The Sudo API allows you to set up an asynchronous webhook to approve or decline transactions in real-time.

Your webhook endpoint can be set up by creating a funding source and setting that funding source while creating a new card or updating an existing one. Sudo creates and sends you an authorization.request event to approve or decline the authorization.

Authorization Requests

Your webhook must approve or decline each authorization request sent by responding with the appropriate response body. If Sudo does not receive a response from you within 4 seconds, the Authorization is automatically approved or declined based on your timeout settings in the card funding source.

If your main wallet balance does not have enough funds for the incoming authorization, it is automatically declined and you will not receive an event on your webhook.

In the example above, we set up an express server and exposed an endpoint /sudo/jitgateway to accept POST requests. This is listening to two event card.balance and authorization.request. Responding to the webhook request with a status 200 and a JSON body with statusCode 200 approves the authorization request.

Optionally, you can add some metadata to the authorization request to be passed to the transaction eventually approved or an ISO 8583 responseCode to be returned for the authorization.

The example response body above rejects a transaction with a response code 51 indicating Insufficient Balance.

Balance Requests

When a balance request is sent to your webhook, take a look at the user and account details then respond with the appropriate body indicating the user’s spendable balance.

Authorization Requests

When an authorization request is sent to your webhook, the amount requested is stored in pendingRequest object.

The top-level amount in the request is set to 0 and approved is false. Once you respond to the request, the top-level amount reflects the total amount approved or declined, the approved field is updated, and pendingRequest is set to null.