> ## Documentation Index
> Fetch the complete documentation index at: https://docs.planewallet.org/llms.txt
> Use this file to discover all available pages before exploring further.

# Create cardholder

> Required permission: `holders:write`. Sandbox is isolated from live funds. Live integration availability is checked server-side.



## OpenAPI

````yaml https://specs.planewallet.org/openapi.json POST /api/v1/holders
openapi: 3.0.3
info:
  title: Plane Business API
  version: 1.0.0
  description: >-
    Company-scoped cards and services. Create keys in the Developers section.
    Operations reserve funds and return queued. Poll operations/{id} or
    subscribe to webhooks for completion. Unknown outcomes remain in
    manual_review with funds held. Live services and TON deposits require
    dedicated configuration and company verification. Webhooks carry a
    Plane-Signature header: t=<unix_seconds>,v1=<HMAC_SHA256(secret,t + "." +
    raw_body)>. Verify the signature and timestamp tolerance, deduplicate by
    event ID, then acknowledge with 2xx. API keys must never be embedded in
    client applications.
servers:
  - url: https://business.planewallet.org
    description: Plane Business API
security: []
paths:
  /api/v1/holders:
    post:
      summary: Create cardholder
      description: >-
        Required permission: `holders:write`. Sandbox is isolated from live
        funds. Live integration availability is checked server-side.
      parameters: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/HolderInput'
      responses:
        '201':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Holder'
        '400':
          description: Validation or business rule failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Invalid or revoked API key
        '403':
          description: Scope, verification or capability denied
        '404':
          description: Object not found in this company
        '409':
          description: Idempotency payload conflict or changed quote
        '429':
          description: Rate limited
      security:
        - bearerAuth: []
components:
  schemas:
    HolderInput:
      type: object
      additionalProperties: false
      required:
        - name
        - email
        - kind
      properties:
        name:
          type: string
        email:
          type: string
          format: email
        kind:
          type: string
          enum:
            - employee
            - customer
        externalId:
          type: string
    Holder:
      type: object
      properties:
        id:
          type: string
        name:
          type: string
        email:
          type: string
        kind:
          type: string
        status:
          type: string
        externalId:
          type: string
    Error:
      type: object
      properties:
        statusCode:
          type: integer
        message:
          type: string
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: Plane API key

````