ROOKDocs
POST

Create an authorization rule

ENDPOINT/v1/authorization-rules

Creates a rule with version 1 as the current version. parameters is discriminated on type. Send Idempotency-Key so retries return the original rule. This operation is program-scoped.

Authentication & Headers

HeaderTypeRequirementDescription
AuthorizationstringREQUIREDAPI key passed as an HTTP Bearer token: Bearer rk_live_...
X-Program-IDUUIDPROGRAM-SCOPEDProgram boundary UUID that scopes the issuing card, wallet, or transfer.
Content-TypestringREQUIREDMust be application/json.
Idempotency-KeystringOPTIONALUnique UUID to prevent duplicate execution of financial creations or mutations.

Request Body Schema

application/json
namestring
REQUIRED

Integrator-visible label for the rule.

statestring
optional

Initial state. Omit to create `ACTIVE`. `INACTIVE` stores the rule without evaluating it.

Enum values:ACTIVEINACTIVE
scopeany
REQUIRED

Where the rule runs. Discriminate on `type`: `PROGRAM` (entire program), `WALLET` (`wallet_ids`), or `CARD` (`card_ids`).

typestring
REQUIRED

Kind of authorization-control rule. `parameters` is a `oneOf` discriminated on the same `type` value.

Enum values:CONDITIONAL_BLOCKVELOCITY_LIMITMERCHANT_LOCKCONDITIONAL_ACTION
parametersany
REQUIRED

Type-specific configuration. Discriminate on `type`. `CONDITIONAL_BLOCK` uses `conditions`. `VELOCITY_LIMIT` uses `velocity`. `MERCHANT_LOCK` uses `merchant_lock`. `CONDITIONAL_ACTION` uses `conditions` and `action`.

Response Codes & Schemas

201The authorization rule was created.
application/json
{
  "id": "8e4c1a92-2f70-4c45-9b3d-0a1e6f7c8290",
  "object": "authorization_rule",
  "name": "Block high-risk MCC",
  "state": "ACTIVE",
  "scope": {
    "type": "PROGRAM"
  },
  "type": "CONDITIONAL_BLOCK",
  "current_version": {
    "id": "b7e3d190-4c6a-4e82-9f15-2d8a0c7b3941",
    "object": "authorization_rule_version",
    "version": 1,
    "parameters": {
      "type": "CONDITIONAL_BLOCK",
      "conditions": [
        {
          "attribute": "MCC",
          "operation": "IS_ONE_OF",
          "value": [
            "7995",
            "5813"
          ]
        }
      ]
    },
    "created_at": "2026-08-12T09:00:00Z",
    "updated_at": "2026-08-12T09:00:00Z"
  },
  "draft_version": null,
  "created_at": "2026-08-12T09:00:00Z",
  "updated_at": "2026-08-19T17:45:00Z"
}
400Bad Request: malformed JSON, failed schema validation, or conflicting parameters.
application/json
{
  "error": {
    "type": "invalid_request_error",
    "code": "invalid_request",
    "message": "invalid order by: foo. Valid options are: [created_at updated_at]",
    "param": "order_by",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/invalid_request"
  }
}
401Unauthorized: missing, malformed, or unknown API key.
application/json
{
  "error": {
    "type": "authentication_error",
    "code": "authentication_error",
    "message": "A valid API key is required.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/authentication_error"
  }
}
403Forbidden: the API key is denied by RBAC, or it cannot access this program. A resource that exists on another program or organization returns `404 not_found`, not `403`.
application/json
{
  "error": {
    "type": "permission_error",
    "code": "permission_denied",
    "message": "The API key cannot access this program.",
    "param": "X-Program-ID",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/permission_denied"
  }
}
404Not Found: unknown id, or the resource is not visible to this API key.
application/json
{
  "error": {
    "type": "not_found_error",
    "code": "not_found",
    "message": "No card found for the given id.",
    "param": "card_id",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/not_found"
  }
}
409Conflict: incompatible state, or Idempotency-Key reused with a different body.
application/json
{
  "error": {
    "type": "conflict_error",
    "code": "conflict",
    "message": "The card cannot be reissued from its current state.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/conflict"
  }
}
422Unprocessable Entity: the document is valid JSON but violates a business rule.
application/json
{
  "error": {
    "type": "invalid_request_error",
    "code": "insufficient_funds",
    "message": "The source financial account does not have enough available balance.",
    "param": "amount",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/insufficient_funds"
  }
}
429Too Many Requests: the API key exceeded its rate limit.
application/json
{
  "error": {
    "type": "rate_limit_error",
    "code": "rate_limited",
    "message": "Rate limit exceeded. Retry after the number of seconds in Retry-After.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/rate_limited"
  }
}
500Internal Server Error: unexpected failure. Retry with the same Idempotency-Key.
application/json
{
  "error": {
    "type": "api_error",
    "code": "internal_error",
    "message": "An unexpected error occurred. Retry with the same Idempotency-Key.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/internal_error"
  }
}