Corporate card programs · Mastercard & Visa

Launch a corporate card program.
Not a bank project.

Issue virtual and physical cards for business expenses, media buying and supplier payments — on our shared live programs in days, or on your own dedicated BIN sponsored in the UK, Hong Kong or the USA. One REST API, real-time controls, spend you can see.

Live on a shared BIN in days Dedicated BIN in 6–10 weeks Unlimited virtual cards REST API + webhooks
Media buying
TikTok · EU Q3
5258 47•• •••• 4021
Limit $250,000 / moDEDICATED BIN
Business expenses
A. Salomatin
5395 02•• •••• 8814
Apple Pay · Google PaySHARED PROGRAM
# Issue a virtual card — one call
curl -X POST https://api.cards.ecapz.com/v2/cards/virtual \
  -H 'X-Project: proj_live_8f2c' \
  -d '{"company_id":"cmp_5e1a…","account_id":"acc_9b1d…",
       "owner_id":"9f8a…","name":"TikTok · EU Q3",
       "limits":{"month":250000}}'

→ {"success":true,"res":{"data":{"id":"card_b3f9…"}}}
Built on 🇬🇧 UK BIN sponsor 🇭🇰 Hong Kong BIN sponsor 🇺🇸 USA BIN sponsor Mastercard · Visa PCI DSS environment 3-D Secure 2 Apple Pay · Google Pay
Choose your program

Three ways to get a card program — pick your trade-off

Speed, control and cost pull against each other. Start on a shared live program today and migrate to your own BIN once volume justifies it — the API and the panel don't change.

Shared live program

⚡ Live in days

Issue on BINs that are already certified, funded and running in production. No sponsorship application, no scheme certification, no minimums.

  • Existing Mastercard / Visa ranges
  • Virtual cards instantly, physical on request
  • KYC/KYB handled by us
  • Pay per top-up and per active card only
  • No setup fee, no monthly platform fee
Best for: teams that need working cards this week, pilots, and programs under ~$1M / month.
Start on a shared BIN

Own program

🏛 12+ weeks · principal

You hold the licence or principal membership; Card Bridge runs the issuing rails, processing, controls and reporting on top of it.

  • Your scheme relationship and economics
  • Interchange and FX accrue to you
  • White-label panel and API under your domain
  • Bring your own BIN sponsor or processor
  • Dedicated environment and SLAs
Best for: licensed EMIs, PSPs and neobanks that want the tech without building an issuing stack.
Talk to solutions
 Shared live programDedicated BINOwn program
Time to first cardDays6–10 weeks12+ weeks
BIN ownershipCard BridgeYours, under our sponsorYours, under your licence
Sponsor jurisdictionPre-selectedUK · Hong Kong · USAYour choice
Traffic isolationShared rangeFull isolationFull isolation
Card art & descriptorStandardCustomCustom
LimitsStandard tiersNegotiatedSet by you
Interchange & FX upsideSharedYours
Setup costNoneOne-offProject-based
Same API & admin panelYesYesYes
BIN sponsorship

Pick the jurisdiction your spend actually lives in

Where your BIN is issued changes acceptance, settlement currency and the compliance regime you operate under. We sponsor in three, and you can run more than one in parallel.

🇬🇧

United Kingdom

FCA-authorised EMI sponsor. The default for European operations and GBP/EUR settlement.

CurrenciesGBP · EUR · USD
SchemesMastercard · Visa
Strongest acceptanceUK · EEA
RegimeFCA / PSR · SCA
Physical cardsYes
🇭🇰

Hong Kong

SFC/HKMA-regulated sponsor. The pragmatic route for APAC-facing spend and USD/HKD settlement.

CurrenciesUSD · HKD
SchemesMastercard · Visa
Strongest acceptanceAPAC · global online
RegimeHKMA · AMLO
Physical cardsYes
🇺🇸

United States

US bank sponsor with a US BIN — the best authorisation rates on US ad platforms and SaaS billing.

CurrenciesUSD
SchemesMastercard · Visa
Strongest acceptanceUS merchants · ad platforms
RegimeFinCEN · BSA/AML
Physical cardsYes
Use cases

One program, every kind of company spend

Issue a card per person, per campaign, per vendor or per invoice — each with its own limit, its own rules and its own line in the ledger.

📈

Media buying

A card per ad account, campaign or geo. High limits, instant replacement, and BIN isolation so one buyer's chargeback doesn't cost the whole team its authorisations.

🧾

Business expenses & T&E

Employee cards with monthly limits, MCC restrictions and receipt capture. Travel, meals and software land pre-coded instead of arriving as an expense report.

🏭

Procurement & AP

Single-use virtual cards per purchase order or invoice. The number is worthless after it's used, and the funding account is never exposed to the supplier.

🌍

Contractors & affiliates

Fund freelancers, agencies and affiliates on cards you can freeze in one call — no bank details, no payout rails, no waiting for cut-off times.

☁️

SaaS & cloud subscriptions

One card per vendor. Renewals stop being a surprise: set the ceiling to the contract value and the next unauthorised uplift simply declines.

✈️

Travel & events

Time-boxed cards for a trip or a conference, issued to a phone wallet in seconds and closed automatically when the dates pass.

For media buyers

Ad spend at full speed — without payment bottlenecks

Ad platforms judge a card by the company it keeps. Cards issued from a shared, mixed-quality BIN inherit everyone else's decline history. Your own BIN doesn't.

🚀

Limits that fit the budget

Program and per-card ceilings sized for six- and seven-figure monthly ad spend, not consumer caps.

🛡

Fewer platform blocks

A dedicated range isolates your authorisation history from other merchants' fraud and chargebacks.

🎯

A card per campaign

Attribute every dollar without a spreadsheet. Kill a campaign, freeze its card — spend stops instantly.

♾️

Unlimited virtual cards

Issue in seconds via API or the panel, share access with the buyer who needs it, revoke in one click.

 Card Bridge dedicated BINTraditional business bank
BIN ownershipYours, isolatedShared with every customer
New cardSeconds, via APIDays to weeks, via a form
Cards per accountUnlimitedA handful
Exposure to others' fraudNoneFull — you share the range
Per-card rulesLimits, MCC, country, velocityOne blanket limit
Spend visibilityReal-time authorisationsNext-day statement
Scaling to 1,000 cardsA loop in your codeA relationship manager
Control & visibility

Take full control over where your money goes — and where it doesn't

Every card carries its own policy. Every authorisation is decided against that policy in real time, and lands in a ledger your finance team can actually close a month with.

🎚

Per-card spending limits

Daily, weekly, monthly and lifetime ceilings. Change them by API and the next authorisation obeys.

🚧

Merchant & MCC rules

Allow or block by merchant category, country and channel. Online-only, ATM-off, single-merchant — your call.

❄️

Freeze, unfreeze, terminate

Stop a card mid-campaign without closing it. Reopen when the review clears. All of it is one endpoint.

Approval workflows

Route new cards, limit increases and top-ups through the approvers you define, with a full trail.

👥

Roles & team access

Admins, finance, buyers and viewers. People see the cards and accounts they're entitled to, and nothing else.

🧮

Reconciliation & exports

Balances, top-ups, authorisations and settlements per account and per card — as data, not as a PDF.

🔔

Webhooks & alerts

Card events, authorisations, declines and KYC status pushed to your systems as they happen.

🪪

KYC & KYB built in

Onboard companies and cardholders through the API — document capture, checks and status, no side portal.

📚

Immutable audit log

Who issued which card, who raised which limit, who approved it and when. Exportable for auditors.

API-first

Everything in the panel is an API call

Card Bridge is a REST API with a management panel on top — not a portal with an API bolted on. Onboarding, issuing, funding, controls and transactions are all addressable.

  • OpenAPI 3.0 specification

    The full contract, published and versioned. Generate a client in your language in one command.

  • Signed requests & idempotency

    HMAC-SHA256 request signing with a project key, plus idempotency keys on every mutating call.

  • Sandbox that behaves like production

    Same endpoints, same error catalogue, test BINs and simulated authorisations.

  • Webhooks for everything that moves

    Card lifecycle, authorisations, declines, top-ups and KYC transitions — signed and retried.

  • Explicit, documented errors

    A complete numeric error catalogue, so your integration can branch on codes instead of strings.

# POST /v2/cards/virtual
{
  "company_id": "cmp_5e1a7b9c-3d2f-4e8a-91b0-d6e4f0c2a134",
  "account_id": "acc_9b1d4f0a-7c1e-4a2b-90d5-0e72c3fa1d11",
  "owner_id":   "9f8a3c7e-2db1-4c0a-9c2e-b8a98e0f1a3d",
  "name":       "Meta Ads · US",
  "card_type":  "virtual",
  "limits":     { "month": 250000 }
}

→ 200 { "success": true,
     "res": { "data": { "id": "card_b3f99a0c-7d51-4d28-9c3e-aa412e8f7c45" } } }
# POST /v2/accounts/topup — fund the account
{ "company_id": "cmp_5e1a…", "account_id": "acc_9b1d…",
  "amount": 50000, "currency": "USD" }

# POST /v2/cards/deposit — move it onto the card
{ "company_id": "cmp_5e1a…", "card_id": "card_b3f9…",
  "amount": 12500 }

→ 200 { "success": true }
# Cards spend only what has been loaded onto them —
# the top-up is your hard spending control.
# POST /v2/cards/spend-limit
{ "company_id": "cmp_5e1a…", "card_id": "card_b3f9…",
  "limits": { "day": 20000, "month": 250000 } }

# Pause spend without closing the card
POST /v2/cards/freeze    { "card_id": "card_b3f9…" }
POST /v2/cards/unfreeze  { "card_id": "card_b3f9…" }

→ the next authorisation is decided against the new policy.
# POST /v2/accounts/transactions
{ "company_id": "cmp_5e1a…", "account_id": "acc_9b1d…",
  "from": "2026-07-01", "to": "2026-07-31" }

→ 200
{ "success": true, "res": { "data": [
    { "card_id": "card_b3f9…", "merchant": "FACEBK ADS",
      "amount": 4820.00, "currency": "USD",
      "status": "settled", "mcc": "7311" } ] } }
# POST https://your-app.example/webhooks/card-bridge
# X-CB-Signature: sha256=…
{
  "event":      "card.authorization.declined",
  "created_at": "2026-07-28T09:14:02Z",
  "data": {
    "card_id":  "card_b3f9…",
    "merchant": "GOOGLE ADS",
    "amount":   1200.00,
    "reason":   "limit_exceeded"
  }
}

# Retried with backoff until you return 2xx.
Pricing

Work out what your program costs

No interchange games, no hidden spread. You pay a percentage on money you load, a small monthly fee per active card, and — on a dedicated program — a setup and platform fee. Move the numbers below to see the whole bill.

Your program

money moved onto cards
$
billed monthly
60% crypto · 40% fiat
● Crypto top-upFiat / bank transfer ●
Adjust the rate card

Defaults are indicative for the selected program. Your commercial terms are fixed at onboarding — edit these to model an agreed rate card.

%
%
$
$
$
$
$
Monthly cost
$7,200
$86,400 per year
Effective rate
0.72%
of the volume you load
Per active card
$7.20
all-in, per month
Cost per transaction
$1.44
5,000 transactions / month

Where it goes

monthly
FeeBasisRateCost
Total per month $7,200.00

Indicative only, and not an offer. Figures exclude scheme and network pass-through charges, FX on non-USD settlement, chargeback handling and any taxes. Card loads are the spending control: a card can only spend what has been loaded onto it, and the load fee is charged at top-up and is not refunded if funds are later unloaded.

🔓

No lock-in

Monthly terms on shared programs. Start with ten cards and grow, or stop — no minimum volume commitment.

📉

Volume pricing

Load rates step down as monthly volume grows. Past $5M a month the conversation is a rate card, not a price list.

🤝

Revenue share

On dedicated and own programs, interchange and FX upside is shared or kept entirely by you.

Trust

Regulated rails, boring security

Card data never touches your infrastructure, and cardholder identity is verified before the first authorisation.

🔐

PCI DSS environment

PANs and CVVs stay inside the certified issuing environment; you handle tokens and references.

🪪

KYC / KYB

Company and cardholder verification with document capture, screening and an auditable status trail.

🛡

3-D Secure 2 & SCA

Strong customer authentication with OTP or in-app approval, tuned per program to keep declines down.

🏛

Licensed sponsors

Every BIN sits under a regulated sponsor — FCA in the UK, HKMA-supervised in Hong Kong, a bank in the US.

FAQ

Questions we get asked first

How fast can we issue our first card?
On a shared live program, in days — the BIN is already certified, so the gating item is your KYB and the cardholder's KYC. Once the company is onboarded, a virtual card is a single API call and is usable immediately. A dedicated BIN takes 6–10 weeks because it involves the sponsor and scheme certification, but you can run on a shared program in the meantime and migrate later.
What's the real difference between a shared and a dedicated BIN?
Isolation. On a shared BIN your cards sit in a range used by other companies, so their chargebacks, fraud and decline history influence how merchants and ad platforms score your cards. A dedicated BIN is exclusively yours: your authorisation history is your own, limits can be sized to your business, and you get your own card art and descriptor. If your spend is concentrated on platforms that are strict about card quality — ad networks in particular — a dedicated BIN pays for itself.
Which jurisdiction should we choose — UK, Hong Kong or the USA?
Follow the spend. UK for GBP/EUR settlement and European operations under the FCA regime. Hong Kong for USD/HKD and APAC-facing spend with a faster onboarding path. USA for a US BIN, which gets the best authorisation rates on US ad platforms and SaaS billing. Programs can run in parallel — many customers use a US BIN for ad spend and a UK BIN for staff expenses.
Is the whole thing available over an API?
Yes. Onboarding companies and cardholders, KYC submission and status, creating accounts, issuing virtual and physical cards, funding, limits, freeze/unfreeze, and reading transactions are all REST endpoints, described in a published OpenAPI 3.0 specification. Requests are HMAC-signed with a project key; mutating calls take an idempotency key; and webhooks push card, authorisation and KYC events to you. The admin panel uses the same API, so there is nothing you can do in the UI that you can't automate.
How do we stop a card overspending?
Two independent mechanisms. First, a card can only spend what has been loaded onto it — top-up is the hard ceiling. Second, each card carries its own policy: daily, weekly and monthly limits, merchant-category and country rules, online-only or single-merchant restrictions. Authorisations are decided against that policy in real time, and you can freeze a card instantly without closing it.
Can we issue physical cards, and do they work with Apple Pay?
Yes to both. Physical cards are ordered through the same API with a delivery address, and cards on supported BINs can be tokenised into Apple Pay and Google Pay so a virtual card is spendable in store within seconds of issuance.
How many cards can we issue?
Virtual cards are effectively unlimited — issue one per campaign, per vendor or per invoice. Practical ceilings come from your program limits and your BIN range, both of which are sized with you up front on a dedicated program.
What does it actually cost?
A percentage of the money you load onto cards, plus a small monthly fee per active card. Dedicated and own programs add a one-off setup and a monthly platform fee, and share interchange and FX upside back with you. Use the fee calculator above to model your own numbers.
Get started

Your card program, running this quarter

Tell us where your spend goes and how much of it there is. We'll come back with a rate card, the right jurisdiction and a sandbox key.