> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fyatu.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update Cardholder

> Update a cardholder's profile fields. PATCH /cardholders/{id}. Requires cardholders:write scope.

## Overview

Update one or more fields on a cardholder profile. Only the fields you include in the request body are changed — absent fields are left unchanged (true PATCH semantics).

## KYC-Locked Fields

After `kycStatus` becomes `APPROVED`, the following fields are **immutable**:

| Locked Field  | Error if changed       |
| ------------- | ---------------------- |
| `firstName`   | `409 KYC_FIELD_LOCKED` |
| `lastName`    | `409 KYC_FIELD_LOCKED` |
| `email`       | `409 KYC_FIELD_LOCKED` |
| `dateOfBirth` | `409 KYC_FIELD_LOCKED` |
| `nationality` | `409 KYC_FIELD_LOCKED` |
| `address`     | `409 KYC_FIELD_LOCKED` |

The fields `phone`, `externalId`, and `metadata` can be updated at any time regardless of KYC status.

## Updatable Fields

| Field         | Type   | Constraint                                                                                                                                                                                   |
| ------------- | ------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `firstName`   | string | KYC-locked after approval                                                                                                                                                                    |
| `middleName`  | string | Max 15 chars. **Editable even after KYC approval.** Send `""` to clear it. Forwarded to the card network on the next card creation to distinguish holders with identical first + last names. |
| `lastName`    | string | KYC-locked after approval                                                                                                                                                                    |
| `email`       | string | Valid email, unique in environment; KYC-locked after approval                                                                                                                                |
| `phone`       | string | E.164 format (e.g. `+12025551234`)                                                                                                                                                           |
| `dateOfBirth` | string | `YYYY-MM-DD`; KYC-locked after approval                                                                                                                                                      |
| `nationality` | string | ISO 3166-1 alpha-2; KYC-locked after approval                                                                                                                                                |
| `address`     | object | Full address object; KYC-locked after approval                                                                                                                                               |
| `externalId`  | string | Your internal user ID                                                                                                                                                                        |
| `metadata`    | object | Arbitrary key/value pairs (max 4096 bytes)                                                                                                                                                   |

## Example

<CodeGroup>
  ```bash cURL theme={null}
  curl -X PATCH https://api.fyatu.com/api/v3.20/cardholders/chl_01HXYZ1234ABCDEF5678 \
    -H "Authorization: Bearer $FYATU_API_KEY" \
    -H "Content-Type: application/json" \
    -d '{
      "phone": "+12025559999",
      "metadata": { "plan": "enterprise", "region": "us-east" }
    }'
  ```

  ```javascript Node.js theme={null}
  const resp = await fetch(
    'https://api.fyatu.com/api/v3.20/cardholders/chl_01HXYZ1234ABCDEF5678',
    {
      method: 'PATCH',
      headers: {
        'Authorization': `Bearer ${process.env.FYATU_API_KEY}`,
        'Content-Type': 'application/json'
      },
      body: JSON.stringify({
        phone: '+12025559999',
        metadata: { plan: 'enterprise' }
      })
    }
  );
  const body = await resp.json();
  console.log('Updated:', body.data.updatedAt);
  ```

  ```python Python theme={null}
  import os, requests

  resp = requests.patch(
      'https://api.fyatu.com/api/v3.20/cardholders/chl_01HXYZ1234ABCDEF5678',
      headers={'Authorization': f'Bearer {os.environ["FYATU_API_KEY"]}'},
      json={
          'phone': '+12025559999',
          'metadata': {'plan': 'enterprise'}
      }
  )
  cardholder = resp.json()['data']
  print('Updated at:', cardholder['updatedAt'])
  ```
</CodeGroup>

## Success Response (200)

Returns the full updated cardholder object:

```json theme={null}
{
  "success": true,
  "status": 200,
  "message": "Cardholder updated",
  "data": {
    "cardholderId": "chl_01HXYZ1234ABCDEF5678",
    "programId":    "prg_01HXYZ9876ABCDEF0000",
    "firstName":    "John",
    "lastName":     "Smith",
    "email":        "john.smith@example.com",
    "phone":        "+12025559999",
    "dateOfBirth":  "1990-05-15",
    "nationality":  "US",
    "address": {
      "line1":      "123 Main Street",
      "line2":      "Apt 4B",
      "city":       "Newark",
      "state":      "Delaware",
      "postalCode": "19701",
      "country":    "US"
    },
    "metadata":    { "plan": "enterprise", "region": "us-east" },
    "status":      "ACTIVE",
    "kycStatus":   "APPROVED",
    "kycVerifiedAt": "2026-05-01T09:05:00Z",
    "totalCards":  2,
    "totalSpendCents": 125000,
    "suspendedAt": null,
    "createdAt":   "2026-05-01T09:00:00Z",
    "updatedAt":   "2026-05-22T10:00:00Z"
  },
  "meta": {
    "requestId": "req_01HXY123456ABCDEF",
    "platform": "Fyatu CaaS",
    "timestamp": "2026-05-22T10:00:00Z"
  }
}
```

## Error Codes

| Code                      | HTTP | Cause                                                             |
| ------------------------- | ---- | ----------------------------------------------------------------- |
| `VALIDATION_ERROR`        | 422  | Invalid field values (bad email format, metadata too large, etc.) |
| `CARDHOLDER_NOT_FOUND`    | 404  | Cardholder does not exist or belongs to another business          |
| `CARDHOLDER_TERMINATED`   | 409  | Terminated cardholder cannot be modified                          |
| `KYC_FIELD_LOCKED`        | 409  | Attempted to change a field that is locked after KYC approval     |
| `CARDHOLDER_EMAIL_EXISTS` | 409  | Updated email is already in use by another cardholder             |
| `INSUFFICIENT_SCOPE`      | 403  | Key lacks `cardholders:write` scope                               |


## OpenAPI

````yaml v3.20/openapi.json PATCH /cardholders/{id}
openapi: 3.1.0
info:
  title: FYATU CaaS API v3.20
  description: >-
    FYATU Cards-as-a-Service API â€” API key authentication, Cardholder
    lifecycle, Card issuance, Transactions, Webhooks, and Programs.
  version: 3.20.0
  contact:
    name: FYATU Support
    url: https://fyatu.com
    email: support@fyatu.com
servers:
  - url: https://api.fyatu.com/api/v3.20
    description: >-
      FYATU CaaS API â€” the environment (LIVE or SANDBOX) is determined by the
      API key, not the URL
security:
  - BearerAuth: []
tags:
  - name: Meta
    description: Liveness, account info, and supported event types
  - name: Account
    description: Account-level balance and funding status
  - name: Programs
    description: Read card program configuration
  - name: Cardholders
    description: Create and manage cardholder profiles
  - name: Cards
    description: Issue, fund, freeze, and terminate virtual cards
  - name: Transactions
    description: Read-only card transaction history
  - name: Webhooks
    description: Manage webhook endpoints for real-time event delivery
  - name: Products
    description: Read card product configurations
paths:
  /cardholders/{id}:
    parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
        example: chl_01HXYZ1234ABCDEF5678
    patch:
      tags:
        - Cardholders
      summary: Update a cardholder
      description: >-
        Partially update a cardholder. KYC-locked fields cannot be changed after
        KYC approval.
      operationId: updateCardholder
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                firstName:
                  type: string
                lastName:
                  type: string
                email:
                  type: string
                  format: email
                phone:
                  type: string
                dateOfBirth:
                  type: string
                  format: date
                nationality:
                  type: string
                address:
                  $ref: '#/components/schemas/Address'
                kycDocument:
                  $ref: '#/components/schemas/KycDocument'
                externalId:
                  type: string
                metadata:
                  type: object
      responses:
        '200':
          description: Cardholder updated
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CardholderResponse'
        '400':
          $ref: '#/components/responses/ValidationError'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          description: KYC field locked or cardholder terminated
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                kycLocked:
                  value:
                    success: false
                    status: 409
                    message: Field locked after KYC approval
                    error:
                      code: KYC_FIELD_LOCKED
                      detail: firstName is locked after KYC approval
                    meta:
                      requestId: req_a1b2c3d4e5f6a7b8c9d0e1f2
                      platform: Fyatu CaaS
                      timestamp: '2026-05-22T15:00:00Z'
                terminated:
                  value:
                    success: false
                    status: 409
                    message: Cardholder is terminated
                    error:
                      code: CARDHOLDER_TERMINATED
                      detail: Cardholder is terminated and cannot be updated
                    meta:
                      requestId: req_a1b2c3d4e5f6a7b8c9d0e1f2
                      platform: Fyatu CaaS
                      timestamp: '2026-05-22T15:00:00Z'
        '422':
          $ref: '#/components/responses/ValidationError'
        '429':
          $ref: '#/components/responses/RateLimitExceeded'
        '500':
          $ref: '#/components/responses/InternalError'
components:
  schemas:
    Address:
      type: object
      properties:
        address:
          type: string
          example: 123 Main Street, Apt 4B
        city:
          type: string
          example: Newark
        state:
          type: string
          nullable: true
          example: Delaware
        postalCode:
          type: string
          nullable: true
          example: '19701'
        country:
          type: string
          description: ISO 3166-1 alpha-2
          example: US
      required:
        - address
        - city
        - country
    KycDocument:
      type: object
      description: >-
        Identity document details for KYC verification. Optional on create;
        patchable via PATCH. Not locked after KYC approval.
      properties:
        documentType:
          type: string
          enum:
            - PASSPORT
            - NATIONAL_ID
            - DRIVERS_LICENSE
            - RESIDENCE_PERMIT
          example: PASSPORT
        documentNumber:
          type: string
          example: AB123456
        issuingCountry:
          type: string
          description: ISO 3166-1 alpha-2
          example: US
        frontUrl:
          type: string
          format: uri
          example: https://storage.example.com/doc-front.jpg
        backUrl:
          type: string
          format: uri
          nullable: true
          description: Not required for passports
          example: null
        selfieUrl:
          type: string
          format: uri
          example: https://storage.example.com/selfie.jpg
    CardholderResponse:
      type: object
      properties:
        success:
          type: boolean
          example: true
        status:
          type: integer
          example: 200
        message:
          type: string
          example: Cardholder retrieved
        data:
          $ref: '#/components/schemas/Cardholder'
        meta:
          $ref: '#/components/schemas/Meta'
    Error:
      type: object
      properties:
        success:
          type: boolean
          example: false
        status:
          type: integer
          example: 422
        message:
          type: string
          example: Human readable message
        error:
          $ref: '#/components/schemas/ErrorBody'
        meta:
          $ref: '#/components/schemas/Meta'
    Cardholder:
      type: object
      properties:
        cardholderId:
          type: string
          example: chl_01HXYZ1234ABCDEF5678
        firstName:
          type: string
          example: John
        lastName:
          type: string
          example: Smith
        email:
          type: string
          format: email
          example: john.smith@example.com
        phone:
          type: string
          nullable: true
          example: '+12025551234'
        dateOfBirth:
          type: string
          format: date
          example: '1990-05-15'
        nationality:
          type: string
          description: ISO 3166-1 alpha-2
          example: US
        address:
          $ref: '#/components/schemas/Address'
        kycDocument:
          $ref: '#/components/schemas/KycDocument'
          nullable: true
        externalId:
          type: string
          nullable: true
          example: usr_123456
        metadata:
          type: object
          nullable: true
          example:
            plan: premium
        status:
          type: string
          enum:
            - ACTIVE
            - SUSPENDED
            - TERMINATED
          example: ACTIVE
        kycStatus:
          type: string
          enum:
            - PENDING
            - APPROVED
            - REJECTED
          example: APPROVED
        kycVerifiedAt:
          type: string
          format: date-time
          nullable: true
          example: '2026-05-10T14:23:00Z'
        kycRejectionReason:
          type: string
          nullable: true
          description: Only present when kycStatus is REJECTED
          example: null
        totalCards:
          type: integer
          example: 2
        suspendedAt:
          type: string
          format: date-time
          nullable: true
          example: null
        terminatedAt:
          type: string
          format: date-time
          nullable: true
          description: Only present when status is TERMINATED
          example: null
        createdAt:
          type: string
          format: date-time
          example: '2026-05-01T09:00:00Z'
        updatedAt:
          type: string
          format: date-time
          example: '2026-05-10T14:23:00Z'
    Meta:
      type: object
      properties:
        requestId:
          type: string
          example: req_a1b2c3d4e5f6a7b8c9d0e1f2
        platform:
          type: string
          example: Fyatu CaaS
        timestamp:
          type: string
          format: date-time
          example: '2026-05-22T15:00:00Z'
    ErrorBody:
      type: object
      properties:
        code:
          type: string
          example: VALIDATION_ERROR
        detail:
          type: string
          example: dateOfBirth must be in YYYY-MM-DD format
  responses:
    ValidationError:
      description: Request validation failed
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            success: false
            status: 422
            message: Validation failed
            error:
              code: VALIDATION_ERROR
              detail: dateOfBirth must be in YYYY-MM-DD format
            meta:
              requestId: req_a1b2c3d4e5f6a7b8c9d0e1f2
              platform: Fyatu CaaS
              timestamp: '2026-05-22T15:00:00Z'
    Unauthorized:
      description: Missing or invalid API key
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            missing:
              summary: API key missing
              value:
                success: false
                status: 401
                message: API key is required
                error:
                  code: AUTH_TOKEN_MISSING
                  detail: API key is required
                meta:
                  requestId: req_a1b2c3d4e5f6a7b8c9d0e1f2
                  platform: Fyatu CaaS
                  timestamp: '2026-05-22T15:00:00Z'
            invalid:
              summary: API key invalid
              value:
                success: false
                status: 401
                message: Invalid API key
                error:
                  code: AUTH_TOKEN_INVALID
                  detail: Invalid API key
                meta:
                  requestId: req_a1b2c3d4e5f6a7b8c9d0e1f2
                  platform: Fyatu CaaS
                  timestamp: '2026-05-22T15:00:00Z'
    Forbidden:
      description: Scope denied or business suspended
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            success: false
            status: 403
            message: Scope denied
            error:
              code: INSUFFICIENT_SCOPE
              detail: This endpoint requires the cards:write scope
            meta:
              requestId: req_a1b2c3d4e5f6a7b8c9d0e1f2
              platform: Fyatu CaaS
              timestamp: '2026-05-22T15:00:00Z'
    NotFound:
      description: Resource not found or does not belong to your business
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    RateLimitExceeded:
      description: Rate limit exceeded
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            success: false
            status: 429
            message: Rate limit exceeded
            error:
              code: RATE_LIMIT_EXCEEDED
              detail: Too many requests
            meta:
              requestId: req_a1b2c3d4e5f6a7b8c9d0e1f2
              platform: Fyatu CaaS
              timestamp: '2026-05-22T15:00:00Z'
    InternalError:
      description: Unexpected server error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            success: false
            status: 500
            message: Internal error
            error:
              code: INTERNAL_ERROR
              detail: An unexpected error occurred
            meta:
              requestId: req_a1b2c3d4e5f6a7b8c9d0e1f2
              platform: Fyatu CaaS
              timestamp: '2026-05-22T15:00:00Z'
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >-
        API key from the FYATU CaaS portal. Pass as `Authorization: Bearer
        <key>`.

````