Skip to main content
For API-created cardholders, subscribe to Virtual Cards to receive card.code when the issuer requests wallet verification. Numero does not email these API cardholders: your application must privately deliver the code to its customer. For dashboard-created cardholders, Numero emails the cardholder instead; the code is not sent to the merchant webhook. The event uses the normal signed Numero webhook envelope. Its data contains:
Verify the webhook signature, deduplicate eventId, and deliver only to the customer who owns that card. Never log the code or expose it to other customers or staff. Acknowledge promptly after secure receipt. Codes are delivered only within a five-minute freshness window. This is a delivery cutoff, not a guarantee of the issuer’s code validity. Codes are redacted from delivery history and cannot be manually or automatically replayed. If delivery fails or the code expires, request a new code from the wallet setup flow. Apple Pay verification has been observed. The same event is handled without assuming a wallet platform; Google Pay eligibility and its verification flow still require issuer confirmation and device testing. Receiving this event does not itself prove successful wallet enrollment.