Skip to main content

Two token paths, one API

Your own account

API credentialsYour tokenYou use API keys to mint a User Access Token for your account.

A customer's account

OAuth grantTheir tokenCustomers authorize your app, and Fluz returns a token scoped to their account.
From there, createVirtualCard is createVirtualCard — no separate platform API to learn.

Onboard and connect customers

Create your OAuth app

Configure your app, redirect URIs, and scopes in the dashboard. Create an OAuth app →

Register or connect the customer

New customers: register individuals or businesses with built-in KYC and KYB. Existing Fluz users: send them through the grant flow. User registration → · KYC verification →

Exchange the grant for a token

The customer authorizes your app; you exchange the code for a token scoped to their account. Grant flow → · Exchange the code →

Run the APIs you already know

Send the customer-scoped token instead of your own. Everything else is identical. Refresh tokens →

What you can do on connected accounts

Every capability applies as written when you use a customer-scoped token.

Virtual cards

Gift cards

Wallets & transfers

Funding sources

Transactions

Authorized users

Take your app live

Anything you build against your own account needs nothing from us. Certifying a public app — one that operates on other verified Fluz accounts — requires a due diligence review first.

Handle account opening and management

Register and verify your customers, or connect existing Fluz users through the grant flow. User registration → · KYC verification → · Business registration →

Build your core capabilities

Implement the capabilities your app needs in staging using a customer-scoped token. Every capability behaves exactly as documented on your own account.

Complete the due diligence form

Submit the form or forms below that apply to your program. Our team reviews the submission and approves your application.

Go live

We certify your public app and release production credentials. Deploying to production →

Due diligence

Platform due diligence is only required to operate on other verified accounts. You do not need it to build an application on your own account for your own activity. Specialized verticals are the exception — those programs are reviewed regardless of whose account you operate on.

Operating on behalf of your customers

Required if you are embedding Fluz to operate on behalf of your customers. Complete the platform due diligence form →

Specialized verticals

Gaming, prediction markets, sweepstakes, and money services businesses follow an enhanced review path before going live. See the process, the timeline, and the form for your vertical →

Direct card interaction (PCI)

Required if you will interact directly with cards we issue, or pass us the actual cards of your users. You must be PCI compliant. Form link coming soon.

Custom card art

Required if cards will carry your brand instead of the standard Fluz design. Bank and network approval adds 6–8 weeks — see the specifications and the submission process →
We need these completed before we can certify your public app to go live. We need these completed before we can certify your public app to go live.