Brex ACTION
Update Card Limit
Updates the spend limit on a vendor card (
limit_type: CARD). This sends a complete spend_controls object, so treat it as a replacement: supply every spend control you want the card to keep, because Brex does not document whether omitted fields are preserved or cleared. Corporate cards draw on their cardholder's limit instead — use Set Limit for User for those. See the documentation- Action
- Writes data
- OAuth
- SDK
- MCP
IMPLEMENTATION
Call this tool
Connect a user's Brex account once, then configure and run Update Card Limit from your backend or agent.
import { PipedreamClient } from "@pipedream/sdk"
const pd = new PipedreamClient({
projectId: process.env.PIPEDREAM_PROJECT_ID!,
clientId: process.env.PIPEDREAM_CLIENT_ID!,
clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
projectEnvironment: "production",
})
const result = await pd.actions.run({
id: "brex-update-card-limit",
externalUserId: "{external_user_id}", // any stable ID for this user in your system
configuredProps: {
brex: { authProvisionId: "apn_xxxxxxx" },
cardId: "Card ID",
amount: 10,
},
})
console.log(result)curl -X POST https://api.pipedream.com/v1/connect/{project_id}/actions/run \
-H "Content-Type: application/json" \
-H "X-PD-Environment: production" \
-H "Authorization: Bearer {access_token}" \
-d '{
"external_user_id": "{external_user_id}",
"id": "brex-update-card-limit",
"configured_props": {
"brex": { "authProvisionId": "apn_xxxxxxx" },
"cardId": "Card ID",
"amount": 10
}
}'// accessToken: mint a short-lived token with the Connect SDK — see the MCP guide
const transport = new StreamableHTTPClientTransport(
new URL("https://remote.mcp.pipedream.net/v3"),
{
requestInit: {
headers: {
Authorization: `Bearer ${accessToken}`,
"x-pd-project-id": "{project_id}",
"x-pd-environment": "production",
"x-pd-external-user-id": "{external_user_id}", // any stable ID for this user in your system
"x-pd-app-slug": "brex",
},
},
},
)
const mcp = new Client({ name: "my-agent", version: "1.0.0" })
await mcp.connect(transport)
const { tools } = await mcp.listTools()
// listTools() hands your model this tool's input schema, so it can
// fill the arguments itself:
const result = await mcp.callTool({
name: "brex-update-card-limit",
arguments: {
cardId: "Card ID",
amount: 10,
},
})SCHEMA
Inputs
Pipedream supplies the connected account. Your application provides the operation-specific values below. Dynamic inputs are resolved against that user's account.
| Property | Type | Description |
|---|---|---|
cardId Card ID | string | The unique ID of the card. Use List Cards to find a card ID by cardholder, name, or last four digits. Required |
amount Spend Limit Amount | integer | The new spend limit, in the currency's smallest denomination — 700 is $7.00 in USD. Required |
currency Spend Limit Currency | string | The currency of the limit, in ISO 4217 format, e.g. USD. Defaults to USD when omitted, so set this explicitly for a card denominated in any other currency. Optional |
spendDuration Spend Duration | string | How often the limit refreshes: MONTHLY, QUARTERLY, or YEARLY to refresh on that cadence, or ONE_TIME for a limit that never refreshes. Sent on every update, so set it to the cadence the card should have from now on — use Get Card to read the card's current duration first if you only mean to change the amount. Required |
reason Reason | string | A free-text note explaining the new limit. Sent on every update, so re-supply the card's existing note if you want to keep it — use Get Card to read it first. Optional |
lockAfterDate Lock After Date | string | Freeze the card automatically after this UTC date, in yyyy-mm-dd format. Sent on every update, so re-supply the card's existing lock date if you want to keep it — use Get Card to read it first. Optional |
REFERENCE
Tool details
Behavior hints are published with the component in the Pipedream registry and surface as MCP tool annotations, so an agent can reason about a tool before it calls it.
- Registry key
- brex-update-card-limit
- Version
- 0.0.1
- App
- Brex
- Authentication
- OAuth
- Read-only
- No
- Destructive
- No
- Open world
- Yes
- Source
- View on GitHub ↗