You can use an OAuth2 JWT bearer token in the Authorization header of your API requests for supported endpoints: Authorization: Bearer <YOUR_JWT_HERE> .
These tokens are valid for 10 minutes and can be requested via the access token endpoint endpoint.
Idempotency key to be used.
Sending again the same key would return the same result without re-executing the update.
Identifier of the resource in Payrails.
New status of the Instrument. If you want to change to "deleted" , you should use the DELETE endpoint instead. Also, note that some status are internal and cannot be changed via API, e.g. transient , etc. Status update requests can also be rejected if an instrument status cannot be changed to the desired one, e.g. deleted instruments.
Available options:
enabled,
disabled
networkTransactionReference
Identifier of the initial payment made with this instrument on the Networks, e.g. Mastercard Trace ID or Visa Transaction ID.
Mastercard Transaction Link Identifier (TLID) of the transaction series this instrument belongs to. Returned by the card network on the initial cardholder-initiated transaction and required on economically related merchant-initiated transactions, such as recurring payments and installments, when the series spans payment providers.
Merchant-provided reference for the instrument.
New payment method of the instrument. Only the methods supporting instruments are accepted.
Available options:
applePay,
card,
googlePay,
payPal
True if the holder wants to make this instrument as default.
Information about a physical address.
The name of the street of a postal address.
billingAddress. doorNumber
The number on the door, building, or room.
billingAddress. complement
Additional addressing information, 2nd line of postal address.
The name of the suburb or area within a city.
The name of the city of a postal address.
billingAddress. postalCode
The name of the state a postal address is in.
The country where the address is in.
billingAddress.country. code
ISO 3166-1 alpha-2 country code.
Pattern: ^[A-Z]{2}$
billingAddress.country. iso3
ISO 3-letter country code. Returned by Payrails, but not interpreted in requests.
Pattern: ^[A-Z]{3}$
billingAddress.country. name
The English name of the country. Returned by Payrails, but not interpreted in requests.
Latitude of the address in the GPS coordinate system.
Longitude of the address in the GPS coordinate system.
The phone to contact in the address (can be different that the customer's).
billingAddress.phone. number
The local number of the phone, such that countryCode + number can be dialed.
Pattern: ^[0-9]+$
billingAddress.phone. countryCode
International prefix of the phone, if known separately.
Pattern: ^\+?[0-9]+$
Name of the address, e.g. home, work.
Name of the person to whom the address belongs to.
Last name of the person to whom the address belongs to.
Email of the person to whom the address belongs to.
createdAt
string<date-time>
required
Date and time when the Instrument was created in Payrails.
updatedAt
string<date-time>
required
When the Instrument was last updated.
Unique identifier of the Holder in Payrails.
Represents the payment method type.
Available options:
alexBankMa7fazty,
applePay,
audi2pay,
bankAccount,
card,
2c2p,
vietQR,
cibSmartWallet,
easypaisa,
etisalatCash,
fawryMobileWallet,
fawryPay,
googlePay,
jazzCash,
nbePhoneCash,
orangeCash,
payPal,
qnbEWallet,
weCash,
genericRedirect,
alfa,
konnect,
eftPro,
netBanking,
upi,
cashFreeWallet,
paytmWallet,
phonePe,
iDeal,
bancontact,
klarnaPayLater,
klarnaPayNow,
klarnaPayOverTime,
scalapay,
payNow,
atome
Status of the instrument.
Available options:
created,
deleted,
enabled,
disabled,
transient
Instrument name suitable for display.
Description of the instrument.
True if this instrument is set as default for the holder.
Merchant-provided reference for the instrument.
System-wide unique identifier of the Instrument. If two Holders have the same instrument stored, this value will be the same for both, but the instrument and token IDs will be different. Cannot be used for payments, should only be used for analytics and fraud prevention.
Represents the future usage to define the payment flows that the stored instrument will be used for.
Available options:
Subscription,
CardOnFile,
UnscheduledCardOnFile
networkTransactionReference
Identifier of the initial payment made with this instrument on the Networks, e.g. Mastercard Trace ID or Visa Transaction ID.
Mastercard Transaction Link Identifier (TLID) of the transaction series this instrument belongs to. Returned by the card network on the initial cardholder-initiated transaction and required on economically related merchant-initiated transactions, such as recurring payments and installments, when the series spans payment providers.
Type-specific information about the instrument.
Card
BankAccount
PayPal
GooglePay
ApplePay
DCB
MBWay
Network of the instrument.
Available options:
unspecified,
visa,
visadankort,
mastercard,
amex,
diners,
discover,
unionpay,
unionpayuzcard,
maestro,
maestrobancontact,
hipercard,
jcb,
jcblankapay,
argencard,
aura,
belkart,
bpfuelcard,
cabal,
carnet,
cirrus,
chjonesfuelcard,
uzcard,
codensa,
dankort,
dinacard,
duet,
ebt,
eftpos,
elo,
euroshellfuelcard,
gecapital,
bc,
hrgstore,
humo,
lankapay,
lukoilfuelcard,
bancontact,
meeza,
newday,
mir,
ourocard,
pagobancomat,
paypak,
paypal,
phhfuelcard,
prostir,
rupay,
sbercard,
sodexo,
starrewards,
cencosud,
naranja,
troy,
uatp,
ukfuelcard,
verve,
voyager,
vpay,
wex,
cmi,
atm,
bankcard,
localbrand,
loyalty,
privatelabel,
fuelcard,
redfuelcard,
redliquidfuelcard
First 6-8 digits of the Card number. Also known as IIN (Issuer Identification Number).
Required string length: 6 - 8
Last digits of the Card number.
Required string length: 4
Network of the instrument.
Available options:
unspecified,
visa,
visadankort,
mastercard,
amex,
diners,
discover,
unionpay,
unionpayuzcard,
maestro,
maestrobancontact,
hipercard,
jcb,
jcblankapay,
argencard,
aura,
belkart,
bpfuelcard,
cabal,
carnet,
cirrus,
chjonesfuelcard,
uzcard,
codensa,
dankort,
dinacard,
duet,
ebt,
eftpos,
elo,
euroshellfuelcard,
gecapital,
bc,
hrgstore,
humo,
lankapay,
lukoilfuelcard,
bancontact,
meeza,
newday,
mir,
ourocard,
pagobancomat,
paypak,
paypal,
phhfuelcard,
prostir,
rupay,
sbercard,
sodexo,
starrewards,
cencosud,
naranja,
troy,
uatp,
ukfuelcard,
verve,
voyager,
vpay,
wex,
cmi,
atm,
bankcard,
localbrand,
loyalty,
privatelabel,
fuelcard,
redfuelcard,
redliquidfuelcard
Information about an issuer by the given BIN (or IIN).
First 6-8 digits of the Card number. Also known as IIN (Issuer Identification Number).
Required string length: 6 - 8
Network of the instrument.
Available options:
unspecified,
visa,
visadankort,
mastercard,
amex,
diners,
discover,
unionpay,
unionpayuzcard,
maestro,
maestrobancontact,
hipercard,
jcb,
jcblankapay,
argencard,
aura,
belkart,
bpfuelcard,
cabal,
carnet,
cirrus,
chjonesfuelcard,
uzcard,
codensa,
dankort,
dinacard,
duet,
ebt,
eftpos,
elo,
euroshellfuelcard,
gecapital,
bc,
hrgstore,
humo,
lankapay,
lukoilfuelcard,
bancontact,
meeza,
newday,
mir,
ourocard,
pagobancomat,
paypak,
paypal,
phhfuelcard,
prostir,
rupay,
sbercard,
sodexo,
starrewards,
cencosud,
naranja,
troy,
uatp,
ukfuelcard,
verve,
voyager,
vpay,
wex,
cmi,
atm,
bankcard,
localbrand,
loyalty,
privatelabel,
fuelcard,
redfuelcard,
redliquidfuelcard
data.binLookup. localNetwork
Card local network that supports the card, e.g. CartesBancaires, Dankort, Mada, Bancontact.
Available options:
bancontact,
cartesbancaires,
dankort,
mada
Name of the bank or institution that issued the card.
data.binLookup. issuerCountry
Country of the bank or institution that issued the card.
data.binLookup.issuerCountry. code
ISO 3166-1 alpha-2 country code.
Pattern: ^[A-Z]{2}$
data.binLookup.issuerCountry. iso3
ISO 3-letter country code. Returned by Payrails, but not interpreted in requests.
Pattern: ^[A-Z]{3}$
data.binLookup.issuerCountry. name
The English name of the country. Returned by Payrails, but not interpreted in requests.
Segment of the card, e.g. gold, black, business.
Type of the card, e.g. credit, debit, prepaid, gift.
data.binLookup. typeDetails
More information about the card type, e.g. personal, commercial.
data.binLookup. isNetworkToken
Indicates whether the card credential represents a network token rather than a primary account number (PAN).
data.binLookup. isFlexCard
Indicates whether the card is enrolled in a Flexible Credential or Flex Card program supported by the network - e.g. Visa Flexible Credential, Mastercard FlexCard.
Billing Address of the instrument.
data.billingAddress. street
The name of the street of a postal address.
data.billingAddress. doorNumber
The number on the door, building, or room.
data.billingAddress. complement
Additional addressing information, 2nd line of postal address.
The name of the suburb or area within a city.
The name of the city of a postal address.
data.billingAddress. postalCode
data.billingAddress. state
The name of the state a postal address is in.
data.billingAddress. country
The country where the address is in.
data.billingAddress.country. code
ISO 3166-1 alpha-2 country code.
Pattern: ^[A-Z]{2}$
data.billingAddress.country. iso3
ISO 3-letter country code. Returned by Payrails, but not interpreted in requests.
Pattern: ^[A-Z]{3}$
data.billingAddress.country. name
The English name of the country. Returned by Payrails, but not interpreted in requests.
data.billingAddress. latitude
Latitude of the address in the GPS coordinate system.
data.billingAddress. longitude
Longitude of the address in the GPS coordinate system.
data.billingAddress. phone
The phone to contact in the address (can be different that the customer's).
data.billingAddress.phone. number
The local number of the phone, such that countryCode + number can be dialed.
Pattern: ^[0-9]+$
data.billingAddress.phone. countryCode
International prefix of the phone, if known separately.
Pattern: ^\+?[0-9]+$
data.billingAddress. alias
Name of the address, e.g. home, work.
Name of the person to whom the address belongs to.
data.billingAddress. lastName
Last name of the person to whom the address belongs to.
data.billingAddress. email
Email of the person to whom the address belongs to.
Expiry month of the Card.
Required string length: 2
Required string length: 4
Name of the owner of the Card.
Payer-provided tax identification number (e.g. CPF in Brazil) collected on the instrument.
List of tokens inside the instrument. Not included by default, includeTokens query parameter must be used.
Id of the token in Payrails.
tokens. createdAt
string<date-time>
required
Date and time when the Token was created in Payrails.
tokens. updatedAt
string<date-time>
required
When the Token was last updated.
Id of the payment instrument the token belongs to.
Available options:
created,
enabled,
disabled,
deleted
Available options:
network,
vault,
psp,
networkOffers,
networkGateway
Id of the provider the token belongs to.
Unique identifier of the token in the provider's system.
Id of the configuration in the provider the token belongs to.
Any merchant or provider-specific data that should be stored for context in the token.
Last modified on October 9, 2026