Skip to main content
POST
This endpoint is gated behind Payment Card Industry Data Security Standard (PCI DSS) compliance. Because it accepts raw card numbers, Card Verification Codes (CVCs), and bank account details, you may only use it if your organization is PCI DSS compliant and has been explicitly enabled by Crossmint. You must provide evidence of your compliance (e.g. your Attestation of Compliance) and reach out to Crossmint to have it turned on — it is disabled by default.If you are not PCI compliant, do not use this endpoint. Instead, use the client-side Save a Card flow, which renders Crossmint’s CrossmintPaymentMethodManagement component. Card data is collected directly by Crossmint in the browser and never touches your servers, so you do not need to be PCI compliant to use it.
This endpoint requires a JWT from an external auth provider (Auth0, Firebase, Stytch, etc.) or a custom JWT backed by a JWKS endpoint. Crossmint Auth is not supported.
This endpoint accepts raw card data and bank account details. Requests must be sent to the vault host (vault.staging.crossmint.com or vault.crossmint.com), which tokenizes sensitive fields before forwarding to the API. Raw card numbers, CVCs, and bank account numbers never reach api.crossmint.com directly.

Authorizations

X-API-KEY
string
header
required

API key required for authentication

Authorization
string
header
required

The end user's JWT, sent as Authorization: Bearer <JWT> together with a client-side API key. Validated against the project's external JWT configuration.

Body

application/json

Send the sub-object that matches type.

bankAccount
object
required

Bank account details. Required when type is a bank type. The fields depend on the country of the account.

type
string
required

Account identifier type: Mexican bank account identified by an 18-digit CLABE. type names the account identifier / capture schema Crossmint collects — never the payment rail; rail selection happens at payment execution time.

Allowed value: "bank-account-mx-clabe"
label
string

The client's own name for this payment method. Free text, echoed back on every read.

Required string length: 1 - 255
userLocator
string

Identifies the target user when authenticating with a server API key. Format: <type>:<value> (e.g., email:alice@example.com, userId:abc123, phoneNumber:+12125551234, twitter:alice). Required for API-key authentication; ignored when authenticating with a JWT (the JWT subject is used).

Minimum string length: 1

Response

The saved payment method, including the derived displayName and the type-specific sub-object (card, bankAccount, or breB).

A saved payment method. Sensitive fields (full PAN, CVC, full account numbers, IBANs, Bre-B keys) are never included.

bankAccount
object
required

Bank account details. Present when type is a bank type. Full account numbers and IBANs are never included.

createdAt
string<date-time>
required

ISO 8601 timestamp when this payment method was created.

Example:

"2024-01-15T10:30:00.000Z"

paymentMethodId
string
required

Unique identifier (UUID v4). Crossmint assigns it on creation.

Minimum string length: 1
reason
string | null
required

Deprecated. Use statusReason, which carries the same value.

status
enum<string>
required

Whether this destination can receive a payout right now. 'pending' while the readiness checks run, 'active' when a provider has confirmed a rail, 'rejected' when it cannot receive funds, 'deleted' when it was deleted. 'pending' moves to 'active', 'rejected' or 'deleted'; 'active' moves to 'rejected' or 'deleted'; 'rejected' moves only to 'deleted'. Branch on this field, never on statusReason.

Available options:
active,
deleted,
pending,
rejected
statusReason
string | null
required

Why the status is 'rejected'. Null on every other status, and on a rejection with no established destination condition. Known values today: destination-not-found, destination-closed, destination-cannot-receive, no-rail-available. New codes can appear at any time, so branch on status and treat an unrecognised code as the status alone.

type
string
required

Payment method type. Selects which sub-object is present: card, bankAccount, or breB.

Allowed value: "bank-account-mx-clabe"
updatedAt
string<date-time>
required

ISO 8601 timestamp when this payment method was last modified.

Example:

"2024-01-15T10:30:00.000Z"

label
string

The client's own name for this payment method, when one was sent.

Minimum string length: 1
lastPayoutAt
string<date-time>

Read-only. ISO 8601 timestamp of the most recent successful offramp payout funded by this bank account. Absent if none.

Example:

"2024-01-15T10:30:00.000Z"