Rank #4 of 5 in Card Issuing Platforms
Install
npm install @marqeta/marqeta-mcpTry itExperimental
See what an agent can do with Marqeta before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; commands tagged live-capable can re-run against the real endpoint from our edge, right now (▶ run live — the exact same request, live and recorded lines always labeled); sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$curl -si https://sandbox-api.marqeta.com/v3/cards | head -3 # self-serve sandbox, keyless → 401recorded session — replayed, not liveVerified integrations
No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.
By theme — the product's score on each story themeBy theme
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Auth decisioning — stories about auth decisioning in this arenaAuth decisioningevidence →
Stories about auth decisioning in this arena
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Card lifecycle — stories about card lifecycle in this arenaCard lifecycleevidence →
Stories about card lifecycle in this arena
Issuing agent access — stories about issuing agent access in this arenaIssuing agent accessevidence →
Stories about issuing agent access in this arena
Issuing compliance — stories about issuing compliance in this arenaIssuing complianceevidence →
Stories about issuing compliance in this arena
Issuing disputes — stories about issuing disputes in this arenaIssuing disputesevidence →
Stories about issuing disputes in this arena
Ledger settlement — stories about ledger settlement in this arenaLedger settlementevidence →
Stories about ledger settlement in this arena
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Program management — stories about program management in this arenaProgram managementevidence →
Stories about program management in this arena
Spend controls — stories about spend controls in this arenaSpend controlsevidence →
Stories about spend controls in this arena
Wallets tokenization — stories about wallets tokenization in this arenaWallets tokenizationevidence →
Stories about wallets tokenization in this arena
Story verdicts — every judged story with its evidenceStory verdicts
Follow the green: where the map greys out is where Marqeta stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
✓8/10
unlocks → Official SDKs · Machine-readable spec · Versioning policy · Official CLI · Full data export
Subscribe to events via webhooks
✓8/10
Build against official SDKs
—0/10
Issue scoped/least-privilege API credentials for an agent
~4/10
Connect an agent via an official MCP server
✓8/10
Download a machine-readable API spec (OpenAPI or equivalent)
—0/10
Rely on versioned APIs with a documented deprecation policy
—0/10
Test against a sandbox environment without touching production data
✓8/10
Explore an interactive API reference with runnable examples
~6/10
Docs for agents
Point an agent at llms.txt or agent-oriented docs
~4/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
n/an/a
Operate the product with natural-language commands
~5/10
Plug MCP servers into this product so it can use their tools
n/an/a
Get AI-generated insights and suggestions from my data inside the product
—0/10
Set up automations that run autonomously in the background
~5/10
Auth decisioning — stories about auth decisioning in this arenaAuth decisioning
Stories about auth decisioning in this arena
Every authorization event carries decision-grade context — merchant name and MCC, enhanced merchant data, wallet and entry-mode details, partial-approval and incremental-auth signals
~5/10
Approve or decline each authorization in real time — a webhook or auth-stream endpoint my code answers inside the network's time budget, with a documented timeout fallback I control
~4/10
Simulate the whole transaction lifecycle in the sandbox — authorizations, clearings, reversals, refunds, and declines — so my auth logic is tested before a real card ever swipes
~7/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Card lifecycle — stories about card lifecycle in this arenaCard lifecycle
Stories about card lifecycle in this arena
The full card lifecycle is API-driven — activate, pause, unpause, report lost or stolen, reissue with a replacement linked to the original, and permanently close
~3/10
Order personalized physical cards through the API — custom card art, bulk orders, shipping methods and tracking — without managing a card manufacturer relationship myself
—0/10
Create a virtual card through the API in one call — PAN, CVV, and expiry available programmatically the moment it's issued — and go from sandbox to a live card without a sales cycle
~6/10
Issuing agent access — stories about issuing agent access in this arenaIssuing agent access
Stories about issuing agent access in this arena
Give an agent its own card — issue a scoped virtual card to an AI agent with merchant locks, amount caps, and expiry so autonomous purchases stay inside policy, a use the vendor documents by name
✓8/10
An agent can operate my card program — read balances and transactions, create and update cards, and adjust spend controls through the API or an MCP surface with scoped credentials
~6/10
Issuing compliance — stories about issuing compliance in this arenaIssuing compliance
Stories about issuing compliance in this arena
Cardholder verification is built into issuance — KYC for consumers and KYB for businesses run through the platform with documented data requirements, review states, and re-verification flows
—–
Show cardholders their own PAN and CVV without inheriting PCI scope — hosted components or ephemeral-key reveal flows the vendor documents as keeping me out of SAQ D
~3/10
Issuing disputes — stories about issuing disputes in this arenaIssuing disputes
Stories about issuing disputes in this arena
File and track disputes on card transactions programmatically — network reason codes, evidence submission, provisional credit handling, and status webhooks through resolution
~5/10
The platform fights fraud on my issued cards — network fraud scores or its own models surfaced at auth time, suspicious-activity alerts, and tooling to block and reissue compromised cards
~3/10
Ledger settlement — stories about ledger settlement in this arenaLedger settlement
Stories about ledger settlement in this arena
See money move in real time — account and card balances, a transaction ledger that ties every authorization to its clearing, and settlement reporting that reconciles to the penny
~5/10
I get machine-readable reconciliation artifacts — daily settlement files or report APIs covering interchange, fees, and network adjustments — that my finance stack can consume automatically
—–
Post-auth events are as programmatic as auth — clearings, refunds, reversals, and chargebacks arrive as webhooks with stable transaction identifiers, so my own ledger never drifts
~6/10
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Program management — stories about program management in this arenaProgram management
Stories about program management in this arena
The platform supports the card types my product needs — debit, prepaid, commercial credit, and consumer credit programs — not just one prepaid rail
—0/10
Choose how transactions are funded — prefunded balances or just-in-time funding where my system approves and funds each authorization — with the cash-flow tradeoffs documented
~5/10
Launch a card program without becoming a bank — BIN sponsorship, network membership, and program management are the platform's problem, and the time from signup to first live card is documented
~4/10
Spend controls — stories about spend controls in this arenaSpend controls
Stories about spend controls in this arena
Set spend limits per card and per cardholder — amount caps over daily, monthly, or all-time windows, and transaction-count velocity rules — enforced by the platform, not my code
✓8/10
Restrict where a card works — merchant category (MCC) allowlists and blocklists, and single-merchant locks — applied at authorization time
✓8/10
Issue single-use and tightly scoped cards — one purchase, one merchant, an exact amount — so a leaked number is worthless the moment it's used
✓8/10
Wallets tokenization — stories about wallets tokenization in this arenaWallets tokenization
Stories about wallets tokenization in this arena
Cardholder credentials are manageable through the API — PIN set and reset flows, 3DS enrollment for online use where the region requires it — without support tickets
—0/10
Network tokens are first-class — I can see and manage the tokens created for a card, know which wallet or merchant holds them, and revoke them independently of the PAN
—–
Cards land in Apple Pay and Google Pay — push provisioning from my app with the entitlements process documented, plus in-wallet card art and manual provisioning as a fallback
—–
Sorted by importance (agentic first) (high → low) · 53/53 stories · click a row’s chevron for the rationale and evidence
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Tprobed | |
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Tprobed | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | 0/10 | ||
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Cclaimed | |
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Tprobed | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Tprobed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Cclaimed | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Tprobed | |
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 4/10 | Tprobed | |
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 4/10 | Tprobed | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | full | 8/10 | Cclaimed | |
Give an agent its own card — issue a scoped virtual card to an AI agent with merchant locks, amount caps, and expiry so autonomous purchases stay inside policy, a use the vendor documents by name C Agent cards | ai-native user | Issuing agent access — stories about issuing agent access in this arenaIssuing agent access | 3 | full | 8/10 | Tprobed | |
Set spend limits per card and per cardholder — amount caps over daily, monthly, or all-time windows, and transaction-count velocity rules — enforced by the platform, not my code C Limits | ops user | Spend controls — stories about spend controls in this arenaSpend controls | 3 | full | 8/10 | Cclaimed | |
Create a virtual card through the API in one call — PAN, CVV, and expiry available programmatically the moment it's issued — and go from sandbox to a live card without a sales cycle C Virtual cards | developer | Card lifecycle — stories about card lifecycle in this arenaCard lifecycle | 3 | partial | 6/10 | Cclaimed | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | partial | 6/10 | Cclaimed | |
See money move in real time — account and card balances, a transaction ledger that ties every authorization to its clearing, and settlement reporting that reconciles to the penny C Balances | finance lead | Ledger settlement — stories about ledger settlement in this arenaLedger settlement | 3 | partial | 5/10 | Cclaimed | |
Approve or decline each authorization in real time — a webhook or auth-stream endpoint my code answers inside the network's time budget, with a documented timeout fallback I control C Auth stream | developer | Auth decisioning — stories about auth decisioning in this arenaAuth decisioning | 3 | partial | 4/10 | Cclaimed | |
Launch a card program without becoming a bank — BIN sponsorship, network membership, and program management are the platform's problem, and the time from signup to first live card is documented C Program launch | founder | Program management — stories about program management in this arenaProgram management | 3 | partial | 4/10 | Cclaimed | |
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | none | 0/10 | ||
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | n/a | untested | none yet | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | n/a | untested | none yet | |
Issue single-use and tightly scoped cards — one purchase, one merchant, an exact amount — so a leaked number is worthless the moment it's used C Scoped cards | developer | Spend controls — stories about spend controls in this arenaSpend controls | 2 | full | 8/10 | Cclaimed | |
Restrict where a card works — merchant category (MCC) allowlists and blocklists, and single-merchant locks — applied at authorization time C Merchant controls | ops user | Spend controls — stories about spend controls in this arenaSpend controls | 2 | full | 8/10 | Cclaimed | |
Simulate the whole transaction lifecycle in the sandbox — authorizations, clearings, reversals, refunds, and declines — so my auth logic is tested before a real card ever swipes C Simulation | developer | Auth decisioning — stories about auth decisioning in this arenaAuth decisioning | 2 | partial | 7/10 | Cclaimed | |
An agent can operate my card program — read balances and transactions, create and update cards, and adjust spend controls through the API or an MCP surface with scoped credentials C Agent operations | ai-native user | Issuing agent access — stories about issuing agent access in this arenaIssuing agent access | 2 | partial | 6/10 | Tprobed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 6/10 | Tprobed | |
Post-auth events are as programmatic as auth — clearings, refunds, reversals, and chargebacks arrive as webhooks with stable transaction identifiers, so my own ledger never drifts C Settlement events | developer | Ledger settlement — stories about ledger settlement in this arenaLedger settlement | 2 | partial | 6/10 | Cclaimed | |
Choose how transactions are funded — prefunded balances or just-in-time funding where my system approves and funds each authorization — with the cash-flow tradeoffs documented C Funding models | finance lead | Program management — stories about program management in this arenaProgram management | 2 | partial | 5/10 | Cclaimed | |
Every authorization event carries decision-grade context — merchant name and MCC, enhanced merchant data, wallet and entry-mode details, partial-approval and incremental-auth signals C Auth context | developer | Auth decisioning — stories about auth decisioning in this arenaAuth decisioning | 2 | partial | 5/10 | Cclaimed | |
File and track disputes on card transactions programmatically — network reason codes, evidence submission, provisional credit handling, and status webhooks through resolution C Dispute filing | ops user | Issuing disputes — stories about issuing disputes in this arenaIssuing disputes | 2 | partial | 5/10 | Cclaimed | |
Show cardholders their own PAN and CVV without inheriting PCI scope — hosted components or ephemeral-key reveal flows the vendor documents as keeping me out of SAQ D C Pci scope | developer | Issuing compliance — stories about issuing compliance in this arenaIssuing compliance | 2 | partial | 3/10 | Cclaimed | |
The full card lifecycle is API-driven — activate, pause, unpause, report lost or stolen, reissue with a replacement linked to the original, and permanently close C Lifecycle states | developer | Card lifecycle — stories about card lifecycle in this arenaCard lifecycle | 2 | partial | 3/10 | Cclaimed | |
The platform fights fraud on my issued cards — network fraud scores or its own models surfaced at auth time, suspicious-activity alerts, and tooling to block and reissue compromised cards C Fraud monitoring | ops user | Issuing disputes — stories about issuing disputes in this arenaIssuing disputes | 2 | partial | 3/10 | Cclaimed | |
Cardholder credentials are manageable through the API — PIN set and reset flows, 3DS enrollment for online use where the region requires it — without support tickets C Credentials | developer | Wallets tokenization — stories about wallets tokenization in this arenaWallets tokenization | 2 | none | 0/10 | ||
Order personalized physical cards through the API — custom card art, bulk orders, shipping methods and tracking — without managing a card manufacturer relationship myself C Physical cards | ops user | Card lifecycle — stories about card lifecycle in this arenaCard lifecycle | 2 | none | 0/10 | ||
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | none | 0/10 | ||
The platform supports the card types my product needs — debit, prepaid, commercial credit, and consumer credit programs — not just one prepaid rail C Card types | founder | Program management — stories about program management in this arenaProgram management | 2 | none | 0/10 | ||
Cardholder verification is built into issuance — KYC for consumers and KYB for businesses run through the platform with documented data requirements, review states, and re-verification flows C Kyc | ops user | Issuing compliance — stories about issuing compliance in this arenaIssuing compliance | 2 | none | untested | none yet | |
Cards land in Apple Pay and Google Pay — push provisioning from my app with the entitlements process documented, plus in-wallet card art and manual provisioning as a fallback C Wallet provisioning | developer | Wallets tokenization — stories about wallets tokenization in this arenaWallets tokenization | 2 | none | untested | none yet | |
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
I get machine-readable reconciliation artifacts — daily settlement files or report APIs covering interchange, fees, and network adjustments — that my finance stack can consume automatically C Recon reports | finance lead | Ledger settlement — stories about ledger settlement in this arenaLedger settlement | 2 | none | untested | none yet | |
Network tokens are first-class — I can see and manage the tokens created for a card, know which wallet or merchant holds them, and revoke them independently of the PAN C Tokenization | developer | Wallets tokenization — stories about wallets tokenization in this arenaWallets tokenization | 2 | none | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | n/a | untested | none yet | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | n/a | untested | none yet | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | none | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 39 stories with headroom
What would move Marqeta’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Openness — open source, data portability, and self-hosting storiesExport all of my data in open formats and leave
nonemoves PA Scoreimpact 30
Marqeta is a card-issuing API platform; there's no evidence of any bulk data export/portability feature in open formats, and probes for llms.txt, docs.md, and openapi specs all returned 404.
Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the product
nonemoves Built-in AIimpact 30
Missing: any dashboard, report, or in-product AI feature that analyzes user data and proactively surfaces insights/recommendations.
Agenticness — how well agents can access and operate the productUse an official CLI
nonemoves agent-readyimpact 30
Missing: any evidence of an official CLI, CLI documentation, or CLI installation instructions.
Agenticness — how well agents can access and operate the productBuild against official SDKs
nonemoves agent-readyimpact 30
The evidence pack documents Marqeta's Core API, sandbox, webhooks, and an MCP server, but contains no mention of official client SDKs (e.g., Python, Java, Node libraries) that AI-native developers could build against.
Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)
nonemoves API qualityimpact 30
Direct probes for OpenAPI/Swagger specs and llms.txt/docs.md all returned 404, and no evidence pack item links to a downloadable machine-readable API spec despite extensive Core API docs; interactive widgets and MCP server access don't substitute for a downloadable spec file.
Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy
nonemoves API qualityimpact 30
Missing: any mention of API versioning, version headers/URLs, or a documented deprecation/sunset policy.
Automation depth — how much of the product can run unattendedPerform bulk operations across many items at once
nonemoves PA Scoreimpact 20
Missing: bulk create/update APIs, batch job endpoints, any documentation of multi-item operations.
Issuing compliance — stories about issuing compliance in this arenaCardholder verification is built into issuance — KYC for consumers and KYB for businesses run through the platform with documented data requirements, review states, and re-verification flows
nonemoves PA Scoreimpact 20
Missing: kYC/KYB documentation, identity verification data requirements, review/approval states, and re-verification workflow evidence.
Showing the top 8 of 39 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map4 surfaces · 29 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
docs28 stories
- Point an agent at llms.txt or agent-oriented docs
- Run the product headlessly / in CI for automation
- Connect an agent via an official MCP server
- Drive the product through a documented public API
- Issue scoped/least-privilege API credentials for an agent
- Subscribe to events via webhooks
- Set up automations that run autonomously in the background
- Operate the product with natural-language commands
- Explore an interactive API reference with runnable examples
- Test against a sandbox environment without touching production data
- Every authorization event carries decision-grade context — merchant name and MCC, enhanced merchant data, wallet and entry-mode details, partial-approval and incremental-auth signals
- Approve or decline each authorization in real time — a webhook or auth-stream endpoint my code answers inside the network's time budget, with a documented timeout fallback I control
- Simulate the whole transaction lifecycle in the sandbox — authorizations, clearings, reversals, refunds, and declines — so my auth logic is tested before a real card ever swipes
- Define rules that trigger actions automatically on events
- The full card lifecycle is API-driven — activate, pause, unpause, report lost or stolen, reissue with a replacement linked to the original, and permanently close
- Create a virtual card through the API in one call — PAN, CVV, and expiry available programmatically the moment it's issued — and go from sandbox to a live card without a sales cycle
- Give an agent its own card — issue a scoped virtual card to an AI agent with merchant locks, amount caps, and expiry so autonomous purchases stay inside policy, a use the vendor documents by name
- An agent can operate my card program — read balances and transactions, create and update cards, and adjust spend controls through the API or an MCP surface with scoped credentials
- File and track disputes on card transactions programmatically — network reason codes, evidence submission, provisional credit handling, and status webhooks through resolution
- The platform fights fraud on my issued cards — network fraud scores or its own models surfaced at auth time, suspicious-activity alerts, and tooling to block and reissue compromised cards
- See money move in real time — account and card balances, a transaction ledger that ties every authorization to its clearing, and settlement reporting that reconciles to the penny
- Post-auth events are as programmatic as auth — clearings, refunds, reversals, and chargebacks arrive as webhooks with stable transaction identifiers, so my own ledger never drifts
- Do everything through the API that I can do in the UI
- Choose how transactions are funded — prefunded balances or just-in-time funding where my system approves and funds each authorization — with the cash-flow tradeoffs documented
- Launch a card program without becoming a bank — BIN sponsorship, network membership, and program management are the platform's problem, and the time from signup to first live card is documented
- Set spend limits per card and per cardholder — amount caps over daily, monthly, or all-time windows, and transaction-count velocity rules — enforced by the platform, not my code
- Restrict where a card works — merchant category (MCC) allowlists and blocklists, and single-merchant locks — applied at authorization time
- Issue single-use and tightly scoped cards — one purchase, one merchant, an exact amount — so a leaked number is worthless the moment it's used
OpenAPI spec3 stories
marqeta.com3 stories
- Create a virtual card through the API in one call — PAN, CVV, and expiry available programmatically the moment it's issued — and go from sandbox to a live card without a sales cycle
- Show cardholders their own PAN and CVV without inheriting PCI scope — hosted components or ephemeral-key reveal flows the vendor documents as keeping me out of SAQ D
- Do everything through the API that I can do in the UI
Probe proofs — replayable recordings from the probe harnessProbe proofs
Replayable recordings from our probe harness — see the Prove-It protocol to submit one.
$curl -si https://sandbox-api.marqeta.com/v3/cards | head -3 # self-serve sandbox, keyless → 401reproduced$ curl -si https://sandbox-api.marqeta.com/v3/cards | head -3 # self-serve sandbox, [redacted]less → 401 HTTP/2 401 date: Tue, 15 Sep 2026 09:12:12 GMT content-type: application/json
$curl -sL https://www.marqeta.com/docs/llms.txt | head -3reproduced$ curl -sL https://www.marqeta.com/docs/llms.txt | head -3 # Marqeta Docs - [Core API Quick Start](https://www.marqeta.com/docs/developer-guides/core-api-quick-start.md): Use this Quick Start to start learning how the Marqeta platform works by simulating transactions in your sandbox.
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
3 of 13 testable claims verified · 0 contradicted → integrity 23/100
14 distinct capability claims found in Marqeta’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
3
Verified
10
Unverified
0
Contradicted
16
Undersold
Verified (3)
“Interactive widgets in the docs let you run live API calls from the browser”
Explore an interactive API reference with runnable examplespartialproof ↗
“Official MCP Server lets AI agents query a set of Core API endpoints”
“Open APIs let you build new payment products or streamline supplier and workforce payments”
Drive the product through a documented public APIfullproof ↗
Unverified (11)
“Create a card via the API after setting up a user and card product”
Create a virtual card through the API in one call — PAN, CVV, and expiry available programmatically the moment it's issued — and go from sandbox to a live card without a sales cyclepartialproof ↗
“Sandbox environment lets you explore and test the Core API without touching production”
Test against a sandbox environment without touching production datafullproof ↗
“Your own system approves or denies funding requests using custom business rules (just-in-time funding)”
Choose how transactions are funded — prefunded balances or just-in-time funding where my system approves and funds each authorization — with the cash-flow tradeoffs documentedpartialproof ↗
“Velocity controls limit how much and how often a user can spend, enforced across combined controls”
Set spend limits per card and per cardholder — amount caps over daily, monthly, or all-time windows, and transaction-count velocity rules — enforced by the platform, not my codefullproof ↗
“Restrict a card to a single merchant or group of merchants”
Restrict where a card works — merchant category (MCC) allowlists and blocklists, and single-merchant locks — applied at authorization timefullproof ↗
“Retrieve transactions filtered by card, merchant, or account holder”
See money move in real time — account and card balances, a transaction ledger that ties every authorization to its clearing, and settlement reporting that reconciles to the pennypartialproof ↗
“Create dispute cases with type-specific detail objects for card transactions”
File and track disputes on card transactions programmatically — network reason codes, evidence submission, provisional credit handling, and status webhooks through resolutionpartialproof ↗
“Webhooks push real-time notifications for API events as they occur”
“Sandbox lets you simulate card network transactions like authorizations, reversals, and balance inquiries”
Simulate the whole transaction lifecycle in the sandbox — authorizations, clearings, reversals, refunds, and declines — so my auth logic is tested before a real card ever swipespartialproof ↗
“Instant-issue virtual cards ready for immediate use, created programmatically”
Create a virtual card through the API in one call — PAN, CVV, and expiry available programmatically the moment it's issued — and go from sandbox to a live card without a sales cyclepartialproof ↗
“Hosted PCI widgets let you display card data (PAN/CVV) without taking on PCI scope”
Show cardholders their own PAN and CVV without inheriting PCI scope — hosted components or ephemeral-key reveal flows the vendor documents as keeping me out of SAQ Dpartialproof ↗
Undersold (16)
Point an agent at llms.txt or agent-oriented docspartialproof ↗
Run the product headlessly / in CI for automationpartialproof ↗
Issue scoped/least-privilege API credentials for an agentpartialproof ↗
Set up automations that run autonomously in the backgroundpartialproof ↗
Operate the product with natural-language commandspartialproof ↗
Every authorization event carries decision-grade context — merchant name and MCC, enhanced merchant data, wallet and entry-mode details, partial-approval and incremental-auth signalspartialproof ↗
Approve or decline each authorization in real time — a webhook or auth-stream endpoint my code answers inside the network's time budget, with a documented timeout fallback I controlpartialproof ↗
Define rules that trigger actions automatically on eventspartialproof ↗
The full card lifecycle is API-driven — activate, pause, unpause, report lost or stolen, reissue with a replacement linked to the original, and permanently closepartialproof ↗
Give an agent its own card — issue a scoped virtual card to an AI agent with merchant locks, amount caps, and expiry so autonomous purchases stay inside policy, a use the vendor documents by namefullproof ↗
An agent can operate my card program — read balances and transactions, create and update cards, and adjust spend controls through the API or an MCP surface with scoped credentialspartialproof ↗
The platform fights fraud on my issued cards — network fraud scores or its own models surfaced at auth time, suspicious-activity alerts, and tooling to block and reissue compromised cardspartialproof ↗
Post-auth events are as programmatic as auth — clearings, refunds, reversals, and chargebacks arrive as webhooks with stable transaction identifiers, so my own ledger never driftspartialproof ↗
Do everything through the API that I can do in the UIpartialproof ↗
Launch a card program without becoming a bank — BIN sponsorship, network membership, and program management are the platform's problem, and the time from signup to first live card is documentedpartialproof ↗
Issue single-use and tightly scoped cards — one purchase, one merchant, an exact amount — so a leaked number is worthless the moment it's usedfullproof ↗
Business model
No public pricing page: contact-sales, priced per program on processing and interchange economics; self-serve sandbox is free. Public company (NASDAQ: MQ) selling to embedded-finance and fintech card programs at volume.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
