minimum array length: 1
Pattern: ^[0-9]{4}$
Example:
blockedMccs
string[]

Merchant category codes the card declines. A replacement must contain every code in the card's effectiveBlockedMccs, so an agent can never lift a block, Grid's default agent blocks included.

Pattern: ^[0-9]{4}$
Example:

Response

Card updated

A card that belongs to the authenticated agent: the card itself and how the agent may use it.

card
object
required
agentId
string
required

The agent the card belongs to.

Example:

"Agent:019542f5-b3e7-1d02-0000-000000000042"

agentCardKind
enum<string>
required

How an agent card is used and funded.

Available options:
STANDARD,
SINGLE_USE,
MERCHANT_LOCKED
effectiveBlockedMccs
string[]
required

Every merchant category code the card declines: blockedMccs plus the categories Grid blocks for agent cards, unless the platform lifted those defaults on a STANDARD card (defaultMccBlocksLifted). A purchase card's defaults cannot be lifted.

Pattern: ^[0-9]{4}$
Example:
spendLimit
object

The issuer-enforced cap. Present for purchase cards.

reservedAmount
integer<int64>

Amount of the agent's spending limits currently held for this card, in the smallest unit of the card's currency. Present for purchase cards.

Required range: x >= 0
Example:

2300

expiresAt
string<date-time>

When Grid closes the card if it is still open. An unused SINGLE_USE card closes at this time and releases its reservation.

Example:

"2026-10-10T15:30:00Z"