Four ways a rule can act
A rule can read
risk_score, amount_in_usd, card_country, card_bin, customer_email, and ip_address. card_bin is the Bank Identification Number of the card used to make the payment: the first six digits of the card number. List fields returns the operators and values each one accepts.
Where you’re unsure, challenge rather than block. A block also turns away real buyers who match, while a challenge lets them prove they’re the cardholder.
Run these examples in a trusted server environment with
WHOP_API_KEY set.
Reuse the imports and client setup from the first example for your language.Block the obvious fraud
Start with the pattern you see most in your disputes. This rule blocks a payment Whop scores 85 or higher on a card issued outside the US.account_id. Without it the rule lands on whichever account your credential defaults to, which is easy to get wrong for a platform that manages several. Rules are published to checkout every minute, so a new or changed rule starts applying within a couple of minutes.
Required permission:
payment:manage to write rules, payment:basic:read to
read them. Add permissions from the Permissions
guide.Challenge large orders
A large order from a stolen card is the chargeback you least want. A large order from a real customer is the sale you least want to lose. A 3D Secure challenge separates the two, and the payment recordsthree_ds_verified: true when the buyer passes.
enforce_3ds is skipped, but still recorded on the payment, when the checkout can’t carry a challenge. That covers off-session payments such as renewals, variants that set their own 3D Secure level, non-card payments, cards the processor can’t challenge, and American Express.
Review a payment before charging it
Areview rule authorizes an eligible card payment without capturing it. The buyer completes checkout and gets membership access at authorization. Use it for orders you fulfil by hand, or for a pattern that’s risky but not certainly fraud. Whop captures automatically 48 hours later unless you act first:
- Capture to collect the money. The payment becomes
paidand Whop sendspayment.succeeded, your signal to fulfil the order. - Void to release the hold. Whop revokes access, returns reserved stock, and sends
payment.canceled.
payment.authorized when the hold starts, and for API-requested authorizations too. A held payment reads status: "authorized" with substatus: "requires_capture". Retrieve the payment status for auto_capture_at.
This rule holds card payments of at least $250 whose card was issued outside the US.
Review limitations
- Only on-session cards can be held. Apple Pay, Google Pay, bank, balance, and off-session payments such as renewals skip review. The match is still recorded in
payment_rule_matches. - Payments created with
capture: falsekeep their own schedule. A review rule never overrides it. - Capture is all or nothing. Refund afterwards to return part of it.
- Buyers have the product before you decide. Tell them if you void.
Keep trusted buyers moving
Anallow rule exempts buyers you trust from your block, review, and challenge rules.
Tighten a rule
What a rule does is fixed once created, so the payments it decided keep naming the rule that decided them. To change its action or conditions, replace it: the old rule is deleted and a successor with a new ID inherits its name,metadata, and active state. Here the block threshold is raised from 85 to 90 after catching too many real buyers.
status: "deleted".
Measure the effect
Each payment lists the rules that matched it inpayment_rule_matches, with the name the rule had at the time.
payment_rule_matches and payment_rule_matched_volume break down by payment_rule_ids or action.
Next steps
Payment Rules reference
Every endpoint, parameter, and response field.
Refunds and disputes
Respond to the chargebacks that still get through.

