# Account Level Rule

# Card Level Rule

# Program Level Rule

# `201      Auth Rule`

**object**

- **token**  
  - **uuid**  
  - **required**

- **Auth Rule Token**

- **state**  
  - **string**  
  - **enum**  
  - **required**  
  - The state of the Auth Rule
  - `ACTIVE``INACTIVE`

- **program_level**  
  - **boolean**  
  - **required**  
  - Whether the Auth Rule applies to all authorizations on the card program.

- **card_tokens**  
  - **array of uuids**  
  - **required**  
  - Card tokens to which the Auth Rule applies.

- **excluded_card_tokens**  
  - **array of uuids**  
  - Card tokens to which the Auth Rule does not apply.

- **excluded_account_tokens**  
  - **array of uuids**  
  - Account tokens to which the Auth Rule does not apply.

- **excluded_business_account_tokens**  
  - **array of uuids**  
  - Business account tokens to which the Auth Rule does not apply.

- **account_tokens**  
  - **array of uuids**  
  - **required**  
  - Account tokens to which the Auth Rule applies.

- **business_account_tokens**  
  - **array of uuids**  
  - **required**  
  - Business Account tokens to which the Auth Rule applies.

- **type**  
  - **string**  
  - **enum**  
  - **required**  
  - The type of Auth Rule. For certain rule types, this determines the event stream during which it will be evaluated. For rules that can be applied to one of several event streams, the effective one is defined by the separate `event_stream` field.
  - - `CONDITIONAL_BLOCK`: Deprecated. Use `CONDITIONAL_ACTION` instead. AUTHORIZATION event stream.
  - - `VELOCITY_LIMIT`: AUTHORIZATION event stream.
  - - `MERCHANT_LOCK`: AUTHORIZATION event stream.
  - - `CONDITIONAL_ACTION`: AUTHORIZATION, THREE_DS_AUTHENTICATION, TOKENIZATION, ACH_CREDIT_RECEIPT, ACH_DEBIT_RECEIPT, CARD_TRANSACTION_UPDATE, or ACH_PAYMENT_UPDATE event stream.
  - - `TYPESCRIPT_CODE`: AUTHORIZATION, THREE_DS_AUTHENTICATION, TOKENIZATION, ACH_CREDIT_RECEIPT, ACH_DEBIT_RECEIPT, CARD_TRANSACTION_UPDATE, or ACH_PAYMENT_UPDATE event stream.
  - `CONDITIONAL_BLOCK``VELOCITY_LIMIT``MERCHANT_LOCK``CONDITIONAL_ACTION``TYPESCRIPT_CODE`

- **current_version**  
  - **null | object**  
  - **required**  
  - null
  - **object**

- **draft_version**  
  - **null | object**  
  - **required**  
  - null
  - **object**

- **name**  
  - **null**  
  - **string**  
  - **required**  
  - Auth Rule Name

- **event_stream**  
  - **string**  
  - **enum**  
  - **required**  
  - The event stream during which the rule will be evaluated.
  - `AUTHORIZATION``THREE_DS_AUTHENTICATION``TOKENIZATION``ACH_CREDIT_RECEIPT``ACH_DEBIT_RECEIPT``CARD_TRANSACTION_UPDATE``ACH_PAYMENT_UPDATE`

- **lithic_managed**  
  - **boolean**  
  - **required**  
  - Indicates whether this auth rule is managed by Lithic. If true, the rule cannot be modified or deleted by the user

# `400      Bad Request`

# `404      Not Found`

### Example Request

curl --request POST \
         --url https://sandbox.lithic.com/v2/auth_rules \
         --header 'accept: application/json' \
         --header 'content-type: application/json' \
         --data '{

"account_tokens": [
          "3fa85f64-5717-4562-b3fc-2c963f66afa6"
      ],

"business_account_tokens": [
          "3fa85f64-5717-4562-b3fc-2c963f66afa6"
      ],

"type": "CONDITIONAL_BLOCK",

"parameters": {
          "conditions": [
              {
                  "attribute": "MCC",
                  "operation": "IS_ONE_OF",
                  "value": "string"
              }
          ]
      },

"name": "string",
      "event_stream": "AUTHORIZATION"
    }'

### Example Response

{
      "token": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
      "state": "ACTIVE",
      "program_level": true,
      "card_tokens": [
          "3fa85f64-5717-4562-b3fc-2c963f66afa6"
      ],
      "excluded_card_tokens": [
          "3fa85f64-5717-4562-b3fc-2c963f66afa6"
      ],
      "excluded_account_tokens": [
          "3fa85f64-5717-4562-b3fc-2c963f66afa6"
      ],
      "excluded_business_account_tokens": [
          "3fa85f64-5717-4562-b3fc-2c963f66afa6"
      ],
      "account_tokens": [
          "3fa85f64-5717-4562-b3fc-2c963f66afa6"
      ],
      "business_account_tokens": [
          "3fa85f64-5717-4562-b3fc-2c963f66afa6"
      ],
      "type": "CONDITIONAL_BLOCK",
      "current_version": {
          "parameters": {
              "conditions": [
                  {
                      "attribute": "MCC",
                      "operation": "IS_ONE_OF",
                      "value": "string"
                  }
              ]
          },
          "version": 0
      },
      "draft_version": {
          "parameters": {
              "conditions": [
                  {
                      "attribute": "MCC",
                      "operation": "IS_ONE_OF",
                      "value": "string"
                  }
              ]
          },
          "version": 0,
          "state": "PENDING",
          "error": "string"
      },
      "name": "string",
      "event_stream": "AUTHORIZATION",
      "lithic_managed": true
    }
