Skip to main content
Each card has spending limits and authorization controls that are checked on every authorization. Online payments can also require 3-D Secure.

Spending limits

Amounts are in the card currency, in minor units. Set a limit to null to remove it. Daily and monthly totals reset at 00:00 UTC.

Authorization controls

You cannot set both the allowed_ and blocked_ list of the same kind. Both PUT endpoints replace the whole object, so send every rule you want to keep. An authorization declined by these rules has decline_reason set to spending_limit_exceeded or authorization_control. See Transactions.

3D Secure

3-D Secure applies to card-not-present payments. It is enabled by default.
OTP challenges are sent to the customer’s phone, so make sure it is set in E.164 format.