curl --request PATCH \
--url https://api.next.orenda.finance/v1/customers/{customerId}/cards/{cardId}/policy \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"version": 3,
"areas": {
"mcc": {
"card": {
"allow": [],
"block": [
"7995"
]
}
}
}
}
'{
"success": true,
"data": {
"cardId": "6f1c…",
"version": 4,
"areas": {
"mcc": {
"enabled": true,
"mode": "ALLOW_ALL_EXCEPT_BLOCKED",
"editable": true,
"card": {
"allow": [],
"block": [
"7995"
]
},
"effective": {
"mode": "ALLOW_ALL_EXCEPT_BLOCKED",
"blocked": [
"5813",
"5921",
"7273",
"7297",
"7995"
]
}
},
"limits": {
"enabled": true,
"mode": "PER_CHANNEL",
"editable": true,
"card": null,
"effective": {
"atm": {
"single": 20000,
"daily": 50000,
"weekly": 0,
"monthly": 0,
"annual": 0,
"count": {
"daily": 0,
"weekly": 0,
"monthly": 0,
"annual": 0
}
},
"pos": {
"single": 100000,
"daily": 250000,
"weekly": 0,
"monthly": 0,
"annual": 0,
"count": {
"daily": 0,
"weekly": 0,
"monthly": 0,
"annual": 0
}
}
}
},
"country": {
"enabled": true,
"mode": "ALLOW_ALL_EXCEPT_BLOCKED",
"editable": true,
"card": null,
"effective": {
"mode": "ALLOW_ALL_EXCEPT_BLOCKED",
"countries": [
"AF",
"BY",
"CU",
"IR",
"KP",
"RU",
"SY"
],
"regions": []
}
}
}
}
}Update this card's policy
Lets a cardholder tighten their own card: block merchant categories or countries, switch off transaction types, or set spending limits below the program’s. Only on accounts whose cards.limits.mode is custom in capabilities; on a preset account use Update card limit group.
How to make a change
- Read the policy first with Get this card’s policy. Keep
data.version; you must send it back. For each area you want to change, note itsmodeandeffective. - Build the body with only the areas you’re changing. Each one is
{ "card": … }, the cardholder’s own layer."card": nullremoves the cardholder’s setting so the card goes back to the program’s defaults. - Send it. The response is the whole policy in the same shape as the GET, with a new
versionandeffectiverecomputed. Render from it; no second GET needed. - Handle two errors.
400 CARD_POLICY_VALIDATION_FAILEDmeans the change would loosen the card; the message names the field, for examplelimits.card.atm.daily: 300000 exceeds program's 250000.409 CARD_POLICY_VERSION_CONFLICTmeans someone changed the policy since step 1: GET again and re-apply on the freshversion.
The four areas and what card looks like in each
mcc: merchant categories, four-digit codes ("7995"gambling,"5813"bars).card: { "allow": [], "block": ["7995"] }country: where the card works.card: { "countries": { "allow": [], "block": ["RU"] }, "regions": { "allow": [], "block": [] } }, with ISO country codes and regionsUKandEU.inputOptions: transaction types by two-digit code ("00"purchase,"01"ATM cash withdrawal,"10"account funding).card: { "allow": [], "block": ["01"] }switches off ATM use.limits: spending caps in minor units (pence or cents), per channel.card: { "atm": {…}, "pos": {…} }, each withsingle,daily,weekly,monthly,annual, and acountobject withdaily,weekly,monthly,annual. Send all of them every time.0means “no limit of my own at this window”, so the program’s value applies.singleis per transaction,daily,weeklyandmonthlyare rolling totals,annualis accepted but not enforced, andcountcaps the number of transactions per window. Iflimits.modeisCOMBINED, ATM and POS share one budget and the tighter value applies to both.
Options a cardholder may choose from returns the codes and labels for mcc, country and inputOptions.
Three rules the API enforces
- Which list to fill depends on
mode.ALLOW_ALL_EXCEPT_BLOCKED(the usual case): put codes inblock, leaveallowempty.ALLOW_ONLY_SPECIFIED: put codes inallow, leaveblockempty. Filling the wrong one is a400. Both keys must always be present. - A list replaces, it doesn’t add. Send the complete list you want every time; the previous one is discarded. To add a second blocked code, send both; to remove one, send the list without it.
- You can only tighten. Compare against
effective: block more, allow fewer, or set a lower amount, never the reverse. Anything the program has blocked stays blocked whatever you send.
An area with editable: false is switched off for the program; a write there is accepted but changes nothing, so hide the control. Changes reach card authorizations within about a minute.
curl --request PATCH \
--url https://api.next.orenda.finance/v1/customers/{customerId}/cards/{cardId}/policy \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"version": 3,
"areas": {
"mcc": {
"card": {
"allow": [],
"block": [
"7995"
]
}
}
}
}
'{
"success": true,
"data": {
"cardId": "6f1c…",
"version": 4,
"areas": {
"mcc": {
"enabled": true,
"mode": "ALLOW_ALL_EXCEPT_BLOCKED",
"editable": true,
"card": {
"allow": [],
"block": [
"7995"
]
},
"effective": {
"mode": "ALLOW_ALL_EXCEPT_BLOCKED",
"blocked": [
"5813",
"5921",
"7273",
"7297",
"7995"
]
}
},
"limits": {
"enabled": true,
"mode": "PER_CHANNEL",
"editable": true,
"card": null,
"effective": {
"atm": {
"single": 20000,
"daily": 50000,
"weekly": 0,
"monthly": 0,
"annual": 0,
"count": {
"daily": 0,
"weekly": 0,
"monthly": 0,
"annual": 0
}
},
"pos": {
"single": 100000,
"daily": 250000,
"weekly": 0,
"monthly": 0,
"annual": 0,
"count": {
"daily": 0,
"weekly": 0,
"monthly": 0,
"annual": 0
}
}
}
},
"country": {
"enabled": true,
"mode": "ALLOW_ALL_EXCEPT_BLOCKED",
"editable": true,
"card": null,
"effective": {
"mode": "ALLOW_ALL_EXCEPT_BLOCKED",
"countries": [
"AF",
"BY",
"CU",
"IR",
"KP",
"RU",
"SY"
],
"regions": []
}
}
}
}
}Authorizations
The user's access_token from authentication. The program and environment come from the token.
Path Parameters
The customer's id.
The card id from create / get cards.
Body
Response
The updated policy, in exactly the shape Get this card's policy returns: recomposed against the live template, so the app can re-render from this response without a second call.