Authorize a Vault funding operation
Authorize the exact Vault-to-escrow transfer for a receive Payment.
actionId from the selected option’s execution object and authorizes Stableyard to execute the exact Vault-to-escrow transfer under the active policy. The client bearer token identifies the payer UPA; X-Stableyard-Payment-Secret binds the command to one Payment.
A successful response means authorization was recorded, not that funds arrived or the Payment completed. Stableyard independently verifies the on-chain transfer to the escrow (chain, token, recipient, amount, success, finality and receipt uniqueness), and only verified escrow receipt evidence advances collection. Underpayments, duplicate receipts, late payments and execution failures follow the Payment’s normal reconciliation and recovery states.
Idempotency-Key is required; reusing it with different input returns 409 idempotency_conflict.Authorizations
Short-lived account-bound token returned by POST /v2/client/auth/exchange.
Payment-specific secret used together with an account-bound Client bearer token. It proves access to exactly one Payment and must never be placed in a URL, analytics event, or log.
Headers
Required retry key for this account-bound Payment mutation. Reuse the same key only with the identical Payment, option, and body; different input returns 409 idempotency_conflict.
1 - 256^[ -~]+$"vault-payment-option-01"
Path Parameters
Canonical receive Payment whose escrow will be funded.
^payment_[A-Za-z0-9_-]+$"payment_123"
Vault option returned by the account-bound option endpoint.
^pay_option_[A-Za-z0-9_-]+$"pay_option_vault_123"
Body
Single-use action identifier returned in option.execution.actionId.
1 - 128"fund_auth_123"
Optional partner metadata. Must be JSON-safe, at most 4096 bytes, depth 3, 25 keys per object, 512 characters per string, and 50 items per array.