1. Cards
Framnex for Developers
  • Introduction
    • Overview
    • Quick Start
    • Authentication
    • Environments
  • Guides
    • Create an outgoing transfer
    • Handle webhooks
    • Transfer documents
  • Bulk Payouts
    • Upload bulk payout
      POST
    • List bulk payouts
      GET
    • Get bulk payout
      GET
    • List bulk payout items
      GET
    • Submit bulk payout
      POST
    • Cancel bulk payout
      POST
  • Cards
    • List card products
      GET
    • List cardholders
      GET
    • Issue card
      POST
    • List cards
      GET
    • Get card
      GET
    • Activate card
      POST
    • Freeze card
      POST
    • Unfreeze card
      POST
    • Close card
      POST
    • Set card limits
      PUT
    • Create encryption envelope
      POST
    • Reveal card details
      POST
    • Set PIN
      PUT
  • Card Transactions
    • List card transactions
    • Get card transaction
  • Accounts
    • Get account
    • List accounts
  • Auth
    • Get access token
  • Exchange Rates
    • Get exchange rate
  • Transfer Documents
    • Download document
    • List documents
    • Upload documents
  • Transfers
    • Create transfer
    • List transfers
    • Get transfer
  • Webhooks
    • Register webhook URL
    • Get webhook URL
    • List webhook deliveries
    • Get webhook delivery
    • Retry webhook delivery
  • Schemas
    • BankClientAPI
      • Account
      • AccountCredentials
      • AccountState
      • AccountType
      • AchCredentials
      • Address
      • BankDetails
      • BusinessEntity
      • ClientIntegrationAuthRequest
      • ClientIntegrationAuthResponse
      • ClientIntegrationErrorResponse
      • CreateExchangeTransferRequest
      • CreateOutgoingTransferRequest
      • CreateTransferRequest
      • CreateTransferType
      • CreatedResponse
      • Credentials
      • CredentialsState
      • CryptoCredentials
      • CustomerTransferStateDto
      • CryptoTransferDetails
      • ExchangeRate
      • DocumentDto
      • ExchangeTransferCancelledWebhookPayload
      • ExchangeTransfer
      • ExchangeTransferExecutedWebhookPayload
      • FasterUkCredentials
      • FedWireCredentials
      • IError
      • GasPaymentWebhookPayload
      • IReason
      • IncomingTransfer
      • LegalEntityType
      • ISuccess
      • IndividualEntity
      • IncomingTransferReceivedWebhookPayload
      • InternalCredentials
      • InternalServerError
      • OperationTypeDto
      • LegalEntity
      • LocalAEDCredentials
      • LocalXafCredentials
      • NeftCredentials
      • OutgoingTransfer
      • OutgoingTransferCancelledWebhookPayload
      • PageInfoDto
      • Participant
      • PaymentMethod
      • OutgoingTransferExecutedWebhookPayload
      • PagedFilterDto
      • TransferGas
      • TransferPagedDataDto
      • PixCredentials
      • TransferState
      • TransferType
      • ProblemDetails
      • TransferTypeDto
      • PaymentSystem
      • SepaCredentials
      • RegisterWebhookRequest
      • SortOrderDto
      • Result
      • SwiftCredentials
      • TedPayCredentials
      • Transfer
      • TransferDetails
      • TransferDetailsType
      • UaeFtsCredentials
      • UaeIppCredentials
      • ValidationProblemDetails
      • WebhookDelivery
      • WebhookDeliveryPagedDataDto
      • WebhookPayload
      • WebhookState
      • WebhookSubscription
      • WebhookType
      • YeePayKesLocalCredentials
      • YeePayMxnLocalCredentials
      • YeePayNgnLocalCredentials
    • BulkPayout
    • CardProduct
    • BulkPayoutState
    • Cardholder
    • BulkPayoutItemState
    • IssueCardRequest
    • BulkPayoutPagedDataDto
    • Card
    • BulkPayoutItemPagedDataDto
    • CardType
    • CardState
    • CardPagedDataDto
    • CloseCardRequest
    • SetCardLimitsRequest
    • CardEncryptionEnvelope
    • CardEncryptedDetailsRequest
    • CardEncryptedDetails
    • BulkPayoutFileFormat
    • SetCardPinRequest
    • BulkPayoutItemCounts
    • CardTransaction
    • CardTransactionState
    • BulkPayoutItem
    • CardTransactionPagedDataDto
    • CardNetwork
    • CardIssuanceFee
    • CardShipping
    • CardSpendingLimit
    • CardLimitInterval
    • CardCloseReason
    • CardSecretType
    • CardEncryptedValue
    • CardMerchant
    • CardWebhookType
    • CardWebhookPayload
    • CardIssuedWebhookPayload
    • CardIssuanceFailedWebhookPayload
    • CardStateChangedWebhookPayload
    • CardTransactionAuthorizedWebhookPayload
    • CardTransactionCompletedWebhookPayload
    • CardTransactionReversedWebhookPayload
    • BulkPayoutItemError
    • BulkPayoutFile
    • BulkPayoutFileItem
    • BulkPayoutWebhookType
    • BulkPayoutWebhookPayload
    • BulkPayoutValidatedWebhookPayload
    • BulkPayoutValidationFailedWebhookPayload
    • BulkPayoutCompletedWebhookPayload
GuidesBaaS API ReferenceBank Client API Reference
GuidesBaaS API ReferenceBank Client API Reference
  1. Cards

Set PIN

PUT
/integration/cards/{id}/pin
Early access - contact your account manager to enable cards for your organization.
Sets a new PIN for a card. The PIN is used for ATM withdrawals and chip-and-PIN payments. Start with POST /integration/cards/{id}/encrypted-envelope; then, on the cardholder's device, format the new 4-digit PIN as an ISO 9564 format 2 PIN block and encrypt it with the session key using AES-GCM.
The new PIN is active immediately. The response has an empty body.
Errors: 400 Bad Request if the PIN block cannot be decrypted, the PIN is not 4 digits, or the envelope has expired; 404 Not Found if the card does not exist; 422 Unprocessable Content if the card is not active or frozen.

Request

Authorization
JWT Bearer
Add the parameter
Authorization
to Headers
Example:
Authorization: ********************
or
Path Params

Body Params application/json

Example
{
    "protocol": "string",
    "encryptedSessionKey": "string",
    "encryptedPinBlock": {
        "iv": "q3Jd2fX0bP1k9sLw",
        "data": "N2Y4ZTFhYzQ5ZDJiM2M1ZTZmN2E4YjljMGQxZTJmM2E="
    }
}

Request Code Samples

Shell
JavaScript
Java
Swift
Go
PHP
Python
HTTP
C
C#
Objective-C
Ruby
OCaml
Dart
R
Request Request Example
Shell
JavaScript
Java
Swift
curl --location --request PUT 'https://my.test-1.account.finlego.com/api/merchant/integration/cards//pin' \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{
    "protocol": "string",
    "encryptedSessionKey": "string",
    "encryptedPinBlock": {
        "iv": "q3Jd2fX0bP1k9sLw",
        "data": "N2Y4ZTFhYzQ5ZDJiM2M1ZTZmN2E4YjljMGQxZTJmM2E="
    }
}'

Responses

🟢200OK
OK
This response does not have a body.
🟠400Bad Request
🟠401Unauthorized
🟠403Forbidden
🟠404Record Not Found
🟠422Parameter Error
🔴500Server Error
Modified at 2026-09-29 11:11:16
Previous
Reveal card details
Next
List card transactions
Built with