> ## Documentation Index
> Fetch the complete documentation index at: https://partner-docs.contro.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Update card spend control

> Set per-transaction-type velocity caps on a card. Accepts both the legacy `{ limit }` body (deprecated, mirrors `spendControl.sales.allTime` and `spendControl.cash.allTime`) and the new `{ spendControl }` body.



## OpenAPI

````yaml /partner-openapi.json patch /partner/cards/{id}/limits
openapi: 3.1.0
info:
  title: Contro Partner API
  version: 1.0.0
  license:
    name: Proprietary
    url: https://contro.me/terms
  description: >-
    The Contro Partner API enables Card-as-a-Service (CaaS) partners to
    programmatically issue cards, manage cardholders, and monitor transactions.


    ## Authentication


    All requests require your partner API key in the `x-contro-api-key` header:


    ```

    x-contro-api-key: sk_live_...

    ```


    Use `sk_test_*` keys for sandbox and `sk_live_*` keys for production.


    ## Rate Limits


    The API allows 1,000 requests per minute per API key. When exceeded,
    responses return HTTP 429 with a `Retry-After` header.


    ## Pagination


    List endpoints use page-based pagination:


    ```json

    {
      "data": [...],
      "page": 1,
      "limit": 20,
      "total": 137
    }

    ```


    Pass `?page=2&limit=20` to paginate. `limit` accepts 1–100 (default 20);
    `page` defaults to 1.


    ## Errors


    All errors return:


    ```json

    {
      "success": false,
      "error": "Human-readable message"
    }

    ```
servers:
  - url: https://api.contro.me/v1
    description: Production server for live traffic
  - url: https://stg-api.contro.dev/v1
    description: Sandbox environment for testing
security:
  - apiKey: []
paths:
  /partner/cards/{id}/limits:
    patch:
      tags:
        - Partner - Cards
      summary: Update card spend control
      description: >-
        Set per-transaction-type velocity caps on a card. Accepts both the
        legacy `{ limit }` body (deprecated, mirrors
        `spendControl.sales.allTime` and `spendControl.cash.allTime`) and the
        new `{ spendControl }` body.
      operationId: updateCardLimits
      parameters:
        - schema:
            type: string
            description: Card ID
            example: card_def456
          required: true
          description: Card ID
          name: id
          in: path
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateCardLimitsBody'
      responses:
        '200':
          description: Card spend control updated
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - true
                required:
                  - success
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '404':
          description: Not Found
        '429':
          description: Rate Limited
        '500':
          description: Internal Server Error
components:
  schemas:
    UpdateCardLimitsBody:
      anyOf:
        - type: object
          properties:
            spendControl:
              type: object
              properties:
                sales:
                  type: object
                  properties:
                    perTransaction:
                      type:
                        - number
                        - 'null'
                      description: >-
                        Maximum amount per single transaction. null/omit = no
                        cap.
                      example: 200
                    daily:
                      type:
                        - number
                        - 'null'
                      description: Maximum total amount per calendar day.
                      example: 1000
                    monthly:
                      type:
                        - number
                        - 'null'
                      description: Maximum total amount per calendar month.
                      example: 20000
                    allTime:
                      type:
                        - number
                        - 'null'
                      description: Maximum total amount over the card's lifetime.
                      example: 50000
                  description: Caps for purchase (point-of-sale) transactions.
                cash:
                  type: object
                  properties:
                    perTransaction:
                      type:
                        - number
                        - 'null'
                      description: >-
                        Maximum amount per single transaction. null/omit = no
                        cap.
                      example: 200
                    daily:
                      type:
                        - number
                        - 'null'
                      description: Maximum total amount per calendar day.
                      example: 1000
                    monthly:
                      type:
                        - number
                        - 'null'
                      description: Maximum total amount per calendar month.
                      example: 20000
                    allTime:
                      type:
                        - number
                        - 'null'
                      description: Maximum total amount over the card's lifetime.
                      example: 50000
                  description: Caps for cash withdrawal (ATM) transactions.
                spent:
                  type: object
                  properties:
                    sales:
                      type: object
                      properties:
                        perTransaction:
                          type:
                            - number
                            - 'null'
                          description: >-
                            Maximum amount per single transaction. null/omit =
                            no cap.
                          example: 200
                        daily:
                          type:
                            - number
                            - 'null'
                          description: Maximum total amount per calendar day.
                          example: 1000
                        monthly:
                          type:
                            - number
                            - 'null'
                          description: Maximum total amount per calendar month.
                          example: 20000
                        allTime:
                          type:
                            - number
                            - 'null'
                          description: Maximum total amount over the card's lifetime.
                          example: 50000
                      description: Velocity caps for one transaction-type bucket.
                    cash:
                      type: object
                      properties:
                        perTransaction:
                          type:
                            - number
                            - 'null'
                          description: >-
                            Maximum amount per single transaction. null/omit =
                            no cap.
                          example: 200
                        daily:
                          type:
                            - number
                            - 'null'
                          description: Maximum total amount per calendar day.
                          example: 1000
                        monthly:
                          type:
                            - number
                            - 'null'
                          description: Maximum total amount per calendar month.
                          example: 20000
                        allTime:
                          type:
                            - number
                            - 'null'
                          description: Maximum total amount over the card's lifetime.
                          example: 50000
                      description: Velocity caps for one transaction-type bucket.
                  description: >-
                    Read-only accrued spend per bucket. Returned by Get card;
                    ignored on update.
              description: >-
                Per-transaction-type velocity controls. Caps not supported by
                the card program are rejected with 400.
          required:
            - spendControl
        - type: object
          properties:
            limit:
              type:
                - number
                - 'null'
              description: >-
                Deprecated. Mapped to `{ spendControl: { sales: { allTime },
                cash: { allTime } } }`. Use `spendControl` directly.
              example: 5000
              deprecated: true
  securitySchemes:
    apiKey:
      type: apiKey
      in: header
      name: x-contro-api-key
      description: Partner API key (sk_live_* for production, sk_test_* for sandbox)

````