Two token paths, one API
Your own account
API credentials → Your tokenYou use API keys to mint a User Access Token for your account.A customer's account
OAuth grant → Their tokenCustomers authorize your app, and Fluz returns a token scoped to their account.From there,
createVirtualCard is createVirtualCard — no separate platform API to learn.Onboard and connect customers
Create your OAuth app
Configure your app, redirect URIs, and scopes in the dashboard. Create an OAuth app →
Register or connect the customer
New customers: register individuals or businesses with built-in KYC and KYB. Existing Fluz users: send them through the grant flow. User registration → · KYC verification →
Exchange the grant for a token
The customer authorizes your app; you exchange the code for a token scoped to their account. Grant flow → · Exchange the code →
Run the APIs you already know
Send the customer-scoped token instead of your own. Everything else is identical. Refresh tokens →
What you can do on connected accounts
Every capability applies as written when you use a customer-scoped token.Virtual cards
Gift cards
Wallets & transfers
Funding sources
Transactions
Authorized users
Take your app live
Anything you build against your own account needs nothing from us. Certifying a public app — one that operates on other verified Fluz accounts — requires a due diligence review first.Handle account opening and management
Register and verify your customers, or connect existing Fluz users through the grant flow. User registration → · KYC verification → · Business registration →
Build your core capabilities
Implement the capabilities your app needs in staging using a customer-scoped token. Every capability behaves exactly as documented on your own account.
Complete the due diligence form
Submit the form or forms below that apply to your program. Our team reviews the submission and approves your application.
Go live
We certify your public app and release production credentials. Deploying to production →
Due diligence
Operating on behalf of your customers
Required if you are embedding Fluz to operate on behalf of your customers. Complete the platform due diligence form →
Specialized verticals
Gaming, prediction markets, sweepstakes, and money services businesses follow an enhanced review path before going live. See the process, the timeline, and the form for your vertical →
Direct card interaction (PCI)
Required if you will interact directly with cards we issue, or pass us the actual cards of your users. You must be PCI compliant. Form link coming soon.
Custom card art
Required if cards will carry your brand instead of the standard Fluz design. Bank and network approval adds 6–8 weeks — see the specifications and the submission process →