GET
Retrieve authorization-rule features
ENDPOINT/v1/authorization-rules/features
Returns calculated feature values for a wallet or card: trailing
authorization counts and spend. Supply wallet_id, card_id, or
both. These counters are inputs to velocity and conditional rules.
This operation is program-scoped.
Authentication & Headers
| Header | Type | Requirement | Description |
|---|---|---|---|
| Authorization | string | REQUIRED | API key passed as an HTTP Bearer token: Bearer rk_live_... |
| X-Program-ID | UUID | PROGRAM-SCOPED | Program boundary UUID that scopes the issuing card, wallet, or transfer. |
Query Parameters
| Parameter | Type | Requirement | Description |
|---|---|---|---|
| wallet_id | string(uuid) | OPTIONAL | Issuing wallet to compute features for. Supply `wallet_id`,
`card_id`, or both. Omitting both is `400` / `invalid_request`.
|
| card_id | string(uuid) | OPTIONAL | Card to compute features for. Supply `wallet_id`, `card_id`, or
both. Omitting both is `400` / `invalid_request`.
|
Response Codes & Schemas
200Feature counters at the current instant.
application/json{
"id": "a3d8e6f5-9b1f-4347-e46a-7c3f5b208496",
"object": "authorization_rule_features",
"wallet_id": "4d8f2a10-6c3e-4b91-9e5a-2f7c8d1e0b44",
"card_id": "0c4e8f16-2a7b-4d93-b5e1-8f3a6c9d0142",
"as_of": "2026-08-27T14:22:00Z",
"updated_at": "2026-08-27T14:22:00Z",
"card_transaction_count_15m": 1,
"card_transaction_count_1h": 2,
"card_transaction_count_24h": 6,
"card_transaction_count_7d": 18,
"card_transaction_count_30d": 41,
"spend_15m": {
"amount": 4280,
"currency": "USD"
},
"spend_1h": {
"amount": 8520,
"currency": "USD"
},
"spend_24h": {
"amount": 21400,
"currency": "USD"
}
}400Bad Request: malformed JSON, failed schema validation, or conflicting parameters.
application/json{
"error": {
"type": "invalid_request_error",
"code": "invalid_request",
"message": "invalid order by: foo. Valid options are: [created_at updated_at]",
"param": "order_by",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/invalid_request"
}
}401Unauthorized: missing, malformed, or unknown API key.
application/json{
"error": {
"type": "authentication_error",
"code": "authentication_error",
"message": "A valid API key is required.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/authentication_error"
}
}403Forbidden: the API key is denied by RBAC, or it cannot access this
program. A resource that exists on another program or organization
returns `404 not_found`, not `403`.
application/json{
"error": {
"type": "permission_error",
"code": "permission_denied",
"message": "The API key cannot access this program.",
"param": "X-Program-ID",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/permission_denied"
}
}404Not Found: unknown id, or the resource is not visible to this API key.
application/json{
"error": {
"type": "not_found_error",
"code": "not_found",
"message": "No card found for the given id.",
"param": "card_id",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/not_found"
}
}429Too Many Requests: the API key exceeded its rate limit.
application/json{
"error": {
"type": "rate_limit_error",
"code": "rate_limited",
"message": "Rate limit exceeded. Retry after the number of seconds in Retry-After.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/rate_limited"
}
}500Internal Server Error: unexpected failure. Retry with the same Idempotency-Key.
application/json{
"error": {
"type": "api_error",
"code": "internal_error",
"message": "An unexpected error occurred. Retry with the same Idempotency-Key.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/internal_error"
}
}