---
title: "Update a card link for a customer profile."
method: PUT
path: "/programs/{programCode}/externalAccounts/customers/{customerToken}/cards/{linkId}"
tags: ["ExternalAccount"]
---

# Update a card link for a customer profile.

`PUT /programs/{programCode}/externalAccounts/customers/{customerToken}/cards/{linkId}`

Update the details of a linked card for a customer profile.

## Path parameters

- `programCode` string, required
- `customerToken` string, required
- `linkId` string, required

## Headers

- `X-GD-RequestId` string, required
- `X-GD-CustomerType` string

## Request body

- UpdateCardLinkRequest — Update Card Link Request – Represents the data required to update a linked card for a customer profile in global fund transfer operations. Used to submit encrypted card information for secure updates, supporting idempotency and partner-specific logic. Inherits standard request metadata from Gd.Bos.DataTransfer.Request.RequestBase.
  - `salt` string, required — Unique identifier (UUID) used by the encryption endpoint. Should match the RequestId provided in the header. Used for idempotency and encryption.
  - `encryptedData` EncryptedData, required — Represents a container for encrypted data used in secure data transfer operations. Contains the encrypted payload and associated cryptographic metadata, including encryption version, ephemeral public key, and public key hash. Used to securely transmit sensitive information such as user data, ensuring confidentiality and integrity during transport.
    - `version` string, nullable — The version of the encryption algorithm used to encrypt the data (e.g., "v1", "v2").
    - `ephemeralPublicKey` string, nullable — The ephemeral public key used in the encryption process, typically for key exchange or session establishment.
    - `publicKeyHash` string, nullable — The hash of the public key used to verify the integrity and authenticity of the encryption key.
    - `data` string, nullable — The encrypted data payload, typically base64-encoded, containing the sensitive information.

## Response `200`

Card link updated successfully.

- UpdateLinkResponse — Update Link Response – Represents the response returned after updating a link (such as a card or bank account) for a customer profile in global fund transfer operations. Provides standard response metadata, including response header and response details, to indicate the outcome of the update operation. Inherits standard response metadata from Gd.Bos.DataTransfer.Response.ResponseBase.
  - `responseDetails` ResponseDetail[], nullable — Required: A list of response details providing status codes, descriptions, and additional information about the result of the operation.
    - `code` integer — The primary status or error code for the response (e.g., 200 for success, 400 for validation error).
    - `subCode` integer, nullable — An optional subcode providing more granular detail about the response or error.
    - `description` string, nullable — A human-readable description of the response, error, or status.
    - `url` string, nullable — A URL linking to documentation or a web page with more information about the response code.

## Other responses

- `401` — Unauthorized
- `403` — Forbidden
- `500` — Internal Server Error
- `503` — Service Unavailable

---

[API](https://skmtc.net/greendot/apis/baas-apis.md) · [All operations](https://skmtc.net/greendot/apis/baas-apis/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/greendot/baas-apis/versions/666553766b78/schema)
