GET
List authorization-rule backtests
ENDPOINT/v1/authorization-rules/{authorization_rule_id}/backtests
Returns backtests for this rule, newest first. A backtest replays historical authorizations against the current and draft versions. This operation is program-scoped.
Authentication & Headers
| Header | Type | Requirement | Description |
|---|---|---|---|
| Authorization | string | REQUIRED | API key passed as an HTTP Bearer token: Bearer rk_live_... |
| X-Program-ID | UUID | PROGRAM-SCOPED | Program boundary UUID that scopes the issuing card, wallet, or transfer. |
Path Parameters
| Parameter | Type | Requirement | Description |
|---|---|---|---|
| authorization_rule_id | string | REQUIRED | Unique identifier of the authorization rule. |
Query Parameters
| Parameter | Type | Requirement | Description |
|---|---|---|---|
| page | integer | OPTIONAL | 1-based page index. Default 1. Values below 1 are treated as 1.
|
| page_size | integer | OPTIONAL | Number of objects to return in the page. Minimum 1, maximum 100, default
10. Also accepted as `page-size`. Values below 1 fall back to the default;
values above 100 are capped at 100.
|
| order_by | string | OPTIONAL | Field to sort by. When omitted, the endpoint uses its default order.
Also accepted as `order-by`. Valid fields are endpoint-specific
(`created_at`, `updated_at`, …).
|
| ascending | boolean | OPTIONAL | Sort direction. Default true (ascending). Pass `false` for descending.
Invalid values are ignored and the default is used.
|
Response Codes & Schemas
200A page of backtests for the rule.
application/json{
"data": [
{
"id": "d9a5f3b2-6e8c-4014-b137-4f0c2e9d5163",
"object": "authorization_rule_backtest",
"authorization_rule_id": "8e4c1a92-2f70-4c45-9b3d-0a1e6f7c8290",
"status": "COMPLETED",
"start": "2026-08-01T00:00:00Z",
"end": "2026-08-07T23:59:59Z",
"results": {
"current_version": {
"version": 1,
"approved": 800,
"declined": 50,
"challenged": 0,
"examples": [
{
"transaction_id": "2b5f7a28-9c4d-4e01-a6f3-1d8e0b7c2354",
"created_at": "2026-08-05T14:22:00Z",
"decision": "APPROVED"
}
]
},
"draft_version": {
"version": 2,
"approved": 820,
"declined": 30,
"challenged": 0,
"examples": [
{
"transaction_id": "2b5f7a28-9c4d-4e01-a6f3-1d8e0b7c2354",
"created_at": "2026-08-05T14:22:00Z",
"decision": "APPROVED"
}
]
}
},
"created_at": "2026-08-21T08:00:00Z",
"updated_at": "2026-08-21T08:04:00Z"
}
],
"total_count": 1
}400Bad Request: malformed JSON, failed schema validation, or conflicting parameters.
application/json{
"error": {
"type": "invalid_request_error",
"code": "invalid_request",
"message": "invalid order by: foo. Valid options are: [created_at updated_at]",
"param": "order_by",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/invalid_request"
}
}401Unauthorized: missing, malformed, or unknown API key.
application/json{
"error": {
"type": "authentication_error",
"code": "authentication_error",
"message": "A valid API key is required.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/authentication_error"
}
}403Forbidden: the API key is denied by RBAC, or it cannot access this
program. A resource that exists on another program or organization
returns `404 not_found`, not `403`.
application/json{
"error": {
"type": "permission_error",
"code": "permission_denied",
"message": "The API key cannot access this program.",
"param": "X-Program-ID",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/permission_denied"
}
}404Not Found: unknown id, or the resource is not visible to this API key.
application/json{
"error": {
"type": "not_found_error",
"code": "not_found",
"message": "No card found for the given id.",
"param": "card_id",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/not_found"
}
}429Too Many Requests: the API key exceeded its rate limit.
application/json{
"error": {
"type": "rate_limit_error",
"code": "rate_limited",
"message": "Rate limit exceeded. Retry after the number of seconds in Retry-After.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/rate_limited"
}
}500Internal Server Error: unexpected failure. Retry with the same Idempotency-Key.
application/json{
"error": {
"type": "api_error",
"code": "internal_error",
"message": "An unexpected error occurred. Retry with the same Idempotency-Key.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/internal_error"
}
}