card.application.awaiting_bind
Physical card ready to bind
When Emitted
Emitted after the physical card reaches the user and the application enters awaiting_bind. Standard applications
under downstream inventory mode automatically move to this state through an in-person handover after approval and entry into the fulfillment queue.
Platform-direct fulfillment requires confirmation of an offline handover or a shipment marked as received by the user.
data.id is the public card application ID, already prefixed with cap_.
Retrieve GET /v1/cards/applications/{data.id}, then call
POST /v1/cards/bind → POST /v1/cards/{id}/activate.
This does not mean issuance is complete: the card is not activated, so do not present it as available.
Neither shipped alone, while the card is in transit, nor pending_activation after binding emits this event.
Successful activation still uses card.application.approved and card.status.updated.
⚠ Not emitted for platform-direct members.
Payload
{
"event_id": "evt_b7c1e02a9d3f4e18ac552d61ab0f9e77",
"event_type": "card.application.awaiting_bind",
"created_at": "2026-09-21T06:37:35Z",
"merchant_id": "acme",
"livemode": true,
"data": {
"object": "card_application",
"id": "cap_9c41f0a8-27d5-4e63-b0a9-1f7c85d2e340",
"external_member_id": "u_88123",
"status": "awaiting_bind",
"status_version": 5
}
}
Payload Fields
| Field | Type | Description |
|---|---|---|
id | string | Use this for deduplication. evt_… remains unchanged when the same event is redelivered. |
type | string | Always card.application.awaiting_bind |
created_at | string | Time the event was created (RFC3339), not its delivery time. It is unchanged on redelivery. |
data.object | string | Object type; determines which endpoint to query with data.id |
data.id | string | Object ID; use it to retrieve details. |
data.status | string | Treat unrecognized values as unknown and raise an alert; do not fall back to “processing” |
data.status_version | number | Monotonically increasing; use it to discard older states that arrive late. |
Signature Verification and Deduplication
Verify the signature against the raw request body bytes. Do not parse and reserialize the JSON: your JSON library may change key order or whitespace, which changes the signature and can look like a key configuration error.
// Node · Run before parsing JSON
const raw = await readRawBody(req); // Buffer / string; do not use parsed req.body
const expect = crypto.createHmac("sha256", WEBHOOK_SECRET).update(raw).digest("hex");
const got = req.headers["z-signature"]; // Format: t=<unix>,v1=<hex>
if (!timingSafeEqual(expect, parseV1(got))) return res.status(400).end();
// Deduplicate using the envelope id, not data.id
if (await seen(JSON.parse(raw).id)) return res.status(200).end();
For the full procedure, including timestamp tolerance and redelivery semantics, see Webhook Guide.