1. Issuing
PIK
  • Start
    • Getting Started
  • Authentication
    • Authentication Token
      POST
  • Global Account
    • Contacts
      • Create Contact
      • List Contacts
      • Get Contact
      • Count Contacts
    • Virtual Accounts
      • Create Virtual Account
      • List Virtual Accounts
      • Get Virtual Account
    • Transactions
      • List Transactions
      • Get Transaction
    • Account Balance
      • List Account Balances
      • Get Balance by Currency
    • Payout
      • Create Payout
  • Payment Links
    • Payment Links
      • Create Payment Link
      • Update Payment Link
      • Get Payment Link Detail
      • Get Payment Link List
    • Transactions
      • Get Transaction List
  • Issuing
    • Card Products
      • List Card Products
    • Cardholders
      • Create Cardholder
      • List Cardholders
      • Get Cardholder
    • Cards
      • Issue Card
      • List Cards
      • Get Card
      • Create Card Secure Session
      • Adjust Card Limit
      • Freeze Card
      • Unfreeze Card
    • Transactions
      • List Transactions
      • Get Transaction
  • Webhook
    • Global Account
      • Deposit Webhook
      • Payout Webhook
      • Virtual Account Webhook
    • Payment Links
      • Overview
      • Order Collect Out Webhook
      • Customer Payment Webhook
      • Customer Refund Webhook
      • Master Recharge Webhook
      • Web3 Direct Payment Webhook
      • Withdraw Out Webhook
    • Issuing
      • Card Operation Failed
      • Card OTP
      • Card Updated
      • Transaction Completed
      • Transaction Declined
      • Transaction Refunded
      • Transaction Reversed
      • Card Activated
      • Card Failed
  1. Issuing

Card OTP

card.otp — delivered when the card network issues a one-time passcode (OTP) for one of your
cards. You deliver the passcode to the cardholder.

When it fires#

sceneWhen
THREE_DSThe cardholder is paying online and the merchant requires 3D Secure verification
WALLET_BINDINGThe cardholder is adding the card to a mobile wallet (Google Pay / Apple Pay)
The cardholder is waiting on a verification page while this event is in flight. Deliver the
passcode through your own channel — your app, SMS, or email — as quickly as you can.
PIK does not email the passcode to the cardholder while your webhook is set up. If your Issuing
credential has no webhook URL, or its webhook is switched off, PIK falls back to emailing the
address you supplied for the cardholder.

How it differs from other events#

Other eventscard.otp
Retries5 attempts, 5 minutes apartOne immediate retry only, then dropped. The retry carries the same eventId and occurredAt
Your time budget10 seconds5 seconds
Recoverable laterYes — query the card or transaction through the APINo — PIK never stores the passcode
The passcode expires within minutes, so a late delivery is useless. If a delivery is lost, the
cardholder requests a new code on the verification page and a new card.otp follows.

Payload#

Envelope#

FieldTypeDescription
eventIdstringUnique per event, and unchanged on the retry. Deduplicate on this value
eventTypestringAlways card.otp
versionstringPayload schema version. Additive changes do not bump it
occurredAtstringWhen PIK first assembled the event; unchanged on the retry (ISO 8601)
dataobjectSee below

data#

FieldTypeDescription
cardNostringPIK card number
scenestringTHREE_DS / WALLET_BINDING. Tolerate values not listed here
otpstringThe passcode. A live credential — see Handling below
referenceCodestringTHREE_DS only: reference code also shown on the cardholder's verification page, so they can tell it is the same request. Otherwise null
transactionAmountstringTHREE_DS only: amount of the purchase being verified. Otherwise null
transactionCurrencystringTHREE_DS only: currency of the purchase. Otherwise null
merchantNamestringTHREE_DS only: merchant name. Otherwise null
walletTypestringWALLET_BINDING only: GOOGLE_PAY / APPLE_PAY. Otherwise null
Show the cardholder the merchant and amount together with the passcode, so they can refuse a
request they did not start.

Example — 3D Secure#

{
  "eventId": "evt_260923K7Q2M9X4TB",
  "eventType": "card.otp",
  "version": "1.0",
  "occurredAt": "2026-09-23T06:02:11Z",
  "data": {
    "cardNo": "CD260811X9Y8Z7",
    "scene": "THREE_DS",
    "otp": "482913",
    "referenceCode": "RC7F",
    "transactionAmount": "40.00",
    "transactionCurrency": "USD",
    "merchantName": "STEAM PURCHASE",
    "walletType": null
  }
}

Example — wallet binding#

{
  "eventId": "evt_260923W2R8N6J1PC",
  "eventType": "card.otp",
  "version": "1.0",
  "occurredAt": "2026-09-23T06:15:40Z",
  "data": {
    "cardNo": "CD260811X9Y8Z7",
    "scene": "WALLET_BINDING",
    "otp": "719052",
    "referenceCode": null,
    "transactionAmount": null,
    "transactionCurrency": null,
    "merchantName": null,
    "walletType": "APPLE_PAY"
  }
}

Handling#

Verify the signature before you deliver anything. A forged card.otp could be used to
phish your cardholder.
Deliver the passcode to the cardholder only. Do not log it, do not show it to your support
staff, and do not store it longer than the delivery takes.
Acknowledge quickly: return 2xx first, then deliver. A slow response counts as a failure and the
single retry may arrive after the cardholder has already given up.

Verifying the signature#

Three headers accompany every delivery:
HeaderValue
X-Webhook-EventEvent category, always ISSUING for this event
X-Webhook-Event-TypeAlways card.otp
X-Webhook-SignatureHMAC-SHA256 signature, lowercase hex
X-Webhook-Signature = hex_lower( HMAC_SHA256( appSecret, rawBody ) )
The signed content is the raw request body only, with no timestamp and no separator. The signing
key is your appSecret — there is no separate webhook secret. Compare in constant time, and
deduplicate on eventId.
See the Webhooks guide for verification code samples.
Modified at 2026-09-30 09:26:56
Previous
Card Operation Failed
Next
Card Updated
Built with