---
title: Credit card Onboarding
description: REST API reference for validating a credit card and checking validation status in Card Not Present Verification's Credit card Onboarding feature.
canonical: https://developer.unico.io/dual-api/developers/regional-solutions/card-not-present-verification/integration/apis/api-reference/credit-card-onboarding
locale: en
generated_by: markdown-export
---

- [/](/)
- Regional Solutions
- [Card Not Present Verification](/dual-api/developers/regional-solutions/card-not-present-verification)
- [Integration](/dual-api/developers/regional-solutions/card-not-present-verification/integration/overview)
- [APIs](/dual-api/developers/regional-solutions/card-not-present-verification/integration/apis)
- [API Reference](/dual-api/developers/regional-solutions/card-not-present-verification/integration/apis/api-reference)
- Credit card Onboarding

**On this page# Credit card Onboarding

### Before you start​

Your API requests are authenticated using an access token. Any request that does not include a valid access token will return an error. Learn more in [Authentication](/developers/regional-solutions/card-not-present-verification/integration/authentication).
Base URL
**UAT**: `https://transactions.transactional.uat.unico.app/api/public/v1`
**Production**: `https://transactions.transactional.unico.app/api/public/v1`

ImportantCredit card Onboarding can be performed either by requesting a selfie from the end user and completing the full registration, **or** by reusing biometric captures from processes executed by other Unico IDCloud platform products:
To reuse processes generated by other IDCloud products, provide the reference process ID in `additionalInfo.processID`;
The reference process used must have been completed no more than **1 hour** prior.

### Validate credit card​

`POST /walletid/transaction` — validates a credit card.
Headers
HeaderValue`Authorization``Bearer {token}` — a valid access token.
Body
```
{  "identity": { "key": "cpf", "value": "12345678900" },  "orderNumber": "onboarding-98765",  "company": "company-id",  "redirectUrl": "https://yourapp.com/wallet/return",  "card": {    "binDigits": "12345678",    "lastDigits": "1234",    "expirationDate": "12/2028",    "name": "John Doe"  },  "value": 5000.00,  "additionalInfo": {    "externalUserID": "YOUR_EXTERNAL_USER_ID"  }}
```

FieldTypeRequiredDescription`identity`objectyesUser identity information.`identity.key`stringyesType of user identifier key.`identity.value`stringyesValue of the user identifier key.`orderNumber`stringyesNumber associated with the onboarding. Used as an index in the portal and as a foreign key between your system and Card Not Present Verification.`company`stringyesID of the company responsible for the transaction, provided by Unico.`redirectUrl`stringnoURL to redirect the user after completing the transaction (an HTTPS URL for web, or a Schema URL for native mobile apps).`card`objectyesCard information used in the transaction.`card.binDigits`stringyesFirst 8 digits of the card.`card.lastDigits`stringyesLast 4 digits of the card.`card.expirationDate`stringnoCard expiration date.`card.name`stringyesCardholder's name — ensure it's correct to avoid encoding issues or approval problems.`value`numbernoMaximum secured value.`additionalInfo`objectnoSend this object with `processID` to reuse biometric captures from other Unico IDCloud platform products, and/or `externalUserID` to enable [Silent Verification](/developers/regional-solutions/card-not-present-verification/integration/silent-verification) for this transaction.`additionalInfo.processID`stringnoReference process ID from the IDCloud platform.`additionalInfo.externalUserID`stringnoThe same identifier configured via the SDK's `externalUserId` when collecting device metadata. Required only to trigger silent validation — without it, the transaction is created normally but always follows the standard visual flow.
dangerThe `orderNumber` field must be filled with the **unique** order number of that purchase in the e-commerce system — using a distinct transactional ID is incorrect, and reusing values can trigger `replicated transaction` errors.
200 OK
```
{  "id": "6ab1771e-dfab-4e47-8316-2452268e5481",  "status": "processing",  "link": "https://developers/regional-solutions/card-not-present-verification.unico.app/t/6ab1771e-dfab-4e47-8316-2452268e5481",  "token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."}
```

FieldDescription`id`ID of the created transaction.`status`Current transaction status.`link`Link related to the transaction. Only returned if `additionalInfo.processID` is **not** provided.`token`Signed token to initialize the Card Not Present Verification web SDK. Only returned if `additionalInfo.processID` is **not** provided.
noteIf `additionalInfo.externalUserID` was sent and the transaction is silently approved, the response also skips the capture link:```
{    "id": "6ab1771e-dfab-4e47-8316-2452268e5481",    "status": "approved"}
```

See [Silent Verification](/developers/regional-solutions/card-not-present-verification/integration/silent-verification) for the full flow, including SDK setup and timing requirements.
### Check validation status​

`GET /walletid/transactions/{transaction_id}` — checks the current status of a specific transaction.
Headers
HeaderValue`Authorization``Bearer {token}` — a valid access token.
200 OK
```
{  "status": "processing",  "hasIdentityChanged": false}
```

FieldDescription`status`Current status of the transaction.`hasIdentityChanged`Optional. Whether an identity swap occurred in the transaction.
See [Enumerated](/dual-api/developers/regional-solutions/card-not-present-verification/integration/apis/enumerated) for all possible statuses. To optimize performance, implement the [Webhook](/developers/regional-solutions/card-not-present-verification/integration/webhook) instead of polling this endpoint.
For error responses, see [Errors — Credit card Onboarding](/dual-api/developers/regional-solutions/card-not-present-verification/integration/apis/errors#credit-card-onboarding).Last updated on Oct 8, 2026**