Submit merchant for approval and initialize auto underwriting process based on API user's ISO settings

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…

Submit Merchant for Approval

Submits a merchant's application into the approval workflow and triggers automated underwriting based on the API user's ISO configuration. The request requires a completed underwriting checklist and optionally accepts risk flag thresholds that the system monitors during processing. On success, the response returns the new merchant status.

Endpoint

POST /api/v1/merchant/approve

Authentication

Basic HTTP Authentication required.
Encode username:password in Base64 and pass in the Authorization header:

Authorization: Basic {base64(username:password)}

When to use

Use this endpoint after the merchant application has been fully completed and all required documentation has been reviewed. The underwriting checklist captures what documents and checks have been completed by the underwriter. The optional riskFlagsSetting block configures automated monitoring thresholds (such as large transaction alerts and chargeback percentage limits) that will apply to the merchant once approved. This is a critical step in the boarding flow — merchants cannot be fully onboarded without passing through this approval gate.

Request Body

Top-level fields

FieldTypeRequiredDescription
idinteger (int32)YesMerchant profile ID to submit for approval
checklistobjectYesUnderwriting checklist documenting what has been reviewed
riskFlagsSettingobjectNoOptional risk monitoring thresholds to apply after approval

UnderwritingChecklist fields

FieldTypeRequiredDescription
underwritersApprovalNotesstringYesNotes from the underwriter supporting the approval decision
lowVolumeLowRiskbooleanNoMerchant is classified as low volume, low risk
highVolumeLowRiskbooleanNoMerchant is classified as high volume, low risk
lowVolumeHighRiskbooleanNoMerchant is classified as low volume, high risk
highVolumeHighRiskbooleanNoMerchant is classified as high volume, high risk
signedandCompleteMerchantApplicationbooleanNoSigned and complete merchant application received
preprintedCheckorBankReferenceLetterbooleanNoVoided check or bank reference letter received
marketingmaterialbooleanNoMarketing material reviewed
siteSurveybooleanNoSite survey completed
matchInquirybooleanNoMATCH list inquiry completed
ofacQuerybooleanNoOFAC query completed
legalInformationbooleanNoLegal information verified
creditReportforPrincipalbooleanNoCredit report for principal obtained
thirdPartySoftwareNameAndVersionstringNoName and version of third-party payment software used
pcidssCompliantbooleanNoMerchant is PCI DSS compliant
isMerchantPCIDSSCompliantbooleanNoAlternate PCI DSS compliance flag
nameofQSAASVstringNoName of the QSA or ASV that performed PCI assessment
calledDBAbooleanNoVerified DBA via phone call
calledHomePhoneNumberCreditReportbooleanNoCalled home phone number from credit report
calledBankbooleanNoCalled the merchant's bank
calledPriorProcessorbooleanNoCalled prior processor for reference
signerstateIDbooleanNoSigner state ID verified
businessFinancialsbooleanNoBusiness financials reviewed
personalFinancialsbooleanNoPersonal financials reviewed
thirdMonthsBankStatementsbooleanNoThree months of bank statements received
thirdMonthsProcessingStatementsbooleanNoThree months of processing statements received
primarySupplierReferencebooleanNoPrimary supplier reference obtained
executiveSummarybooleanNoExecutive summary reviewed
businessPlanbooleanNoBusiness plan reviewed
processingStatementsReceivedMonthsstring (enum)NoMonths of processing statements received: Zero, OneTwo, ThreeFour, FivePlus
bankStatementsReceivedMonthsstring (enum)NoMonths of bank statements received: Zero, OneTwo, ThreeFour, FivePlus
financialsReceivedMonthsstring (enum)NoMonths of financials received: Zero, OneTwo, ThreeFour, FivePlus
companysOfficialDetailsbooleanNoCompany official details verified
billedDescriptorbooleanNoBilling descriptor reviewed
customerServiceTelephoneNumberbooleanNoCustomer service phone number verified
termsAndConditionsbooleanNoTerms and conditions reviewed on website
clearPostingbooleanNoClear posting policy verified
listingOfProductsbooleanNoProduct listing reviewed
websitePayPagebooleanNoWebsite pay page reviewed
domainRegisteredUnderCompanybooleanNoDomain registered under company name
requireUsernamePasswordbooleanNoSite requires username/password for access
checkVisaMasterCardAndAllbooleanNoAccepted card brands verified on site
checkLinksToOtherWebsitesbooleanNoLinks to other websites checked
checkHowLongOfferRefundsbooleanNoRefund policy duration verified
checkBillingInformationbooleanNoBilling information verified
checkAlexaComRatingbooleanNoAlexa.com rating checked
checkNotInvolvedIllegalActivitybooleanNoConfirmed not involved in illegal activity
complianceLegalRegulationsbooleanNoCompliance with legal regulations confirmed
complianceRegulationsCreditCardCompaniesbooleanNoCompliance with card brand regulations confirmed
nameAndLegalConsistentlybooleanNoBusiness name and legal name consistent
discloseProductLinesOrServicesbooleanNoProducts/services clearly disclosed
disclosePricingModelbooleanNoPricing model disclosed
disclosePriceAndComponentsbooleanNoPrice components disclosed
websiteSecuritybooleanNoWebsite security measures verified
isCcardholderVerifiedbooleanNoCardholder verification in place
isCardCheckDigitbooleanNoCard check digit validation active
isIdentificationCardholderbooleanNoCardholder identification process in place
isDescriptorListedOnPaypagebooleanNoDescriptor listed on pay page
isOnlineCancellationbooleanNoOnline cancellation option available
isCancellationPolicybooleanNoCancellation policy disclosed
isOnlineCancellationSubscriptionProcessbooleanNoSubscription cancellation process available online
freeCheapInitialTrialsOfferedbooleanNoFree or discounted trial offers present
isProcessCardholderNotifiedbooleanNoCardholder notified before processing
isDetailedInformationbooleanNoDetailed transaction information provided
isAutoRenewalMechanismbooleanNoAuto-renewal mechanism disclosed
reservebooleanNoReserve requirement applies
reserveTypestring (enum)NoType of reserve: Upfront, Rolling, NA
reservePercentageinteger (int32)NoReserve percentage (e.g., 10 for 10%)
reservePeriodstring (enum)NoReserve period in months: One through Twelve
reserveTargetAmountinteger (int32)NoTarget reserve dollar amount

RiskFlagsSetting fields

FieldTypeRequiredDescription
largeTransactionnumber (double)NoAlert threshold for a single large transaction amount
averageTicketnumber (double)NoExpected average ticket amount
keyedPercentageTransactionByVolumenumber (double)NoMax acceptable keyed transaction percentage by volume
keyedPercentageTransactionByCountnumber (double)NoMax acceptable keyed transaction percentage by count
monthlyVolumenumber (double)NoExpected monthly processing volume
maxMonthlyVolumenumber (double)NoMaximum allowed monthly processing volume
chargebacksPercentageTransactionByVolumenumber (double)NoMax acceptable chargeback rate by volume
chargebacksPercentageTransactionByCountnumber (double)NoMax acceptable chargeback rate by count
enableForeignTransactionbooleanNoWhether foreign transactions are permitted
enableOnHoldTransactionbooleanNoWhether on-hold transactions trigger alerts
enableForcedTransactionbooleanNoWhether forced transactions are permitted
enableStaleAuthorizationbooleanNoWhether stale authorization alerts are enabled
enableDeclinedTransactionbooleanNoWhether declined transaction alerts are enabled
{
  "id": 48291,
  "checklist": {
    "underwritersApprovalNotes": "All required documentation received and verified. Merchant is a low-risk retail business with 3 years of clean processing history.",
    "lowVolumeLowRisk": true,
    "signedandCompleteMerchantApplication": true,
    "preprintedCheckorBankReferenceLetter": true,
    "matchInquiry": true,
    "ofacQuery": true,
    "creditReportforPrincipal": true,
    "pcidssCompliant": true,
    "thirdMonthsBankStatements": true,
    "thirdMonthsProcessingStatements": true,
    "bankStatementsReceivedMonths": "ThreeFour",
    "processingStatementsReceivedMonths": "ThreeFour",
    "reserve": false,
    "reserveType": "NA"
  },
  "riskFlagsSetting": {
    "largeTransaction": 5000.00,
    "averageTicket": 85.00,
    "monthlyVolume": 50000.00,
    "maxMonthlyVolume": 75000.00,
    "chargebacksPercentageTransactionByVolume": 1.0,
    "chargebacksPercentageTransactionByCount": 1.0,
    "enableForeignTransaction": false,
    "enableDeclinedTransaction": true
  }
}

Response

200 OK

FieldTypeDescription
data.statusstring (enum)Resulting merchant status after approval submission
data.successbooleantrue if the approval was successfully initiated
statusstringHTTP status label
errorstringError message if the request failed
warningstringNon-fatal warning message, if any
validationResultsarrayList of field-level validation errors
requestIdintegerUnique identifier for this API request

Possible data.status values include: Approved, PreApproved, Declined, Pending, UnderReview, Underwriting, ConditionallyApproved, RequestChanges, and others.

{
  "data": {
    "status": "Underwriting",
    "success": true
  },
  "status": "OK",
  "error": null,
  "warning": null,
  "validationResults": [],
  "requestId": 90512
}

Error Codes

CodeWhen it happens
400id or checklist is missing, or underwritersApprovalNotes is empty
401Invalid or missing Basic Auth credentials
403User does not have permission for this operation
404Merchant with the specified id not found
500Internal server error

Common Mistakes

  • Omitting underwritersApprovalNotes inside the checklist object — it is the only required field within the checklist and cannot be blank.
  • Setting reserveType without setting reserve: true — if a reserve applies, both fields should be populated consistently.
  • Using an invalid enum value for reservePeriod (e.g., passing "4" instead of "For") — use the exact enum string values.
  • Not completing the merchant application data before calling this endpoint — the merchant record must be fully populated before approval can succeed.

Related Endpoints

  • GET /api/v1/merchant/status — check the current merchant status
  • GET /api/v1/merchant/underwritingNotes — retrieve existing underwriting notes
  • POST /api/v1/merchant/note — add notes to the merchant record before submitting for approval

Example

curl -X POST https://hq.staging.netevia.dev/api/v1/merchant/approve \
  -H "Authorization: Basic $(echo -n 'username:password' | base64)" \
  -H "Content-Type: application/json" \
  -d '{
    "id": 48291,
    "checklist": {
      "underwritersApprovalNotes": "All documentation verified. Low-risk retail merchant approved.",
      "lowVolumeLowRisk": true,
      "signedandCompleteMerchantApplication": true,
      "matchInquiry": true,
      "ofacQuery": true,
      "reserve": false,
      "reserveType": "NA"
    },
    "riskFlagsSetting": {
      "monthlyVolume": 50000.00,
      "maxMonthlyVolume": 75000.00,
      "chargebacksPercentageTransactionByCount": 1.0
    }
  }'
Body Params
int32
required
checklist
object
required
riskFlagsSetting
object
Headers
string
enum
Defaults to application/json

Generated from available response content types

Allowed:
string
enum
Defaults to application/json

Generated from available request content types

Allowed:
Response

Language
Credentials
Basic
base64
:
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
text/json