> ## Documentation Index
> Fetch the complete documentation index at: https://help.dash.fi/llms.txt
> Use this file to discover all available pages before exploring further.

# Unfreeze a card

> Unfreeze a card. Once a card is unfrozen, it can be used for new transactions.

The endpoint returns 204 upon successful unfreezing or if the card is already unfrozen. 400 is returned if the card is archived.



## OpenAPI

````yaml https://api.dash.fi/v1/public/swagger/doc.json post /cards/{card-id}/unfreeze
openapi: 3.1.0
info:
  contact:
    email: support@dash.fi
    name: Dash.fi Support
  description: >-
    Service allows to fetch or operate on the data from the Dash.fi API.
    Requires API key authentication via Bearer token.

    Provide your API key as a Bearer token in the `Authorization` header.
    Example: `Authorization: Bearer YOUR_API_KEY`
  title: Public Dash.fi API
  version: '1.0'
servers:
  - url: https://api.dash.fi/v1/public
security:
  - BearerAuth: []
tags:
  - description: >
      Subscribe URLs to receive POSTed events as they happen in your account.
      Each endpoint subscribes to one or more **topics**; when a topic fires,
      Dash.fi delivers the event to your URL with a JSON body matching the
      topic's payload schema. There is no envelope — the body is the event
      payload directly. Event metadata (id, topic, timestamp, signature) is
      carried in headers.


      ### Topic → payload schema


      Topics are versioned: the format is `<domain>.<event>.v<major>`. Breaking

      changes ship as a **new** topic (`.v2`) — the old version keeps delivering
      its

      existing schema until it's retired, so subscriptions are pinned and never

      shift schema underneath you.


      | Topic | Body schema |

      |---|---|

      | `card.financial_event.v1` | `CardFinancialEvent` — see `GET
      /cards/{id}/financial-events` in the **Card** section for the
      authoritative field list. |


      ### Delivery shape


      ```

      POST <your URL> HTTP/1.1

      Content-Type: application/json

      X-Outpost-Event-Id: evt_abc123

      X-Outpost-Topic: card.financial_event.v1

      X-Outpost-Timestamp: 2026-05-05T10:00:00Z

      X-Outpost-Signature: v0=<hex hmac-sha256>


      { ...payload matching the topic's schema... }

      ```


      | Header | Meaning |

      |---|---|

      | `X-Outpost-Event-Id` | Stable event identifier — the same id is sent on
      retries. Use it to deduplicate; delivery is **at-least-once**. |

      | `X-Outpost-Topic` | The topic that fired this delivery. |

      | `X-Outpost-Timestamp` | RFC 3339 time the event was emitted. Reject
      deliveries where this drifts too far from your clock to mitigate replay. |

      | `X-Outpost-Signature` | `v0=<hex>` HMAC-SHA256 of the raw request body,
      keyed with your endpoint's signing secret. |


      ### Verifying the signature


      The signature is computed over the **raw request body**:


      ```

      HMAC-SHA256(signing_secret, raw_body)

      ```


      Encoded as hex, prefixed with `v0=`. **Use a constant-time comparison** to
      avoid timing attacks.


      `rawBody` is the unparsed request body — the exact `Buffer` or string you
      received over the wire, not a re-serialised JSON object.


      ```js

      import { createHmac, timingSafeEqual } from 'node:crypto';


      function verify(rawBody, signatureHeader, secret) {
        if (!signatureHeader) return false;
        const expected =
          'v0=' + createHmac('sha256', secret).update(rawBody).digest('hex');
        // Header may carry multiple comma-separated signatures during a rotation window.
        return signatureHeader.split(',').some((sig) => {
          const got = Buffer.from(sig.trim());
          const want = Buffer.from(expected);
          return got.length === want.length && timingSafeEqual(got, want);
        });
      }

      ```


      ### Secret rotation


      Rotating a signing secret keeps the previous secret valid for 24 hours so
      you can roll the new one out without dropped deliveries. During that
      window, the `X-Outpost-Signature` header carries comma-separated
      signatures (`v0=<new>,v0=<previous>`); accept either.


      The new secret is shown **once** at rotation and is never retrievable
      later.
    name: Webhooks
externalDocs:
  description: OpenAPI JSON Specification
  url: /v1/public/swagger/doc.json
paths:
  /cards/{card-id}/unfreeze:
    post:
      tags:
        - Card
      summary: Unfreeze a card
      description: >-
        Unfreeze a card. Once a card is unfrozen, it can be used for new
        transactions.


        The endpoint returns 204 upon successful unfreezing or if the card is
        already unfrozen. 400 is returned if the card is archived.
      parameters:
        - description: Card ID
          in: path
          name: id
          required: true
          schema:
            type: string
      responses:
        '204':
          description: No Content
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationErrorResponse'
          description: Response containing error code and message
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnauthorizedErrorResponse'
          description: Unauthorized error response
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ForbiddenErrorResponse'
          description: Forbidden error response
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NotFoundErrorResponse'
          description: Not found error response
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InternalServerErrorResponse'
          description: Internal server error response
      security:
        - BearerAuth: []
components:
  schemas:
    ValidationErrorResponse:
      properties:
        code:
          type: string
        message:
          type: string
      required:
        - code
      type: object
    UnauthorizedErrorResponse:
      properties:
        code:
          example: unauthorized
          type: string
        message:
          example: authorization header not provided
          type: string
      required:
        - code
      type: object
    ForbiddenErrorResponse:
      properties:
        code:
          example: forbidden
          type: string
        message:
          example: access to this resource is not provided
          type: string
      required:
        - code
      type: object
    NotFoundErrorResponse:
      properties:
        code:
          example: not-found
          type: string
        message:
          example: resource was not found
          type: string
      required:
        - code
      type: object
    InternalServerErrorResponse:
      properties:
        code:
          example: internal-server-error
          type: string
        message:
          type: string
      required:
        - code
      type: object
  securitySchemes:
    BearerAuth:
      description: >-
        Type "Bearer" followed by a space and your API token. Obtain your key
        from the Dash.fi dashboard. Example: "Bearer YOUR_API_KEY"
      in: header
      name: Authorization
      type: apiKey

````