> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.mangopay.com/api-reference/cards/deactivate-edit-card/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.mangopay.com/_mcp/server. # Deactivate or edit a Card PUT https://api.sandbox.mangopay.com/v2.01/{ClientId}/cards/{CardId} Content-Type: application/json **Warning – Implement card deactivation** Because card information cannot be kept without the end user's approval, you should implement a way to deactivate the end user's card systematically when relevant. Deactivate or edit a Card This call serves one of two purposes: * Setting the card as inactive, and thereby disabling it from being used again. This action is irreversible but doesn't prevent the card being registered again with [POST Create a Card Registration](/api-reference/card-registrations/create-card-registration). * Adding the `CardHolderName` to an existing Card object. The `CardHolderName` cannot be modified once added to a Card object. It can also be done during registration with [PUT Update a Card Registration](/api-reference/card-registrations/update-card-registration), in which case attempting to edit it with this endpoint returns an error. Reference: https://docs.mangopay.com/api-reference/cards/deactivate-edit-card ## Authentication - `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer `, where token is your auth token. If your platform is using a [proxy](/guides/sca/proxy-management) to take SCA-triggering action on behalf of users, you also need to integrate [mTLS authentication](/guides/sca/platform) and use the `api-mtls` base URL. ## Servers - `https://api.sandbox.mangopay.com` (Sandbox, default) - `https://api.mangopay.com` (Production) - `https://api-mtls.sandbox.mangopay.com` (mTLS Sandbox) - `https://api-mtls.mangopay.com` (mTLS Production) ## Request ### Path parameters - `ClientId` (string, required) — Platform's API account identifier, associated with the API key. - `CardId` (string, required) — The unique identifier of the Card object, which is returned after updating the Card Registration object with the `RegistrationData`. ### Body (application/json) This endpoint expects a DeactivateOrEditACardRequest. - `Active` (boolean, optional) — Whether the card is active or not. Setting this parameter to `false` is irreversible and should be done once the pay-in is successful. - `CardHolderName` (string, optional) — Max. length: 45 characters passed to card network, 255 accepted by the API The cardholder's name shown on the payment card. This value is passed to the card network for use in transaction risk analysis. The value should only contain unmarked alphabetic characters (A-Z, a-z), hyphens (-), apostrophes ('), and spaces. Letters with diacritics (e.g. É, Ü, ẞ), honorifics (e.g. MRS.) and other special characters are not recommended (they are transformed before being sent to the card network). The `CardHolderName` is not returned in the Card Registration object; it is added to the Card object. ## Response ### 200 Success - `ExpirationDate` (string, optional) — Format: “MMYY” The expiration date of the card. - `Alias` (string, optional) — The card number, partially obfuscated. - `CardType` (string, optional) — **Returned values:** `CB_VISA_MASTERCARD`, `AMEX`, `MAESTRO`, `BCMC` **Default value:** `CB_VISA_MASTERCARD` The type of the card. If not supplied, the default value will be taken into account. - `CardProvider` (string, optional) — **Allowed values:** `CB`, `VISA`, `MASTERCARD`, `AMEX`, `MAESTRO`, `BCMC`, `JCB`, `DISCOVER` The provider of the card. - `Country` (string, optional) — Format: ISO-3166-1 alpha-3 three-letter country code (e.g., “FRA”) The country of the card (which is the same as the country of the issuer). - `Product` (string, optional) — The product type of the card. - `BankCode` (string, optional) — The name of the card issuing bank. - `Active` (boolean, optional) — Whether the card is active or not. Setting this parameter to `false` is irreversible and should be done once the pay-in is successful. - `Currency` (string, optional) — **Returned values:** The three-letter ISO 4217 code (EUR, GBP, etc.) of a supported currency (depends on feature, contract, and activation settings). The currency of the card. - `Validity` (string, optional) — **Returned values:** `UNKNOWN`, `VALID`, `INVALID` Whether the card is valid or not. - `UNKNOWN` – No payment or card validation has been processed, so the validity of the card remains unknown. - `VALID` – The first payment or card validation using the card was processed successfully within 24 hours of the initial card registration. - `INVALID` – The first payment or card validation using the card was attempted and failed, or the status of the corresponding card registration was `CREATED` for more than 24 hours. Once a card is set to `INVALID`, it cannot be set back to `VALID`. A new card registration will be necessary to make a payment. - `UserId` (string, optional) — The unique identifier of the user the card belongs to. - `Id` (string, optional) — Max length: 128 characters (see [data formats](/api-reference/overview/data-formats) for details) The unique identifier of the object. - `Tag` (string, optional) — Max. length: 255 characters Custom data added to this object. This value is inherited from the Card Registration object and cannot be edited. - `Fingerprint` (string, optional) — The unique representation of the card number. This string can be used to track the card behavior while keeping the card information confidential. - `CardHolderName` (string, optional) — Max. length: 45 characters The cardholder's name shown on the payment card. This value is passed to the card network for use in transaction risk analysis. ## Errors ### 400 Bad Request Error Bad Request - `Message` (string, optional) — Description of the error. - `Type` (string, optional) — The category of the error. - `Id` (string, optional) — Unique identifier of the error instance, useful when contacting Mangopay for support. - `Date` (double, optional) — Unix timestamp (UTC) of the date and time the error was triggered. - `errors` (map from string to string, optional, nullable) — Object containing one or more field-level errors. ## Examples **Request** ```json { "body": { "Active": false } } ``` **Response** ```json { "ExpirationDate": "1229", "Alias": "497010XXXXXX8183", "CardType": "CB_VISA_MASTERCARD", "CardProvider": "VISA", "Country": "FRA", "Product": "I", "BankCode": "unknown", "Active": true, "Currency": "EUR", "Validity": "VALID", "UserId": "user_m_01HZSK5MX04KS9Q7SQSSRGQQ4Q", "Id": "card_m_01J0KPBMM32MMSET50CZZ3RMVJ", "Tag": null, "Fingerprint": "48d63bbcfc2c47fcbc19df35e47b2f8d", "CardHolderName": "ALEX SMITH", "CreationDate": 1718647902 } ``` **SDK Code** ```python from pprint import pprint import mangopay mangopay.client_id='your-client-id' mangopay.apikey='your-api-key' from mangopay.api import APIRequest handler = APIRequest(sandbox=True) from mangopay.resources import Card user_card = Card( id = '213601128', active = False ) deactive_card = user_card.save() pprint(deactive_card) ``` ```javascript const mangopayInstance = require('mangopay4-nodejs-sdk') const mangopay = new mangopayInstance({ clientId: 'your-client-id', clientApiKey: 'your-api-key', }) let myCard = { Id: '156285393', Active: false, } const deactivateCard = async (card) => { return await mangopay.Cards.update(card) .then((response) => { console.info(response) return response }) .catch((err) => { console.log(err) return false }) } deactivateCard(myCard) ``` ```java import com.google.gson.Gson; import com.google.gson.GsonBuilder; import com.mangopay.MangoPayApi; import com.mangopay.entities.Card; public class DeactivateCard { public static void main(String[] args) throws Exception { MangoPayApi mangopay = new MangoPayApi(); mangopay.getConfig().setClientId("your-client-id"); mangopay.getConfig().setClientPassword("your-api-key"); String cardId = "card_m_01HXYAVH217SC0ARVDHSE0HQJ0"; Card card = mangopay.getCardApi().get(cardId); Card disableCard = mangopay.getCardApi().disable(card); Gson prettyPrint = new GsonBuilder().setPrettyPrinting().create(); String prettyJson = prettyPrint.toJson(disableCard); System.out.println(prettyJson); } } ``` ```csharp using MangoPay.SDK; using MangoPay.SDK.Entities.PUT; using Newtonsoft.Json; class Program { static async Task Main(string[] args) { MangoPayApi api = new MangoPayApi(); api.Config.ClientId = "your-client-id"; api.Config.ClientPassword = "your-api-key"; var cardId = "card_m_01J2Y4W2R4RWKVEME5WG180SQ3"; var card = new CardPutDTO { Active = false }; var deactivateCard = await api.Cards.UpdateAsync(card, cardId); string prettyPrint = JsonConvert.SerializeObject(deactivateCard, Formatting.Indented); Console.WriteLine(prettyPrint); } } ``` ```php Config->ClientId = 'your-client-id'; $api->Config->ClientPassword = 'your-api-key'; $api->Config->TemporaryFolder = 'tmp/'; try { $card = new \MangoPay\Card(); $card->Id = '198660883'; $card->Active = false; $response = $api->Cards->Update($card); print_r($response); } catch(MGPResponseException $e) { print_r($e); } catch(MGPException $e) { print_r($e); } ``` ```ruby require 'mangopay' MangoPay.configure do |client| client.preproduction = true client.client_id = 'your-client-id' client.client_apiKey = 'your-api-key' client.log_file = File.join(Dir.pwd, 'mangopay.log') end def deactivateCard(cardId, cardObject) begin response = MangoPay::Card.update(cardId, cardObject) puts response return response rescue MangoPay::ResponseError => error puts "Failed to deactivate card: #{error.message}" puts "Error details: #{error.details}" return false end end myCard = { Id: '194579926', Active: false } deactivateCard(myCard[:Id], myCard) ```