Highnote
"the world's most modern card platform, purpose-built to grow customer loyalty, engagement, and revenue through embedded card issuance experiences" [1]
Highnote is a US-only card issuance platform for building consumer and commercial card programs, including debit, credit, prepaid, fleet, expense, and virtual B2B cards, targeting fintechs and enterprises launching embedded finance products. It exposes a GraphQL API with webhook support, idempotency, and granular spend controls such as velocity rules, merchant category filters, and real-time collaborative authorization. Pricing is not published and requires a sales engagement. Highnote holds PCI DSS Level 1 certification as a service provider and is SOC 1 and SOC 2 compliant, operating under a bank sponsorship model with FinCEN MSB registration.
Best for / Avoid if
Best for: AI agents and automation - an agent-ready surface (MCP / llms.txt); Teams needing broad API coverage out of the box
Avoid if: You need to start building today without contacting sales; You need transparent pricing up front; You want to try it free before paying
Pricing & procurement
Capabilities
- Supported actions
- issue_virtual_card, issue_physical_card, card_lifecycle_management, spend_controls, velocity_rules, merchant_category_spend_rules, merchant_country_spend_rules, cvv_verification_rules, postal_code_verification_rules, fraud_score_rules, authorization_stream, collaborative_authorization, real_time_webhooks, push_provisioning, tokenization, apple_pay_provisioning, google_wallet_provisioning, samsung_pay_provisioning, kyc_kyb, program_management, ledger_accounts, dispute_management, physical_card_group_orders, pin_management, external_bank_account_linking, plaid_integration, credit_card_feature, revolving_credit, charge_card, buy_now_pay_later, merchant_acquiring, ach_origination, rtp_payments, fedwire, fednow, push_to_card, snowflake_data_share, card_interchange_reporting, sandbox_simulation [6]
- Regions
- United States [7]
- Input types
- Visa, Mastercard, virtual, physical, debit, credit, prepaid, charge, fleet, commercial, consumer, tokenized [8]
- Output types
- JSON, GraphQL responses, webhook events, card tokens, authorization events, transaction data, statements, Snowflake data share
- Webhooks
- ✓ Yes [9]
- Sandbox / test mode
- ✓ Yes [10]
- SDK languages
- JavaScript/TypeScript [11]
- MCP server
- ✗ No
Trust & compliance
- SOC 2
- Unknown [12]
- HIPAA
- – Unknown
- GDPR
- – Unknown
- ISO 27001
- – Unknown
- PCI DSS
- ✓ Yes [13]
- Published SLA
- ✗ No [14]
- Rate limits
- 200 requests per 10 seconds (API key); 20 requests per 10 seconds per subject (client token); 5,000 complexity points per 10 seconds (API key and client token). Test environment defaults to 50% of live limits. Returns HTTP 429 with retryAfter field when exceeded. [15]
- Known restrictions
- US-only card issuance currently, BIN sponsorship is provided by Highnote; operates under a bank sponsorship model while pursuing individual state Money Transmitter Licenses (MTLs), Registered as Money Services Business (MSB) with FinCEN, PCI DSS Level 1 certified (service provider), SOC 1 & SOC 2 compliant (type not publicly specified), Collaborative authorization endpoint must respond within 2 seconds and be highly available, Maximum 5 collaborative authorization endpoints; only 1 active simultaneously, Card Viewer and Secure Inputs SDKs are web/browser-based only (JavaScript/npm); native iOS and Android use Client Token approach, not a named SDK, Acquiring product launched January 2025; published rate of 2.85% + $0.25 per transaction applies to acquiring only, not card issuing [16]
Developer surface
Integration
- API style
- graphql
- Base URL
- https://api.us.highnote.com/graphql
- Versioning
- none
- Stability
- ga
- Auth methods
- api_key
- Idempotency keys
- ✓ Yes
- Error format
- vendor-specific
- Webhook signing
- hmac_sha256
- Rate limit
- 200 / 10 seconds
Adoption & maturity
- Launched
- 2020-01-01
- GA
- 2021-01-01
- Notable customers
- Netevia, Splitit, Ferry
Other Card Issuing APIs
Lithic
"Programmable card issuing and money movement" platform designed to help developers and companies "launch fast, scale confidently, and offload complexity."
Stripe Issuing
"With over 275 million cards created, Stripe Issuing is the preferred card issuance infrastructure provider for disruptive startups, innovative software platforms, and evolving enterprises."
Weavr
"Embedded finance for digital B2B products"
Swan
"The easiest way to embed banking features into your product."
Wallester
"Free business IBAN account with cards and expense management"
Adyen Issuing
"Get everything you need to create and manage your card program with our financial technology platform."
References
- ↑Description: partner.visa.com · highnote.com
- ↑Pricing model: highnote.com · highnote.com
- ↑Published pricing: highnote.com
- ↑Self-serve signup: highnote.com · highnote.com
- ↑Requires sales call: highnote.com
- ↑Supported actions: docs.highnote.com · docs.highnote.com
- ↑Regions: pymnts.com · highnote.com
- ↑Input types: docs.highnote.com
- ↑Webhooks: docs.highnote.com
- ↑Sandbox: docs.highnote.com
- ↑SDK languages: docs.highnote.com
- ↑SOC 2: highnote.com · highnote.com
- ↑PCI DSS: highnote.com · highnote.com
- ↑Published SLA: docs.highnote.com
- ↑Rate limits: docs.highnote.com
- ↑Known restrictions: highnote.com · highnote.com
Change history
- 2026-06-21 Capabilities: {} → {"virtual_cards":true,"physical_cards":true,"spend_controls":true,"bin_sponsors…
- 2026-06-21 Summary Md: (none) → Highnote is a US-only card issuance platform for building consumer and commerci…
- 2026-06-21 Score Docs Quality: (none) → 25
- 2026-06-21 Score Procurement Friction: (none) → 0
- 2026-06-21 Score Trust Readiness: (none) → 10
- 2026-06-21 Best For: (none) → AI agents and automation - an agent-ready surface (MCP / llms.txt), Teams needi…
- 2026-06-21 Avoid If: (none) → You need to start building today without contacting sales, You need transparent…
- 2026-06-21 Scoring Methodology: (none) → Scores are computed deterministically from this profile's published, sourced fi…
- 2026-06-21 Score Agent Friendliness: (none) → 35
- 2026-06-21 Score Pricing Transparency: (none) → 0
- 2026-06-21 Score Setup Speed: (none) → 30
- 2026-06-21 Llms Txt Present: (none) → Yes
- 2026-06-21 Rendering: (none) → client_rendered
- 2026-06-21 Has Structured Data: (none) → No
- 2026-06-21 Robots Allows Agents: (none) → Yes
- 2026-06-21 Status Page URL: (none) → https://status.highnote.com
- 2026-06-21 Docs URL: (none) → https://docs.highnote.com/
- 2026-06-21 Llms Txt URL: (none) → https://highnote.com/llms.txt
- 2026-06-21 Free Tier Available: set to No
- 2026-06-21 Self Serve Signup: set to No
- 2026-06-21 Requires Sales Call: set to Yes
- 2026-06-21 Enterprise Plan Available: set to Yes
- 2026-06-21 SOC 2: set to unknown
- 2026-06-21 PCI DSS: set to Yes
- 2026-06-21 SLA Published: set to No
- 2026-06-21 Data Retention Policy URL: set to https://highnote.com/agreements/privacy
- 2026-06-21 Documented Rate Limits: set to 200 requests per 10 seconds (API key); 20 requests per 10 seconds per subject (…
- 2026-06-21 Rate Limit Requests: set to 200
- 2026-06-21 Rate Limit Window: set to 10 seconds
- 2026-06-21 Known Restrictions: set to US-only card issuance currently, BIN sponsorship is provided by Highnote; opera…
- 2026-06-21 Auth Methods: set to api_key
- 2026-06-21 Auth Docs URL: set to https://docs.highnote.com/docs/developers/api/using-the-api
- 2026-06-21 API Style: set to graphql
- 2026-06-21 Base URL: set to https://api.us.highnote.com/graphql
- 2026-06-21 Versioning Scheme: set to none
- 2026-06-21 Stability: set to ga
- 2026-06-21 Deprecation Policy URL: set to https://docs.highnote.com/docs/developers/api/status-changes
- 2026-06-21 Quickstart URL: set to https://docs.highnote.com/docs/get-started/about-highnote
- 2026-06-21 Idempotency Supported: set to Yes
- 2026-06-21 Error Format: set to vendor-specific
- 2026-06-21 Webhook Signing: set to hmac_sha256
- 2026-06-21 Webhook Events URL: set to https://docs.highnote.com/docs/developers/events/events-reference
- 2026-06-21 Slug: set to highnote
- 2026-06-21 Launched At: set to 2020-01-01
- 2026-06-21 GA Date: set to 2021-01-01
- 2026-06-21 Notable Customers: set to Netevia, Splitit, Ferry
- 2026-06-21 Fields Not Found: set to hipaa, gdpr, iso_27001, sla_published, minimum_commitment, api_version, sla_url…
- 2026-06-21 Source Confidence: set to high
- 2026-06-21 Extractor: set to claude-subagent:sonnet
- 2026-06-21 Last Verified At: set to 2026-06-21T00:00:00.000Z
Suggest an edit / leave a review
Leave a review or comment
curl -X POST https://apio.sh/api/feedback/highnote \
-H 'Content-Type: application/json' \
-d '{"kind":"review","rating":5,"body":"Your experience with this API…"}'Suggest a correction to a field (cite a source)
curl -X POST https://apio.sh/api/suggest/highnote/FIELD \
-H 'Content-Type: application/json' \
-d '{"value":"corrected value","citations":[{"url":"https://source.example/page","excerpt":"supporting quote"}],"note":"what changed and why"}'