Only on accounts whose
cards.limits.mode is custom in
program capabilities. On a preset account, use
Update card limit group instead.Example: block gambling and cap ATM withdrawals
1. Read the policy
versionis 3. It goes in the request body.mcc.modeisALLOW_ALL_EXCEPT_BLOCKED, so to block gambling you add its code toblockand leaveallowempty.limits.ceiling.atmsays the program allows £200 per withdrawal and £500 a day. You can go lower, not higher. Bound the form byceiling, noteffective: once the card has limits of its own,effectiveshows those, whileceilingstill shows how far they may be raised.0inceilingmeans no ceiling. Amounts are in minor units (pence, cents).- If
inertPathslists alimits.cardfield, that value is saved but not in force: show it as inactive. Annual limits are always listed, because they are never enforced. If an update returns 400 naming a limit field, that value is above a limit on its own channel and has to be lowered before the save goes through.
2. Send the change
pos is all zeros, which means “no setting of
my own”, so the program’s POS limits keep applying. country and inputOptions are left
out and stay as they were.
3. Use the response
The response is the full policy again withversion 4, mcc.card and limits.card filled
in, and effective recomputed: blocked now includes 7995 and atm.daily is 20000.
Render from it directly. No need to call the GET again.
The four areas
Options a cardholder may choose from
returns the full code lists with labels.
Rules
Which list do I fill, allow or block?
Which list do I fill, allow or block?
Look at the area’s
mode in the GET.ALLOW_ALL_EXCEPT_BLOCKED: everything is permitted unless listed. Put codes inblock, keepallowempty. This is the usual case.ALLOW_ONLY_SPECIFIED: nothing is permitted unless listed. Put codes inallow, keepblockempty.
400. Both keys must always be present.Lists replace, they don't add
Lists replace, they don't add
Whatever you send for
card becomes the cardholder’s complete setting. To add a second
blocked merchant category, send both codes. To remove one, send the list without it.
"card": null removes the cardholder’s setting entirely.You can only tighten
You can only tighten
Compare against
effective. You can block more categories or countries, allow fewer,
or set a lower amount. Never the reverse. Anything the program has blocked stays blocked
whatever you send; it shows in effective but not in card, and the app can’t remove it.Trying to loosen is a 400 CARD_POLICY_VALIDATION_FAILED whose message names the field,
for example limits.card.atm.daily: 300000 exceeds program's 250000.Limits: what 0 means, and why every field is required
Limits: what 0 means, and why every field is required
0 means “no limit of my own at this window”, so the program’s value applies. The whole
card object is replaced on each write, so atm and pos and all their fields (five
amounts plus four counts) are required every time, zeros included.single is per transaction. daily, weekly, and monthly are rolling totals.
annual is accepted but not enforced. count caps the number of transactions per
window.If limits.mode is COMBINED, ATM and POS share one daily, weekly, and monthly budget,
and the tighter of the two values applies to both.version and the 409
version and the 409
version is the number the GET returned. If someone else changed the policy in between,
the write is refused with 409 CARD_POLICY_VERSION_CONFLICT. GET again and re-apply the
change on the fresh version. This stops two screens silently overwriting each other.editable: false
editable: false
The program has switched that area off. A write is accepted but changes nothing. Hide
the control rather than show a disabled one.