curl --request POST \
--url https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/json' \
--header 'Idempotency-Key: <idempotency-key>' \
--data '
{
"recipient": {
"chainId": 42161,
"address": "0xdFD4ab80E163D6864E26F37540563cBf2E52A582",
"tokenAddress": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831"
},
"token": {
"chainId": 42161,
"tokenAddress": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
"symbol": "USDC",
"decimals": 6
},
"amountLimit": "1000000",
"period": "daily",
"startsAt": "2026-08-28T10:00:00.000Z",
"expiresAt": "2026-08-28T10:00:00.000Z",
"reason": "Requested by partner"
}
'import requests
url = "https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates"
payload = {
"recipient": {
"chainId": 42161,
"address": "0xdFD4ab80E163D6864E26F37540563cBf2E52A582",
"tokenAddress": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831"
},
"token": {
"chainId": 42161,
"tokenAddress": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
"symbol": "USDC",
"decimals": 6
},
"amountLimit": "1000000",
"period": "daily",
"startsAt": "2026-08-28T10:00:00.000Z",
"expiresAt": "2026-08-28T10:00:00.000Z",
"reason": "Requested by partner"
}
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Basic <encoded-value>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
recipient: {
chainId: 42161,
address: '0xdFD4ab80E163D6864E26F37540563cBf2E52A582',
tokenAddress: '0xaf88d065e77c8cC2239327C5EDb3A432268e5831'
},
token: {
chainId: 42161,
tokenAddress: '0xaf88d065e77c8cC2239327C5EDb3A432268e5831',
symbol: 'USDC',
decimals: 6
},
amountLimit: '1000000',
period: 'daily',
startsAt: '2026-08-28T10:00:00.000Z',
expiresAt: '2026-08-28T10:00:00.000Z',
reason: 'Requested by partner'
})
};
fetch('https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'recipient' => [
'chainId' => 42161,
'address' => '0xdFD4ab80E163D6864E26F37540563cBf2E52A582',
'tokenAddress' => '0xaf88d065e77c8cC2239327C5EDb3A432268e5831'
],
'token' => [
'chainId' => 42161,
'tokenAddress' => '0xaf88d065e77c8cC2239327C5EDb3A432268e5831',
'symbol' => 'USDC',
'decimals' => 6
],
'amountLimit' => '1000000',
'period' => 'daily',
'startsAt' => '2026-08-28T10:00:00.000Z',
'expiresAt' => '2026-08-28T10:00:00.000Z',
'reason' => 'Requested by partner'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Basic <encoded-value>",
"Content-Type: application/json",
"Idempotency-Key: <idempotency-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates"
payload := strings.NewReader("{\n \"recipient\": {\n \"chainId\": 42161,\n \"address\": \"0xdFD4ab80E163D6864E26F37540563cBf2E52A582\",\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\"\n },\n \"token\": {\n \"chainId\": 42161,\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\",\n \"symbol\": \"USDC\",\n \"decimals\": 6\n },\n \"amountLimit\": \"1000000\",\n \"period\": \"daily\",\n \"startsAt\": \"2026-08-28T10:00:00.000Z\",\n \"expiresAt\": \"2026-08-28T10:00:00.000Z\",\n \"reason\": \"Requested by partner\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Idempotency-Key", "<idempotency-key>")
req.Header.Add("Authorization", "Basic <encoded-value>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates")
.header("Idempotency-Key", "<idempotency-key>")
.header("Authorization", "Basic <encoded-value>")
.header("Content-Type", "application/json")
.body("{\n \"recipient\": {\n \"chainId\": 42161,\n \"address\": \"0xdFD4ab80E163D6864E26F37540563cBf2E52A582\",\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\"\n },\n \"token\": {\n \"chainId\": 42161,\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\",\n \"symbol\": \"USDC\",\n \"decimals\": 6\n },\n \"amountLimit\": \"1000000\",\n \"period\": \"daily\",\n \"startsAt\": \"2026-08-28T10:00:00.000Z\",\n \"expiresAt\": \"2026-08-28T10:00:00.000Z\",\n \"reason\": \"Requested by partner\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Idempotency-Key"] = '<idempotency-key>'
request["Authorization"] = 'Basic <encoded-value>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"recipient\": {\n \"chainId\": 42161,\n \"address\": \"0xdFD4ab80E163D6864E26F37540563cBf2E52A582\",\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\"\n },\n \"token\": {\n \"chainId\": 42161,\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\",\n \"symbol\": \"USDC\",\n \"decimals\": 6\n },\n \"amountLimit\": \"1000000\",\n \"period\": \"daily\",\n \"startsAt\": \"2026-08-28T10:00:00.000Z\",\n \"expiresAt\": \"2026-08-28T10:00:00.000Z\",\n \"reason\": \"Requested by partner\"\n}"
response = http.request(request)
puts response.read_body{
"id": "vault_mandate_123",
"mandateId": "vault_mandate_123",
"policyId": "vault_policy_123",
"status": "pending_authorization",
"nextAction": {
"id": "vault_action_123",
"vaultId": "vault_123",
"policyId": "vault_policy_123",
"type": "sign_policy",
"status": "pending",
"nextAction": null,
"resourceVersion": 1,
"createdAt": "2026-08-28T10:00:00.000Z",
"updatedAt": "2026-08-28T10:00:00.000Z"
}
}{
"error": {
"code": "bad_request",
"message": "The request is invalid",
"details": "example"
}
}{
"error": {
"code": "bad_request",
"message": "The request is invalid",
"details": "example"
}
}{
"error": {
"code": "bad_request",
"message": "The request is invalid",
"details": "example"
}
}{
"error": {
"code": "bad_request",
"message": "The request is invalid",
"details": "example"
}
}{
"error": {
"code": "bad_request",
"message": "The request is invalid",
"details": "example"
}
}{
"error": {
"code": "bad_request",
"message": "The request is invalid",
"details": "example"
}
}{
"error": {
"code": "bad_request",
"message": "The request is invalid",
"details": "example"
}
}Create a Vault mandate
Propose a Vault spending mandate as a policy update.
curl --request POST \
--url https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/json' \
--header 'Idempotency-Key: <idempotency-key>' \
--data '
{
"recipient": {
"chainId": 42161,
"address": "0xdFD4ab80E163D6864E26F37540563cBf2E52A582",
"tokenAddress": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831"
},
"token": {
"chainId": 42161,
"tokenAddress": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
"symbol": "USDC",
"decimals": 6
},
"amountLimit": "1000000",
"period": "daily",
"startsAt": "2026-08-28T10:00:00.000Z",
"expiresAt": "2026-08-28T10:00:00.000Z",
"reason": "Requested by partner"
}
'import requests
url = "https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates"
payload = {
"recipient": {
"chainId": 42161,
"address": "0xdFD4ab80E163D6864E26F37540563cBf2E52A582",
"tokenAddress": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831"
},
"token": {
"chainId": 42161,
"tokenAddress": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
"symbol": "USDC",
"decimals": 6
},
"amountLimit": "1000000",
"period": "daily",
"startsAt": "2026-08-28T10:00:00.000Z",
"expiresAt": "2026-08-28T10:00:00.000Z",
"reason": "Requested by partner"
}
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Basic <encoded-value>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
recipient: {
chainId: 42161,
address: '0xdFD4ab80E163D6864E26F37540563cBf2E52A582',
tokenAddress: '0xaf88d065e77c8cC2239327C5EDb3A432268e5831'
},
token: {
chainId: 42161,
tokenAddress: '0xaf88d065e77c8cC2239327C5EDb3A432268e5831',
symbol: 'USDC',
decimals: 6
},
amountLimit: '1000000',
period: 'daily',
startsAt: '2026-08-28T10:00:00.000Z',
expiresAt: '2026-08-28T10:00:00.000Z',
reason: 'Requested by partner'
})
};
fetch('https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'recipient' => [
'chainId' => 42161,
'address' => '0xdFD4ab80E163D6864E26F37540563cBf2E52A582',
'tokenAddress' => '0xaf88d065e77c8cC2239327C5EDb3A432268e5831'
],
'token' => [
'chainId' => 42161,
'tokenAddress' => '0xaf88d065e77c8cC2239327C5EDb3A432268e5831',
'symbol' => 'USDC',
'decimals' => 6
],
'amountLimit' => '1000000',
'period' => 'daily',
'startsAt' => '2026-08-28T10:00:00.000Z',
'expiresAt' => '2026-08-28T10:00:00.000Z',
'reason' => 'Requested by partner'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Basic <encoded-value>",
"Content-Type: application/json",
"Idempotency-Key: <idempotency-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates"
payload := strings.NewReader("{\n \"recipient\": {\n \"chainId\": 42161,\n \"address\": \"0xdFD4ab80E163D6864E26F37540563cBf2E52A582\",\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\"\n },\n \"token\": {\n \"chainId\": 42161,\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\",\n \"symbol\": \"USDC\",\n \"decimals\": 6\n },\n \"amountLimit\": \"1000000\",\n \"period\": \"daily\",\n \"startsAt\": \"2026-08-28T10:00:00.000Z\",\n \"expiresAt\": \"2026-08-28T10:00:00.000Z\",\n \"reason\": \"Requested by partner\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Idempotency-Key", "<idempotency-key>")
req.Header.Add("Authorization", "Basic <encoded-value>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates")
.header("Idempotency-Key", "<idempotency-key>")
.header("Authorization", "Basic <encoded-value>")
.header("Content-Type", "application/json")
.body("{\n \"recipient\": {\n \"chainId\": 42161,\n \"address\": \"0xdFD4ab80E163D6864E26F37540563cBf2E52A582\",\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\"\n },\n \"token\": {\n \"chainId\": 42161,\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\",\n \"symbol\": \"USDC\",\n \"decimals\": 6\n },\n \"amountLimit\": \"1000000\",\n \"period\": \"daily\",\n \"startsAt\": \"2026-08-28T10:00:00.000Z\",\n \"expiresAt\": \"2026-08-28T10:00:00.000Z\",\n \"reason\": \"Requested by partner\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Idempotency-Key"] = '<idempotency-key>'
request["Authorization"] = 'Basic <encoded-value>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"recipient\": {\n \"chainId\": 42161,\n \"address\": \"0xdFD4ab80E163D6864E26F37540563cBf2E52A582\",\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\"\n },\n \"token\": {\n \"chainId\": 42161,\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\",\n \"symbol\": \"USDC\",\n \"decimals\": 6\n },\n \"amountLimit\": \"1000000\",\n \"period\": \"daily\",\n \"startsAt\": \"2026-08-28T10:00:00.000Z\",\n \"expiresAt\": \"2026-08-28T10:00:00.000Z\",\n \"reason\": \"Requested by partner\"\n}"
response = http.request(request)
puts response.read_body{
"id": "vault_mandate_123",
"mandateId": "vault_mandate_123",
"policyId": "vault_policy_123",
"status": "pending_authorization",
"nextAction": {
"id": "vault_action_123",
"vaultId": "vault_123",
"policyId": "vault_policy_123",
"type": "sign_policy",
"status": "pending",
"nextAction": null,
"resourceVersion": 1,
"createdAt": "2026-08-28T10:00:00.000Z",
"updatedAt": "2026-08-28T10:00:00.000Z"
}
}{
"error": {
"code": "bad_request",
"message": "The request is invalid",
"details": "example"
}
}{
"error": {
"code": "bad_request",
"message": "The request is invalid",
"details": "example"
}
}{
"error": {
"code": "bad_request",
"message": "The request is invalid",
"details": "example"
}
}{
"error": {
"code": "bad_request",
"message": "The request is invalid",
"details": "example"
}
}{
"error": {
"code": "bad_request",
"message": "The request is invalid",
"details": "example"
}
}{
"error": {
"code": "bad_request",
"message": "The request is invalid",
"details": "example"
}
}{
"error": {
"code": "bad_request",
"message": "The request is invalid",
"details": "example"
}
}recipient, token, amountLimit and period (daily, weekly or monthly), and its window from startsAt to expiresAt. expiresAt must be after startsAt and no more than 366 days later.
The mandate is created as a policy update and is not active until the owner authorizes it and the policy is installed. A mandate constrains Vault spending; it does not schedule recurring Payments. Idempotency-Key is required.Authorizations
HTTP Basic auth. Username is the Stableyard app ID. Password is the app secret. The optional Stableyard-Version request header must match the environment pin.
Headers
Use this for retry-safe payment operations from your backend.
"payment-request-001"
Optional contract-version assertion. Omit it to use the app environment's pinned version. A different supported version is accepted only after that environment is explicitly migrated.
2026-09-09 Path Parameters
Canonical account id returned by the Accounts API.
"acct_123"
Body
Show child attributes
Show child attributes
Show child attributes
Show child attributes
^[0-9]+$daily, weekly, monthly Mandate expiry. It must be after startsAt and no more than 366 days later.
280Response
Pending mandate policy update
Canonical mandate identifier. Equal to mandateId.
"vault_mandate_123"
"vault_mandate_123"
pending_authorization, pending_revocation, revoked Pending policy version that must be authorized and installed before the mandate change takes effect.
"vault_policy_123"
Show child attributes
Show child attributes