Creates an authorisation rule. It won't be enabled unless it is applied.
An ALLOW rule permits only the transactions that match the specified criteria and blocks all others. For instance, a rule allowing SGD transactions will block all transactions that are not in SGD.
Security
ClientCredentialsToken
Optional UUID for correlating requests across systems. If provided, Wise echoes it back in the response. Maximum 36 characters. Learn more.
Example:f47ac10b-58cc-4372-a567-0e02b2c3d479
- Production Environmenthttps://api.wise.com/2026Q4/spend/applications/{clientId}/spend-controls/rules
- Sandbox Environmenthttps://api.wise-sandbox.com/2026Q4/spend/applications/{clientId}/spend-controls/rules
curl -i -X POST \
'https://api.wise.com/2026Q4/spend/applications/{clientId}/spend-controls/rules' \
-H 'Authorization: Bearer <YOUR_JWT_HERE>' \
-H 'Content-Type: application/json' \
-H 'X-External-Correlation-Id: f47ac10b-58cc-4372-a567-0e02b2c3d479' \
-d '{
"description": "Blocking all transactions from MCC 1234 and 5678",
"type": "MCC",
"operation": "BLOCK",
"values": [
"1234",
"5678"
]
}'The created rule.
Headers
Echoed back when X-External-Correlation-Id was included in the request. Learn more.
Example:"f47ac10b-58cc-4372-a567-0e02b2c3d479"
Determines whether the transactions should be allowed or blocked.
Enum:"ALLOW""BLOCK"
Example:"BLOCK"
Response
{ "id": 123, "description": "my authorisation rule", "type": "MCC", "operation": "BLOCK", "values": [ "1234", "5678" ] }