Skip to content

Apply an authorisation rule

Request

Apply an authorisation rule. This will result in the rule being evaluated against every incoming card authorisation request.

Security
ClientCredentialsToken
Path
clientIdstringrequired

The application client ID.

Headers
X-External-Correlation-Idstring, (uuid), <= 36 characters

Optional UUID for correlating requests across systems. If provided, Wise echoes it back in the response. Maximum 36 characters. Learn more.

Example:f47ac10b-58cc-4372-a567-0e02b2c3d479
Bodyapplication/jsonrequired
ruleIdstring

The ID of the authorisation rule.

curl -i -X POST \
  'https://api.wise.com/2026Q4/spend/applications/{clientId}/spend-controls/rules/apply' \
  -H 'Authorization: Bearer <YOUR_JWT_HERE>' \
  -H 'Content-Type: application/json' \
  -H 'X-External-Correlation-Id: f47ac10b-58cc-4372-a567-0e02b2c3d479' \
  -d '{
    "ruleId": "123"
  }'

Responses

Rule applied successfully.

Headers
X-External-Correlation-Idstring, (uuid), <= 36 characters

Echoed back when X-External-Correlation-Id was included in the request. Learn more.

Example:"f47ac10b-58cc-4372-a567-0e02b2c3d479"
x-trace-idstring

Unique trace identifier assigned by Wise. Useful when contacting support about a specific request.

Example:"fba501b6d453b96789f52338f019341f"
Response
No content