Enable or disable multiple spending permissions on a card in a single request.
This is the recommended endpoint for updating card permissions as it allows updating multiple permissions atomically.
Security
UserToken
Optional UUID for correlating requests across systems. If provided, Wise echoes it back in the response. Maximum 36 characters. Learn more.
Example:f47ac10b-58cc-4372-a567-0e02b2c3d479
- Production Environmenthttps://api.wise.com/2026Q3/spend/profiles/{profileId}/cards/{cardToken}/spending-permissions
- Sandbox Environmenthttps://api.wise-sandbox.com/2026Q3/spend/profiles/{profileId}/cards/{cardToken}/spending-permissions
curl -i -X PATCH \
https://api.wise.com/2026Q3/spend/profiles/123456/cards/ca0c8154-1e14-4464-a1ce-dcea7dc3de52/spending-permissions \
-H 'Authorization: Bearer <YOUR_JWT_HERE>' \
-H 'Content-Type: application/json' \
-H 'X-External-Correlation-Id: f47ac10b-58cc-4372-a567-0e02b2c3d479' \
-d '{
"permissions": [
{
"type": "ECOM",
"isEnabled": true
},
{
"type": "POS_CHIP",
"isEnabled": true
}
]
}'Permissions updated successfully.
Headers
Echoed back when X-External-Correlation-Id was included in the request. Learn more.
Example:"f47ac10b-58cc-4372-a567-0e02b2c3d479"
Response
No content