cards create, cards bulk-create, cards update-limits, and cards update-restrictions take their request as a JSON document with --body, because its shape depends on the card level. The fields are described on each command’s API reference page.
Creating a physical card, and some changes to an existing card, require Strong Customer Authentication: the command waits until you approve in the Qonto app. Reporting a card as lost or stolen, and discarding it, cannot be undone.
qonto cards data-view returns a short-lived link that shows the card number, expiry date, and CVV. Treat it like a password.