> ## Documentation Index
> Fetch the complete documentation index at: https://agents.laso.finance/llms.txt
> Use this file to discover all available pages before exploring further.

# Withdraw from a reloadable card balance

> Move unspent money off the account holder's reloadable card. The balance behind a reloadable card is held by the card issuer, and this asks the issuer to pay `amount` of it out as USDC on **Base** to the `destination_address` you supply. It is the reverse of `GET /fund-card-balance`, and free: the money is the holder's own, and Laso moves nothing itself.

**Base only.** The issuer pays on Base and nowhere else, so the destination must be a Base wallet you control. A Laso managed agent wallet holds USDC on **Solana** and cannot receive this. The card deposit address from `GET /get-card-deposit-address` is not a valid destination either.

**Not instant.** The issuer processes payouts manually, usually within 1-3 business days, and emails the account holder when the payout is sent. The response carries the issuer's `withdrawal_id`; there is no status route to poll. The request is recorded as a `withdrawal` event under `card_events` in `GET /list-card-transactions`, and the balance from `GET /get-card-deposit-address` drops once it is paid.

**Amount:** \$2 to \$10,000, and no more than the balance the issuer can release. Withdrawals the issuer has not paid yet still count against the balance, so a second request can only take what remains.

Confirm the amount and destination with the account holder before calling this. A linked card issuer account is required; the holder sets it up at https://laso.finance/agent/dashboard/verified/card.

Requires a Bearer token from `/auth` or `/get-card`.



## OpenAPI

````yaml /api-reference/openapi.json post /withdraw-card-balance
openapi: 3.1.0
info:
  title: Laso Finance x402 API
  version: 1.0.0
  x-docs-revision: 4a76ba2a603c
  x-docs-manifest: https://laso.finance/.well-known/docs-version.json
  contact:
    email: agents+support@laso.finance
  x-guidance: >-
    Laso Finance is a payment-gated (x402) API that lets an AI agent spend USDC
    on real-world financial products: prepaid cards (U.S. and international),
    gift cards, push-to-card transfers to USD/EUR/GBP debit cards, and
    Venmo/PayPal payouts.


    Payment: every paid route is an x402 v2 endpoint. Call it with no payment
    header to receive a 402 challenge listing the accepted networks, then replay
    with a signed USDC payment. Both Base (eip155:8453) and Solana
    (solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp) are accepted on every paid route;
    the caller picks either chain.


    Identity: `GET /auth` is free and identity-only. Prove wallet ownership with
    a `SIGN-IN-WITH-X` (CAIP-122) header to receive a Firebase id_token, then
    send that token as a Bearer credential to the authenticated read routes
    (`get-card-data`, `get-account-balance`, `get-kyc-status`, etc.). Paid
    routes also return fresh auth credentials in their response, so a payment is
    never required just to obtain a token.


    Recommended flow: (1) `GET /auth` to establish identity, (2) call a paid
    route (e.g. `GET /get-card`) to purchase a product, paying USDC on Base or
    Solana, (3) poll the authenticated read routes with the returned Bearer
    token to fetch the resulting card/transfer details. Full machine-readable
    instructions live at https://laso.finance/SKILL.md.
  description: >-
    Payment-gated API for Laso Finance. All paywalled routes use the x402
    protocol — the caller includes a USDC payment header on Base (eip155:8453)
    or Solana (solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp) and the server verifies
    payment before processing. Free routes require no payment header. The same
    402 also carries an MPP (Machine Payments Protocol) challenge in
    WWW-Authenticate; an MPP client pays with USDC on Base by replaying with
    `Authorization: Payment ...`, and routes, prices, and responses are
    identical.


    ## Getting started


    To set up a wallet for making x402 payments, choose a provider:


    - **Locus** (default): https://paywithlocus.com/SKILL.md

    - **Sponge**: https://wallet.paysponge.com/skill.md — automatic x402 service
    discovery

    - **Ampersend**: https://www.ampersend.ai/getting-started.md — self-custody
    on Base or Solana with dual-approval spending limits. Laso Finance is a
    default skill, so no manual endpoint registration is needed.


    ## How x402 works


    1. Call a paywalled endpoint without a payment header → receive a `402
    Payment Required` response containing payment details (price, recipient
    address, network).

    2. Construct an x402 payment header using the details from the 402 response.

    3. Replay the request with the payment header → the server verifies payment
    and processes the request.


    ## Authentication flow


    `GET /auth` is free: callers prove wallet ownership by sending a
    `SIGN-IN-WITH-X` header (CAIP-122 wallet signature). Paywalled routes
    (`/get-card`, `/order-gift-card`, `/get-push-to-card`, `/order-intl-card`)
    also return fresh auth credentials in their responses, so a payment is never
    required just to obtain a token.


    Most routes return auth credentials (`id_token`, `refresh_token`,
    `expires_in`). Use the `id_token` as a Bearer token to call authenticated
    Laso Finance endpoints like `/get-card-data`. When the `id_token` expires,
    use `POST /auth` with `grant_type: refresh_token` to get a new one.


    ## Important notes


    The `/get-card` USA prepaid card endpoint is U.S. only — issued in USD,
    usable at U.S.-based merchants only, and physical goods must ship to a U.S.
    address. For non-U.S. merchants or non-USD currencies, use `GET
    /order-intl-card` instead (international prepaid card, admin-fulfilled
    within 24 hours). All cards are intended for the caller's own use.


    ## Rate limits


    Every response carries the request budget so you can pace yourself without
    probing for a limit:


    | Header | Meaning |

    | --- | --- |

    | `RateLimit-Limit` | Requests permitted per window |

    | `RateLimit-Remaining` | Requests still available |

    | `RateLimit-Reset` | Seconds until the window rolls over |

    | `RateLimit-Policy` | The policy these numbers describe, as
    `limit;w=seconds` |


    The same values are repeated as `X-RateLimit-*` for clients that only parse
    that spelling.


    Most routes advertise the service-wide ceiling. `POST /signup` enforces its
    own per-IP budget on top of it and overwrites these headers with its own
    numbers. `POST /refresh-card-data` is limited per card rather than per
    caller, so its headers keep the service-wide values and the per-card budget
    is reported only on rejection.


    Every rejection is a `429` carrying `Retry-After` in seconds and a matching
    `retry_after_seconds` field in the body, computed from the limit that
    actually rejected the request. Wait that long and retry once. Do not retry
    in a tight loop.


    For step-by-step instructions, read https://laso.finance/SKILL.md
servers:
  - url: https://laso.finance
    description: Production
security: []
paths:
  /withdraw-card-balance:
    post:
      tags:
        - cards
      summary: Withdraw from a reloadable card balance
      description: >-
        Move unspent money off the account holder's reloadable card. The balance
        behind a reloadable card is held by the card issuer, and this asks the
        issuer to pay `amount` of it out as USDC on **Base** to the
        `destination_address` you supply. It is the reverse of `GET
        /fund-card-balance`, and free: the money is the holder's own, and Laso
        moves nothing itself.


        **Base only.** The issuer pays on Base and nowhere else, so the
        destination must be a Base wallet you control. A Laso managed agent
        wallet holds USDC on **Solana** and cannot receive this. The card
        deposit address from `GET /get-card-deposit-address` is not a valid
        destination either.


        **Not instant.** The issuer processes payouts manually, usually within
        1-3 business days, and emails the account holder when the payout is
        sent. The response carries the issuer's `withdrawal_id`; there is no
        status route to poll. The request is recorded as a `withdrawal` event
        under `card_events` in `GET /list-card-transactions`, and the balance
        from `GET /get-card-deposit-address` drops once it is paid.


        **Amount:** \$2 to \$10,000, and no more than the balance the issuer can
        release. Withdrawals the issuer has not paid yet still count against the
        balance, so a second request can only take what remains.


        Confirm the amount and destination with the account holder before
        calling this. A linked card issuer account is required; the holder sets
        it up at https://laso.finance/agent/dashboard/verified/card.


        Requires a Bearer token from `/auth` or `/get-card`.
      operationId: withdrawCardBalance
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - amount
                - destination_address
              properties:
                amount:
                  type: number
                  minimum: 2
                  maximum: 10000
                  description: >-
                    USD to withdraw from the card balance (min \$2, max
                    \$10,000).
                destination_address:
                  type: string
                  description: >-
                    The 0x-prefixed Base wallet address that receives the USDC.
                    Must be one you control; Base only.
            example:
              amount: 25
              destination_address: '0x1234567890abcdef1234567890abcdef12345678'
      responses:
        '200':
          description: The issuer accepted the withdrawal request.
          content:
            application/json:
              schema:
                type: object
                properties:
                  withdrawal_id:
                    type: string
                    description: >-
                      The card issuer's reference for this payout request. Quote
                      it to support; it also appears on the matching
                      `withdrawal` card event.
                  status:
                    type: string
                    example: requested
                    description: >-
                      Always `requested`: the issuer has accepted the request
                      and will pay it out manually.
                  amount:
                    type: number
                    description: USD the issuer will pay out.
                  destination_address:
                    type: string
                    description: The Base address the USDC goes to.
                  network:
                    type: string
                    example: base
                  asset:
                    type: string
                    example: USDC
                  note:
                    type: string
                    description: Timing and where to see the request afterwards.
        '400':
          description: >-
            Invalid `amount` (`amount_below_minimum`, `amount_above_maximum`),
            an invalid or non-Base `destination_address`
            (`invalid_destination_address`), no linked card issuer account, or
            the issuer refused the request: `insufficient_card_balance` (the
            `error` names how much can be withdrawn right now),
            `withdrawals_disabled`, `withdrawals_unavailable`, or
            `withdrawal_rejected`. The `error` carries the issuer's own reason.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error: >-
                  The user can withdraw at most $18.50 right now (open requests
                  count against the balance). Ask them to pick an amount within
                  that.
                code: insufficient_card_balance
                hint: >-
                  Read the current balance with GET /get-card-deposit-address
                  and request that amount or less. Withdrawals the issuer has
                  not paid yet still count against it.
        '401':
          description: Missing or invalid Bearer token
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error: Missing or invalid Authorization header
        '403':
          description: >-
            Account is frozen. The response includes a `frozen_message` field
            explaining why.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/FrozenError'
              example:
                error: Account is frozen
                frozen_message: >-
                  Your account is frozen pending a compliance review. Contact
                  support@laso.finance.
      security:
        - BearerAuth: []
components:
  schemas:
    Error:
      type: object
      properties:
        error:
          type: string
    FrozenError:
      type: object
      properties:
        error:
          type: string
          example: Account is frozen
        frozen_message:
          type: string
          description: Human-readable explanation of why the account is frozen
  securitySchemes:
    BearerAuth:
      type: apiKey
      in: header
      name: Authorization
      description: >-
        Firebase ID token from `/auth` or any paid route, sent as a Bearer
        token: `Authorization: Bearer <id_token>` (the `Bearer ` prefix is
        required).

````