> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stableyard.fi/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a Vault mandate

> Propose a Vault spending mandate as a policy update.

Define the mandate's `recipient`, `token`, `amountLimit` and `period` (`daily`, `weekly` or `monthly`), and its window from `startsAt` to `expiresAt`. `expiresAt` must be after `startsAt` and no more than 366 days later.

The mandate is created as a policy update and is not active until the owner authorizes it and the policy is installed. A mandate constrains Vault spending; it does not schedule recurring Payments. `Idempotency-Key` is required.


## OpenAPI

````yaml openapi.json POST /v2/accounts/{accountId}/vault/mandates
openapi: 3.1.0
info:
  title: Stableyard Partner API
  version: 2.0.0-staging
  x-stableyard-api-version: '2026-09-09'
  x-stableyard-supported-api-versions:
    - '2026-09-09'
  summary: Backend API for UPAs, Payments, activity, and optional financial products.
  description: >

    Use this API from a trusted partner backend with an app ID and app secret.


    ## Recommended integration


    1. Call `GET /v2/partners/config` to verify credentials and discover enabled
    capabilities.

    2. Create a UPA only when your product needs a persistent Stableyard
    account.

    3. Create a receive or send Payment with `POST /v2/payments`.

    4. Redirect a payer to the returned `paymentUrl` or pass the Payment
    credentials to an official Stableyard interface SDK.

    5. Process signed webhooks and fetch the Payment by ID for reconciliation.


    Checkout execution and account-bound browser endpoints are intentionally
    documented in the separate Interfaces & SDKs reference. Console endpoints
    are dashboard implementation details and are not part of the partner
    integration contract.
  x-stableyard-documentation-surface: partner
servers:
  - url: https://prod-api.stableyard.fi
    description: Production
  - url: https://staging-api-v2.stableyard.fi
    description: Staging
  - url: http://localhost:3001
    description: Local
security: []
tags:
  - name: Authentication
    x-displayName: API authentication
    description: Verify your app ID and app secret before calling UPA APIs.
  - name: Accounts
    x-displayName: UPA Accounts
    description: Create Universal Payment Accounts and manage account settings.
  - name: Deposit Addresses
    description: Create reusable receive addresses and verify inbound deposits.
  - name: Identity & KYC
    description: >-
      Verify the UPA email and run provider-neutral identity verification.
      Managed vaults and fiat payment rails use this same verified UPA identity.
  - name: Vaults
    description: >-
      Create Safe/Zodiac controlled stablecoin vaults and manage policy updates
      for accounts.
  - name: Payments
    description: >-
      Create escrow-first payments, issue partner-authenticated send
      instructions or executions, power public checkout, and reconcile
      collection through final account settlement.
  - name: Balances & Transactions
    description: >-
      Read Stableyard-posted financial activity. Balances are ledger projections
      of activity Stableyard processed; they are not live balances of externally
      controlled wallets.
paths:
  /v2/accounts/{accountId}/vault/mandates:
    post:
      tags:
        - Vaults
      summary: Create vault mandate
      description: >-
        Creates a mandate as a policy update. The mandate is not active until
        the owner authorizes and the policy is installed.
      operationId: createVaultMandate
      parameters:
        - name: accountId
          in: path
          required: true
          schema:
            type: string
            example: acct_123
          description: Canonical account id returned by the Accounts API.
        - name: Idempotency-Key
          in: header
          required: true
          schema:
            type: string
            example: payment-request-001
          description: Use this for retry-safe payment operations from your backend.
        - name: Stableyard-Version
          in: header
          required: false
          schema:
            type: string
            enum:
              - '2026-09-09'
          description: >-
            Optional contract-version assertion. Omit it to use the app
            environment's pinned version. A different supported version is
            accepted only after that environment is explicitly migrated.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              additionalProperties: false
              required:
                - recipient
                - token
                - amountLimit
                - period
                - startsAt
                - expiresAt
              properties:
                recipient:
                  $ref: '#/components/schemas/VaultMandateRecipient'
                token:
                  $ref: '#/components/schemas/VaultMandateToken'
                amountLimit:
                  type: string
                  pattern: ^[0-9]+$
                period:
                  type: string
                  enum:
                    - daily
                    - weekly
                    - monthly
                startsAt:
                  type: string
                  format: date-time
                expiresAt:
                  type: string
                  format: date-time
                  description: >-
                    Mandate expiry. It must be after startsAt and no more than
                    366 days later.
                reason:
                  type: string
                  maxLength: 280
            examples:
              example:
                summary: Create vault mandate request
                value:
                  recipient:
                    chainId: 42161
                    address: '0xdFD4ab80E163D6864E26F37540563cBf2E52A582'
                    tokenAddress: '0xaf88d065e77c8cC2239327C5EDb3A432268e5831'
                  token:
                    chainId: 42161
                    tokenAddress: '0xaf88d065e77c8cC2239327C5EDb3A432268e5831'
                    symbol: USDC
                    decimals: 6
                  amountLimit: '1000000'
                  period: daily
                  startsAt: '2026-08-28T10:00:00.000Z'
                  expiresAt: '2026-08-28T10:00:00.000Z'
                  reason: Requested by partner
      responses:
        '200':
          description: Pending mandate policy update
          headers:
            Stableyard-Version:
              description: >-
                Effective date-based Stableyard API contract version for this
                response.
              schema:
                type: string
                enum:
                  - '2026-09-09'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/VaultMandateMutationResponse'
              examples:
                example:
                  summary: Create vault mandate 200 response
                  value:
                    id: vault_mandate_123
                    mandateId: vault_mandate_123
                    policyId: vault_policy_123
                    status: pending_authorization
                    nextAction:
                      id: vault_action_123
                      vaultId: vault_123
                      policyId: vault_policy_123
                      type: sign_policy
                      status: pending
                      nextAction: null
                      resourceVersion: 1
                      createdAt: '2026-08-28T10:00:00.000Z'
                      updatedAt: '2026-08-28T10:00:00.000Z'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          $ref: '#/components/responses/Conflict'
        '424':
          $ref: '#/components/responses/FailedDependency'
        '429':
          $ref: '#/components/responses/TooManyRequests'
      security:
        - partnerBasicAuth: []
components:
  schemas:
    VaultMandateRecipient:
      type: object
      additionalProperties: false
      required:
        - chainId
        - address
        - tokenAddress
      properties:
        chainId:
          type: integer
          enum:
            - 42161
          description: Vault mandates currently execute from Arbitrum Vault assets.
        address:
          type: string
          pattern: ^0x[a-fA-F0-9]{40}$
          example: '0xdFD4ab80E163D6864E26F37540563cBf2E52A582'
        tokenAddress:
          type: string
          pattern: ^0x[a-fA-F0-9]{40}$
          example: '0xaf88d065e77c8cC2239327C5EDb3A432268e5831'
    VaultMandateToken:
      type: object
      additionalProperties: false
      required:
        - chainId
        - tokenAddress
        - symbol
        - decimals
      properties:
        chainId:
          type: integer
          enum:
            - 42161
          description: Vault mandates currently execute from Arbitrum Vault assets.
        tokenAddress:
          type: string
          pattern: ^0x[a-fA-F0-9]{40}$
          example: '0xaf88d065e77c8cC2239327C5EDb3A432268e5831'
        symbol:
          type: string
          enum:
            - USDC
            - USDT
        decimals:
          type: integer
          enum:
            - 6
    VaultMandateMutationResponse:
      type: object
      additionalProperties: false
      required:
        - id
        - mandateId
        - status
      properties:
        id:
          type: string
          example: vault_mandate_123
          description: Canonical mandate identifier. Equal to mandateId.
        mandateId:
          type: string
          example: vault_mandate_123
        policyId:
          type: string
          example: vault_policy_123
          description: >-
            Pending policy version that must be authorized and installed before
            the mandate change takes effect.
        status:
          type: string
          enum:
            - pending_authorization
            - pending_revocation
            - revoked
        nextAction:
          $ref: '#/components/schemas/VaultAction'
    VaultAction:
      type: object
      additionalProperties: false
      required:
        - id
        - vaultId
        - type
        - status
        - resourceVersion
        - createdAt
        - updatedAt
      properties:
        id:
          type: string
          example: vault_action_123
        vaultId:
          type: string
          example: vault_123
        policyId:
          type:
            - string
            - 'null'
          example: vault_policy_123
        type:
          type: string
          enum:
            - sign_policy
            - approve_managed_policy
            - install_policy
            - auto_supply_yield
            - redeem_yield
            - execute_payment
        status:
          type: string
          enum:
            - pending
            - queued
            - processing
            - completed
            - failed
            - cancelled
        nextAction:
          type:
            - object
            - 'null'
          additionalProperties: true
          description: >-
            Public wallet, signature, email approval, or wait instruction. Treat
            the action type as the discriminator and never modify transaction
            calldata. `execute_safe_transaction` includes a `completion` request
            descriptor for submitting the mined transaction hash.
        resourceVersion:
          type: integer
          minimum: 1
        failureCode:
          type:
            - string
            - 'null'
        expiresAt:
          type:
            - string
            - 'null'
          format: date-time
        createdAt:
          type: string
          format: date-time
        updatedAt:
          type: string
          format: date-time
    ErrorResponse:
      type: object
      additionalProperties: false
      required:
        - error
      properties:
        error:
          type: object
          additionalProperties: false
          required:
            - code
            - message
          properties:
            code:
              type: string
              minLength: 1
              maxLength: 128
              example: bad_request
            message:
              type: string
              minLength: 1
              maxLength: 1000
              example: The request is invalid
            details: {}
  responses:
    BadRequest:
      description: Bad request
      headers:
        Stableyard-Version:
          description: >-
            Effective date-based Stableyard API contract version for this
            response.
          schema:
            type: string
            enum:
              - '2026-09-09'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            example:
              summary: BadRequest response
              value:
                error:
                  code: bad_request
                  message: The request is invalid
                  details: example
    Unauthorized:
      description: Unauthorized
      headers:
        Stableyard-Version:
          description: >-
            Effective date-based Stableyard API contract version for this
            response.
          schema:
            type: string
            enum:
              - '2026-09-09'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            example:
              summary: Unauthorized response
              value:
                error:
                  code: bad_request
                  message: The request is invalid
                  details: example
    Forbidden:
      description: The app secret does not include the required scope
      headers:
        Stableyard-Version:
          description: >-
            Effective date-based Stableyard API contract version for this
            response.
          schema:
            type: string
            enum:
              - '2026-09-09'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            example:
              summary: Forbidden response
              value:
                error:
                  code: bad_request
                  message: The request is invalid
                  details: example
    NotFound:
      description: Not found
      headers:
        Stableyard-Version:
          description: >-
            Effective date-based Stableyard API contract version for this
            response.
          schema:
            type: string
            enum:
              - '2026-09-09'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            example:
              summary: NotFound response
              value:
                error:
                  code: bad_request
                  message: The request is invalid
                  details: example
    Conflict:
      description: Conflict
      headers:
        Stableyard-Version:
          description: >-
            Effective date-based Stableyard API contract version for this
            response.
          schema:
            type: string
            enum:
              - '2026-09-09'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            example:
              summary: Conflict response
              value:
                error:
                  code: bad_request
                  message: The request is invalid
                  details: example
    FailedDependency:
      description: Required chain, network, or provider configuration is missing
      headers:
        Stableyard-Version:
          description: >-
            Effective date-based Stableyard API contract version for this
            response.
          schema:
            type: string
            enum:
              - '2026-09-09'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            example:
              summary: FailedDependency response
              value:
                error:
                  code: bad_request
                  message: The request is invalid
                  details: example
    TooManyRequests:
      description: >-
        Rate limit, payment-option limit, selection cooldown, or temporary abuse
        block
      headers:
        Stableyard-Version:
          description: >-
            Effective date-based Stableyard API contract version for this
            response.
          schema:
            type: string
            enum:
              - '2026-09-09'
        Retry-After:
          description: Seconds until the caller should retry.
          schema:
            type: integer
            minimum: 1
        RateLimit-Limit:
          description: Quota for the most constrained policy.
          schema:
            type: integer
            minimum: 1
        RateLimit-Remaining:
          description: Requests remaining in that policy window.
          schema:
            type: integer
            minimum: 0
        RateLimit-Reset:
          description: Seconds until that policy window resets.
          schema:
            type: integer
            minimum: 0
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            example:
              summary: TooManyRequests response
              value:
                error:
                  code: bad_request
                  message: The request is invalid
                  details: example
  securitySchemes:
    partnerBasicAuth:
      type: http
      scheme: basic
      description: >-
        HTTP Basic auth. Username is the Stableyard app ID. Password is the app
        secret. The optional Stableyard-Version request header must match the
        environment pin.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.