Skip to content

Add a new authorisation rule

Request

Creates an authorisation rule. It won't be enabled unless it is applied.

An ALLOW rule permits only the transactions that match the specified criteria and blocks all others. For instance, a rule allowing SGD transactions will block all transactions that are not in SGD.

Security
ClientCredentialsToken
Path
clientIdstringrequired

The application client ID.

Headers
X-External-Correlation-Idstring, (uuid), <= 36 characters

Optional UUID for correlating requests across systems. If provided, Wise echoes it back in the response. Maximum 36 characters. Learn more.

Example:f47ac10b-58cc-4372-a567-0e02b2c3d479
Bodyapplication/jsonrequired
typestring

The type of authorisation rule.

Enum:"MCC""CURRENCY"
operationstring

Determines whether the transactions should be allowed or blocked.

Enum:"ALLOW""BLOCK"
descriptionstring

The description of the authorisation rule.

valuesArray of strings

A list of values based on the type of rule. For example, setting MCC as type requires values to be set as ["1234", "5678"].

curl -i -X POST \
  'https://api.wise.com/2026Q4/spend/applications/{clientId}/spend-controls/rules' \
  -H 'Authorization: Bearer <YOUR_JWT_HERE>' \
  -H 'Content-Type: application/json' \
  -H 'X-External-Correlation-Id: f47ac10b-58cc-4372-a567-0e02b2c3d479' \
  -d '{
    "description": "Blocking all transactions from MCC 1234 and 5678",
    "type": "MCC",
    "operation": "BLOCK",
    "values": [
      "1234",
      "5678"
    ]
  }'

Responses

The created rule.

Headers
X-External-Correlation-Idstring, (uuid), <= 36 characters

Echoed back when X-External-Correlation-Id was included in the request. Learn more.

Example:"f47ac10b-58cc-4372-a567-0e02b2c3d479"
x-trace-idstring

Unique trace identifier assigned by Wise. Useful when contacting support about a specific request.

Example:"fba501b6d453b96789f52338f019341f"
Bodyapplication/json
idinteger, (int64)

The unique ID for the authorisation rule.

Example:123
typestring

The type of authorisation rule.

Enum:"MCC""CURRENCY"
Example:"MCC"
operationstring

Determines whether the transactions should be allowed or blocked.

Enum:"ALLOW""BLOCK"
Example:"BLOCK"
descriptionstring

The description of the authorisation rule.

Example:"my authorisation rule"
valuesArray of strings

A list of values based on the type of rule configured.

Example:
[ "1234", "5678" ]
Response
{ "id": 123, "description": "my authorisation rule", "type": "MCC", "operation": "BLOCK", "values": [ "1234", "5678" ] }