Skip to content

Bulk update card permissions

Request

Enable or disable multiple spending permissions on a card in a single request.

This is the recommended endpoint for updating card permissions as it allows updating multiple permissions atomically.

Security
UserToken
Path
profileIdinteger, (int64)required

The ID of the profile that owns the card.

Example:123456
cardTokenstring, (uuid)required

The unique token identifying the card.

Example:ca0c8154-1e14-4464-a1ce-dcea7dc3de52
Headers
X-External-Correlation-Idstring, (uuid), <= 36 characters

Optional UUID for correlating requests across systems. If provided, Wise echoes it back in the response. Maximum 36 characters. Learn more.

Example:f47ac10b-58cc-4372-a567-0e02b2c3d479
Bodyapplication/jsonrequired
permissionsArray of objects, <= 6 items, uniquerequired

List of permissions to update.

curl -i -X PATCH \
  https://api.wise.com/2026Q3/spend/profiles/123456/cards/ca0c8154-1e14-4464-a1ce-dcea7dc3de52/spending-permissions \
  -H 'Authorization: Bearer <YOUR_JWT_HERE>' \
  -H 'Content-Type: application/json' \
  -H 'X-External-Correlation-Id: f47ac10b-58cc-4372-a567-0e02b2c3d479' \
  -d '{
    "permissions": [
      {
        "type": "ECOM",
        "isEnabled": true
      },
      {
        "type": "POS_CHIP",
        "isEnabled": true
      }
    ]
  }'

Responses

Permissions updated successfully.

Headers
X-External-Correlation-Idstring, (uuid), <= 36 characters

Echoed back when X-External-Correlation-Id was included in the request. Learn more.

Example:"f47ac10b-58cc-4372-a567-0e02b2c3d479"
x-trace-idstring

Unique trace identifier assigned by Wise. Useful when contacting support about a specific request.

Example:"fba501b6d453b96789f52338f019341f"
Response
No content