Unfreeze a card (transitional state: unfreezing; separate endpoint from freezing)
On behalf of a member ·
x-on-behalf-of required
Requires x-idempotency-key
The target state is active; the transitional state is unfreezing, not freezing. The previously reduced spending limit is restored at the same time.
⚠ risk_frozen cannot be unfrozen by you. It is imposed by our risk controls and can be lifted only through our administration system. Showing an Unfreeze button for it guarantees a failed request. Read status from GET /v1/cards/{id}: only frozen can be unfrozen by you. suspended, an operations suspension, requires restoration rather than unfreezing and is also excluded.
An empty request object ({}) is sufficient.
Prerequisites
- The card status is
frozen;risk_frozen/suspendedare controlled by us and cannot be unfrozen by a merchant.
Path Parameters
| Field | Type | Required | Description |
|---|---|---|---|
id |
string | Required | Card ID |
Request Headers
| Field | Type | Required | Description |
|---|---|---|---|
x-on-behalf-of |
string | Required | The member on whose behalf to call. |
Response
200Accepted; the card has entered a transitional state.
{
"id": "crd_9f2c1b7a-3d51-4a2e-9c08-6b1f0d4e77aa",
"status": "unfreezing"
}400
state_invalid: the current status cannot be unfrozen. product_not_available: issuer unavailable.
idempotency_key_required / idempotency_key_invalid.
⚠ Risk freezes (risk_frozen) and upstream rejections both currently return 500 api_error.404
not_found: the card does not exist or does not belong to this member.Emitted Events
Green = successful terminal state · Red = terminal state requiring action · Purple = intermediate state. Open an event for its payload and signature verification details.
Request
curl -X POST 'https://api.zinfra.vip/v1/cards/{id}/unfreeze' \
-H 'x-auth-token: Bearer $TOKEN' \
-H 'x-on-behalf-of: $MEMBER_ID' \
-H 'x-idempotency-key: $IDEMPOTENCY_KEY'const res = await fetch("https://api.zinfra.vip/v1/cards/{id}/unfreeze", {
method: "POST",
headers: {
"x-auth-token": "Bearer $TOKEN",
"x-on-behalf-of": "$MEMBER_ID",
"x-idempotency-key": "$IDEMPOTENCY_KEY",
},
});
// Keep monetary amounts as strings, never numbers.
const data = await res.json();import requests
res = requests.post(
"https://api.zinfra.vip/v1/cards/{id}/unfreeze",
headers={
"x-auth-token": "Bearer $TOKEN",
"x-on-behalf-of": "$MEMBER_ID",
"x-idempotency-key": "$IDEMPOTENCY_KEY",
},
)
# Use Decimal(str(...)) for amounts, not float.
data = res.json()req, _ := http.NewRequest("POST", "https://api.zinfra.vip/v1/cards/{id}/unfreeze",
nil)
req.Header.Set("x-auth-token", "Bearer $TOKEN")
req.Header.Set("x-on-behalf-of", "$MEMBER_ID")
req.Header.Set("x-idempotency-key", "$IDEMPOTENCY_KEY")
res, err := http.DefaultClient.Do(req)
// Decode amount fields as string, not float64.HttpRequest req = HttpRequest.newBuilder()
.uri(URI.create("https://api.zinfra.vip/v1/cards/{id}/unfreeze"))
.header("x-auth-token", "Bearer $TOKEN")
.header("x-on-behalf-of", "$MEMBER_ID")
.header("x-idempotency-key", "$IDEMPOTENCY_KEY")
.method("POST", HttpRequest.BodyPublishers.noBody())
.build();
// Use String / BigDecimal for amounts, not double.$ch = curl_init('https://api.zinfra.vip/v1/cards/{id}/unfreeze');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
'x-auth-token: Bearer $TOKEN',
'x-on-behalf-of: $MEMBER_ID',
'x-idempotency-key: $IDEMPOTENCY_KEY',
],
]);
$res = curl_exec($ch);
// Use bcmath / strings for amounts, not floatval.
200
{
"id": "crd_9f2c1b7a-3d51-4a2e-9c08-6b1f0d4e77aa",
"status": "unfreezing"
}