Skip to main content
POST
Replace a payment rule

Authorizations

Authorization
string
header
required

An Account API key, an App API key, an account access token, an account-scoped user token, or a user OAuth token. Prepend the key or token with Bearer, for example Bearer ***************************. See Auth & API keys for how to get each one.

Headers

Idempotency-Key
string

A unique key that makes this request safe to retry. See Idempotent requests.

Maximum string length: 255
Example:

"d9105228-4a08-46b1-8b91-42fed586d383"

Api-Version-Date
string

Pins the request to a dated API version.

Example:

"2026-10-06"

Path Parameters

id
string
required

The payment rule ID.

Body

application/json
action
enum<string>
required

What this account's rule requests when every condition matches. One applicable account-rule action wins, in this order: allow, block, review, enforce_3ds. An allow overrides this account's other rules, never Whop's own fraud controls. A review requests authorization without capture for an eligible on-session card payment through Whop Payments. Automatic capture is scheduled for 48 hours after authorization; capture or void the payment before then to decide sooner. Capture may complete later or fail. Review is skipped for unsupported methods, off-session payments, and payments already configured for manual capture. An enforce_3ds is skipped when the account rule cannot apply a challenge. Other 3DS requirements still apply.

Available options:
allow,
block,
review,
enforce_3ds
Example:

"review"

conditions
object
required

The conditions a payment is matched against. Up to 10 conditions, and 8 KiB once serialized.

Example:

Response

The rule that replaced this one

account_id
string
required

Account ID, prefixed biz_.

Example:

"biz_xxxxxxxxxxxxxx"

action
enum<string>
required

What this account's rule requests when every condition matches. One applicable account-rule action wins, in this order: allow, block, review, enforce_3ds. An allow overrides this account's other rules, never Whop's own fraud controls. A review requests authorization without capture for an eligible on-session card payment through Whop Payments. Automatic capture is scheduled for 48 hours after authorization; capture or void the payment before then to decide sooner. Capture may complete later or fail. Review is skipped for unsupported methods, off-session payments, and payments already configured for manual capture. An enforce_3ds is skipped when the account rule cannot apply a challenge. Other 3DS requirements still apply.

Available options:
allow,
block,
review,
enforce_3ds
Example:

"block"

conditions
object
required

The conditions a payment is matched against. Up to 10 conditions, and 8 KiB once serialized.

created_at
string
required

When the rule was created, as an ISO 8601 timestamp.

Example:

"2026-01-01T12:00:00.000Z"

deleted_at
string | null
required

When the rule was deleted, as an ISO 8601 timestamp. null unless status is deleted.

Example:

null

id
string
required

Payment rule ID, prefixed prule_.

Example:

"prule_xxxxxxxxxxxxxx"

metadata
object
required

Custom string-to-string values for your integration. Maximum 50 keys, 40 characters per key, 500 characters per value.

Example:
name
string
required

A name for this rule. Up to 255 characters.

Example:

"Block high risk"

status
enum<string>
required

Whether the rule is applied to payments. A deleted rule is kept so the payments it already decided still name it.

Available options:
active,
inactive,
deleted
Example:

"active"

updated_at
string
required

When the rule was last changed, as an ISO 8601 timestamp.

Example:

"2026-01-01T12:00:00.000Z"