Z Zise Developers 简体中文

Transfer funds from a card to the wallet (not an on-chain withdrawal)

POST /v1/cards/{id}/withdrawals scope: cards:write
On behalf of a member · x-on-behalf-of required Requires x-idempotency-key Moves funds · Card funds (`member.card` bucket) → member available balance; fees follow product configuration.
This endpoint moves funds

See the response table below for failure handling. Retry timeouts (504) with the same idempotency key — we may already have processed the request; use a new key after a business failure; the same key replays that failure.

Returns card funds to the member's available balance. This is not an on-chain withdrawal: funds never leave our platform. On-chain withdrawals use the separate withdrawals business line.

⚠ Returns only the card currency (USD), not the original funding asset. A card topped up with USDT returns USD when funds are withdrawn. To obtain USDT, perform a separate formal exchange. State this in your interface: a promise to return the original asset would make users believe their assets had been withheld.

⚠ Before creating the order, the amount is rounded down to the upstream's supported precision, two decimal places for USD. Sending "10.505" actually withdraws 10.50. Rounding down is deliberate: the card does not contain the extra fraction that rounding up would return.

Like top-ups, this uses two asynchronous stages: 201 only means accepted; credit is confirmed by card.withdraw.completed. Shared-limit cards may already return completed with 201, but still emit this event. Reusing the same idempotency key replays the original outcome, including failure.

Prerequisites

  • The card belongs to this member.
  • The member is not in funds-protection mode.
  • Amount ≤ withdrawable maximum: upstream balance minus authorized but unsettled holds, capped at the card funds recorded in our ledger.

Path Parameters

FieldTypeRequiredDescription
id string Required Card ID
FieldTypeRequiredDescription
x-on-behalf-of string Required The member on whose behalf to call.

Request Body

FieldTypeRequiredDescription
amount string Required Withdrawal amount, a decimal string in the card currency.USD is rounded down to two decimal places in practice: "10.50".

Response

201Accepted. status: processing (awaiting upstream confirmation) · completed (shared-limit card completed immediately).
{
  "id": "cwd_5b1c7e08-2f94-4a6d-9c33-71ae0d4b8265",
  "status": "processing"
}
400product_not_available: issuer or product unavailable. state_invalid: card status does not allow the action. idempotency_key_required / idempotency_key_invalid. ⚠ Exceeding the withdrawable amount, upstream rejection, and funds-protection mode currently return 500 api_error (internal codes exist but are not registered in the public catalog).
404not_found: the card does not exist or does not belong to this member.
504upstream_timeout: outcome unknown; retry with the same idempotency key.

Emitted Events

Green = successful terminal state · Red = terminal state requiring action · Purple = intermediate state. Open an event for its payload and signature verification details.

Request
curl -X POST 'https://api.zinfra.vip/v1/cards/{id}/withdrawals' \
  -H 'x-auth-token: Bearer $TOKEN' \
  -H 'x-on-behalf-of: $MEMBER_ID' \
  -H 'x-idempotency-key: $IDEMPOTENCY_KEY' \
  -H 'content-type: application/json' \
  -d '{
    "amount": "10.50"
  }'
const res = await fetch("https://api.zinfra.vip/v1/cards/{id}/withdrawals", {
  method: "POST",
  headers: {
    "x-auth-token": "Bearer $TOKEN",
    "x-on-behalf-of": "$MEMBER_ID",
    "x-idempotency-key": "$IDEMPOTENCY_KEY",
    "content-type": "application/json",
  },
  body: JSON.stringify({
    "amount": "10.50"
  }),
});
// Keep monetary amounts as strings, never numbers.
const data = await res.json();
import requests

res = requests.post(
    "https://api.zinfra.vip/v1/cards/{id}/withdrawals",
    headers={
        "x-auth-token": "Bearer $TOKEN",
        "x-on-behalf-of": "$MEMBER_ID",
        "x-idempotency-key": "$IDEMPOTENCY_KEY",
        "content-type": "application/json",
    },
    json={
      "amount": "10.50"
    },
)
# Use Decimal(str(...)) for amounts, not float.
data = res.json()
req, _ := http.NewRequest("POST", "https://api.zinfra.vip/v1/cards/{id}/withdrawals",
    strings.NewReader(`{
  "amount": "10.50"
}`))
req.Header.Set("x-auth-token", "Bearer $TOKEN")
req.Header.Set("x-on-behalf-of", "$MEMBER_ID")
req.Header.Set("x-idempotency-key", "$IDEMPOTENCY_KEY")
req.Header.Set("content-type", "application/json")
res, err := http.DefaultClient.Do(req)
// Decode amount fields as string, not float64.
HttpRequest req = HttpRequest.newBuilder()
    .uri(URI.create("https://api.zinfra.vip/v1/cards/{id}/withdrawals"))
    .header("x-auth-token", "Bearer $TOKEN")
    .header("x-on-behalf-of", "$MEMBER_ID")
    .header("x-idempotency-key", "$IDEMPOTENCY_KEY")
    .header("content-type", "application/json")
    .method("POST", HttpRequest.BodyPublishers.ofString("""
{
  "amount": "10.50"
}
"""))
    .build();
// Use String / BigDecimal for amounts, not double.
$ch = curl_init('https://api.zinfra.vip/v1/cards/{id}/withdrawals');
curl_setopt_array($ch, [
  CURLOPT_CUSTOMREQUEST => 'POST',
  CURLOPT_RETURNTRANSFER => true,
  CURLOPT_HTTPHEADER => [
    'x-auth-token: Bearer $TOKEN',
    'x-on-behalf-of: $MEMBER_ID',
    'x-idempotency-key: $IDEMPOTENCY_KEY',
    'content-type: application/json',
  ],
  CURLOPT_POSTFIELDS => <<<'JSON'
{
  "amount": "10.50"
}
JSON,
]);
$res = curl_exec($ch);
// Use bcmath / strings for amounts, not floatval.
201
{
  "id": "cwd_5b1c7e08-2f94-4a6d-9c33-71ae0d4b8265",
  "status": "processing"
}