Retrieves all the existing authorisation rules, regardless of whether or not they are applied.
Security
ClientCredentialsToken
Optional UUID for correlating requests across systems. If provided, Wise echoes it back in the response. Maximum 36 characters. Learn more.
Example:f47ac10b-58cc-4372-a567-0e02b2c3d479
- Production Environmenthttps://api.wise.com/2026Q4/spend/applications/{clientId}/spend-controls/rules
- Sandbox Environmenthttps://api.wise-sandbox.com/2026Q4/spend/applications/{clientId}/spend-controls/rules
curl -i -X GET \
'https://api.wise.com/2026Q4/spend/applications/{clientId}/spend-controls/rules' \
-H 'Authorization: Bearer <YOUR_JWT_HERE>' \
-H 'X-External-Correlation-Id: f47ac10b-58cc-4372-a567-0e02b2c3d479'A list of authorisation rules.
Headers
Echoed back when X-External-Correlation-Id was included in the request. Learn more.
Example:"f47ac10b-58cc-4372-a567-0e02b2c3d479"
Array []
Determines whether the transactions should be allowed or blocked.
Enum:"ALLOW""BLOCK"
Example:"BLOCK"
Response
[ { "id": 1, "description": "Blacklist gambling MCCs", "type": "MCC", "operation": "BLOCK", "values": [ "7801", "7802", "7995", "9754" ] } ]