Skip to content

Card rail

Authorise a card payment (any issuer)

POST/issuing/:wid/generic/authorize

Signed with immiscible-signature. Approved only against an unused receipt for the same payee and currency covering the amount.

#Authentication

Issuer signature

No bearer credential: the caller proves itself by signing the raw request body. Anything that does not verify is refused (or, on the card rail, declined) before the body is read.

The immiscible-signature: t=<unix seconds>,v1=<hex> header: an HMAC-SHA256 of <t>.<raw body> with the workspace's issuer secret. Five minute window.

#Path parameters

widstringrequired

Workspace id