Merchant Rules
Use merchant to constrain where a card can be used. Penny checks configured merchant ID, merchant category code (MCC), and merchant name conditions. A failed check declines the authorization.
merchant_id_rules and merchant_category_codes_rules accept an allowlist or denylist array. MCC entries may be individual codes or ranges such as 7999-8999. An allowlist permits only matching values; a denylist blocks matching values and permits all others. A value can’t appear in both lists. If you set both on merchant_category_codes_rules, only the allowlist is checked; if you set both on merchant_id_rules, the denylist governs. See Allowlists and denylists.
Each merchant_name_rules entry has match_type (equals, contains, starts_with, ends_with, or regex), condition_values, and match_result. A match produces match_result; a non-match produces the opposite. Every configured name condition must pass. Call GET /spend_controls/rule_types for the current configuration schema before constructing a request.