Change / reset a PIN (use the CVV branch if the old PIN is forgotten)
x-on-behalf-of required
The initial PIN is set during activation: POST /v1/cards/{id}/activate accepts pin. This endpoint supports later recovery when users forget their PIN or are locked out after incorrect ATM attempts. Previously there was no recovery path: offline functions, including ATM and chip & pin, were effectively lost and replacement was the only option.
Choose one of two modes:
- Change: provide
current_pin+new_pin. - Reset: provide
cvv+new_pinwhen the old PIN is forgotten.
⚠⚠ PIN and CVV are never stored in our database or logs. They exist only in the current request's memory. To display the card number / CVV / expiry date, use POST /v1/cards/{id}/secure-session, which returns plaintext after ownership verification. Whether your own servers retain these values is your responsibility.
⚠ Every call requires step-up authentication, not only the first. The cvv branch can otherwise act as a CVV oracle: the upstream succeeds for a correct CVV and rejects an incorrect one, while CVV has only 1000 possible values. Each brute-force attempt must therefore cost one factor verification completed personally by the end user, in addition to a 5 calls/hour/member rate limit. Exceeding it returns 429 rate_limited. The limit is per member; switching cards does not reset it.
⚠ We do not validate PIN length. The upstream and card network determine it. Guessing a restriction such as exactly 4 digits would block legitimate users, while the upstream already explicitly rejects incorrect values. We reject only clearly impossible forms: empty or nondigit values.
⚠ invalid_fields also covers an incorrect CVV / old PIN, as determined by the upstream, as well as missing fields detected locally, which include a fields array. Use the presence of fields to distinguish the two cases.
Prerequisites
- The card belongs to this member.
- The issuer supports PIN management.
Path Parameters
| Field | Type | Required | Description |
|---|---|---|---|
id |
string | Required | Card ID |
Request Headers
| Field | Type | Required | Description |
|---|---|---|---|
x-idempotency-key |
string | Required | |
x-step-up |
string | Optional | The challenge_id obtained after the end user completes step-up authentication on our hosted screen. |
x-on-behalf-of |
string | Required | The member on whose behalf to call. |
Request Body
| Field | Type | Required | Description |
|---|---|---|---|
new_pin |
string | Required | New PIN, digits only. Do not store it on your side. |
current_pin |
string | Optional | Old PIN for the change branch. Supply either this or cvv. |
cvv |
string | Optional | Three-digit code on the back of the card for the reset branch when the old PIN is forgotten. Supply either this or current_pin. |
Response
{
"id": "crd_9f2c1b7a-3d51-4a2e-9c08-6b1f0d4e77aa",
"updated": true
}step_up_required: step-up authentication required. After the end user completes it, resend the same body
with the same idempotency key, adding x-step-up.
invalid_fields: missing fields (with fields) or incorrect CVV / old PIN (without fields).
state_invalid: the card status does not allow the action.
product_not_available: issuer unavailable.not_found: the card does not exist or does not belong to this member.rate_limited: more than 5 calls/hour/member. Back off; do not keep trying.curl -X POST 'https://api.zinfra.vip/v1/cards/{id}/pin' \
-H 'x-auth-token: Bearer $TOKEN' \
-H 'x-on-behalf-of: $MEMBER_ID' \
-H 'content-type: application/json' \
-d '{
"cvv": "123",
"new_pin": "4821"
}'const res = await fetch("https://api.zinfra.vip/v1/cards/{id}/pin", {
method: "POST",
headers: {
"x-auth-token": "Bearer $TOKEN",
"x-on-behalf-of": "$MEMBER_ID",
"content-type": "application/json",
},
body: JSON.stringify({
"cvv": "123",
"new_pin": "4821"
}),
});
// Keep monetary amounts as strings, never numbers.
const data = await res.json();import requests
res = requests.post(
"https://api.zinfra.vip/v1/cards/{id}/pin",
headers={
"x-auth-token": "Bearer $TOKEN",
"x-on-behalf-of": "$MEMBER_ID",
"content-type": "application/json",
},
json={
"cvv": "123",
"new_pin": "4821"
},
)
# Use Decimal(str(...)) for amounts, not float.
data = res.json()req, _ := http.NewRequest("POST", "https://api.zinfra.vip/v1/cards/{id}/pin",
strings.NewReader(`{
"cvv": "123",
"new_pin": "4821"
}`))
req.Header.Set("x-auth-token", "Bearer $TOKEN")
req.Header.Set("x-on-behalf-of", "$MEMBER_ID")
req.Header.Set("content-type", "application/json")
res, err := http.DefaultClient.Do(req)
// Decode amount fields as string, not float64.HttpRequest req = HttpRequest.newBuilder()
.uri(URI.create("https://api.zinfra.vip/v1/cards/{id}/pin"))
.header("x-auth-token", "Bearer $TOKEN")
.header("x-on-behalf-of", "$MEMBER_ID")
.header("content-type", "application/json")
.method("POST", HttpRequest.BodyPublishers.ofString("""
{
"cvv": "123",
"new_pin": "4821"
}
"""))
.build();
// Use String / BigDecimal for amounts, not double.$ch = curl_init('https://api.zinfra.vip/v1/cards/{id}/pin');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
'x-auth-token: Bearer $TOKEN',
'x-on-behalf-of: $MEMBER_ID',
'content-type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"cvv": "123",
"new_pin": "4821"
}
JSON,
]);
$res = curl_exec($ch);
// Use bcmath / strings for amounts, not floatval.
{
"id": "crd_9f2c1b7a-3d51-4a2e-9c08-6b1f0d4e77aa",
"updated": true
}