Create an ACH debit mandate

Creates a reusable Payer or PayerEngagement authorization. Phase one supports Business checking accounts and server-derived CCD only. An unlinked Payer uses a signed Vault PDF and enters PendingReview; a linked Payer accepts interactively from its own Account context.

Requires a session with recent MFA step-up for HighRiskWriteAction. If step-up is missing or expired, this operation returns 403 StepUpMfaRequired; create and verify an MFA challenge at /v3/platform/mfa-challenges with requiredFor: "HighRiskWriteAction", then retry.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params
subject
object
required

Subject accepted on standalone authorization create. InvoicePayment subjects are created only through the pay request.

string
required
string
enum
required
Allowed:
string
enum
required
Allowed:
string
string
length between 1 and 200

Legal signer name for signed-document evidence; derived from session for interactive acceptance.

string
length between 1 and 100
amountRule
object
required
date-time
date-time
metadata
object

Free-form key-value pairs. Max 50 keys; key length at most 40 characters; value length at most 500 characters. Where a list endpoint declares metadata filtering, it uses the QueryQL namespace via filter[metadata.{key}][eq]=value or filter[metadata.{key}][in][]=value. Endpoints that do not declare the dynamic Metadata filter do not support Metadata filtering.

Headers
string
required
length between 1 and 255
^[\x21-\x7e]{1,255}$

REQUIRED idempotency token for money-moving requests (e.g. transfers). The token is used by the API so a retry after a 5xx/timeout replays the original result instead of moving funds twice. Reuse the same key to retry safely; use a NEW key to issue a genuinely new transfer. Use 1-255 printable ASCII characters.

string
^(?:[A-Za-z0-9_.]{22}|[a-f0-9]{24})$

Select the Account for an Account-scoped operation. A direct ServiceAccount API key MUST supply this header, and the target must be within the ServiceAccount owner's or Authorization grant's Account boundary. A Person bearer may select an Account on which it has an active Stakeholder, and an Account session may select its bound Account (or a descendant only when the session explicitly includes descendants).

string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json