Skip to content

List all authorisation rules

Request

Retrieves all the existing authorisation rules, regardless of whether or not they are applied.

Security
ClientCredentialsToken
Path
clientIdstringrequired

The application client ID.

Headers
X-External-Correlation-Idstring, (uuid), <= 36 characters

Optional UUID for correlating requests across systems. If provided, Wise echoes it back in the response. Maximum 36 characters. Learn more.

Example:f47ac10b-58cc-4372-a567-0e02b2c3d479
curl -i -X GET \
  'https://api.wise.com/2026Q4/spend/applications/{clientId}/spend-controls/rules' \
  -H 'Authorization: Bearer <YOUR_JWT_HERE>' \
  -H 'X-External-Correlation-Id: f47ac10b-58cc-4372-a567-0e02b2c3d479'

Responses

A list of authorisation rules.

Headers
X-External-Correlation-Idstring, (uuid), <= 36 characters

Echoed back when X-External-Correlation-Id was included in the request. Learn more.

Example:"f47ac10b-58cc-4372-a567-0e02b2c3d479"
x-trace-idstring

Unique trace identifier assigned by Wise. Useful when contacting support about a specific request.

Example:"fba501b6d453b96789f52338f019341f"
Bodyapplication/json
Array [
idinteger, (int64)

The unique ID for the authorisation rule.

Example:123
typestring

The type of authorisation rule.

Enum:"MCC""CURRENCY"
Example:"MCC"
operationstring

Determines whether the transactions should be allowed or blocked.

Enum:"ALLOW""BLOCK"
Example:"BLOCK"
descriptionstring

The description of the authorisation rule.

Example:"my authorisation rule"
valuesArray of strings

A list of values based on the type of rule configured.

Example:
[ "1234", "5678" ]
]
Response
[ { "id": 1, "description": "Blacklist gambling MCCs", "type": "MCC", "operation": "BLOCK", "values": [ "7801", "7802", "7995", "9754" ] } ]