Update a Payment Rule
Changes the rule’s name or metadata, keeping its ID and everything recorded against it. What the rule does is fixed once created, so the payments it decided keep naming the rule that decided them; use replace to change that.
Authorizations
An Account API key, an App API key, an account access token, an account-scoped user token, or a user OAuth token. Prepend the key or token with Bearer, for example Bearer ***************************. See Auth & API keys for how to get each one.
Headers
Pins the request to a dated API version.
"2026-10-06"
Path Parameters
The payment rule ID.
Body
Response
The updated rule
Account ID, prefixed biz_.
"biz_xxxxxxxxxxxxxx"
What this account's rule requests when every condition matches. One applicable account-rule action wins, in this order: allow, block, review, enforce_3ds. An allow overrides this account's other rules, never Whop's own fraud controls. A review requests authorization without capture for an eligible on-session card payment through Whop Payments. Automatic capture is scheduled for 48 hours after authorization; capture or void the payment before then to decide sooner. Capture may complete later or fail. Review is skipped for unsupported methods, off-session payments, and payments already configured for manual capture. An enforce_3ds is skipped when the account rule cannot apply a challenge. Other 3DS requirements still apply.
allow, block, review, enforce_3ds "block"
The conditions a payment is matched against. Up to 10 conditions, and 8 KiB once serialized.
When the rule was created, as an ISO 8601 timestamp.
"2026-01-01T12:00:00.000Z"
When the rule was deleted, as an ISO 8601 timestamp. null unless status is deleted.
null
Payment rule ID, prefixed prule_.
"prule_xxxxxxxxxxxxxx"
Custom string-to-string values for your integration. Maximum 50 keys, 40 characters per key, 500 characters per value.
A name for this rule. Up to 255 characters.
"Block high risk"
Whether the rule is applied to payments. A deleted rule is kept so the payments it already decided still name it.
active, inactive, deleted "active"
When the rule was last changed, as an ISO 8601 timestamp.
"2026-01-01T12:00:00.000Z"

