> ## Documentation Index
> Fetch the complete documentation index at: https://docs.dakota.xyz/llms.txt
> Use this file to discover all available pages before exploring further.

# Simulate a card authorization

> Presents a card authorization to Dakota as if a merchant had swiped the
card. The authorization runs the production path: the authorization
service decides it, the hold lands on the wallet, and the
`card_transaction.created` webhook fires. Only the trigger is synthetic.

A decline is a normal outcome, not an HTTP error. A card with too little
spendable balance produces a `card_transaction` carrying the real
decline result, so read the transaction rather than the status code to
learn whether the authorization was approved.

An authorization holds more than its own amount. The hold carries a
buffer for network adjustments, so a 2 USD authorization needs about
2.60 USD of spendable balance. Fund the wallet with two faucet calls
before you simulate a 2 USD purchase.

The card must belong to a customer of the authenticated client.
Available in sandbox mode only.




## OpenAPI

````yaml /openapi.yaml post /sandbox/cards/simulate/transaction
openapi: 3.0.3
info:
  title: Dakota Platform API
  version: 1.0.0
  description: >-
    Combined API specification for Dakota Platform services:

    - Issuance API: Asset minting and burning operations

    - Onboarding API: Know Your Business/Customer verification

    - On/Off Ramp API: Managing on-ramp and off-ramp accounts

    - Recipients API: Managing destinations for KYB'd entities

    - Transactions API: Viewing transaction history across platform operations


    ## Authentication and API Headers


    All API endpoints require the following headers:


    - `X-Idempotency-Key`: Required for all POST endpoints to ensure request
    idempotency

    - `x-api-key`: Required for authentication across all endpoints


    Note: On /applications endpoints you need a token for authentication instead
    of a x-api-key

    - `x-application-token`: Required for authentication on public /applications
    endpoints (alternative to `x-api-key` where documented)



    ## Rate Limits


    Requests are rate limited per API key. Every response includes the following
    headers:


    | Header | Description |

    | --- | --- |

    | `X-RateLimit-Limit` | Maximum requests allowed in the current one-minute
    window. |

    | `X-RateLimit-Remaining` | Requests remaining in the current window. |

    | `X-RateLimit-Reset` | Absolute Unix timestamp (seconds since epoch) when
    the current rate-limit window resets. |


    When a request is throttled (`429`), responses also include `Retry-After`
    with seconds to wait before retrying.
servers:
  - url: https://api.platform.dakota.xyz
    description: Production environment
  - url: https://api.platform.sandbox.dakota.xyz
    description: Sandbox — safe for testing with simulated data
security:
  - ApiKeyAuth: []
tags:
  - name: Agentic Payments
    x-beta: true
    description: >-
      Beta — agent-driven payments: provision agents, draft and approve spending
      mandates, accept reviewed instructions, and manage scheduled payments.


      **Prerequisites:** Customer onboarded; signer groups attached for
      recognition.

      **Related:** Wallets, Signer Groups, Transactions
  - name: Mandates
    x-beta: true
    description: >-
      Beta — spending mandates: signed, signer-bound authorizations governing
      what may be spent, approved or cancelled by a second recognized signer (§8
      — the dual-control rule that every mandate mutation must be signed by a
      recognized signer OTHER than the bound one). Independent of agents and
      scheduled payments.


      **Prerequisites:** Signer groups attached for recognition.

      **Related:** Signer Groups, Transactions
  - name: Insights
    x-beta: true
    description: >-
      Beta — read-only insight: a deterministic report over a customer's agentic
      activity (funding balances, upcoming obligations, failures, mandate
      headroom and expiry), or — via `GET /insights` — over the whole client's
      book, with portfolio KPIs, daily series and a per-customer roll-up. Never
      moves money, never creates or changes anything.


      **Prerequisites:** Customer onboarded; insight is computed from the
      customer's scheduled payments, mandates, and wallets.

      **Related:** Agentic Payments, Mandates
  - name: Customers
    description: >-
      Manage customer entities representing businesses and organizations
      onboarded to Dakota.


      **Prerequisites:** Complete KYB via Onboarding endpoints before initiating
      money movement.

      **Related:** Onboarding, Recipients, Transactions, Accounts, Wallets
  - name: Wallets
    description: >-
      Manage wallets, balances, and wallet-to-signer-group relationships for
      custody and movement controls.


      **Prerequisites:** Customer must exist. Configure signer groups before
      policy-enforced workflows.

      **Related:** Signer Groups, Policies, Transactions, Customers
  - name: Transactions
    description: >-
      Create, cancel, and retrieve transaction records across account and wallet
      flows.


      **Prerequisites:** Accounts or destinations must be configured based on
      flow type.

      **Related:** Accounts, Recipients, Policies, Events
  - name: Recipients
    description: >-
      Manage recipient entities and destination rails used by customers for
      payouts and transfers.


      **Prerequisites:** Customer must be onboarded and active.

      **Related:** Customers, Transactions, Accounts, Onboarding
  - name: Accounts
    description: >-
      Manage account resources used for onramp, offramp, and swap operations.


      **Prerequisites:** Customer must be created and network/asset constraints
      must be known.

      **Related:** Customers, Transactions, Auto Transactions, Info
  - name: Auto Transactions
    description: >-
      Manage automated transaction configurations and execution history for
      account automation workflows.


      **Prerequisites:** Source account must exist and be configured for
      automation.

      **Related:** Accounts, Transactions, Events
  - name: Onboarding
    description: >-
      Manage KYB/KYC onboarding lifecycle, application documents, attestations,
      and verification steps.


      **Prerequisites:** Customer context and required entity/application
      metadata.

      **Related:** Customers, Exceptions, Recipients, Transactions
  - name: Policies
    description: >-
      Define and manage policy objects and rules used for transaction governance
      and risk controls.


      **Prerequisites:** Wallet and signer group resources should be configured
      for enforcement scenarios.

      **Related:** Wallets, Signer Groups, Transactions
  - name: Signer Groups
    description: >-
      Manage signer groups and signer assignments for multi-party authorization
      models.


      **Prerequisites:** Wallets should exist before linking signer groups.

      **Related:** Wallets, Policies, Transactions
  - name: Authentication
    description: >-
      Manage API authentication credentials and key lifecycle for platform
      access.


      **Prerequisites:** Client organization must be provisioned.

      **Related:** Users, Info
  - name: Users
    description: >-
      Manage client users, roles, and identity metadata for platform access
      control.


      **Prerequisites:** Auth credentials and client context must be
      established.

      **Related:** Authentication
  - name: Webhooks
    description: >-
      Manage outbound webhook targets and delivery configuration for event
      notifications.


      **Prerequisites:** Subscriber endpoint must be reachable and secured.

      **Related:** Events, Authentication
  - name: Payouts
    description: >-
      Manage where Dakota sends your accrued developer-fee payouts.


      **Prerequisites:** Auth credentials and client context must be
      established.

      **Related:** Events
  - name: RD Marketing Fee
    description: >-
      Everything behind your RD marketing fee: read what a month came to,
      declare the wallets you hold outside Dakota so the RD in them counts, and
      say where the fee should be sent.


      **Prerequisites:** Client must be in the RD marketing-fee programme. A
      month is readable once it has closed.

      **Related:** Wallets, Events
  - name: Self Serve
    description: >-
      Buy and track prepaid credits, and read the tiers and pricing they are
      sold at.


      **Prerequisites:** Auth credentials and client context must be
      established.

      **Related:** Billing
  - name: Events
    description: >-
      Retrieve event records emitted by platform operations for audit and
      troubleshooting.


      **Prerequisites:** Requesting client must have access to referenced
      resources.

      **Related:** Webhooks, Transactions, Onboarding
  - name: Info
    description: >-
      Read platform capability metadata, such as supported rails, networks, and
      assets.

      These operations are served under `/capabilities/*` - `GET
      /capabilities/countries`

      and `GET /capabilities/networks`. The tag name does not appear in the
      request paths.


      **Prerequisites:** Valid authentication headers.

      **Related:** Accounts, Transactions
  - name: Sandbox
    description: >-
      Trigger sandbox-only simulation endpoints for safe end-to-end integration
      testing with synthetic data. The sandbox host
      (`https://api.platform.sandbox.dakota.xyz`) also accepts a family of
      `X-Sandbox-*` request headers on most write endpoints (`Customers`,
      `Accounts`, `Transactions`, simulate endpoints) that let integrators drive
      deterministic failure modes — pick a preset via `X-Sandbox-Scenario`, or
      compose a custom one with
      `X-Sandbox-Error-Step`/`X-Sandbox-Error-Status`/`X-Sandbox-Error-Message`.
      `X-Sandbox-Instant-Completion` collapses async flows to a single
      synchronous step, and `X-Sandbox-Skip-Auto-Approval` keeps newly created
      KYB applications in `pending` for manual-review testing. All `X-Sandbox-*`
      headers are ignored in production.


      **Prerequisites:** Sandbox environment and test customer data.

      **Related:** Customers, Accounts, Transactions, Onboarding
  - name: Legal
    description: |-
      The legal documents customers accept — terms of service, privacy policy,
      e-sign notice, and partner agreements.

      Dakota publishes these here, and this is the authoritative source: the
      hosted onboarding flow, the dakota.xyz website, and your own integration
      all read the same revisions. Present the current revision to your customer
      before capturing their acceptance so the record reflects the text they
      actually saw.
paths:
  /sandbox/cards/simulate/transaction:
    post:
      tags:
        - Sandbox
      summary: Simulate a card authorization
      description: |
        Presents a card authorization to Dakota as if a merchant had swiped the
        card. The authorization runs the production path: the authorization
        service decides it, the hold lands on the wallet, and the
        `card_transaction.created` webhook fires. Only the trigger is synthetic.

        A decline is a normal outcome, not an HTTP error. A card with too little
        spendable balance produces a `card_transaction` carrying the real
        decline result, so read the transaction rather than the status code to
        learn whether the authorization was approved.

        An authorization holds more than its own amount. The hold carries a
        buffer for network adjustments, so a 2 USD authorization needs about
        2.60 USD of spendable balance. Fund the wallet with two faucet calls
        before you simulate a 2 USD purchase.

        The card must belong to a customer of the authenticated client.
        Available in sandbox mode only.
      operationId: simulateCardTransaction
      parameters:
        - $ref: '#/components/parameters/IdempotencyKeyHeader'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SandboxCardTransactionRequest'
            example:
              card_id: 1NFHrqBHb3cTfLVkFSGmHZqdDPi
              amount: '2.00'
              merchant:
                descriptor: COFFEE ROASTERS
                mcc: '5814'
                city: BROOKLYN
                state: NY
                country: USA
              type: authorization
      responses:
        '202':
          description: Card simulation accepted
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SandboxCardSimulationResponse'
              example:
                simulation_id: sim_card_01J8ZQ4T7K2M9X
                card_transaction_id: 2ZFHrqBHb3cTfLVkFSGmHZqdDPi
                status: completed
        '400':
          description: Invalid request
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: https://docs.dakota.xyz/api-reference/errors#invalid-request
                title: Invalid request
                status: 400
                detail: >-
                  amount must be a positive decimal with at most two decimal
                  places
                instance: >-
                  https://api.platform.dakota.xyz/sandbox/cards/simulate/transaction
                request_id: req_01hzy6y7v8w9x0y1z2a3b4c5d6
        '403':
          description: Not available outside sandbox mode
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: https://docs.dakota.xyz/api-reference/errors#forbidden
                title: Forbidden
                status: 403
                detail: Endpoint only available in sandbox mode
                instance: >-
                  https://api.platform.dakota.xyz/sandbox/cards/simulate/transaction
                request_id: req_01hzy6y7v8w9x0y1z2a3b4c5d6
        '404':
          description: Card not found
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: https://docs.dakota.xyz/api-reference/errors#not-found
                title: Card not found
                status: 404
                detail: Card not found
                instance: >-
                  https://api.platform.dakota.xyz/sandbox/cards/simulate/transaction
                request_id: req_01hzy6y7v8w9x0y1z2a3b4c5d6
        '409':
          description: |
            The card cannot present a transaction, the idempotency key was
            reused with different parameters, or the simulation under this
            idempotency key was abandoned before it recorded a result. The last
            one never resolves under the same key: retry it with a new
            `X-Idempotency-Key`.
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: https://docs.dakota.xyz/api-reference/errors#card-not-active
                title: Card Not Active
                status: 409
                detail: The card must be active to present a simulated transaction.
                instance: >-
                  https://api.platform.dakota.xyz/sandbox/cards/simulate/transaction
                request_id: req_01hzy6y7v8w9x0y1z2a3b4c5d6
        '422':
          description: |
            Amount over the sandbox per-transaction cap, or a client that is not
            provisioned at the provider yet.
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: >-
                  https://docs.dakota.xyz/api-reference/errors#sandbox-amount-cap-exceeded
                title: Sandbox Amount Cap Exceeded
                status: 422
                detail: >-
                  amount 25 exceeds sandbox cap of 2; reduce the amount and
                  retry
                instance: >-
                  https://api.platform.dakota.xyz/sandbox/cards/simulate/transaction
                request_id: req_01hzy6y7v8w9x0y1z2a3b4c5d6
        '429':
          description: |
            The client has used its card-simulation allowance for the day. The
            allowance restores itself within 24 hours.
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: >-
                  https://docs.dakota.xyz/api-reference/errors#sandbox-card-simulation-daily-limit
                title: Sandbox Card Simulation Daily Limit
                status: 429
                detail: >-
                  This client has used its card-simulation allowance for the
                  day. Retry within 24 hours.
                instance: >-
                  https://api.platform.dakota.xyz/sandbox/cards/simulate/transaction
                request_id: req_01hzy6y7v8w9x0y1z2a3b4c5d6
        '500':
          description: Platform failed to process the request
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: https://docs.dakota.xyz/api-reference/errors#internal-error
                title: Internal Error
                status: 500
                detail: An internal error occurred
                instance: >-
                  https://api.platform.dakota.xyz/sandbox/cards/simulate/transaction
                request_id: req_01hzy6y7v8w9x0y1z2a3b4c5d6
        '501':
          description: Card simulation is not enabled in this deployment
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: https://docs.dakota.xyz/api-reference/errors#not-implemented
                title: Not Implemented
                status: 501
                detail: card simulation is not available in this deployment yet
                instance: >-
                  https://api.platform.dakota.xyz/sandbox/cards/simulate/transaction
                request_id: req_01hzy6y7v8w9x0y1z2a3b4c5d6
        '502':
          description: Provider gRPC call failed
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: https://docs.dakota.xyz/api-reference/errors#provider-error
                title: Provider Error
                status: 502
                detail: provider sandbox service returned an error
                instance: >-
                  https://api.platform.dakota.xyz/sandbox/cards/simulate/transaction
                request_id: req_01hzy6y7v8w9x0y1z2a3b4c5d6
      externalDocs:
        description: Read full guide in docs
        url: >-
          https://docs.dakota.xyz/api-reference/sandbox/simulate-card-transactions
components:
  parameters:
    IdempotencyKeyHeader:
      name: x-idempotency-key
      in: header
      required: true
      description: >-
        Unique key to ensure request idempotency. If the same key is used within
        a certain time window, the original response will be returned instead of
        executing the request again.
      schema:
        type: string
        format: uuid
  schemas:
    SandboxCardTransactionRequest:
      type: object
      description: A request to present a simulated authorization on a card.
      required:
        - card_id
      properties:
        card_id:
          $ref: '#/components/schemas/KSUID'
        amount:
          type: string
          description: |
            Amount in decimal USD, at most two decimal places. Capped by the
            sandbox per-transaction limit.

            Required for every `type` except `balance_inquiry`, which moves no
            funds and so takes no amount: omit it, or send `"0"`. A
            `balance_inquiry` naming a non-zero amount is refused.
          example: '2.00'
        merchant:
          $ref: '#/components/schemas/SandboxCardMerchant'
        type:
          type: string
          default: authorization
          description: |
            Which network message the simulation opens. `authorization` is a
            standard purchase; `financial_authorization` clears immediately;
            `balance_inquiry` checks the spendable balance and moves no funds,
            so it is the one type that takes no `amount`.
          enum:
            - authorization
            - credit_authorization
            - financial_authorization
            - balance_inquiry
          example: authorization
        partial_approval_capable:
          type: boolean
          description: |
            Whether the merchant accepts a partial approval. A merchant that
            does gets an approval for the available balance instead of a
            decline.
    SandboxCardSimulationResponse:
      type: object
      description: An accepted card simulation.
      required:
        - simulation_id
        - status
      properties:
        simulation_id:
          type: string
          description: |
            Simulation identifier. Resolve it with
            `GET /sandbox/simulations/{simulation_id}`.
          example: sim_card_01J8ZQ4T7K2M9X
        card_transaction_id:
          $ref: '#/components/schemas/KSUID'
        status:
          $ref: '#/components/schemas/SandboxCardSimulationStatus'
    ProblemDetails:
      type: object
      required:
        - type
        - title
        - status
      description: |
        Error response following RFC 9457 Problem Details.
        Public API error responses use this format.
      example:
        type: https://docs.dakota.xyz/api-reference/errors#not-found
        title: Customer Not Found
        status: 404
        detail: Customer cst_2abc123 was not found in your organization.
        instance: https://api.platform.dakota.xyz/customers/cst_2abc123
        request_id: req_7f3a8b2c
      properties:
        type:
          type: string
          format: uri
          description: |
            URI reference identifying the problem type.
            Resolves to human-readable documentation.
          example: https://docs.dakota.xyz/api-reference/errors#not-found
        title:
          type: string
          description: >-
            Short, human-readable summary of the problem type. Stable across
            occurrences.
          example: Customer Not Found
        status:
          type: integer
          description: HTTP status code for this occurrence.
          example: 404
        detail:
          type: string
          description: Human-readable explanation specific to this occurrence.
          example: Customer cst_2abc123 was not found in your organization.
        instance:
          type: string
          format: uri
          description: The request path that triggered this error.
          example: https://api.platform.dakota.xyz/customers/cst_2abc123
        request_id:
          type: string
          description: Unique request identifier. Include when contacting support.
          example: req_7f3a8b2c
        errors:
          type: array
          description: Field-level validation errors (present for validation failures).
          items:
            $ref: '#/components/schemas/ValidationError'
        resolution_url:
          type: string
          format: uri
          description: |
            A link the customer can follow to CLEAR this error, present only on
            problems with a concrete self-service remedy.

            Today this is returned by
            `#terms-not-accepted`, where it points at the hosted flow in which
            the outstanding agreement can be signed. The link is token-gated and
            usable as-is — send the customer to it directly rather than parsing
            it out of `detail`.
          example: >-
            https://onboarding.dakota.xyz/applications/2abc123?token=tok_7f3a8b2c
        user_message:
          type: string
          description: |
            A plain-language rendition of `detail` written for the end
            customer, present when one exists for this error. `detail` names
            request fields and actions so a machine caller (such as a payment
            agent drafting proposals) can self-correct; `user_message` says the
            same thing without API vocabulary. Clients that relay errors into a
            human surface (chat, email, UI) should show `user_message` when
            present and fall back to `detail`.
          example: >-
            ACH payments pay out USD, so a USDC payout isn't possible on this
            rail. Change the payout currency to USD and try again.
    KSUID:
      type: string
      title: KSUID
      description: >-
        KSUID is a 27-character globally unique ID that combines a timestamp
        with a random component. Used for all entity identifiers in the Dakota
        platform.
      pattern: ^[0-9A-Za-z]{27}$
      minLength: 27
      maxLength: 27
      example: 1NFHrqBHb3cTfLVkFSGmHZqdDPi
    SandboxCardMerchant:
      type: object
      description: The merchant presenting a simulated card transaction.
      required:
        - descriptor
      properties:
        descriptor:
          type: string
          minLength: 1
          maxLength: 40
          description: Merchant name as it appears on the transaction.
          example: COFFEE ROASTERS
        mcc:
          type: string
          pattern: ^[0-9]{4}$
          description: Merchant category code, four digits.
          example: '5814'
        acceptor_id:
          type: string
          maxLength: 32
          description: Card acceptor identifier assigned by the acquirer.
        city:
          type: string
          maxLength: 32
          description: Merchant city.
          example: BROOKLYN
        state:
          type: string
          maxLength: 32
          description: Merchant state or region.
          example: NY
        country:
          type: string
          pattern: ^[A-Za-z]{3}$
          description: ISO 3166-1 alpha-3 country code.
          example: USA
    SandboxCardSimulationStatus:
      type: string
      description: |
        Where a card simulation stands. `completed` means the card transaction
        exists and this response names it. `pending` means the simulation was
        accepted but the transaction has not been materialized yet; poll
        `GET /sandbox/simulations/{simulation_id}` for the identifier. `failed`
        means the simulation was not accepted: a refusal the endpoint could
        classify comes back as a problem response instead, so `failed` is what
        an unclassified one looks like. It can still name a card transaction,
        because the response reports whichever transaction the call resolved.
        A declined card authorization is not a failed simulation: the
        simulation succeeded and the decline arrives on the card transaction.
      enum:
        - pending
        - completed
        - failed
    ValidationError:
      type: object
      required:
        - field
        - message
      properties:
        field:
          type: string
          description: Field path using dot notation for nested fields.
          example: bank_account.routing_number
        message:
          type: string
          description: Human-readable description of the field error.
          example: Routing number must be exactly 9 digits
        code:
          type: string
          description: Machine-readable error code for this field.
          example: invalid_format
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key

````