Aurora — card issuing, tokenisation and lifecycle servicing (Java 21 / Spring Boot 3.3).
The source tree is organised by business domain, not by technical layer.
| Slice | Responsibility |
|---|---|
issuing |
Application preflight, PAN minting, card assembly, registry, card.issued event |
validation |
Luhn checksum and check digit, PAN format and masking, BIN ranges, expiry arithmetic |
tokenisation |
Network token generation, token vault, wallet/device bindings, reissue |
lifecycle |
Card state machine ISSUED → ACTIVE → BLOCKED → REPLACED → CLOSED, state history, replacement policy |
limits |
Product limit policies, daily/monthly spend accumulation, limit evaluation and reservation |
identity / ledger / fraud / notification |
Outbound clients to the neighbouring Aurora services |
| Verb | Path |
|---|---|
| POST | /api/v1/cards/issue |
| GET | /api/v1/cards/details |
| POST | /api/v1/cards/activate |
| POST | /api/v1/cards/replace |
| GET | /api/v1/cards/limits |
| Verb | Target |
|---|---|
| POST | aurora-ledger — /api/v1/ledger/holds |
| GET | aurora-identity — /api/v1/customers/profile |
| POST | aurora-fraud — /api/v1/fraud/assessments |
| POST | aurora-notifications — /api/v1/notifications/dispatch |
Kafka producer: topic card.issued, published at the end of the issuing flow.
ISSUED -> ACTIVE | REPLACED | CLOSED
ACTIVE -> BLOCKED | REPLACED | CLOSED
BLOCKED -> ACTIVE | REPLACED | CLOSED
REPLACED-> CLOSED
CLOSED -> (terminal)
Anything outside that set is refused with IllegalCardTransitionException. A card may be
replaced at most twice before a new application is required.