Clear the card's list (restore unrestricted use)
On behalf of a member ·
x-on-behalf-of required
If no list exists, this is a successful no-op; deletion is inherently idempotent.
⚠ Deletion failures are returned truthfully; we do not erase the local list. Erasing it would make you believe the restriction was removed while the upstream still enforced it. With an allowlist, the card would remain restricted to those merchants while troubleshooting showed an empty rule.
⚠ No idempotency key is needed, because the action itself is idempotent. On 502, resend directly. With an idempotency key, the retry would replay a result when what you need is another actual attempt.
Path Parameters
| Field | Type | Required | Description |
|---|---|---|---|
id |
string | Required | Card ID |
Request Headers
| Field | Type | Required | Description |
|---|---|---|---|
x-on-behalf-of |
string | Required | The member on whose behalf to call. |
Response
200Cleared, or no list existed.
{
"id": "crd_9f2c1b7a-3d51-4a2e-9c08-6b1f0d4e77aa",
"rule_type": null,
"merchant_names": [],
"mcc_list": []
}400
state_invalid: card closed or expired. product_not_available: issuer unavailable.
invalid_request: upstream rejection.404
not_found: the card does not exist or does not belong to this member.502
upstream_error: outcome unknown. Retry with the same idempotency key.Request
curl -X DELETE 'https://api.zinfra.vip/v1/cards/{id}/merchant-rules' \
-H 'x-auth-token: Bearer $TOKEN' \
-H 'x-on-behalf-of: $MEMBER_ID'const res = await fetch("https://api.zinfra.vip/v1/cards/{id}/merchant-rules", {
method: "DELETE",
headers: {
"x-auth-token": "Bearer $TOKEN",
"x-on-behalf-of": "$MEMBER_ID",
},
});
// Keep monetary amounts as strings, never numbers.
const data = await res.json();import requests
res = requests.delete(
"https://api.zinfra.vip/v1/cards/{id}/merchant-rules",
headers={
"x-auth-token": "Bearer $TOKEN",
"x-on-behalf-of": "$MEMBER_ID",
},
)
# Use Decimal(str(...)) for amounts, not float.
data = res.json()req, _ := http.NewRequest("DELETE", "https://api.zinfra.vip/v1/cards/{id}/merchant-rules",
nil)
req.Header.Set("x-auth-token", "Bearer $TOKEN")
req.Header.Set("x-on-behalf-of", "$MEMBER_ID")
res, err := http.DefaultClient.Do(req)
// Decode amount fields as string, not float64.HttpRequest req = HttpRequest.newBuilder()
.uri(URI.create("https://api.zinfra.vip/v1/cards/{id}/merchant-rules"))
.header("x-auth-token", "Bearer $TOKEN")
.header("x-on-behalf-of", "$MEMBER_ID")
.method("DELETE", HttpRequest.BodyPublishers.noBody())
.build();
// Use String / BigDecimal for amounts, not double.$ch = curl_init('https://api.zinfra.vip/v1/cards/{id}/merchant-rules');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'DELETE',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
'x-auth-token: Bearer $TOKEN',
'x-on-behalf-of: $MEMBER_ID',
],
]);
$res = curl_exec($ch);
// Use bcmath / strings for amounts, not floatval.
200
{
"id": "crd_9f2c1b7a-3d51-4a2e-9c08-6b1f0d4e77aa",
"rule_type": null,
"merchant_names": [],
"mcc_list": []
}