capability values at issue) and your entitlement status. Use this instead of hardcoding product codes. You can only issue from products with entitlementStatus: Approved.
Card endpoints use the same base URL and API key as the rest of the API, and are signature-gated: sendX-Numero-SignatureandX-Numero-Signature-Version: v2as well. See Request signing.