# cards.save

Add a card or account number (kind card_last4 or account_last4 and four digits) to an account, or change its label, cardholder or whether it is on, with idempotencyKey (and id with expectedRevision for changes). Receipts paid with that card are placed on its account. A number active on another account is refused.

`POST /api/v1/accounting/cards.save`

Permissions: `accounting:read`, `accounting:write` · Roles: admin, finance · Idempotency key required · Send `expectedRevision`

MCP tool: `accounting_cards_save`

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `id` | string (ID) |  | The record's ID. |
| `expectedRevision` | integer |  | The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again. at most 9007199254740991; greater than 0. |
| `accountId` | string (ID) |  | The ID of a bank, card or payment account, from accounts.list. |
| `kind` | enum |  | Which kind of record or job this is. One of: `card_last4`, `account_last4`. |
| `value` | string |  | Four-digit year. |
| `label` | string |  | at most 80 characters. |
| `cardholderUserId` | string |  | at most 200 characters. |
| `cardholderName` | string |  | at most 120 characters. |
| `active` | boolean |  | Whether the record is turned on. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/accounting/cards.save \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{}'
```

Reference page: https://app.getoatmilk.com/docs/api/cards.save
