Watch notification. One step: no form, no support ticket, no new card, and the merchant stays allowed on that card from then on. The loop is three lines: the purchase is refused and you are told why; you run this command naming the merchant; the card resumes and the retry goes through. The pause or watch notice carries this command with the card id and merchant filled in. The pattern is a case-insensitive substring of the merchant descriptor: starbucks matches STARBUCKS #123. The rest of the preset stays in force; spend, place, currency, time, and --only-from rules still apply.
Strict categories, the card network still enforces the category lock it was given when the card was made, and we cannot widen it afterwards. A purchase made directly at that merchant, outside Agentcard checkout, can still be declined by the network; the output tells you when that applies. If you need both to work, create a new card from the same preset. If a multi-use card was paused after settlement: allow the merchant, run agent-cards cards resume <card-id>, then retry. See Allow a refused merchant.
Captured from a local sandbox after a grocery charge paused a reusable ai_labs card: