Read the card's merchant / MCC list
x-on-behalf-of required
Controls which merchants or merchant categories this card may use. Restricts recipients, not amounts, independently of /limits; neither control replaces the other.
⚠ synced: false is the most important field in this response. Rules are enforced on the upstream issuing network, not in our database. false means we have stored the list, but the upstream has not confirmed receiving it because the last update's outcome is unknown. The card may therefore still be unrestricted. Do not present the rule as active to the end user.
rule_type: null means no list has been configured and the card may spend anywhere. This differs from an empty allowlist, which would prohibit all spending. We therefore reject empty lists when writing rules; use DELETE to remove restrictions.
Path Parameters
| Field | Type | Required | Description |
|---|---|---|---|
id |
string | Required | Card ID |
Request Headers
| Field | Type | Required | Description |
|---|---|---|---|
x-on-behalf-of |
string | Required | The member on whose behalf to call. |
Response
{
"id": "crd_9f2c1b7a-3d51-4a2e-9c08-6b1f0d4e77aa",
"rule_type": "white",
"merchant_names": [
"AMAZON",
"UBER"
],
"mcc_list": [
"5411",
"4121"
],
"synced": true,
"synced_at": "2026-08-13T02:11:47.000Z"
}not_found: the card does not exist or does not belong to this member.curl -X GET 'https://api.zinfra.vip/v1/cards/{id}/merchant-rules' \
-H 'x-auth-token: Bearer $TOKEN' \
-H 'x-on-behalf-of: $MEMBER_ID'const res = await fetch("https://api.zinfra.vip/v1/cards/{id}/merchant-rules", {
method: "GET",
headers: {
"x-auth-token": "Bearer $TOKEN",
"x-on-behalf-of": "$MEMBER_ID",
},
});
// Keep monetary amounts as strings, never numbers.
const data = await res.json();import requests
res = requests.get(
"https://api.zinfra.vip/v1/cards/{id}/merchant-rules",
headers={
"x-auth-token": "Bearer $TOKEN",
"x-on-behalf-of": "$MEMBER_ID",
},
)
# Use Decimal(str(...)) for amounts, not float.
data = res.json()req, _ := http.NewRequest("GET", "https://api.zinfra.vip/v1/cards/{id}/merchant-rules",
nil)
req.Header.Set("x-auth-token", "Bearer $TOKEN")
req.Header.Set("x-on-behalf-of", "$MEMBER_ID")
res, err := http.DefaultClient.Do(req)
// Decode amount fields as string, not float64.HttpRequest req = HttpRequest.newBuilder()
.uri(URI.create("https://api.zinfra.vip/v1/cards/{id}/merchant-rules"))
.header("x-auth-token", "Bearer $TOKEN")
.header("x-on-behalf-of", "$MEMBER_ID")
.method("GET", HttpRequest.BodyPublishers.noBody())
.build();
// Use String / BigDecimal for amounts, not double.$ch = curl_init('https://api.zinfra.vip/v1/cards/{id}/merchant-rules');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
'x-auth-token: Bearer $TOKEN',
'x-on-behalf-of: $MEMBER_ID',
],
]);
$res = curl_exec($ch);
// Use bcmath / strings for amounts, not floatval.
{
"id": "crd_9f2c1b7a-3d51-4a2e-9c08-6b1f0d4e77aa",
"rule_type": "white",
"merchant_names": [
"AMAZON",
"UBER"
],
"mcc_list": [
"5411",
"4121"
],
"synced": true,
"synced_at": "2026-08-13T02:11:47.000Z"
}