> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hifi.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Submit an external card session

> Submit the counter party and card details collected by a hosted session.
Creates the counter party (if not already attached) and the external card.
The session must be `PENDING` and not expired. Restricted to HIFI's hosted
session UI; not callable with a client API key.




## OpenAPI

````yaml https://production.hifi.com/api/v3/openapi.json post /v3/users/{userId}/external-card-sessions/{cardSessionId}/submit
openapi: 3.0.0
info:
  title: Hifi API
  version: 3.0.0
  description: API documentation for HIFI
servers:
  - url: https://production.hifi.com
    description: Production server
  - url: https://sandbox.hifi.com
    description: Sandbox server
security:
  - bearerAuth: []
tags:
  - name: Common
    description: Common endpoints
  - name: User
    description: User endpoints
  - name: Counter Party
    description: Counter party endpoints
  - name: Crypto Transfer
    description: Crypto transfer and batch transfer endpoints
  - name: Wallet
    description: Wallet and wallet offer endpoints
  - name: External Account
    description: External bank account endpoints (under a counter party)
  - name: External Wallet
    description: External wallet endpoints (under a counter party)
  - name: External Card
    description: External card endpoints (under a counter party)
  - name: Token Swap
    description: Token swap endpoints
  - name: Bridge
    description: Bridge endpoints
  - name: Virtual Account
    description: Virtual account endpoints
  - name: Compliance
    description: Compliance and compliance link endpoints
  - name: Webhook Endpoint
    description: Webhook endpoint endpoints
  - name: File
    description: File upload endpoints
  - name: Onramp
    description: Onramp (fiat to crypto) endpoints
  - name: Offramp
    description: Offramp (crypto to fiat) endpoints
  - name: Orchestration Address
    description: Orchestration (liquidation) address endpoints
  - name: KYC Link
    description: Hosted and custom KYC/KYB link endpoints
  - name: Transfer Approval
    description: Transfer approval endpoints
  - name: Corridor
    description: Supported fiat/crypto transfer corridor endpoints
  - name: Migration
    description: v2-to-v3 ID mapping endpoints
paths:
  /v3/users/{userId}/external-card-sessions/{cardSessionId}/submit:
    post:
      tags:
        - External Card
      summary: Submit an external card session
      description: >
        Submit the counter party and card details collected by a hosted session.

        Creates the counter party (if not already attached) and the external
        card.

        The session must be `PENDING` and not expired. Restricted to HIFI's
        hosted

        session UI; not callable with a client API key.
      operationId: v3SubmitExternalCardSession
      parameters:
        - $ref: '#/components/parameters/UserIdPathParameter'
        - $ref: '#/components/parameters/CardSessionIdPathParameter'
      requestBody:
        $ref: '#/components/requestBodies/SubmitExternalCardSessionBody'
      responses:
        '200':
          $ref: '#/components/responses/SubmitExternalCardSessionResponse'
        '400':
          $ref: '#/components/responses/BadRequestResponse'
        '401':
          $ref: '#/components/responses/UnauthorizedResponse'
        '403':
          $ref: '#/components/responses/UnauthorizedResponse'
        '404':
          $ref: '#/components/responses/NotFoundResponse'
        '422':
          $ref: '#/components/responses/ResourceNotEligibleResponse'
        '500':
          $ref: '#/components/responses/InternalServerErrorResponse'
components:
  parameters:
    UserIdPathParameter:
      name: userId
      in: path
      schema:
        type: string
        pattern: ^user_[A-Za-z0-9]+$
      description: ID of the user.
      required: true
    CardSessionIdPathParameter:
      name: cardSessionId
      in: path
      required: true
      schema:
        type: string
      description: Public ID of the external card session (prefixed with `ecs_`)
      example: ecs_2mNpXwZ7bV1aLcs3Kf9dQ
  requestBodies:
    SubmitExternalCardSessionBody:
      required: true
      description: |
        Counter party and card details collected by the hosted session. Omit
        `counterParty` if the session was created with a `counterPartyId`.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ExternalCardSessionSubmit'
          example:
            counterParty:
              type: INDIVIDUAL
              firstName: Jane
              lastName: Doe
            externalCard:
              firstName: Jane
              lastName: Doe
              cardNumber: '4111111111111111'
              expiryMonth: '09'
              expiryYear: '28'
              cvv: '123'
  responses:
    SubmitExternalCardSessionResponse:
      description: >-
        External card session submitted successfully. The counter party and
        external card have been created.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ExternalCardSessionSubmitResult'
          example:
            externalCardId: extcrd_2mNpXwZ7bV1aLcs3Kf9dQ
            counterPartyId: cpty_7bV1aLcs3Kf9dQ2mNpXwZ
    BadRequestResponse:
      description: Bad Request — the request was malformed or failed validation.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
          example:
            type: VALIDATION_ERROR
            message: One or more fields are invalid or missing.
            fields:
              - code: invalid_value
                message: Must be a valid email address
                field: email
    UnauthorizedResponse:
      description: Unauthorized
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Unauthorized'
    NotFoundResponse:
      description: Not Found
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/NotFound'
    ResourceNotEligibleResponse:
      description: >-
        Unprocessable Entity — the resource exists but is not eligible for the
        requested operation in its current state.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
          example:
            type: ACTION_NOT_ALLOWED
            message: This action is not allowed
    InternalServerErrorResponse:
      description: Internal Server Error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/InternalServerError'
  schemas:
    ExternalCardSessionSubmit:
      type: object
      description: >
        Submits the collected counter party and card details for an external
        card

        session. `counterParty` is required unless the session was created with
        a

        `counterPartyId`, in which case it must be omitted.
      required:
        - externalCard
      properties:
        counterParty:
          oneOf:
            - $ref: '#/components/schemas/CounterPartyCreateIndividual'
            - $ref: '#/components/schemas/CounterPartyCreateBusiness'
          discriminator:
            propertyName: type
        externalCard:
          $ref: '#/components/schemas/ExternalCardCreate'
    ExternalCardSessionSubmitResult:
      type: object
      description: The counter party and external card created from a submitted session.
      properties:
        externalCardId:
          type: string
          description: Public ID of the created external card (prefixed with `extcrd_`).
          example: extcrd_2mNpXwZ7bV1aLcs3Kf9dQ
        counterPartyId:
          type: string
          description: >-
            Public ID of the counter party the card was created under (prefixed
            with `cpty_`).
          example: cpty_7bV1aLcs3Kf9dQ2mNpXwZ
    ApiError:
      type: object
      description: >-
        Standard v3 error shape, returned by validation failures and
        business-logic errors alike.
      properties:
        type:
          type: string
          description: >-
            Machine-readable error type, e.g. VALIDATION_ERROR,
            ACTION_NOT_ALLOWED, RESOURCE_CONFLICT.
          example: VALIDATION_ERROR
        message:
          type: string
          description: Human-readable error message.
          example: One or more fields are invalid or missing.
        fields:
          type: array
          description: >-
            Present on field-level validation errors. One entry per problem
            field.
          items:
            type: object
            properties:
              code:
                type: string
                description: Error code related to the field issue.
              message:
                type: string
                description: Error message for the specific issue.
              field:
                type: string
                description: The name of the field that has an issue.
    Unauthorized:
      type: object
      properties:
        type:
          type: string
          description: Unauthorized enum
          example: UNAUTHORIZED
        message:
          type: string
          description: Unauthorized message
          example: Authentication required
    NotFound:
      type: object
      properties:
        type:
          type: string
          example: RESOURCE_NOT_FOUND
          description: The error type, e.g., RESOURCE_NOT_FOUND
        message:
          type: string
          description: A descriptive error message
        fields:
          type: array
          description: List of specific field errors
          items:
            type: object
            properties:
              code:
                type: string
                description: Error code related to the field issue
              message:
                type: string
                description: Error message for the specific issue
              field:
                type: string
                description: The name of the field that has an issue
    InternalServerError:
      type: object
      properties:
        type:
          type: string
          example: INTERNAL_SERVER_ERROR
          description: Internal server error enum
        message:
          type: string
          example: An internal server error occurred
          description: Internal server error message
    CounterPartyCreateIndividual:
      type: object
      description: >
        An individual counter party. Only `type`, `firstName`, and `lastName`
        are

        always required; the other fields become required depending on what is
        later

        attached (external wallet needs the name only; external account needs

        phoneNumber, email, dateOfBirth, taxId, taxIdType, nationality,
        address).
      required:
        - type
        - firstName
        - lastName
      properties:
        type:
          type: string
          enum:
            - INDIVIDUAL
          example: INDIVIDUAL
        firstName:
          type: string
          example: Jane
        lastName:
          type: string
          example: Doe
        phoneNumber:
          type: string
          description: Phone number.
          example: '+14155552671'
        email:
          type: string
          format: email
          example: jane.doe@example.com
        dateOfBirth:
          type: string
          format: date
          description: Date of birth in YYYY-MM-DD format.
          example: '1990-01-15'
        taxId:
          type: string
          description: Tax identification number.
          example: 123-45-6789
        taxIdType:
          type: string
          description: Type of tax identifier (e.g. SSN, ITIN).
          example: SSN
        taxIdCountry:
          type: string
          description: ISO 3166-1 alpha-3 country that issued the tax ID.
          example: USA
        nationality:
          type: string
          description: ISO 3166-1 alpha-3 country code.
          example: USA
        address:
          $ref: '#/components/schemas/CounterPartyAddress'
    CounterPartyCreateBusiness:
      type: object
      description: >
        A business counter party. Only `type` and `businessName` are always
        required;

        the other fields become required depending on what is later attached
        (external

        account needs phoneNumber, email, incorporationDate, taxId, taxIdType,

        incorporationCountry, address).
      required:
        - type
        - businessName
      properties:
        type:
          type: string
          enum:
            - BUSINESS
          example: BUSINESS
        businessName:
          type: string
          example: Acme Corp
        phoneNumber:
          type: string
          description: Phone number.
          example: '+14155552671'
        incorporationDate:
          type: string
          format: date
          description: Date of incorporation in YYYY-MM-DD format.
          example: '2015-06-01'
        taxId:
          type: string
          description: Tax identification number.
          example: 12-3456789
        taxIdType:
          type: string
          description: Type of tax identifier (e.g. EIN, VAT).
          example: EIN
        taxIdCountry:
          type: string
          description: ISO 3166-1 alpha-3 country that issued the tax ID.
          example: USA
        registrationNumber:
          type: string
          description: Business registration number.
          example: C1234567
        incorporationCountry:
          type: string
          description: ISO 3166-1 alpha-3 country of incorporation.
          example: USA
        email:
          type: string
          format: email
          example: ops@acme.example.com
        address:
          $ref: '#/components/schemas/CounterPartyAddress'
    ExternalCardCreate:
      type: object
      description: |
        Card details to tokenize. The card number is tokenized with the card
        provider and never stored in plaintext; only the last four digits are
        retained.
      required:
        - firstName
        - lastName
        - cardNumber
        - expiryMonth
        - expiryYear
        - cvv
      properties:
        firstName:
          type: string
          description: Cardholder first name.
          example: John
        lastName:
          type: string
          description: Cardholder last name.
          example: Doe
        cardNumber:
          type: string
          description: Full card number (PAN).
          example: '4111111111111111'
        expiryMonth:
          type: string
          minLength: 2
          maxLength: 2
          description: Card expiry month (2 digits).
          example: '09'
        expiryYear:
          type: string
          minLength: 2
          maxLength: 2
          description: Card expiry year (2 digits).
          example: '28'
        cvv:
          type: string
          description: Card verification value.
          example: '123'
    CounterPartyAddress:
      type: object
      description: Address of the counter party.
      required:
        - addressLine1
        - city
        - stateProvinceRegion
        - postalCode
        - country
      properties:
        addressLine1:
          type: string
          description: Primary address line.
          example: 123 Main Street
        addressLine2:
          type: string
          description: Secondary address line (apartment, suite, etc.).
          example: Suite 100
        city:
          type: string
          description: City name.
          example: New York
        stateProvinceRegion:
          type: string
          maxLength: 10
          description: State, province, or region.
          example: NY
        postalCode:
          type: string
          description: Postal or ZIP code.
          example: '10001'
        country:
          type: string
          description: ISO 3166-1 alpha-3 country code.
          example: USA
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT

````