curl --request POST \
--url https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/json' \
--header 'Idempotency-Key: <idempotency-key>' \
--data '
{
"recipient": {
"chainId": 42161,
"address": "0x3333333333333333333333333333333333333333",
"tokenAddress": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831"
},
"token": {
"chainId": 42161,
"tokenAddress": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
"symbol": "USDC",
"decimals": 6
},
"amountLimit": "1000000",
"period": "daily",
"startsAt": "2026-08-28T10:00:00.000Z",
"expiresAt": "2026-08-28T10:00:00.000Z",
"reason": "Requested by partner"
}
'import requests
url = "https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates"
payload = {
"recipient": {
"chainId": 42161,
"address": "0x3333333333333333333333333333333333333333",
"tokenAddress": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831"
},
"token": {
"chainId": 42161,
"tokenAddress": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
"symbol": "USDC",
"decimals": 6
},
"amountLimit": "1000000",
"period": "daily",
"startsAt": "2026-08-28T10:00:00.000Z",
"expiresAt": "2026-08-28T10:00:00.000Z",
"reason": "Requested by partner"
}
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Basic <encoded-value>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
recipient: {
chainId: 42161,
address: '0x3333333333333333333333333333333333333333',
tokenAddress: '0xaf88d065e77c8cC2239327C5EDb3A432268e5831'
},
token: {
chainId: 42161,
tokenAddress: '0xaf88d065e77c8cC2239327C5EDb3A432268e5831',
symbol: 'USDC',
decimals: 6
},
amountLimit: '1000000',
period: 'daily',
startsAt: '2026-08-28T10:00:00.000Z',
expiresAt: '2026-08-28T10:00:00.000Z',
reason: 'Requested by partner'
})
};
fetch('https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'recipient' => [
'chainId' => 42161,
'address' => '0x3333333333333333333333333333333333333333',
'tokenAddress' => '0xaf88d065e77c8cC2239327C5EDb3A432268e5831'
],
'token' => [
'chainId' => 42161,
'tokenAddress' => '0xaf88d065e77c8cC2239327C5EDb3A432268e5831',
'symbol' => 'USDC',
'decimals' => 6
],
'amountLimit' => '1000000',
'period' => 'daily',
'startsAt' => '2026-08-28T10:00:00.000Z',
'expiresAt' => '2026-08-28T10:00:00.000Z',
'reason' => 'Requested by partner'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Basic <encoded-value>",
"Content-Type: application/json",
"Idempotency-Key: <idempotency-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates"
payload := strings.NewReader("{\n \"recipient\": {\n \"chainId\": 42161,\n \"address\": \"0x3333333333333333333333333333333333333333\",\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\"\n },\n \"token\": {\n \"chainId\": 42161,\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\",\n \"symbol\": \"USDC\",\n \"decimals\": 6\n },\n \"amountLimit\": \"1000000\",\n \"period\": \"daily\",\n \"startsAt\": \"2026-08-28T10:00:00.000Z\",\n \"expiresAt\": \"2026-08-28T10:00:00.000Z\",\n \"reason\": \"Requested by partner\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Idempotency-Key", "<idempotency-key>")
req.Header.Add("Authorization", "Basic <encoded-value>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates")
.header("Idempotency-Key", "<idempotency-key>")
.header("Authorization", "Basic <encoded-value>")
.header("Content-Type", "application/json")
.body("{\n \"recipient\": {\n \"chainId\": 42161,\n \"address\": \"0x3333333333333333333333333333333333333333\",\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\"\n },\n \"token\": {\n \"chainId\": 42161,\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\",\n \"symbol\": \"USDC\",\n \"decimals\": 6\n },\n \"amountLimit\": \"1000000\",\n \"period\": \"daily\",\n \"startsAt\": \"2026-08-28T10:00:00.000Z\",\n \"expiresAt\": \"2026-08-28T10:00:00.000Z\",\n \"reason\": \"Requested by partner\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Idempotency-Key"] = '<idempotency-key>'
request["Authorization"] = 'Basic <encoded-value>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"recipient\": {\n \"chainId\": 42161,\n \"address\": \"0x3333333333333333333333333333333333333333\",\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\"\n },\n \"token\": {\n \"chainId\": 42161,\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\",\n \"symbol\": \"USDC\",\n \"decimals\": 6\n },\n \"amountLimit\": \"1000000\",\n \"period\": \"daily\",\n \"startsAt\": \"2026-08-28T10:00:00.000Z\",\n \"expiresAt\": \"2026-08-28T10:00:00.000Z\",\n \"reason\": \"Requested by partner\"\n}"
response = http.request(request)
puts response.read_body{
"id": "vault_mandate_123",
"mandateId": "vault_mandate_123",
"policyId": "vault_policy_123",
"status": "pending_authorization",
"nextAction": {
"id": "vault_action_123",
"vaultId": "vault_123",
"policyId": "vault_policy_123",
"type": "sign_policy",
"status": "pending",
"nextAction": null,
"resourceVersion": 1,
"createdAt": "2026-08-28T10:00:00.000Z",
"updatedAt": "2026-08-28T10:00:00.000Z"
}
}{
"error": {
"code": "bad_request",
"message": "The request is invalid"
}
}{
"error": {
"code": "unauthorized",
"message": "Authentication is required"
}
}{
"error": {
"code": "forbidden",
"message": "The credential does not allow this operation"
}
}{
"error": {
"code": "not_found",
"message": "The resource was not found"
}
}{
"error": {
"code": "idempotency_conflict",
"message": "The Idempotency-Key was already used with a different request"
}
}{
"error": {
"code": "chain_config_missing",
"message": "The requested network is not configured for this environment"
}
}{
"error": {
"code": "rate_limited",
"message": "Too many requests"
}
}Create a Vault mandate
Propose a Vault spending mandate as a policy update.
curl --request POST \
--url https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/json' \
--header 'Idempotency-Key: <idempotency-key>' \
--data '
{
"recipient": {
"chainId": 42161,
"address": "0x3333333333333333333333333333333333333333",
"tokenAddress": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831"
},
"token": {
"chainId": 42161,
"tokenAddress": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
"symbol": "USDC",
"decimals": 6
},
"amountLimit": "1000000",
"period": "daily",
"startsAt": "2026-08-28T10:00:00.000Z",
"expiresAt": "2026-08-28T10:00:00.000Z",
"reason": "Requested by partner"
}
'import requests
url = "https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates"
payload = {
"recipient": {
"chainId": 42161,
"address": "0x3333333333333333333333333333333333333333",
"tokenAddress": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831"
},
"token": {
"chainId": 42161,
"tokenAddress": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
"symbol": "USDC",
"decimals": 6
},
"amountLimit": "1000000",
"period": "daily",
"startsAt": "2026-08-28T10:00:00.000Z",
"expiresAt": "2026-08-28T10:00:00.000Z",
"reason": "Requested by partner"
}
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Basic <encoded-value>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
recipient: {
chainId: 42161,
address: '0x3333333333333333333333333333333333333333',
tokenAddress: '0xaf88d065e77c8cC2239327C5EDb3A432268e5831'
},
token: {
chainId: 42161,
tokenAddress: '0xaf88d065e77c8cC2239327C5EDb3A432268e5831',
symbol: 'USDC',
decimals: 6
},
amountLimit: '1000000',
period: 'daily',
startsAt: '2026-08-28T10:00:00.000Z',
expiresAt: '2026-08-28T10:00:00.000Z',
reason: 'Requested by partner'
})
};
fetch('https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'recipient' => [
'chainId' => 42161,
'address' => '0x3333333333333333333333333333333333333333',
'tokenAddress' => '0xaf88d065e77c8cC2239327C5EDb3A432268e5831'
],
'token' => [
'chainId' => 42161,
'tokenAddress' => '0xaf88d065e77c8cC2239327C5EDb3A432268e5831',
'symbol' => 'USDC',
'decimals' => 6
],
'amountLimit' => '1000000',
'period' => 'daily',
'startsAt' => '2026-08-28T10:00:00.000Z',
'expiresAt' => '2026-08-28T10:00:00.000Z',
'reason' => 'Requested by partner'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Basic <encoded-value>",
"Content-Type: application/json",
"Idempotency-Key: <idempotency-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates"
payload := strings.NewReader("{\n \"recipient\": {\n \"chainId\": 42161,\n \"address\": \"0x3333333333333333333333333333333333333333\",\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\"\n },\n \"token\": {\n \"chainId\": 42161,\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\",\n \"symbol\": \"USDC\",\n \"decimals\": 6\n },\n \"amountLimit\": \"1000000\",\n \"period\": \"daily\",\n \"startsAt\": \"2026-08-28T10:00:00.000Z\",\n \"expiresAt\": \"2026-08-28T10:00:00.000Z\",\n \"reason\": \"Requested by partner\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Idempotency-Key", "<idempotency-key>")
req.Header.Add("Authorization", "Basic <encoded-value>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates")
.header("Idempotency-Key", "<idempotency-key>")
.header("Authorization", "Basic <encoded-value>")
.header("Content-Type", "application/json")
.body("{\n \"recipient\": {\n \"chainId\": 42161,\n \"address\": \"0x3333333333333333333333333333333333333333\",\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\"\n },\n \"token\": {\n \"chainId\": 42161,\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\",\n \"symbol\": \"USDC\",\n \"decimals\": 6\n },\n \"amountLimit\": \"1000000\",\n \"period\": \"daily\",\n \"startsAt\": \"2026-08-28T10:00:00.000Z\",\n \"expiresAt\": \"2026-08-28T10:00:00.000Z\",\n \"reason\": \"Requested by partner\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://prod-api.stableyard.fi/v2/accounts/{accountId}/vault/mandates")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Idempotency-Key"] = '<idempotency-key>'
request["Authorization"] = 'Basic <encoded-value>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"recipient\": {\n \"chainId\": 42161,\n \"address\": \"0x3333333333333333333333333333333333333333\",\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\"\n },\n \"token\": {\n \"chainId\": 42161,\n \"tokenAddress\": \"0xaf88d065e77c8cC2239327C5EDb3A432268e5831\",\n \"symbol\": \"USDC\",\n \"decimals\": 6\n },\n \"amountLimit\": \"1000000\",\n \"period\": \"daily\",\n \"startsAt\": \"2026-08-28T10:00:00.000Z\",\n \"expiresAt\": \"2026-08-28T10:00:00.000Z\",\n \"reason\": \"Requested by partner\"\n}"
response = http.request(request)
puts response.read_body{
"id": "vault_mandate_123",
"mandateId": "vault_mandate_123",
"policyId": "vault_policy_123",
"status": "pending_authorization",
"nextAction": {
"id": "vault_action_123",
"vaultId": "vault_123",
"policyId": "vault_policy_123",
"type": "sign_policy",
"status": "pending",
"nextAction": null,
"resourceVersion": 1,
"createdAt": "2026-08-28T10:00:00.000Z",
"updatedAt": "2026-08-28T10:00:00.000Z"
}
}{
"error": {
"code": "bad_request",
"message": "The request is invalid"
}
}{
"error": {
"code": "unauthorized",
"message": "Authentication is required"
}
}{
"error": {
"code": "forbidden",
"message": "The credential does not allow this operation"
}
}{
"error": {
"code": "not_found",
"message": "The resource was not found"
}
}{
"error": {
"code": "idempotency_conflict",
"message": "The Idempotency-Key was already used with a different request"
}
}{
"error": {
"code": "chain_config_missing",
"message": "The requested network is not configured for this environment"
}
}{
"error": {
"code": "rate_limited",
"message": "Too many requests"
}
}recipient, token, amountLimit and period (daily, weekly or monthly), and its window from startsAt to expiresAt. expiresAt must be after startsAt and no more than 366 days later.
The mandate is created as a policy update and is not active until the owner authorizes it and the policy becomes active. A mandate constrains Vault spending; it does not schedule recurring Payments. Idempotency-Key is required.Authorizations
HTTP Basic auth. Username is the Stableyard app ID. Password is the app secret. The optional Stableyard-Version request header must match the environment pin.
Headers
Retry key. Reuse a key only with the identical request; different input returns a conflict.
"request-key-001"
Optional contract-version assertion. Omit it to use the app environment's pinned version. A different supported version is accepted only after that environment is explicitly migrated.
2026-09-09 Path Parameters
Canonical account id returned by the Accounts API.
"acct_123"
Body
Show child attributes
Show child attributes
Show child attributes
Show child attributes
^[0-9]+$daily, weekly, monthly Mandate expiry. It must be after startsAt and no more than 366 days later.
280Response
Pending mandate policy update
Canonical mandate identifier. Equal to mandateId.
"vault_mandate_123"
"vault_mandate_123"
pending_authorization, pending_revocation, revoked Pending policy version that must be authorized and installed before the mandate change takes effect.
"vault_policy_123"
Show child attributes
Show child attributes