/
25 minute read
October 28, 2021

Authorization Controls

Hidden

An authorization control limits spending by specified users at specified merchants. You can limit spending at a single merchant or at a group of merchants, and you can limit spending by a single user, users with a particular card product, or all users.

You can block spending at all merchants by default and then allow it for specific merchants, or you can allow spending at all merchants by default and block it at specific merchants.

Tip
See Controlling Spending for a tutorial that walks you through the creation of a spend control, as well as links to more information about merchant category codes.

Create authorization control

Action: POST
Endpoint: /authcontrols

Limit where a user can make transactions to a single merchant or group of merchants. If multiple authorization controls apply to the same user, the limits of all controls are combined.

Request body
Fields Description

active

boolean
Optional

Indicates whether the authorization control is active. If the control will be used for Commando Mode, set to false and then enable it using commando_mode_enables. See Update Commando Mode control set.

Allowable Values:

true, false

Default value:
true

association

object
Optional

Defines the group of users to which the authorization control applies. This object is required if the merchant_scope object is not included in your request. Your request can include both the association and merchant_scope objects.

If you include this object in your request, you must populate one or more of its fields. If no fields are populated, the authorization control applies to all users.

Allowable Values:

A valid association object

association.card_product_token

string
Optional

Token identifying a card product.

Specify a card product token in the card_product_token field to apply the authorization control to all users holding active cards associated with the card product.

Pass either card_product_token or user_token, not both.

Allowable Values:

1–36 chars

association.user_token

string
Optional

Token identifying a user.

Specify a user token in the user_token field to apply the authorization control to a single user.

Pass either card_product_token or user_token, not both.

Allowable Values:

1–36 chars

end_time

datetime
Optional

The date and time when the exception ends.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

merchant_scope

object
Optional

Defines the group of merchants to which the authorization control applies. This object is required if the association object is not included in your request. Your request can include both the merchant_scope and association objects.

If you include this object in your request, you must populate one or more of its fields. If no fields are populated, the authorization control applies to all merchants.

Allowable Values:

A valid merchant_scope object.

merchant_scope.mcc

string
Optional

A single MCC (Merchant Category Code). Identifies the type of goods or services provided by the merchant.

Enter a value to control access to a particular type of product or service.

See Controlling Spending for links to more information about merchant category codes.

Allowable Values:

1–4 chars

merchant_scope.mcc_group

string
Optional

Token identifying a group of MCCs.

Enter a value to control access to a group of product or service types.

Allowable Values:

1–36 chars

Send a GET request to /mccgroups to retrieve MCC group tokens.

merchant_scope.merchant_group_token

string
Optional

The unique identifier of a merchant group.

Enter a value to control access to a group of merchants.

Allowable Values:

1–36 chars

merchant_scope.mid

string
Optional

MID (Merchant ID). The unique identification number of a merchant.

Enter a value to control access to a particular merchant.

Allowable Values:

1–36 chars

name

string
Required

The name of the authorization control.

Allowable Values:

255 char max

start_time

datetime
Optional

The date and time when the exception goes into effect.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

token

string
Optional

The unique identifier of the authorization control.

If you do not include a token, the system will generate one automatically. This token is necessary for use in other API calls, so we recommend that rather than let the system generate one, you use a simple string that is easy to remember. This value cannot be updated.

Allowable Values:

1–36 chars

Response body
Fields Description

active

boolean
Conditionally returned

Indicates whether the authorization control is active.

Allowable Values:

true, false

association

object
Conditionally returned

Defines the group of users to which the authorization control applies.

Allowable Values:

A valid association object.

association.card_product_token

string
Conditionally returned

Token identifying a card product.

Allowable Values:

1–36 chars

association.user_token

string
Conditionally returned

Token identifying a user.

Allowable Values:

1–36 chars

end_time

datetime
Conditionally returned

The date and time when the exception ends.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

merchant_scope

object
Conditionally returned

Defines the group of merchants to which the authorization control applies.

Allowable Values:

A valid merchant_scope object.

merchant_scope.mcc

string
Conditionally returned

A single MCC (Merchant Category Code). Identifies the type of goods or services provided by the merchant.

Allowable Values:

1–4 chars

merchant_scope.mcc_group

string
Conditionally returned

Token identifying a group of MCCs.

Allowable Values:

1–36 chars

merchant_scope.merchant_group_token

string
Conditionally returned

The unique identifier of a merchant group.

Enter a value to control access to a group of merchants.

Allowable Values:

1–36 chars

merchant_scope.mid

string
Conditionally returned

MID (Merchant ID). The unique identification number of a merchant.

Allowable Values:

1–36 chars

name

string
Returned

The name of the authorization control.

Allowable Values:

255 char max

start_time

datetime
Conditionally returned

The date and time when the exception goes into effect.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

token

string
Conditionally returned

The unique identifier of the authorization control.

Allowable Values:

1–36 chars

Sample request body
Copied

Is this helpful?

Yes
No
Sample response body
Copied

Is this helpful?

Yes
No

List authorization controls

Action: GET
Endpoint: /authcontrols

List all authorization controls associated with a specific user or card product, or list all authorization controls defined in your program.

Include either a user or a card_product query parameter to indicate the user or card product whose associated authorization controls you want to retrieve (do not include both).

To list all authorization controls for your program, omit the user and card_product query parameters from your request.

URL query parameters
Fields Description

card_product

string
Optional

The token identifying the card product whose associated authorization controls you want to retrieve.

Enter the string "null" to list authorization controls that are not associated with a card product.

Allowable Values:

Existing card product token or the string null

user

string
Optional

The token identifying the user whose associated authorization controls you want to retrieve.

Enter the string "null" to list authorization controls that are not associated with a user.

Allowable Values:

Existing user or the string null

count

integer
Optional

The number of resources to retrieve.

Allowable Values:

1-100

start_index

integer
Optional

The sort order index of the first resource in the returned array.

Allowable Values:

Any integer

fields

string
Optional

Comma-delimited list of fields to return (field_1,field_2, and so on). Leave blank to return all fields.

Allowable Values:

A comma-delimited list of fields, or blank

sort_by

string
Optional

Field on which to sort. Use any field in the resource model, or one of the system fields lastModifiedTime or createdTime. Prefix the field name with a hyphen (-) to sort in descending order. Omit the hyphen to sort in ascending order.

Allowable Values:

lastModifiedTime, createdTime, or any field in the resource model

Response body
Fields Description

count

integer
Conditionally returned

The number of resources retrieved.

Allowable Values:

1-100

data

array of objects
Conditionally returned

An array of objects in a returned resource.

Allowable Values:

A valid data array

data[].active

boolean
Conditionally returned

Indicates whether the authorization control is active.

Allowable Values:

true, false

data[].association

object
Conditionally returned

Defines the group of users to which the authorization control applies.

Allowable Values:

A valid association object

data[].association.card_product_token

string
Conditionally returned

Token identifying a card product.

Allowable Values:

1–36 chars

data[].association.user_token

string
Conditionally returned

Token identifying a user.

Allowable Values:

1–36 chars

data[].end_time

datetime
Conditionally returned

The date and time when the exception ends.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

data[].merchant_scope

object
Conditionally returned

Defines the group of merchants to which the authorization control applies.

Allowable Values:

A valid merchant_scope object.

data[].merchant_scope.mcc

string
Conditionally returned

A single MCC (Merchant Category Code). Identifies the type of goods or services provided by the merchant.

Allowable Values:

1–4 chars

data[].merchant_scope.mcc_group

string
Conditionally returned

Token identifying a group of MCCs.

Allowable Values:

1–36 chars

data[].merchant_scope.merchant_group_token

string
Conditionally returned

The unique identifier of a merchant group.

Allowable Values:

1–36 chars

data[].merchant_scope.mid

string
Conditionally returned

MID (Merchant ID). The unique identification number of a merchant.

Allowable Values:

1–36 chars

data[].name

string
Returned

The name of the authorization control.

Allowable Values:

255 char max

data[].start_time

datetime
Conditionally returned

The date and time when the exception goes into effect.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

data[].token

string
Conditionally returned

The unique identifier of the authorization control.

Allowable Values:

1–36 chars

end_index

integer
Conditionally returned

The sort order index of the last resource in the returned array.

Allowable Values:

Any integer

is_more

boolean
Conditionally returned

A value of true indicates that more unreturned resources exist.

Allowable Values:

true, false

start_index

integer
Conditionally returned

The sort order index of the first resource in the returned array.

Allowable Values:

Any integer

Sample response body
Copied

Is this helpful?

Yes
No

Retrieve authorization control

Action: GET
Endpoint: /authcontrols/{token}

Retrieve a specific authorization control.

URL path parameters
Fields Description

token

string
Required

Existing authorization control token.

Send a GET request to /authcontrols to retrieve authorization control tokens.

Allowable Values:

1-36 chars

URL query parameters
Fields Description

fields

string
Optional

Comma-delimited list of fields to return (field_1,field_2, and so on). Leave blank to return all fields.

Allowable Values:

A comma-delimited list of fields, or blank

Response body
Fields Description

active

boolean
Conditionally returned

Indicates whether the authorization control is active.

Allowable Values:

true, false

association

object
Conditionally returned

Defines the group of users to which the authorization control applies.

Allowable Values:

A valid association object

association.card_product_token

string
Conditionally returned

Token identifying a card product.

Allowable Values:

1–36 chars

association.user_token

string
Conditionally returned

Token identifying a user.

Allowable Values:

1–36 chars

end_time

datetime
Conditionally returned

The date and time when the exception ends.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

merchant_scope

object
Conditionally returned

Defines the group of merchants to which the authorization control applies.

Allowable Values:

A valid merchant_scope object

merchant_scope.mcc

string
Conditionally returned

A single MCC (Merchant Category Code). Identifies the type of goods or services provided by the merchant.

Allowable Values:

1–4 chars

merchant_scope.mcc_group

string
Conditionally returned

Token identifying a group of MCCs.

Allowable Values:

1–36 chars

merchant_scope.merchant_group_token

string
Conditionally returned

The unique identifier of a merchant group.

Allowable Values:

1–36 chars

merchant_scope.mid

string
Conditionally returned

MID (Merchant ID). The unique identification number of a merchant.

Allowable Values:

1–36 chars

name

string
Returned

The name of the authorization control.

Allowable Values:

255 char max

start_time

datetime
Conditionally returned

The date and time when the exception goes into effect.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

token

string
Conditionally returned

The unique identifier of the authorization control.

Allowable Values:

1–36 chars

Sample response body
Copied

Is this helpful?

Yes
No

Update authorization control

Action: PUT
Endpoint: /authcontrols/{token}

Update a specific authorization control.

URL path parameters
Fields Description

token

string
Required

Existing authorization control token.

Send a GET request to /authcontrols to retrieve authorization control tokens.

Allowable Values:

1-36 chars

Request body
Fields Description

active

boolean
Optional

Indicates whether the authorization control is active.

Allowable Values:

true, false

Default value:
true

association

object
Optional

Defines the group of users to which the authorization control applies. This object is required if the merchant_scope object is not included in your request. Your request can include both the association and merchant_scope objects.

If you include this object in your request, you must populate one or more of its fields. If no fields are populated, the authorization control applies to all users.

Allowable Values:

A valid association object

association.card_product_token

string
Optional

Token identifying a card product.

Specify a card product token in the card_product_token field to apply the authorization control to all users holding active cards associated with the card product.

Pass either card_product_token or user_token, not both.

Allowable Values:

1–36 chars

association.user_token

string
Optional

Token identifying a user.

Specify a user token in the user_token field to apply the authorization control to a single user.

Pass either card_product_token or user_token, not both.

Allowable Values:

1–36 chars

end_time

datetime
Optional

The date and time when the exception ends.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

merchant_scope

object
Optional

Defines the group of merchants to which the authorization control applies. This object is required if the association object is not included in your request. Your request can include both the merchant_scope and association objects.

If you include this object in your request, you must populate one or more of its fields. If no fields are populated, the authorization control applies to all merchants.

Allowable Values:

A valid merchant_scope object

merchant_scope.mcc

string
Optional

A single MCC (Merchant Category Code). Identifies the type of goods or services provided by the merchant.

Enter a value to control access to a particular type of product or service.

See Controlling Spending for links to more information about merchant category codes.

Allowable Values:

1–4 chars

merchant_scope.mcc_group

string
Optional

Token identifying a group of MCCs.

Enter a value to control access to a group of product or service types.

Allowable Values:

1–36 chars

Send a GET request to /mccgroups to retrieve MCC group tokens.

merchant_scope.merchant_group_token

string
Optional

The unique identifier of a merchant group.

Enter a value to control access to a group of merchants.

Allowable Values:

1–36 chars

merchant_scope.mid

string
Optional

MID (Merchant ID). The unique identification number of a merchant.

Enter a value to control access to a particular merchant.

Allowable Values:

1–36 chars

name

string
Optional

The name of the authorization control.

Allowable Values:

255 char max

start_time

datetime
Optional

The date and time when the exception goes into effect.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

token

string
Required

Existing authorization control token.

Allowable Values:

1–36 chars

Response body
Fields Description

active

boolean
Conditionally returned

Indicates whether the authorization control is active.

Allowable Values:

true, false

association

object
Conditionally returned

Defines the group of users to which the authorization control applies.

Allowable Values:

A valid association object

association.card_product_token

string
Conditionally returned

Token identifying a card product.

Allowable Values:

1–36 chars

association.user_token

string
Conditionally returned

Token identifying a user.

Allowable Values:

1–36 chars

end_time

datetime
Conditionally returned

The date and time when the exception ends.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

merchant_scope

object
Conditionally returned

Defines the group of merchants to which the authorization control applies.

Allowable Values:

A valid merchant_scope object

merchant_scope.mcc

string
Conditionally returned

A single MCC (Merchant Category Code). Identifies the type of goods or services provided by the merchant.

Allowable Values:

1–4 chars

merchant_scope.mcc_group

string
Conditionally returned

Token identifying a group of MCCs.

Allowable Values:

1–36 chars

merchant_scope.merchant_group_token

string
Conditionally returned

The unique identifier of a merchant group.

Enter a value to control access to a group of merchants.

Allowable Values:

1–36 chars

merchant_scope.mid

string
Conditionally returned

MID (Merchant ID). The unique identification number of a merchant.

Allowable Values:

1–36 chars

name

string
Returned

The name of the authorization control.

Allowable Values:

255 char max

start_time

datetime
Conditionally returned

The date and time when the exception goes into effect.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

token

string
Conditionally returned

The unique identifier of the authorization control.

Allowable Values:

1–36 chars

Sample request body
Copied

Is this helpful?

Yes
No
Sample response body
Copied

Is this helpful?

Yes
No

Create a merchant identifier (MID) exemption

Action: POST
Endpoint: /authcontrols/exemptmids

Exempt an individual merchant from authorization controls by merchant identifier (MID). Transactions originating from this MID ignore any otherwise applicable authorization controls.

Note
You can create MID exemptions in your user sandbox. However, you must work with your Marqeta representative to create MID exemptions in a production environment.
Request body
Fields Description

association

object
Optional

Defines the group of users to which the authorization control applies. This object is required if the merchant_scope object is not included in your request. Your request can include both the association and merchant_scope objects.

If you include this object in your request, you must populate one or more of its fields. If no fields are populated, the authorization control applies to all users.

Allowable Values:

A valid association object

association.card_product_token

string
Optional

Token identifying a card product.

Specify a card product token in the card_product_token field to apply the authorization control to all users holding active cards associated with the card product.

Pass either card_product_token or user_token, not both.

Allowable Values:

1–36 chars

association.user_token

string
Optional

Token identifying a user.

Specify a user token in the user_token field to apply the authorization control to a single user.

Pass either card_product_token or user_token, not both.

Allowable Values:

1–36 chars

end_time

datetime
Optional

The date and time when the exception ends, in UTC. 2021-10-26T20:03:05Z, for example.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

merchant_group_token

string
Optional

The token of the merchant group to be exempted. This field is required if there is no entry in the mid field. Pass either this field or the mid field, not both.

Allowable Values:

1–36 chars

mid

string
Optional

The merchant to be exempted. This field is required if there is no entry in the merchant_group_token field. Use either this field or the merchant_group_token field, not both.

Allowable Values:

1–36 chars

name

string
Required

The name of the merchant identifier authorization control exemption.

Allowable Values:

255 char max

start_time

datetime
Optional

The date and time when the exception starts, in UTC. 2020-10-26T20:03:05Z, for example.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

token

string
Optional

The unique identifier of the merchant identifier authorization control exemption.

If you do not include a token, the system will generate one automatically. This token is necessary for use in other API calls, so we recommend that rather than let the system generate one, you use a simple string that is easy to remember. This value cannot be updated.

Allowable Values:

1-36 chars

Response body
Fields Description

active

boolean
Conditionally returned

Indicates whether the merchant identifier authorization control exception is active.

Allowable Values:

true, false

association

object
Conditionally returned

Defines the group of users to which the authorization control applies.

Allowable Values:

A valid association object

association.card_product_token

string
Conditionally returned

Token identifying a card product.

Allowable Values:

1–36 chars

association.user_token

string
Conditionally returned

Token identifying a user.

Allowable Values:

1–36 chars

created

datetime
Conditionally returned

The date and time when the resource was created, in UTC. 2020-10-26T20:03:05Z, for example.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

end_time

datetime
Conditionally returned

The date and time when the exception ends, in UTC. 2021-10-26T20:03:05Z, for example.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

last_updated

datetime
Conditionally returned

The date and time when the resource was last updated, in UTC. 2020-10-26T20:03:15Z, for example.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

merchant_group_token

string
Conditionally returned

The token of the merchant group to be exempted.

Allowable Values:

1–36 chars

mid

string
Conditionally returned

The merchant to be exempted.

Allowable Values:

1–36 chars

name

string
Returned

The name of the merchant identifier authorization control exemption.

Allowable Values:

255 char max

start_time

datetime
Conditionally returned

The date and time when the exception starts, in UTC. 2020-10-26T20:03:05Z, for example.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

token

string
Conditionally returned

The unique identifier of the merchant identifier authorization control exemption.

Allowable Values:

1-36 chars

Sample request body
Copied

Is this helpful?

Yes
No
Sample response body
Copied

Is this helpful?

Yes
No

List merchant identifier (MID) exemptions

Action: GET
Endpoint: /authcontrols/exemptmids

Retrieve a list of all merchant (MID) exemptions.

URL query parameters
Fields Description

card_product

string
Optional

The token identifying the card product whose associated MID exemptions you want to retrieve.

Enter the string "null" to list MID exemptions that are not associated with a card product.

Allowable Values:

1-36 chars

user

string
Optional

The token identifying the user whose associated MID exemptions you want to retrieve.

Enter the string "null" to list MID exemptions that are not associated with a user.

Allowable Values:

1-36 chars

count

integer
Optional

The number of resources to retrieve.

Allowable Values:

1-100

start_index

integer
Optional

The sort order index of the first resource in the returned array.

Allowable Values:

Any integer

fields

string
Optional

Comma-delimited list of fields to return (field_1,field_2, and so on). Leave blank to return all fields.

Allowable Values:

A comma-delimited list of fields, or blank

sort_by

string
Optional

Field on which to sort. Use any field in the resource model, or one of the system fields lastModifiedTime or createdTime. Prefix the field name with a hyphen (-) to sort in descending order. Omit the hyphen to sort in ascending order.

Allowable Values:

lastModifiedTime, createdTime, or any field in the resource model.

Response body
Fields Description

count

integer
Conditionally returned

The number of resources retrieved.

Allowable Values:

1-100

data

array of objects
Conditionally returned

An array of objects in a returned resource.

Allowable Values:

A valid data array

data[].active

boolean
Conditionally returned

Indicates whether the merchant identifier authorization control exception is active.

Allowable Values:

true, false

data[].association

object
Conditionally returned

Defines the group of users to which the authorization control applies.

Allowable Values:

A valid association object

data[].association.card_product_token

string
Conditionally returned

Token identifying a card product.

Allowable Values:

1–36 chars

data[].association.user_token

string
Conditionally returned

Token identifying a user.

Allowable Values:

1–36 chars

data[].created

datetime
Conditionally returned

The date and time when the resource was created, in UTC. 2020-10-26T20:03:05Z, for example.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

data[].end_time

datetime
Conditionally returned

The date and time when the exception ends, in UTC. 2021-10-26T20:03:05Z, for example.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

data[].last_updated

datetime
Conditionally returned

The date and time when the resource was last updated, in UTC. 2020-10-26T20:03:15Z, for example.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

data[].merchant_group_token

string
Conditionally returned

The token of the merchant group to be exempted.

Allowable Values:

1–36 chars

data[].mid

string
Conditionally returned

The merchant to be exempted.

Allowable Values:

1–36 chars

data[].name

string
Returned

The name of the merchant identifier authorization control exemption.

Allowable Values:

255 char max

data[].start_time

datetime
Conditionally returned

The date and time when the exception starts, in UTC. 2020-10-26T20:03:05Z, for example.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

data[].token

string
Conditionally returned

The unique identifier of the merchant identifier authorization control exemption.

Allowable Values:

1-36 chars

end_index

integer
Conditionally returned

The sort order index of the last resource in the returned array.

Allowable Values:

Any integer

is_more

boolean
Conditionally returned

A value of true indicates that more unreturned resources exist.

Allowable Values:

true, false

start_index

integer
Conditionally returned

The sort order index of the first resource in the returned array.

Allowable Values:

Any integer

Sample response body
Copied

Is this helpful?

Yes
No

Retrieve a merchant identifier (MID) exemption

Action: GET
Endpoint: /authcontrols/exemptmids/{token}

Retrieve a merchant (MID) exemption.

URL path parameters
Fields Description

token

string
Required

The unique identifier of the authorization control.

Allowable Values:

1-36 chars

Response body
Fields Description

active

boolean
Conditionally returned

Indicates whether the merchant identifier authorization control exception is active.

Allowable Values:

true, false

association

object
Conditionally returned

Defines the group of users to which the authorization control applies.

Allowable Values:

A valid association object

association.card_product_token

string
Conditionally returned

Token identifying a card product.

Allowable Values:

1–36 chars

association.user_token

string
Conditionally returned

Token identifying a user.

Allowable Values:

1–36 chars

created

datetime
Conditionally returned

The date and time when the resource was created, in UTC. 2020-10-26T20:03:05Z, for example.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

end_time

datetime
Conditionally returned

The date and time when the exception ends, in UTC. 2021-10-26T20:03:05Z, for example.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

last_updated

datetime
Conditionally returned

The date and time when the resource was last updated, in UTC. 2020-10-26T20:03:15Z, for example.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

merchant_group_token

string
Conditionally returned

The token of the merchant group to be exempted.

Allowable Values:

1–36 chars

mid

string
Conditionally returned

The merchant to be exempted.

Allowable Values:

1–36 chars

name

string
Returned

The name of the merchant identifier authorization control exemption.

Allowable Values:

255 char max

start_time

datetime
Conditionally returned

The date and time when the exception starts, in UTC. 2020-10-26T20:03:05Z, for example.

Allowable Values:

yyyy-MM-ddThh:mm:ssZ

token

string
Conditionally returned

The unique identifier of the merchant identifier authorization control exemption.

Allowable Values:

1-36 chars

Sample response body
Copied

Is this helpful?

Yes
No

Update a merchant identifier (MID) exemption

Action: PUT
Endpoint: /authcontrols/exemptmids/{token}

Update a merchant identifier exemption.

URL path parameters
Fields Description

token

string
Required

The unique identifier of the authorization control.

Allowable Values:

1-36 chars

Request body
Fields Description

active

boolean
Optional

Indicates whether the merchant identifier authorization control exception is active. If the control will be used for Commando Mode, set to false and then enable it using commando_mode_enables. See Update Commando Mode control set.

Allowable Values:

true, false

Default value:
false

Sample request body
Copied

Is this helpful?

Yes
No
Sample response body
Copied

Is this helpful?

Yes
No

Feedback on this page?

If you feel we can do anything better, please let our team know.