> ## Documentation Index
> Fetch the complete documentation index at: https://next-developers.opencard.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Update card holder

> `reference_id` is required. `email` is optional — omit to keep the current value (including null for identity-linked holders). Resends PDPC email only when unsigned/no identity, `skip_pdpc_email` is false, and an email address exists. Duplicate `reference_id` within the organization returns 400.



## OpenAPI

````yaml /openapi/ems-api.json put /accounts/{accountId}/organizations/{organizationId}/cardholders/{cardHolderId}
openapi: 3.0.3
info:
  title: OpenCard EMS API
  version: '1.0'
  description: >-
    API for Expense Management Systems. Manage TPAs, organizations, card
    holders, and webhooks. Receive transaction data via webhooks — not by
    polling this API.
  contact:
    email: support@opencard.io
servers:
  - url: https://api.opencard.io/api/v1/application
    description: Production
  - url: https://sandbox-api.opencard.io/api/v1/application
    description: Sandbox
security: []
paths:
  /accounts/{accountId}/organizations/{organizationId}/cardholders/{cardHolderId}:
    put:
      tags:
        - Card Holders
      summary: Update card holder
      description: >-
        `reference_id` is required. `email` is optional — omit to keep the
        current value (including null for identity-linked holders). Resends PDPC
        email only when unsigned/no identity, `skip_pdpc_email` is false, and an
        email address exists. Duplicate `reference_id` within the organization
        returns 400.
      operationId: updateCardHolder
      parameters:
        - $ref: '#/components/parameters/accountId'
        - $ref: '#/components/parameters/organizationId'
        - name: cardHolderId
          in: path
          required: true
          description: Card holder ID
          schema:
            type: integer
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CardHolderUpdate'
            example:
              reference_id: employee_john_99
      responses:
        '200':
          description: Updated card holder
          content:
            application/json:
              example:
                id: 15
                reference_id: employee_john_42
                organization_id: 3
                identity_id: 123
                email: john@acme.se
                created_at: '2026-06-08T10:00:00.000000Z'
                updated_at: '2026-06-08T10:30:00.000000Z'
                meta:
                  ssn: true
                  signed: true
                  signed_at: '2026-06-08T10:30:00.000000Z'
                  email_status: delivered
                  pdpc_url: >-
                    https://sandbox-api.opencard.io/accounts/1/pdpcs/8/sign/abc...
                  system: Acme EMS
                  organization_number: '5561234567'
                identity:
                  name: Anna Andersson
                  employee_id: '001'
        '400':
          description: Bad request
          content:
            application/json:
              example:
                error: Card holder reference employee_john_42 already exists
      security:
        - opencard_auth:
            - card-holders-write
components:
  parameters:
    accountId:
      name: accountId
      in: path
      required: true
      description: Your account ID
      schema:
        type: integer
    organizationId:
      name: organizationId
      in: path
      required: true
      description: Organization ID
      schema:
        type: integer
  schemas:
    CardHolderUpdate:
      type: object
      required:
        - reference_id
      description: >-
        Update card holder. Only `reference_id` is required; other fields are
        optional.
      properties:
        reference_id:
          type: string
        email:
          type: string
          nullable: true
          format: email
          description: Omit to leave unchanged
        skip_pdpc_email:
          type: boolean
        language:
          type: string
          enum:
            - sv
            - 'no'
            - da
            - en
            - fi
  securitySchemes:
    opencard_auth:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://api.opencard.io/oauth/token
          scopes:
            accounts-read: Read your account
            accounts-write: Update your account
            oauth-clients-read: Read OAuth clients
            oauth-clients-write: Create OAuth clients
            public-records-read: Company registry lookup
            account-tpas-read: Read TPAs
            account-tpas-write: Create TPAs
            account-tpas-delete: Delete TPAs
            account-tpa-signatories-read: Read TPA signatories
            account-tpa-signatories-write: Add TPA signatories
            account-tpa-identities-read: List identities on TPA
            billings-write: Create billing profiles
            card-issuers-read: List available card programs (catalog)
            account-card-issuers-read: List enabled issuers
            account-card-issuers-write: Enable issuers
            account-card-issuers-delete: Disable issuers
            organizations-read: Read organizations
            organizations-write: Create organizations
            card-holders-read: Read card holders
            card-holders-write: Create and update card holders
            card-holders-delete: Delete card holders
            webhooks-read: Read webhooks
            webhooks-write: Create webhooks
            webhook-events-read: Read webhook delivery log
            receipts-write: Scan receipts (OCR)

````