Update card holder
curl --request PUT \
--url https://api.opencard.io/api/v1/application/accounts/{accountId}/organizations/{organizationId}/cardholders/{cardHolderId} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"reference_id": "employee_john_99"
}
'const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({reference_id: 'employee_john_99'})
};
fetch('https://api.opencard.io/api/v1/application/accounts/{accountId}/organizations/{organizationId}/cardholders/{cardHolderId}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.opencard.io/api/v1/application/accounts/{accountId}/organizations/{organizationId}/cardholders/{cardHolderId}"
payload = { "reference_id": "employee_john_99" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.opencard.io/api/v1/application/accounts/{accountId}/organizations/{organizationId}/cardholders/{cardHolderId}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'reference_id' => 'employee_john_99'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"id": 15,
"reference_id": "employee_john_42",
"organization_id": 3,
"identity_id": 123,
"email": "john@acme.se",
"created_at": "2026-06-08T10:00:00.000000Z",
"updated_at": "2026-06-08T10:30:00.000000Z",
"meta": {
"ssn": true,
"signed": true,
"signed_at": "2026-06-08T10:30:00.000000Z",
"email_status": "delivered",
"pdpc_url": "https://sandbox-api.opencard.io/accounts/1/pdpcs/8/sign/abc...",
"system": "Acme EMS",
"organization_number": "5561234567"
},
"identity": {
"name": "Anna Andersson",
"employee_id": "001"
}
}{
"error": "Card holder reference employee_john_42 already exists"
}Card Holders
Update card holder
reference_id is required. email is optional — omit to keep the current value (including null for identity-linked holders). Resends PDPC email only when unsigned/no identity, skip_pdpc_email is false, and an email address exists. Duplicate reference_id within the organization returns 400.
PUT
/
accounts
/
{accountId}
/
organizations
/
{organizationId}
/
cardholders
/
{cardHolderId}
Update card holder
curl --request PUT \
--url https://api.opencard.io/api/v1/application/accounts/{accountId}/organizations/{organizationId}/cardholders/{cardHolderId} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"reference_id": "employee_john_99"
}
'const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({reference_id: 'employee_john_99'})
};
fetch('https://api.opencard.io/api/v1/application/accounts/{accountId}/organizations/{organizationId}/cardholders/{cardHolderId}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.opencard.io/api/v1/application/accounts/{accountId}/organizations/{organizationId}/cardholders/{cardHolderId}"
payload = { "reference_id": "employee_john_99" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.opencard.io/api/v1/application/accounts/{accountId}/organizations/{organizationId}/cardholders/{cardHolderId}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'reference_id' => 'employee_john_99'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"id": 15,
"reference_id": "employee_john_42",
"organization_id": 3,
"identity_id": 123,
"email": "john@acme.se",
"created_at": "2026-06-08T10:00:00.000000Z",
"updated_at": "2026-06-08T10:30:00.000000Z",
"meta": {
"ssn": true,
"signed": true,
"signed_at": "2026-06-08T10:30:00.000000Z",
"email_status": "delivered",
"pdpc_url": "https://sandbox-api.opencard.io/accounts/1/pdpcs/8/sign/abc...",
"system": "Acme EMS",
"organization_number": "5561234567"
},
"identity": {
"name": "Anna Andersson",
"employee_id": "001"
}
}{
"error": "Card holder reference employee_john_42 already exists"
}Authorizations
The access token received from the authorization server in the OAuth 2.0 flow.
Path Parameters
Your account ID
Organization ID
Card holder ID
Body
application/json
Response
Updated card holder

