https://api.agentcard.sh
There is no separate sandbox host. Whether a call runs in sandbox or production is decided by the credential you use, never by the URL.
Resources
Access tokens
Exchange client credentials for the platform token every call needs.
Connections
Connect a user to your platform and get a token that acts as them.
Vault
Store a user’s own card and authorize checkouts with it.
Purchases
One conversational endpoint that places real orders.
Cards
One-time virtual cards created against a member’s added card.
Identity verification
KYC: documents, extra fields, face scan, status.
Webhook endpoints
Register where events are delivered and rotate signing secrets.
Blooio connection
Let Agentcard send Vault links from your Blooio numbers.
Authentication
Every endpoint is called from your backend with a platform access token:client_id and client_secret (dashboard → Organization → Developer → Credentials). A sandbox client mints sandbox tokens, a production client mints production tokens. Tokens live one hour.
Two tokens, two jobs
The connection token belongs to the user. Platform endpoints name the user with
user_id instead of taking their token. Keep it fresh with Refresh the connection.
Test from this reference
- Open Create an access token, paste a sandbox
client_idandclient_secret, hit Send. - Paste the
access_tokeninto the Authorization field on any endpoint page. It is remembered as you move between pages. - Fill the parameters and hit Send. You are hitting the live API. In sandbox the connect code is always
111111.
Ids
Every id Agentcard issues starts with a prefix that names the object it points to, then an underscore and a random part, such ascard_3f9a1c2e4b5d6a7f8e9d0c1b. The prefix tells you what an id holds when you read a log, a response, or a webhook.
An id you received earlier may carry no prefix, such as
cmturxopj0004cbpswhqdeyju on a stored card. Treat every id as an opaque string: store it and pass it back exactly as you received it, never parse it, and never check it for a prefix. Three values are not Agentcard object ids and keep their own shape: client_id is your OAuth client identifier, external_user_id is the id you gave Agentcard for a user, and the id on a transaction.* event is the card network’s reference for that charge.
Errors
Every error uses the same envelope:code is stable and machine-readable. Branch on it. message is safe to log. Each endpoint page lists the codes it can return.