Unable to add customer card - INVALID_REQUEST_ERROR / INVALID_CARD_DATA / source_id

We are seeing issues with card creation (POST /v2/cards) using the web SDK (version 2023-10-20).

The following error is being reported: Invalid card data (source_id).

We are successfully storing cards (350+ in the past month) with 63 reported failures like this during the same period.

Below is our latest example of failure:

{
    "idempotency_key": "657b4dede6112",
    "source_id": "cnon:CBASEExIK5JYkJ5aSDFgJzenV6Q",
    "card": {
        "billing_address": null,
        "cardholder_name": "",
        "customer_id": "JR3QTAR3R0KKKHMZBMY8V59CB0"
    }
}

This is under application ID sq0idp-mWRA6OZ7ff-zyPi24pIY1A.

Is there a way to get more information to better understand what is happening?

Any assistance will be greatly appreciated.

:wave: I’m Square Dev AI, here to help answer your question!
Based on the information you’ve provided, the following documentation will help answer your question:

Additional Documentation

Cards API Overview
Manage Customer Cards on File
Card Payments

If this documentation helped you find a solution, please check the box indicating that this reply solves the problem.
Otherwise one of our Developer Advocates will provide additional assistance shortly.

The invalid card data error means that the card information that was tokenized by the Web payments SDK was invalid. This is often caused by a customer incorrectly inputing the card information. You’ll need to have the customer re-enter their information and try again.

We specifically return this generic error so bad actors don’t take advantage of a specific incorrect field like CVV or AVS for malicious purposes. :slightly_smiling_face:

Your reply helped me to understand more about Square’s tokenise process, which led me to find this: Even if the CVV of the credit card is wrong, a token can be generated, is this correct behavior? - #2 by Bryan-Square

So basically, the card tokenisation generated from Square’s card web form will tokenise both valid AND invalid cards. It’s not until the cards API step that the card details are truly validated. Is that correct?

Yes, this is the correct behavior with the tokenized card. :slightly_smiling_face:

Hi
could you help me please

I have the same issue
and face it again and again and struggling with it several hours
everything is clear with creating customer, but creating card always return the error


{“errors”:[{“category”:“INVALID_REQUEST_ERROR”,“code”:“INVALID_CARD_DATA”,“detail”:“Invalid card data.”,“field”:“source_id”}]}
I tried to use different cards with verification and without it, but the the result is the same, nothing changed
application id sandbox-sq0idb-dV-NBldaWcNX_tMBrQHZHA
please help me as soon as possible, the issue is highly urgent

I just tested that test value charging the card and storing the card on file and it worked as expected. What are the steps to reproduce this error? :slightly_smiling_face:

Hi Bryan.

I have something very interesting, In sandbox everything works perfect, but in production expecially international cards, to be exact Ecuadorian cards, in some cards, I have this example of a real payment

request:

{
“idempotency_key”: “savecard_6aab5b4f670877.92960336”,
“source_id”: “[redacted]”,
“card”: {
“cardholder_name”: “Diego Guerrero G”,
“billing_address”: {
“address_line_1”: “Av narcisa de Jesús”,
“address_line_2”: “Urb la Romareda”,
“locality”: “Guayaquil”,
“administrative_district_level_1”: “G”,
“postal_code”: “090703”,
“country”: “EC”
},
“customer_id”: “JD36QEJ14JC13HHR7W7HZBRCBG”
}
}

response:

{
“errors”: [
{
“category”: “INVALID_REQUEST_ERROR”,
“code”: “INVALID_CARD_DATA”,
“detail”: “Invalid card data.”,
“field”: “source_id”
}
]
}

Could you please explain me why happen this ? It Is Problem in my side or customer or the source bank, any advice?

thank you in advance

P.d . the cards has founds

this is my personal log:

{"timestamp":"2026-09-16 23:15:25","stage":"WEB_TOKENIZATION_DIAGNOSTIC","bookid":5346,"data":{"phase":"TOKENIZE_RETURNED","status":"OK","token_created":true,"payment_method":"Card","card_brand":"MASTERCARD","card_type":"CREDIT","prepaid_type":"NOT_PREPAID","last4":"1694","billing_country":"EC","billing_state":"G","postal_code_present":true,"amount":"358.37","currency":"USD","intent":"CHARGE_AND_STORE","customer_initiated":true,"seller_keyed_in":false,"errors":[],"exception_name":null,"exception_message":null,"client_ip":"157.100.40.19","bookid":5346}}
{"timestamp":"2026-09-16 23:15:27","stage":"CREATE_PAYMENT","bookid":5346,"data":{"result":"SUCCESS","amount_cents":35837,"amount_dollars":358.37,"payment_status":"COMPLETED","payment_id":"L9qXmTBy5hJmaGHrWeZPGsb31wCZY","card_brand":"MASTERCARD","last4":"1694","card_type":"CREDIT","prepaid_type":"NOT_PREPAID","urlReceipt":"https://squareup.com/receipt/preview/L9qXmTBy5hJmaGHrWeZPGsb31wCZY"}}
{"timestamp":"2026-09-16 23:15:27","stage":"UPDATE_RESERVATION_PAYMENT_ID","bookid":5346,"data":{"result":"SUCCESS","payment_id":"L9qXmTBy5hJmaGHrWeZPGsb31wCZY","affected_rows":1}}
{"timestamp":"2026-09-16 23:15:27","stage":"CHECK_EXISTING_CARD","bookid":5346,"data":{"result":"NO_MATCH","payment_id":"L9qXmTBy5hJmaGHrWeZPGsb31wCZY","customer_id":"JD36QEJ14JC13HHR7W7HZBRCBG","fingerprint_available":true}}
{"timestamp":"2026-09-16 23:15:28","stage":"CREATE_CARD_FROM_PAYMENT","bookid":5346,"data":{"result":"FAILED","payment_id":"L9qXmTBy5hJmaGHrWeZPGsb31wCZY","customer_id":"JD36QEJ14JC13HHR7W7HZBRCBG","country":"EC","amount_cents":35837,"errors":[{"category":"INVALID_REQUEST_ERROR","code":"INVALID_CARD_DATA","detail":"Invalid card data.","field":"source_id"}]}}
{"timestamp":"2026-09-16 23:15:28","stage":"STORE_CARD_AFTER_PAYMENT","bookid":5346,"data":{"result":"FAILED","payment_completed":true,"payment_id":"L9qXmTBy5hJmaGHrWeZPGsb31wCZY","save_card_error":[{"category":"INVALID_REQUEST_ERROR","code":"INVALID_CARD_DATA","detail":"Invalid card data.","field":"source_id"}]}}
{"timestamp":"2026-09-16 23:15:28","stage":"DB_SAVE_PAYMENT","bookid":5346,"data":{"result":"RESPONSE_RECEIVED","payment_id":"L9qXmTBy5hJmaGHrWeZPGsb31wCZY"}}


the last stage is to save the data in my data base.

{"timestamp":"2026-09-16 23:15:28","stage":"DB_SAVE_PAYMENT","bookid":5346,"data":{"result":"RESPONSE_RECEIVED","payment_id":"L9qXmTBy5hJmaGHrWeZPGsb31wCZY"}}

Why is the $0 card verification performed by CreateCard failing with INVALID_CARD_DATA/source_id for this Ecuador-issued Visa, when the source Payment is CAPTURED, CVV_ACCEPTED, risk NORMAL, entry_method KEYED, and AVS is AVS_NOT_CHECKED rather than AVS_REJECTED?

We reproduced the same failure both with a billing postal code and with no postal code at all.

I appreciate your help.

Thanks