> ## Documentation Index
> Fetch the complete documentation index at: https://docs.laso.finance/llms.txt
> Use this file to discover all available pages before exploring further.

# Save the account holder's own card

> Let the account holder save a card they already own, locked behind their passkey, so your agent can pay with it and the holder approves each purchase on their own device.

## Overview

A saved card is a card the account holder already owns, typed once on the card issuer's page and locked behind their passkey. Nothing is issued and nothing is prefunded: the holder's own card pays, and every purchase waits for their approval on their own device.

It needs **no identity verification**. The only prerequisite is a card account linked to the wallet, which the holder does once in the [dashboard](https://laso.finance/agent/dashboard/verified/saved-card) with a one-time code.

Laso never sees the card number. The holder types it on the issuer's page, which encrypts it on their device before it is stored.

## Save a card

Saving the card is the holder's step, the same way identity verification is. You mint the link and hand it over; you never open it yourself.

1. `GET /get-saved-cards` to see what the holder already has. Never send a holder with a saved card through the flow again.
2. If `cards` is empty, `POST /create-saved-card-link` and send the returned `url` to your human.
3. Poll `GET /get-saved-cards` until the card appears.

```bash theme={null}
curl -X POST "https://laso.finance/create-saved-card-link" \
  -H "Authorization: Bearer $LASO_ID_TOKEN" \
  -H "Idempotency-Key: $(uuidgen)"
```

```json theme={null}
{
  "url": "https://.../v?vs=...",
  "expires_at": 1759203733257,
  "note": "Send this url to the account holder..."
}
```

The page first sends a one-time code to the contact on the holder's card account, then asks for the card and a passkey. Each link works once; mint a new one if it expires.

```bash theme={null}
curl "https://laso.finance/get-saved-cards" \
  -H "Authorization: Bearer $LASO_ID_TOKEN"
```

```json theme={null}
{
  "cards": [
    {
      "card_id": "vc_7f3a9c2e1b4d6f8a0c2e4b6d",
      "last4": "4832",
      "expiry_month": 12,
      "expiry_year": 2029,
      "created_at": 1756838467000
    }
  ],
  "note": "Each purchase paid with a saved card is approved by the account holder on their own device."
}
```

Name the card when you talk to your human ("your card ending 4832"), so an approval request reads as a yes or no rather than a question.

## Errors

| Status | Meaning | What to do |
| - | - | - |
| `400` | No card account is linked to this wallet. | Ask the holder to link one at [https://laso.finance/agent/dashboard/verified/saved-card](https://laso.finance/agent/dashboard/verified/saved-card). It takes a one-time code, not an identity check. |
| `409` / `422` | `Idempotency-Key` in progress, or reused for a different request. | See [error handling](/guides/error-handling). |
