card.application.approved
Card issued successfully and available for use
When Emitted
Emitted after the issuer successfully issues the card and the card record is stored.
data.id is the public card application ID, already prefixed with cap_; retrieve it through GET /v1/cards/applications/{data.id}.
To retrieve the card itself, use GET /v1/cards with x-on-behalf-of: <external_member_id>.
⚠ Before 2026-08-13 this event contained the internal member ID, despite data.object being
card_application; retrieval inevitably returned 404. This is fixed. Follow the convention above.
Execution failure or cardholder rejection that fails the application emits card.application.rejected.
Payload
{
"event_id": "evt_2e6c98a04f1b47d3850ac7e195b3d602",
"event_type": "card.application.approved",
"created_at": "2026-08-12T16:03:27Z",
"merchant_id": "acme",
"livemode": true,
"data": {
"object": "card_application",
"id": "cap_9c41f0a8-27d5-4e63-b0a9-1f7c85d2e340",
"external_member_id": "u_88123",
"status": "approved",
"status_version": 5
}
}
Payload Fields
| Field | Type | Description |
|---|---|---|
id | string | Use this for deduplication. evt_… remains unchanged when the same event is redelivered. |
type | string | Always card.application.approved |
created_at | string | Time the event was created (RFC3339), not its delivery time. It is unchanged on redelivery. |
data.object | string | Object type; determines which endpoint to query with data.id |
data.id | string | Object ID; use it to retrieve details. |
data.status | string | Treat unrecognized values as unknown and raise an alert; do not fall back to “processing” |
data.status_version | number | Monotonically increasing; use it to discard older states that arrive late. |
Signature Verification and Deduplication
Verify the signature against the raw request body bytes. Do not parse and reserialize the JSON: your JSON library may change key order or whitespace, which changes the signature and can look like a key configuration error.
// Node · Run before parsing JSON
const raw = await readRawBody(req); // Buffer / string; do not use parsed req.body
const expect = crypto.createHmac("sha256", WEBHOOK_SECRET).update(raw).digest("hex");
const got = req.headers["z-signature"]; // Format: t=<unix>,v1=<hex>
if (!timingSafeEqual(expect, parseV1(got))) return res.status(400).end();
// Deduplicate using the envelope id, not data.id
if (await seen(JSON.parse(raw).id)) return res.status(200).end();
For the full procedure, including timestamp tolerance and redelivery semantics, see Webhook Guide.