This document outlines the deployed specification for two new authenticated endpoints to the Cardigan API.

<aside> ✅ This specification is the current version of the API. Previous versions:

Cardigan API Spec v1.0

</aside>



Overview

The Cardigan API is a REST-based API that uses a simple JSON data format for requests and responses.

Authentication

Authentication is achieved via a Bearer token provided in the Authorization header. The token in use is scoped to a specific Shopify store and can be retrieved from the Cardigan settings page for each store.

An example token may look like this:

PD32xweQynoAbsi7dZVxRvK1SAMcQjiVa5VncZPVDGiqDGfhTFdNFYqFp7KYGDaNXAQyPo8qT8s76Uq4H1CEy1Rw1wr29wJzKnSvYpNW73v9yRJNvMQCSx3daK8qhUsv

with the corresponding header looking like this:

Authorization: Bearer PD32xweQynoAbsi7dZVxRvK1SAMcQjiVa5VncZPVDGiqDGfhTFdNFYqFp7KYGDaNXAQyPo8qT8s76Uq4H1CEy1Rw1wr29wJzKnSvYpNW73v9yRJNvMQCSx3daK8qhUsv

Endpoints

The base URL for the API is https://app.runcardigan.com/api/v1/:shopify_subdomain, where :shopify_subdomain is the Shopify subdomain for the relevant store — for example, the store my-store.myshopify.com would have an API base URL of https://app.runcardigan.com/api/v1/my-store.

Activate card

The activate endpoint allows integrators to request the activation of an existing physical card with a specified value.

Example request

To activate a card with the number 892302452925087802753 and a value of CAD$100.00, the following request would be made:

POST <https://app.runcardigan.com/api/v1/my-store/activated_cards.json>
Authorization: Bearer PD32xweQynoAbsi7dZVxRvK1SAMcQjiVa5VncZPVDGiqDGfhTFdNFYqFp7KYGDaNXAQyPo8qT8s76Uq4H1CEy1Rw1wr29wJzKnSvYpNW73v9yRJNvMQCSx3daK8qhUsv
Content-Type: application/json
{
  "amount": "100.00",
  "currency_code": "CAD",
  "number": "892302452925087802753",
  "source_name": "Return RA45738953"
}