> ## Documentation Index
> Fetch the complete documentation index at: https://docs.planewallet.org/llms.txt
> Use this file to discover all available pages before exploring further.

# Freeze or unfreeze a card

> Required permission: `cards:write`. Sandbox is isolated from live funds. Live integration availability is checked server-side.



## OpenAPI

````yaml https://specs.planewallet.org/openapi.json PATCH /api/v1/cards/{id}
openapi: 3.0.3
info:
  title: Plane Business API
  version: 1.0.0
  description: >-
    Company-scoped cards and services. Create keys in the Developers section.
    Operations reserve funds and return queued. Poll operations/{id} or
    subscribe to webhooks for completion. Unknown outcomes remain in
    manual_review with funds held. Live services and TON deposits require
    dedicated configuration and company verification. Webhooks carry a
    Plane-Signature header: t=<unix_seconds>,v1=<HMAC_SHA256(secret,t + "." +
    raw_body)>. Verify the signature and timestamp tolerance, deduplicate by
    event ID, then acknowledge with 2xx. API keys must never be embedded in
    client applications.
servers:
  - url: https://business.planewallet.org
    description: Plane Business API
security: []
paths:
  /api/v1/cards/{id}:
    patch:
      summary: Freeze or unfreeze a card
      description: >-
        Required permission: `cards:write`. Sandbox is isolated from live funds.
        Live integration availability is checked server-side.
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - status
              properties:
                status:
                  type: string
                  enum:
                    - active
                    - frozen
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                  status:
                    type: string
        '400':
          description: Validation or business rule failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Invalid or revoked API key
        '403':
          description: Scope, verification or capability denied
        '404':
          description: Object not found in this company
        '409':
          description: Idempotency payload conflict or changed quote
        '429':
          description: Rate limited
      security:
        - bearerAuth: []
components:
  schemas:
    Error:
      type: object
      properties:
        statusCode:
          type: integer
        message:
          type: string
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: Plane API key

````