Skip to main content
POST
Create vault mandate
Define the mandate’s recipient, token, amountLimit and period (daily, weekly or monthly), and its window from startsAt to expiresAt. expiresAt must be after startsAt and no more than 366 days later. The mandate is created as a policy update and is not active until the owner authorizes it and the policy is installed. A mandate constrains Vault spending; it does not schedule recurring Payments. Idempotency-Key is required.

Authorizations

Authorization
string
header
required

HTTP Basic auth. Username is the Stableyard app ID. Password is the app secret. The optional Stableyard-Version request header must match the environment pin.

Headers

Idempotency-Key
string
required

Use this for retry-safe payment operations from your backend.

Example:

"payment-request-001"

Stableyard-Version
enum<string>

Optional contract-version assertion. Omit it to use the app environment's pinned version. A different supported version is accepted only after that environment is explicitly migrated.

Available options:
2026-09-09

Path Parameters

accountId
string
required

Canonical account id returned by the Accounts API.

Example:

"acct_123"

Body

application/json
recipient
object
required
token
object
required
amountLimit
string
required
Pattern: ^[0-9]+$
period
enum<string>
required
Available options:
daily,
weekly,
monthly
startsAt
string<date-time>
required
expiresAt
string<date-time>
required

Mandate expiry. It must be after startsAt and no more than 366 days later.

reason
string
Maximum string length: 280

Response

Pending mandate policy update

id
string
required

Canonical mandate identifier. Equal to mandateId.

Example:

"vault_mandate_123"

mandateId
string
required
Example:

"vault_mandate_123"

status
enum<string>
required
Available options:
pending_authorization,
pending_revocation,
revoked
policyId
string

Pending policy version that must be authorized and installed before the mandate change takes effect.

Example:

"vault_policy_123"

nextAction
object