# Update saved payment details

Update a customer's saved payment details by sending a PATCH request to the Update Secure Token endpoint or a POST request to the Update Account Details endpoint using a single-use token.

**Prerequisites:** [Authentication](/api/authentication) · [Save payment details](/guides/payments/save-payment-details)

Integrate with our API to update a customer’s saved payment details. Our API has two endpoints to update payment details represented by a secure token:

- [Update saved payment details](/guides/payments/update-saved-payment-details#update-saved-payment-details)  – Use our Update Secure Token endpoint if you are sending the raw payment details, for example, if you are updating a card’s expiry date or a billing address.
- [Update saved payment details with a single-use token](/guides/payments/update-saved-payment-details#update-saved-payment-details-with-a-single-use-token)  – Use our Update Account Details endpoint if you have a single-use token that represents updated payment details, for example, if you have a single-use token from Hosted Fields.

**Note:** To update saved payment details, you need the ID of the secure token that represents the payment details. If you don’t know the ID, go to List Secure Tokens.

<a id="before-you-begin"></a>
## Before you begin

[Authenticate your requests](/api/authentication) before making API calls. If your request fails, see [Errors](/api/errors).

<a id="update-saved-payment-details"></a>
## Update saved payment details

Use the Update Secure Token method if you have the raw information that a customer wants to update. You can update the following payment details:

- Sensitive payment details, including:- **Card** - Cardholder name and expiry date
  - **ACH** - Accountholder name and account type
  - **PAD** - Accountholder name and institution number
- MIT agreement
- Customer’s contact details
- Customer’s address details

<a id="integration-steps"></a>
## Integration steps

- Update a secure token

<a id="update-a-secure-token"></a>
## Update a secure token

To update the payment details represented by a secure token, send a PATCH request to our Update Secure Token endpoint.

| Environment | URL |
| --- | --- |
| Test | [https://api.uat.payroc.com/v1/processing-terminals/\{processingTerminalId\}/secure-tokens/\{secureTokenId\}](https://api.uat.payroc.com/v1/processing-terminals/%7BprocessingTerminalId%7D/secure-tokens/%7BsecureTokenId%7D) |
| Production | [https://api.payroc.com/v1/processing-terminals/\{processingTerminalId\}/secure-tokens/\{secureTokenId\}](https://api.payroc.com/v1/processing-terminals/%7BprocessingTerminalId%7D/secure-tokens/%7BsecureTokenId%7D) |

**Note:** The request format follows the RFC 6902 standard.

<a id="request-parameters"></a>
### Request parameters

To create the body of your request, use the following parameters:

<a id="schema-requestbody"></a>
### Schema (`request.body`)

[Request body schema for `PATCH /processing-terminals/{processingTerminalId}/secure-tokens/{secureTokenId}`](/api/update-secure-token)

<a id="example-request"></a>
### Example request

<a id="request"></a>
### Request

PATCH [https://api.payroc.com/v1/processing-terminals/\{processingTerminalId\}/secure-tokens/\{secureTokenId\}](https://api.payroc.com/v1/processing-terminals/%7BprocessingTerminalId%7D/secure-tokens/%7BsecureTokenId%7D)

**`Update secure token`**

```curl
curl -X PATCH https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa \
     -H "Idempotency-Key: 8e03978e-40d5-43e8-bc93-6894a57f9324" \
     -H "Authorization: Bearer <token>" \
     -H "Content-Type: application/json" \
     -d '[
  {
    "op": "add",
    "path": "/customer/lastName",
    "value": null
  },
  {
    "op": "add",
    "path": "/shippingAddress/recipientName",
    "value": null
  },
  {
    "op": "add",
    "path": "/source/cardDetails/cardholderName",
    "value": null
  }
]'
```

**`Update secure token`**

```python
import requests

url = "https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa"

payload = [
    {
        "op": "add",
        "path": "/customer/lastName",
        "value": None
    },
    {
        "op": "add",
        "path": "/shippingAddress/recipientName",
        "value": None
    },
    {
        "op": "add",
        "path": "/source/cardDetails/cardholderName",
        "value": None
    }
]
headers = {
    "Idempotency-Key": "8e03978e-40d5-43e8-bc93-6894a57f9324",
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.patch(url, json=payload, headers=headers)

print(response.json())
```

**`Update secure token`**

```javascript
const url = 'https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa';
const options = {
  method: 'PATCH',
  headers: {
    'Idempotency-Key': '8e03978e-40d5-43e8-bc93-6894a57f9324',
    Authorization: 'Bearer <token>',
    'Content-Type': 'application/json'
  },
  body: '[{"op":"add","path":"/customer/lastName","value":null},{"op":"add","path":"/shippingAddress/recipientName","value":null},{"op":"add","path":"/source/cardDetails/cardholderName","value":null}]'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

**`Update secure token`**

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa"

	payload := strings.NewReader("[\n  {\n    \"op\": \"add\",\n    \"path\": \"/customer/lastName\",\n    \"value\": null\n  },\n  {\n    \"op\": \"add\",\n    \"path\": \"/shippingAddress/recipientName\",\n    \"value\": null\n  },\n  {\n    \"op\": \"add\",\n    \"path\": \"/source/cardDetails/cardholderName\",\n    \"value\": null\n  }\n]")

	req, _ := http.NewRequest("PATCH", url, payload)

	req.Header.Add("Idempotency-Key", "8e03978e-40d5-43e8-bc93-6894a57f9324")
	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

**`Update secure token`**

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Patch.new(url)
request["Idempotency-Key"] = '8e03978e-40d5-43e8-bc93-6894a57f9324'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "[\n  {\n    \"op\": \"add\",\n    \"path\": \"/customer/lastName\",\n    \"value\": null\n  },\n  {\n    \"op\": \"add\",\n    \"path\": \"/shippingAddress/recipientName\",\n    \"value\": null\n  },\n  {\n    \"op\": \"add\",\n    \"path\": \"/source/cardDetails/cardholderName\",\n    \"value\": null\n  }\n]"

response = http.request(request)
puts response.read_body
```

**`Update secure token`**

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.patch("https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa")
  .header("Idempotency-Key", "8e03978e-40d5-43e8-bc93-6894a57f9324")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("[\n  {\n    \"op\": \"add\",\n    \"path\": \"/customer/lastName\",\n    \"value\": null\n  },\n  {\n    \"op\": \"add\",\n    \"path\": \"/shippingAddress/recipientName\",\n    \"value\": null\n  },\n  {\n    \"op\": \"add\",\n    \"path\": \"/source/cardDetails/cardholderName\",\n    \"value\": null\n  }\n]")
  .asString();
```

**`Update secure token`**

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa', [
  'body' => '[
  {
    "op": "add",
    "path": "/customer/lastName",
    "value": null
  },
  {
    "op": "add",
    "path": "/shippingAddress/recipientName",
    "value": null
  },
  {
    "op": "add",
    "path": "/source/cardDetails/cardholderName",
    "value": null
  }
]',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
    'Idempotency-Key' => '8e03978e-40d5-43e8-bc93-6894a57f9324',
  ],
]);

echo $response->getBody();
```

**`Update secure token`**

```csharp
using RestSharp;

var client = new RestClient("https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa");
var request = new RestRequest(Method.PATCH);
request.AddHeader("Idempotency-Key", "8e03978e-40d5-43e8-bc93-6894a57f9324");
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "[\n  {\n    \"op\": \"add\",\n    \"path\": \"/customer/lastName\",\n    \"value\": null\n  },\n  {\n    \"op\": \"add\",\n    \"path\": \"/shippingAddress/recipientName\",\n    \"value\": null\n  },\n  {\n    \"op\": \"add\",\n    \"path\": \"/source/cardDetails/cardholderName\",\n    \"value\": null\n  }\n]", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

**`Update secure token`**

```swift
import Foundation

let headers = [
  "Idempotency-Key": "8e03978e-40d5-43e8-bc93-6894a57f9324",
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = [
  [
    "op": "add",
    "path": "/customer/lastName",
    "value": 
  ],
  [
    "op": "add",
    "path": "/shippingAddress/recipientName",
    "value": 
  ],
  [
    "op": "add",
    "path": "/source/cardDetails/cardholderName",
    "value": 
  ]
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "PATCH"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

<a id="response-fields"></a>
### Response fields

If your request is successful, we update the secure token and return the details represented by the secure token.

<a id="schema-responsebody"></a>
### Schema (`response.body`)

[Response body schema for `PATCH /processing-terminals/{processingTerminalId}/secure-tokens/{secureTokenId}`](/api/update-secure-token)

<a id="example-response"></a>
### Example response

<a id="response-200"></a>
### Response (200)

```json
{
  "secureTokenId": "MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa",
  "processingTerminalId": "1234001",
  "source": {
    "type": "card",
    "cardNumber": "453985******7062",
    "cardholderName": "Sarah Reed",
    "expiryDate": "1230"
  },
  "token": "296753123456",
  "status": "notValidated",
  "mitAgreement": "unscheduled",
  "customer": {
    "firstName": "Sarah",
    "lastName": "Reed",
    "dateOfBirth": "1990-07-15",
    "referenceNumber": "Customer-12",
    "billingAddress": {
      "address1": "1 Example Ave.",
      "address2": "Example Address Line 2",
      "address3": "Example Address Line 3",
      "city": "Chicago",
      "state": "Illinois",
      "country": "US",
      "postalCode": "60056"
    },
    "shippingAddress": {
      "recipientName": "Sarah Reed",
      "address": {
        "address1": "1 Example Ave.",
        "address2": "Example Address Line 2",
        "address3": "Example Address Line 3",
        "city": "Chicago",
        "state": "Illinois",
        "country": "US",
        "postalCode": "60056"
      }
    },
    "contactMethods": [
      {
        "type": "email",
        "value": "sarah.hopper@example.com"
      }
    ],
    "notificationLanguage": "en"
  },
  "customFields": [
    {
      "name": "yourCustomField",
      "value": "abc123"
    }
  ]
}
```

<a id="update-saved-payment-details-with-a-single-use-token"></a>
## Update saved payment details with a single-use token

If you use our Hosted Fields solution, our gateway creates a single-use token to represent the customer’s updates to their card, ACH, or PAD details. Send the single-use token to our gateway so that we can update the details represented by the secure token.

You can also send a secondary request to our gateway to update other details that the single-use token doesn’t change:

- MIT agreement
- Customer’s contact details
- Customer’s address details

<a id="integration-steps-1"></a>
## Integration steps

**Step 1.** Update saved payment details with a single-use token  
**Step 2.** (Optional) Update a secure token

<a id="step-1-update-saved-payment-details-with-a-single-use-token"></a>
## Step 1. Update saved payment details with a single-use token

To update saved payment details with a single-use token, send a POST request to our Update Account Details endpoint.

| Environment | URL |
| --- | --- |
| Test | [https://api.uat.payroc.com/v1/processing-terminals/\{processingTerminalId\}/secure-tokens/\{secureTokenId\}/update-account](https://api.uat.payroc.com/v1/processing-terminals/%7BprocessingTerminalId%7D/secure-tokens/%7BsecureTokenId%7D/update-account) |
| Production | [https://api.payroc.com/v1/processing-terminals/\{processingTerminalId\}/secure-tokens/\{secureTokenId\}/update-account](https://api.payroc.com/v1/processing-terminals/%7BprocessingTerminalId%7D/secure-tokens/%7BsecureTokenId%7D/update-account) |

<a id="request-parameters-1"></a>
### Request parameters

To create the body of your request, use the following parameters:

<a id="schema-requestbody-1"></a>
### Schema (`request.body`)

[Request body schema for `POST /processing-terminals/{processingTerminalId}/secure-tokens/{secureTokenId}/update-account`](/api/account-update)

<a id="example-request-1"></a>
### Example request

<a id="request-1"></a>
### Request

POST [https://api.payroc.com/v1/processing-terminals/\{processingTerminalId\}/secure-tokens/\{secureTokenId\}/update-account](https://api.payroc.com/v1/processing-terminals/%7BprocessingTerminalId%7D/secure-tokens/%7BsecureTokenId%7D/update-account)

**`Update account details`**

```curl
curl -X POST https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa/update-account \
     -H "Idempotency-Key: 8e03978e-40d5-43e8-bc93-6894a57f9324" \
     -H "Authorization: Bearer <token>" \
     -H "Content-Type: application/json" \
     -d '{
  "type": "singleUseToken",
  "token": "abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890"
}'
```

**`Update account details`**

```python
import requests

url = "https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa/update-account"

payload = {
    "type": "singleUseToken",
    "token": "abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890"
}
headers = {
    "Idempotency-Key": "8e03978e-40d5-43e8-bc93-6894a57f9324",
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

**`Update account details`**

```javascript
const url = 'https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa/update-account';
const options = {
  method: 'POST',
  headers: {
    'Idempotency-Key': '8e03978e-40d5-43e8-bc93-6894a57f9324',
    Authorization: 'Bearer <token>',
    'Content-Type': 'application/json'
  },
  body: '{"type":"singleUseToken","token":"abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890"}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

**`Update account details`**

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa/update-account"

	payload := strings.NewReader("{\n  \"type\": \"singleUseToken\",\n  \"token\": \"abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890\"\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Idempotency-Key", "8e03978e-40d5-43e8-bc93-6894a57f9324")
	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

**`Update account details`**

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa/update-account")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Idempotency-Key"] = '8e03978e-40d5-43e8-bc93-6894a57f9324'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"type\": \"singleUseToken\",\n  \"token\": \"abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890\"\n}"

response = http.request(request)
puts response.read_body
```

**`Update account details`**

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa/update-account")
  .header("Idempotency-Key", "8e03978e-40d5-43e8-bc93-6894a57f9324")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("{\n  \"type\": \"singleUseToken\",\n  \"token\": \"abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890\"\n}")
  .asString();
```

**`Update account details`**

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa/update-account', [
  'body' => '{
  "type": "singleUseToken",
  "token": "abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890"
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
    'Idempotency-Key' => '8e03978e-40d5-43e8-bc93-6894a57f9324',
  ],
]);

echo $response->getBody();
```

**`Update account details`**

```csharp
using RestSharp;

var client = new RestClient("https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa/update-account");
var request = new RestRequest(Method.POST);
request.AddHeader("Idempotency-Key", "8e03978e-40d5-43e8-bc93-6894a57f9324");
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"type\": \"singleUseToken\",\n  \"token\": \"abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890\"\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

**`Update account details`**

```swift
import Foundation

let headers = [
  "Idempotency-Key": "8e03978e-40d5-43e8-bc93-6894a57f9324",
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = [
  "type": "singleUseToken",
  "token": "abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890"
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa/update-account")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

<a id="response-fields-1"></a>
### Response fields

If your request is successful, we update the secure token and return the details represented by the secure token.

<a id="schema-responsebody-1"></a>
### Schema (`response.body`)

[Response body schema for `POST /processing-terminals/{processingTerminalId}/secure-tokens/{secureTokenId}/update-account`](/api/account-update)

<a id="example-response-1"></a>
### Example response

<a id="response-200-1"></a>
### Response (200)

```json
{
  "secureTokenId": "MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa",
  "processingTerminalId": "1234001",
  "source": {
    "type": "card",
    "cardNumber": "453985******7062",
    "cardholderName": "Sarah Hazel Hopper",
    "expiryDate": "1230"
  },
  "token": "296753123456",
  "status": "notValidated",
  "mitAgreement": "unscheduled",
  "customer": {
    "firstName": "Sarah",
    "lastName": "Hopper",
    "dateOfBirth": "1990-07-15",
    "referenceNumber": "Customer-12",
    "billingAddress": {
      "address1": "1 Example Ave.",
      "address2": "Example Address Line 2",
      "address3": "Example Address Line 3",
      "city": "Chicago",
      "state": "Illinois",
      "country": "US",
      "postalCode": "60056"
    },
    "shippingAddress": {
      "recipientName": "Sarah Hopper",
      "address": {
        "address1": "1 Example Ave.",
        "address2": "Example Address Line 2",
        "address3": "Example Address Line 3",
        "city": "Chicago",
        "state": "Illinois",
        "country": "US",
        "postalCode": "60056"
      }
    },
    "contactMethods": [
      {
        "type": "email",
        "value": "sarah.hopper@example.com"
      }
    ],
    "notificationLanguage": "en"
  },
  "customFields": [
    {
      "name": "yourCustomField",
      "value": "abc123"
    }
  ]
}
```

<a id="step-2-optional-update-a-secure-token"></a>
## Step 2. (Optional) Update a secure token

To update the payment details represented by a secure token, send a PATCH request to our Update Secure Token endpoint.

| Environment | URL |
| --- | --- |
| Test | [https://api.uat.payroc.com/v1/processing-terminals/\{processingTerminalId\}/secure-tokens/\{secureTokenId\}](https://api.uat.payroc.com/v1/processing-terminals/%7BprocessingTerminalId%7D/secure-tokens/%7BsecureTokenId%7D) |
| Production | [https://api.payroc.com/v1/processing-terminals/\{processingTerminalId\}/secure-tokens/\{secureTokenId\}](https://api.payroc.com/v1/processing-terminals/%7BprocessingTerminalId%7D/secure-tokens/%7BsecureTokenId%7D) |

**Note:** The request format follows the RFC 6902 standard.

<a id="request-parameters-2"></a>
### Request parameters

To create the body of your request, use the following parameters:

<a id="schema-requestbody-2"></a>
### Schema (`request.body`)

[Request body schema for `PATCH /processing-terminals/{processingTerminalId}/secure-tokens/{secureTokenId}`](/api/update-secure-token)

<a id="example-request-2"></a>
### Example request

<a id="request-2"></a>
### Request

PATCH [https://api.payroc.com/v1/processing-terminals/\{processingTerminalId\}/secure-tokens/\{secureTokenId\}](https://api.payroc.com/v1/processing-terminals/%7BprocessingTerminalId%7D/secure-tokens/%7BsecureTokenId%7D)

**`Update secure token`**

```curl
curl -X PATCH https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa \
     -H "Idempotency-Key: 8e03978e-40d5-43e8-bc93-6894a57f9324" \
     -H "Authorization: Bearer <token>" \
     -H "Content-Type: application/json" \
     -d '[
  {
    "op": "add",
    "path": "/customer/lastName",
    "value": null
  },
  {
    "op": "add",
    "path": "/shippingAddress/recipientName",
    "value": null
  },
  {
    "op": "add",
    "path": "/source/cardDetails/cardholderName",
    "value": null
  }
]'
```

**`Update secure token`**

```python
import requests

url = "https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa"

payload = [
    {
        "op": "add",
        "path": "/customer/lastName",
        "value": None
    },
    {
        "op": "add",
        "path": "/shippingAddress/recipientName",
        "value": None
    },
    {
        "op": "add",
        "path": "/source/cardDetails/cardholderName",
        "value": None
    }
]
headers = {
    "Idempotency-Key": "8e03978e-40d5-43e8-bc93-6894a57f9324",
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.patch(url, json=payload, headers=headers)

print(response.json())
```

**`Update secure token`**

```javascript
const url = 'https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa';
const options = {
  method: 'PATCH',
  headers: {
    'Idempotency-Key': '8e03978e-40d5-43e8-bc93-6894a57f9324',
    Authorization: 'Bearer <token>',
    'Content-Type': 'application/json'
  },
  body: '[{"op":"add","path":"/customer/lastName","value":null},{"op":"add","path":"/shippingAddress/recipientName","value":null},{"op":"add","path":"/source/cardDetails/cardholderName","value":null}]'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

**`Update secure token`**

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa"

	payload := strings.NewReader("[\n  {\n    \"op\": \"add\",\n    \"path\": \"/customer/lastName\",\n    \"value\": null\n  },\n  {\n    \"op\": \"add\",\n    \"path\": \"/shippingAddress/recipientName\",\n    \"value\": null\n  },\n  {\n    \"op\": \"add\",\n    \"path\": \"/source/cardDetails/cardholderName\",\n    \"value\": null\n  }\n]")

	req, _ := http.NewRequest("PATCH", url, payload)

	req.Header.Add("Idempotency-Key", "8e03978e-40d5-43e8-bc93-6894a57f9324")
	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

**`Update secure token`**

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Patch.new(url)
request["Idempotency-Key"] = '8e03978e-40d5-43e8-bc93-6894a57f9324'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "[\n  {\n    \"op\": \"add\",\n    \"path\": \"/customer/lastName\",\n    \"value\": null\n  },\n  {\n    \"op\": \"add\",\n    \"path\": \"/shippingAddress/recipientName\",\n    \"value\": null\n  },\n  {\n    \"op\": \"add\",\n    \"path\": \"/source/cardDetails/cardholderName\",\n    \"value\": null\n  }\n]"

response = http.request(request)
puts response.read_body
```

**`Update secure token`**

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.patch("https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa")
  .header("Idempotency-Key", "8e03978e-40d5-43e8-bc93-6894a57f9324")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("[\n  {\n    \"op\": \"add\",\n    \"path\": \"/customer/lastName\",\n    \"value\": null\n  },\n  {\n    \"op\": \"add\",\n    \"path\": \"/shippingAddress/recipientName\",\n    \"value\": null\n  },\n  {\n    \"op\": \"add\",\n    \"path\": \"/source/cardDetails/cardholderName\",\n    \"value\": null\n  }\n]")
  .asString();
```

**`Update secure token`**

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('PATCH', 'https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa', [
  'body' => '[
  {
    "op": "add",
    "path": "/customer/lastName",
    "value": null
  },
  {
    "op": "add",
    "path": "/shippingAddress/recipientName",
    "value": null
  },
  {
    "op": "add",
    "path": "/source/cardDetails/cardholderName",
    "value": null
  }
]',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
    'Idempotency-Key' => '8e03978e-40d5-43e8-bc93-6894a57f9324',
  ],
]);

echo $response->getBody();
```

**`Update secure token`**

```csharp
using RestSharp;

var client = new RestClient("https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa");
var request = new RestRequest(Method.PATCH);
request.AddHeader("Idempotency-Key", "8e03978e-40d5-43e8-bc93-6894a57f9324");
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "[\n  {\n    \"op\": \"add\",\n    \"path\": \"/customer/lastName\",\n    \"value\": null\n  },\n  {\n    \"op\": \"add\",\n    \"path\": \"/shippingAddress/recipientName\",\n    \"value\": null\n  },\n  {\n    \"op\": \"add\",\n    \"path\": \"/source/cardDetails/cardholderName\",\n    \"value\": null\n  }\n]", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

**`Update secure token`**

```swift
import Foundation

let headers = [
  "Idempotency-Key": "8e03978e-40d5-43e8-bc93-6894a57f9324",
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = [
  [
    "op": "add",
    "path": "/customer/lastName",
    "value": 
  ],
  [
    "op": "add",
    "path": "/shippingAddress/recipientName",
    "value": 
  ],
  [
    "op": "add",
    "path": "/source/cardDetails/cardholderName",
    "value": 
  ]
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.payroc.com/v1/processing-terminals/1234001/secure-tokens/MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "PATCH"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

<a id="response-fields-2"></a>
### Response fields

If your request is successful, we update the secure token and return the details represented by the secure token.

<a id="schema-responsebody-2"></a>
### Schema (`response.body`)

[Response body schema for `PATCH /processing-terminals/{processingTerminalId}/secure-tokens/{secureTokenId}`](/api/update-secure-token)

<a id="example-response-2"></a>
### Example response

<a id="response-200-2"></a>
### Response (200)

```json
{
  "secureTokenId": "MREF_abc1de23-f4a5-6789-bcd0-12e345678901fa",
  "processingTerminalId": "1234001",
  "source": {
    "type": "card",
    "cardNumber": "453985******7062",
    "cardholderName": "Sarah Reed",
    "expiryDate": "1230"
  },
  "token": "296753123456",
  "status": "notValidated",
  "mitAgreement": "unscheduled",
  "customer": {
    "firstName": "Sarah",
    "lastName": "Reed",
    "dateOfBirth": "1990-07-15",
    "referenceNumber": "Customer-12",
    "billingAddress": {
      "address1": "1 Example Ave.",
      "address2": "Example Address Line 2",
      "address3": "Example Address Line 3",
      "city": "Chicago",
      "state": "Illinois",
      "country": "US",
      "postalCode": "60056"
    },
    "shippingAddress": {
      "recipientName": "Sarah Reed",
      "address": {
        "address1": "1 Example Ave.",
        "address2": "Example Address Line 2",
        "address3": "Example Address Line 3",
        "city": "Chicago",
        "state": "Illinois",
        "country": "US",
        "postalCode": "60056"
      }
    },
    "contactMethods": [
      {
        "type": "email",
        "value": "sarah.hopper@example.com"
      }
    ],
    "notificationLanguage": "en"
  },
  "customFields": [
    {
      "name": "yourCustomField",
      "value": "abc123"
    }
  ]
}
```
