generateVCShareLinks resolves to a Fluz-hosted activation page at https://fluz.app/virtual-prepaid-card/{share_request_id}. The recipient claims their card there — no app download, no password.
The recipient becomes an authorized user of that virtual card object only. They do not gain access to your account, your balances, or any other cards.
See it in action: desktop flow · mobile flow.
Claim flow
1
Landing & sign-in
The recipient sees the activation page branded with the sender’s business. They sign in through the Fluz auth portal (new recipients onboard here).
2
Two-factor authentication
On initial load, existing users are taken to the 2FA screen. 2FA is required before the card can be viewed or claimed.
3
Billing address (if needed)
If the recipient has no billing address on file, they’re prompted to add one. Billing address is required for online purchases.
4
Card issued & claimed
A single-load virtual card is created and assigned to the recipient, funded from the sender’s account, with a lock date equal to the link’s expiration date. No PIN prompt occurs during activation.
5
Reveal & PIN
The card is not auto-revealed on claim. When the recipient chooses to reveal card details, they’re prompted to enter their PIN — or create one, if they haven’t set one yet.
6
Use the card
Once revealed, the recipient can see card details, transactions, spend online, and (where supported) add the card to Apple Pay or Google Pay in one tap.
Already claimed? If the same user opens a link they already claimed, they land on their card and are prompted for their PIN to reveal it. If a different user opens a link that someone else already claimed, they’re shown an access-denied state after 2FA.
Funding timing. The card limit is drawn against the sender’s spend account at claim time, not when the link is generated.
What the recipient sees for expiration
The link’s expiration date — set by the sender viadaysUntilExpiration, defaulting to 30 days — is surfaced to the recipient, typically as a “Valid until” date.
- Before claim, that date is the last day the link can be claimed.
- After claim, that date is the card’s freeze / lock date (end of day). After it, the card can no longer be spent.
- The printed card expiry is aligned to the end of that month (e.g., a freeze date of 6/15/2026 yields a card expiry of 6/30/2026).
Recipient-facing link errors
Program rules to communicate to recipients
These are program-level rules for hosted (open-loop) virtual cards. Confirm the exact values for your program with your Fluz representative — several are partner-negotiated.
Customer support for recipients: 1-888-360-6660 · humans@fluz.app
The full partner-facing reference (terminology, recipient walkthrough with screenshots, funding instructions, restricted categories, and support) lives in the Partner Guide — Hosted URL Virtual Cards. Ask your Fluz contact for the latest copy for your program.
Next steps
Send open-loop cards
Generate, list, and deactivate hosted virtual card links from the API.
Create a bulk order
Issue many cards at once for programmatic distribution.