Kardlane
Get started

Quickstart

From an API key to your first verdict.

  1. Set up a project in the dashboard

    Sign in at kardlane.com, create a project, link a WhatsApp number (scan the QR code) and choose the vendor groups the bot may use.

  2. Create an API key and a webhook

    On the project’s Integration page, create an API key and add your webhook URL. Copy the signing secret (whsec_…) — you’ll use it to verify webhooks.

  3. Send a trade
    curl -X POST https://api.kardlane.com/v1/trades \
      -H "Authorization: Bearer $KARDLANE_API_KEY" \
      -H "Content-Type: application/json" \
      -d '{
        "externalRef": "sale_8213",
        "cardType": "APPLE_ITUNES",
        "country": "USD",
        "value": 100,
        "customerRate": 1080,
        "assets": ["https://cdn.example.com/cards/8213.jpg"]
      }'

    You get 202 with a tradeId straight away; the bot works in the background. Re-sending the same externalRef never creates a duplicate.

  4. Handle the webhook

    When the trade finishes you receive trade.succeeded, trade.failed or trade.escalated. Verify the signature, dedupe on the delivery id, then act — pay your customer on success.

    webhook.js
    app.post('/webhooks/kardlane', express.raw({ type: 'application/json' }), (req, res) => {
      if (!verifyKardlaneSignature(req.body, req.get('X-Kardlane-Signature'), process.env.KARDLANE_WEBHOOK_SECRET)) {
        return res.sendStatus(401);
      }
      const event = JSON.parse(req.body);
      switch (event.type) {
        case 'trade.succeeded': /* pay your customer */ break;
        case 'trade.failed':    /* tell them event.data.failure.message */ break;
        case 'trade.escalated': /* decide via event.data.review */ break;
      }
      res.sendStatus(200);
    });

    See Webhooks for verifyKardlaneSignature.

Tip: Watch the trade live in the dashboard while it runs — every rate request, vendor reply and decision is on its timeline.