## card_token

**uuid**  
*required*  
The unique token of the card to add to the device's digital wallet.

## Update request.

### digital_wallet

**string**  
*enum*  
Name of digital wallet provider.

*Allowed:*  
`APPLE_PAY` `GOOGLE_PAY`

### server_session_id

**uuid**  
Only applicable if `digital_wallet` is GOOGLE_PAY. Google Pay Web Push Provisioning session identifier required for the FPAN flow.

### client_device_id

**uuid**  
Only applicable if `digital_wallet` is GOOGLE_PAY. Google Pay Web Push Provisioning device identifier required for the tokenization flow.

### client_wallet_account_id

**uuid**  
Only applicable if `digital_wallet` is GOOGLE_PAY. Google Pay Web Push Provisioning wallet account identifier required for the tokenization flow.

## Response Codes

### `200 OK`

**AppleWebPushProvisioningResponse GoogleWebPushProvisioningResponse**

#### jws

**object**  
*required*  
JWS object required for handoff to Apple's script.

##### header

**object**  
JWS unprotected headers containing header parameters that aren't integrity-protected by the JWS signature.

###### header object

**protected**  
**string**  
Base64url encoded JWS protected headers containing the header parameters that are integrity-protected by the JWS signature.

**payload**  
**string**  
Base64url encoded JSON object containing the provisioning payload.

**signature**  
**string**  
Base64url encoded signature of the JWS object.

**state**  
**string**  
*required*  
A unique identifier for the JWS object.

### `400`
A parameter in the query given in the request does not match the valid queries for the endpoint.

### `401`
| Description | Reason |
| --- | --- |
| User has not been authenticated | Invalid or missing API key |
|  | API key is not active | The API key used is no longer active |
|  | Could not find API key | The API key provided is not associated with any user |
|  | Please provide API key in Authorization header | The Authorization header is not in the request |
|  | Please provide API key in the form Authorization: \[api-key\] | The Authorization header is not formatted properly |
|  | Insufficient privileges. Issuing API key required | Write access requires an Issuing API key. Reach out at [lithic.com/contact](/content/contact/index.html) |
|  | Insufficient privileges to create virtual cards. | Creating virtual cards requires an additional privilege |

### `404`
The specified resource was not found.

### `422`
Unprocessable entity.

### `429`
Client has exceeded the number of allowed requests in a given time period.
| Description | Reason |
| --- | --- |
| Rate limited, too many requests per second | User has exceeded their per second rate limit |
| Rate limited, reached daily limit | User has exceeded their daily rate limit |
| Rate limited, too many keys tried | One IP has queried too many different API keys |

## Example

### cURL Request

```bash
curl --request POST \
     --url https://sandbox.lithic.com/v1/cards/card_token/web_provision \
     --header 'accept: application/json' \
     --header 'content-type: application/json' \
     --data '
{
  "digital_wallet": "APPLE_PAY"
}
'
```

### Response Example

```json
{
  "jws": {
    "header": {
      "kid": "8dc7aed4-29e3-41e4-9cdb-673a05e6615c"
    },
    "protected": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9",
    "payload": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9",
    "signature": "SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c"
  },
  "state": "3cc4c292-727b-4ca8-b9a8-f96c15485f4e"
}
```
