Merchant Rules

Control merchant IDs, categories, and names.

Use merchant to constrain where a card can be used. Penny checks configured merchant ID, merchant category code (MCC), and merchant name conditions. A failed check declines the authorization.

Merchant rule config
{
"rule_type": "merchant",
"applicable_transaction_authorizations": ["debit"],
"applicable_card_issuance_modes": ["managed"],
"configuration": {
"merchant_category_codes_rules": {
"denylist": ["7995"]
},
"merchant_name_rules": [
{
"match_type": "contains",
"condition_values": ["test merchant"],
"match_result": false
}
]
}
}

merchant_id_rules and merchant_category_codes_rules accept an allowlist or denylist array. MCC entries may be individual codes or ranges such as 7999-8999. An allowlist permits only matching values; a denylist blocks matching values and permits all others. A value can’t appear in both lists. If you set both on merchant_category_codes_rules, only the allowlist is checked; if you set both on merchant_id_rules, the denylist governs. See Allowlists and denylists.

Each merchant_name_rules entry has match_type (equals, contains, starts_with, ends_with, or regex), condition_values, and match_result. A match produces match_result; a non-match produces the opposite. Every configured name condition must pass. Call GET /spend_controls/rule_types for the current configuration schema before constructing a request.