---
title: "Request PIN Control access token by cardId."
method: POST
path: "/v1/card/{cardId}"
tags: ["PIN Control handling"]
deprecated: true
---

# Request PIN Control access token by cardId.

`POST /v1/card/{cardId}`

> **Deprecated.**

This operation is used to create the PIN control access token. If there are multiple active plastics on one
card object, the one with the highest sequence number will be used.

The successful response from this call returns an _id_ and a _pinURL_ if request was for viewing pin.
The cardholder device should be instructed to do a POST call to the _pinURL_ with the content of the _id_
in a form field named _controlId_.

## Path parameters

- `cardId` string, biginteger, required

## Query parameters

- `auditUser` string, required

## Request body

- PinControlResourceBody
  - `scope` 'VIEW_PIN' | 'SET_PIN', required — Describes the scope of the operation that is authorized by the user.

## Response `201`

Successful creation of the access token

- PinControlResponseBody
  - `id` string, required — The ID of this PIN Control access token.
  - `pinURL` string — The URL that the cardholder's mobile device webview should browse to for accessing the PIN.
  - `pinFrameURL` string — The URL of the iframe for desktop browser based flows for accessing PIN.

## Other responses

- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found
- `500` — Internal server error

---

[API](https://skmtc.net/enfuce/apis/transfer-api.md) · [All operations](https://skmtc.net/enfuce/apis/transfer-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/enfuce/transfer-api/versions/dc4a41118f80/schema)
