---
title: "Link a card to a source customer profile by GFT."
method: POST
path: "/programs/{programCode}/externalAccounts/sourceCustomers/{customerToken}/links"
tags: ["ExternalAccount"]
---

# Link a card to a source customer profile by GFT.

`POST /programs/{programCode}/externalAccounts/sourceCustomers/{customerToken}/links`

Link a card to a source customer profile for global fund transfer operations.

## Path parameters

- `programCode` string, required
- `customerToken` string, required

## Headers

- `X-GD-RequestId` string, required
- `X-GD-CustomerType` string

## Request body

- LinkCustomerProfileCardGlobalFundTransferRequest — Link Customer Profile Card Global Fund Transfer Request – Represents the data required to link a card to a customer profile for global fund transfer operations. Used to submit encrypted card information for secure linking, supporting idempotency and partner-specific logic. Inherits standard request metadata from Gd.Bos.DataTransfer.Request.RequestBase.
  - `salt` string, required — Unique identifier (UUID) used by the encryption endpoint. Should match the RequestId provided in the header. Used for idempotency and encryption.
  - `encryptedData` EncryptedData, required — Represents a container for encrypted data used in secure data transfer operations. Contains the encrypted payload and associated cryptographic metadata, including encryption version, ephemeral public key, and public key hash. Used to securely transmit sensitive information such as user data, ensuring confidentiality and integrity during transport.
    - `version` string, nullable — The version of the encryption algorithm used to encrypt the data (e.g., "v1", "v2").
    - `ephemeralPublicKey` string, nullable — The ephemeral public key used in the encryption process, typically for key exchange or session establishment.
    - `publicKeyHash` string, nullable — The hash of the public key used to verify the integrity and authenticity of the encryption key.
    - `data` string, nullable — The encrypted data payload, typically base64-encoded, containing the sensitive information.

## Response `201`

Card linked successfully.

- LinkCustomerProfileGlobalFundTransferResponse — Represents the response returned after linking a card to a customer profile for global fund transfer operations. Contains the customer profile reference and the status of the card link. Inherits standard response metadata from Gd.Bos.DataTransfer.Response.ResponseBase.
  - `link` GlobalFundTransferLink — Global Fund Transfer Link – Represents the status and details of the link between a card and an external account for global fund transfer operations. Used to convey the link identifier, funds availability, and current status of the linked card.
    - `linkId` string, nullable — Unique identifier for the link relation between the card and the external account.
    - `fundsAvailability` string, nullable — Availability of funds for the linked card (e.g., Immediate, NextBusinessDay, TwoToFiveBusinessDays).
    - `status` string, nullable — Status of the linked card (e.g., Active, Inactive, Deleted, Expired, Blocked).
  - `responseDetails` ResponseDetail[], nullable — Required: A list of response details providing status codes, descriptions, and additional information about the result of the operation.
    - `code` integer — The primary status or error code for the response (e.g., 200 for success, 400 for validation error).
    - `subCode` integer, nullable — An optional subcode providing more granular detail about the response or error.
    - `description` string, nullable — A human-readable description of the response, error, or status.
    - `url` string, nullable — A URL linking to documentation or a web page with more information about the response code.

## Other responses

- `401` — Unauthorized
- `403` — Forbidden
- `500` — Internal Server Error
- `503` — Service Unavailable

---

[API](https://skmtc.net/greendot/apis/baas-apis.md) · [All operations](https://skmtc.net/greendot/apis/baas-apis/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/greendot/baas-apis/versions/666553766b78/schema)
