> For the complete documentation index, see [llms.txt](https://tri.gitbook.io/tri-doc/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://tri.gitbook.io/tri-doc/liquidity-pool/add-mastercard-card/save-mastercard-card.md).

# Save MasterCard Card

### Liquidity Pool

<mark style="color:green;">`POST`</mark> <https://sandbox.triangle.digital/api/v2/liquidity\\_pool/clients/{client\\_id}/mastercard>

**Step 2 of 2** of [Add MasterCard Card](/tri-doc/liquidity-pool/add-mastercard-card.md). Start with [Start MasterCard Enrolment](/tri-doc/liquidity-pool/add-mastercard-card/start-mastercard-enrolment.md) — this call takes that flow's result, never card details.

Stores the enrolment the browser captured in MasterCard's Consent UI, so the holder — an employee or an individual consumption — has a MasterCard card on file.

Call it only after the widget reported `Close` with `status: 'success'` — a card that has not passed authentication must not be stored.

`consent_id` is required, not optional: without it the card could never be revoked, and it would stay on the holder with no way to remove it.

One MasterCard card per holder: a holder that already has one is refused. A Stripe card on the same holder is independent and stays.

**Path parameters**

<table data-full-width="true" data-search="false"><thead><tr><th width="230">Name</th><th width="110">Type</th><th>Description</th><th width="210">Where to take it from</th></tr></thead><tbody><tr><td><code>client_id</code></td><td>integer</td><td><strong>Required.</strong> The client the holder belongs to.</td><td><a href="/tri-doc/liquidity-pool/get-clients.md">Get Clients</a> — <code>client_id</code></td></tr></tbody></table>

**Headers**

<table data-full-width="true"><thead><tr><th>Name</th><th>Value</th></tr></thead><tbody><tr><td>Content-Type</td><td><code>application/json</code></td></tr></tbody></table>

**Body**

<table data-full-width="true" data-search="false"><thead><tr><th width="250">Name</th><th width="110">Type</th><th>Description</th><th width="260">Example</th></tr></thead><tbody><tr><td><code>hash</code></td><td>string</td><td><strong>Required.</strong> API key.</td><td>fk5f0iuy-rr06-j4x3-i75b-fy2s67s4ilo1</td></tr><tr><td><code>employee_id</code></td><td>integer</td><td>The employee the card belongs to. Exactly one of <code>employee_id</code> and <code>individual_consumption_id</code> is required, and it has to be the holder the enrolment was started for. From <a href="/tri-doc/liquidity-pool/get-employees.md">Get Employees</a> — <code>employee_id</code>.</td><td>345</td></tr><tr><td><code>individual_consumption_id</code></td><td>uuid</td><td>The individual consumption the card belongs to; Business clients only. Exactly one of <code>employee_id</code> and <code>individual_consumption_id</code> is required. From <a href="/tri-doc/liquidity-pool/get-individual-consumptions.md">Get Individual Consumptions</a> — <code>individual_consumption_id</code>.</td><td>68117898-4278-499f-b96b-78173f3d2040</td></tr><tr><td><code>card_reference</code></td><td>string</td><td><strong>Required.</strong> The card reference MasterCard returned in the widget's <code>Close</code> message.</td><td>a1b2c3d4-5e6f-7081-92a3-b4c5d6e7f809</td></tr><tr><td><code>consent_id</code></td><td>string</td><td><strong>Required.</strong> The consent id from the same message. Kept so the card can be revoked later.</td><td>0f1e2d3c-4b5a-6978-8796-a5b4c3d2e1f0</td></tr><tr><td><code>card_name</code></td><td>string</td><td>Short label for the card, stored trimmed to 12 characters.</td><td>Corporate</td></tr></tbody></table>

```json
{
    "hash": "fk5f0iuy-rr06-j4x3-i75b-fy2s67s4ilo1",
    "employee_id": 345,
    "card_reference": "a1b2c3d4-5e6f-7081-92a3-b4c5d6e7f809",
    "consent_id": "0f1e2d3c-4b5a-6978-8796-a5b4c3d2e1f0",
    "card_name": "Corporate"
}
```

**Response fields**

<table data-full-width="true" data-search="false"><thead><tr><th width="300">Field</th><th width="110">Type</th><th>Description</th></tr></thead><tbody><tr><td><code>message</code></td><td>string</td><td>Human-readable result of the call.</td></tr><tr><td><code>success</code></td><td>boolean</td><td>Whether the card was stored; a refused call answers HTTP 400.</td></tr><tr><td><code>data.card.card_name</code></td><td>string</td><td>The stored label, trimmed to 12 characters; empty when none was sent.</td></tr><tr><td><code>data.card.card_last4</code></td><td>string</td><td>Last 4 digits of the card. Empty on a fresh card — MasterCard reports the digits only with the card's transactions, so the value appears once those are read.</td></tr><tr><td><code>data.employee</code></td><td>object</td><td>The holder when it is an employee — <code>employee_id</code>, <code>employee_number</code>, <code>employee_name</code>. Absent for an individual consumption.</td></tr><tr><td><code>data.individual_consumption</code></td><td>object</td><td>The holder when it is an individual consumption — <code>individual_consumption_id</code>, <code>name</code>, <code>email</code>. Absent for an employee.</td></tr><tr><td><code>operations_count</code></td><td>integer</td><td>Always <code>1</code>.</td></tr></tbody></table>

**Response**

{% tabs %}
{% tab title="201" %}
{% code fullWidth="false" %}

```json
{
    "message": "MasterCard card added successfully.",
    "success": true,
    "data": {
        "card": {
            "card_name": "Corporate",
            "card_last4": ""
        },
        "employee": {
            "employee_id": 345,
            "employee_number": "D2354324",
            "employee_name": "John Smith"
        }
    },
    "operations_count": 1
}
```

{% endcode %}
{% endtab %}

{% tab title="400" %}
Nothing was stored. The `message` says what exactly: `'card_reference' is required.`; `'consent_id' is required.`; `MasterCard card already set.`; `Provide either employee_id or individual_consumption_id.` or `Provide either employee_id or individual_consumption_id, not both.`; `'employee_id' must be a positive integer.`; `Employee not found for this client.` or `Individual consumption not found for this client.`; `This client is not a Business account.` — an individual consumption was named for a non-Business client; `Could not save the card. Please try again.`

```json
{
    "message": "'consent_id' is required.",
    "success": false,
    "data": [],
    "operations_count": 1
}
```

{% endtab %}
{% endtabs %}
