> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pointzero.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Spending and authorization controls

> Set per-card spending limits, allow or block merchant categories, countries and channels, and configure 3-D Secure for online payments.

Each card has spending limits and authorization controls that are checked on every authorization. Online payments can also require 3-D Secure.

## Spending limits

```bash theme={null}
curl -X PUT https://api.pointzero.io/v1/cards/card_01JZ8N2K4M/spending-controls \
  -H "Authorization: Bearer $POINTZERO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "single_transaction_limit": 100000,
    "daily_limit": 500000,
    "monthly_limit": 2500000
  }'
```

Amounts are in the card currency, in minor units. Set a limit to `null` to remove it. Daily and monthly totals reset at 00:00 UTC.

## Authorization controls

```bash theme={null}
curl -X PUT https://api.pointzero.io/v1/cards/card_01JZ8N2K4M/authorization-controls \
  -H "Authorization: Bearer $POINTZERO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "blocked_mccs": ["7995", "6051"],
    "allowed_countries": ["ES", "PT", "FR"],
    "allow_online": true,
    "allow_contactless": true,
    "allow_cash_withdrawal": false
  }'
```

| Field | Description |
| - | - |
| `allowed_mccs` / `blocked_mccs` | Merchant category codes to allow only, or to block. |
| `allowed_countries` / `blocked_countries` | Merchant countries to allow only, or to block. |
| `allow_online` | Card-not-present payments. Default `true`. |
| `allow_contactless` | Contactless and wallet payments in store. Default `true`. |
| `allow_cash_withdrawal` | ATM withdrawals. Default `false`. |

You cannot set both the `allowed_` and `blocked_` list of the same kind. Both `PUT` endpoints replace the whole object, so send every rule you want to keep.

An authorization declined by these rules has `decline_reason` set to `spending_limit_exceeded` or `authorization_control`. See [Transactions](/guides/transactions#decline-reasons).

## 3D Secure

3-D Secure applies to card-not-present payments. It is enabled by default.

```bash theme={null}
curl -X PUT https://api.pointzero.io/v1/cards/card_01JZ8N2K4M/3ds \
  -H "Authorization: Bearer $POINTZERO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "enabled": true,
    "challenge_preference": "no_preference",
    "exemptions": ["low_value"]
  }'
```

| Field | Description |
| - | - |
| `enabled` | Turns 3DS on or off for the card. Default `true`. |
| `challenge_preference` | `no_preference`, `challenge_requested` or `challenge_avoided`. Default `no_preference`. |
| `exemptions` | SCA exemptions the issuer may apply: `low_value`, `trusted_beneficiary`, `transaction_risk_analysis`. |

OTP challenges are sent to the customer's `phone`, so make sure it is set in E.164 format.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.