Sample - Plaid API
POST/payment_initiation/consent/create

Create payment consent

Creates a payment consent that can authorize future payments on behalf of an end user. Supply the recipient, reference, and payment constraints, and use type to select sweeping or commercial payments. The consent starts with UNAUTHORISED status and must be authorized before it can initiate payments.

  • RetriesRetries up to 2×, 500ms backoff, 30s timeout.

10 body fields

Payment consent details, including its recipient, payment type, limits, optional payer details, and deprecated scope and option fields.

client_idstringoptional
Your Plaid API `client_id`. The `client_id` is required and may be provided either in the `PLAID-CLIENT-ID` header or as part of a request body.
secretstringoptional
Your Plaid API `secret`. The `secret` is required and may be provided either in the `PLAID-SECRET` header or as part of a request body.
recipient_idstringrequired
The ID of the recipient the payment consent is for. The created consent can be used to transfer funds to this recipient only.
user_idstringoptional
The `user_id` of the end user the payment consent is for, as returned by [`/user/create`](https://plaid.com/docs/api/users/#usercreate). The user must have a `name` and either an email address or a phone number. Payments created from this consent inherit this `user_id`. Required for new integrations.
referencestringrequired
A reference for the payment consent. This must be an alphanumeric string with at most 18 characters and must not contain any special characters.
scopesarray<PaymentInitiationConsentScope>deprecatedoptional
An array of payment consent scopes.
typestringoptional
Payment consent type. Defines possible use case for payments made with the given consent. `SWEEPING`: Allows moving money between accounts owned by the same user. `COMMERCIAL`: Allows initiating payments from the user's account to third parties.
Allowed:SWEEPINGCOMMERCIAL
constraintsobjectrequired
Limitations that will be applied to payments initiated using the payment consent.
optionsobjectdeprecatedoptional
(Deprecated) Additional payment consent options. Please use `payer_details` to specify the account.
payer_detailsobjectoptional
An object representing the payment consent payer details. Payer `name` and account `numbers` are required to lock the account to which the consent can be created.

2 status codes
200Returns the consent's unique `consent_id`, its initial status, and a unique `request_id`.
consent_idstringrequired
A unique ID identifying the payment consent.
statusstringrequired
The status of the payment consent. `UNAUTHORISED`: Consent created, but requires user authorisation. `REJECTED`: Consent authorisation was rejected by the bank. `AUTHORISED`: Consent is active and ready to be used. `REVOKED`: Consent has been revoked and can no longer be used. `EXPIRED`: Consent is no longer valid.
Allowed:UNAUTHORISEDAUTHORISEDREVOKEDREJECTEDEXPIRED
request_idstringrequired
A unique identifier for the request, which can be used for troubleshooting. This identifier, like all Plaid identifiers, is case sensitive.
defaultError response
error_typestringrequired
A broad categorization of the error. Safe for programmatic use.
Allowed:INVALID_REQUESTINVALID_RESULTINVALID_INPUTINSTITUTION_ERRORRATE_LIMIT_EXCEEDEDAPI_ERRORITEM_ERRORASSET_REPORT_ERRORBASE_REPORT_ERRORRECAPTCHA_ERROROAUTH_ERRORPAYMENT_ERROR
error_codestringrequired
The particular error code. Safe for programmatic use.
error_code_reasonstringoptional
The specific reason for the error code. Currently, reasons are only supported for OAuth-based item errors; `null` will be returned otherwise. Safe for programmatic use. Possible values: `OAUTH_INVALID_TOKEN`: The user's OAuth connection to this institution has been invalidated. `OAUTH_CONSENT_EXPIRED`: The user's access consent for this OAuth connection to this institution has expired. `OAUTH_USER_REVOKED`: The user's OAuth connection to this institution is invalid because the user revoked their connection.
error_messagestringrequired
A developer-friendly representation of the error code. This may change over time and is not safe for programmatic use.
display_messagestringrequired
A user-friendly representation of the error code. `null` if the error is not related to user action. This may change over time and is not safe for programmatic use.
request_idstringoptional
A unique ID identifying the request, to be used for troubleshooting purposes. This field will be omitted in errors provided by webhooks.
causesarrayoptional
In this product, a request can pertain to more than one Item. If an error is returned for such a request, `causes` will return an array of errors containing a breakdown of these errors on the individual Item level, if any can be identified. `causes` will be provided for the `error_type` `ASSET_REPORT_ERROR` or `CHECK_REPORT_ERROR`. `causes` will also not be populated inside an error nested within a `warning` object.
statusintegeroptional
The HTTP status code associated with the error. This will only be returned in the response body when the error information is provided via a webhook.
documentation_urlstringoptional
The URL of a Plaid documentation page with more information about the error
suggested_actionstringoptional
Suggested steps for resolving the error
required_account_subtypesarray<string>optional
A list of the account subtypes that were requested via the `account_filters` parameter in `/link/token/create`. Currently only populated for `NO_ACCOUNTS` errors from Items with `investments_auth` as an enabled product.
provided_account_subtypesarray<string>optional
A list of the account subtypes that were extracted but did not match the requested subtypes via the `account_filters` parameter in `/link/token/create`. Currently only populated for `NO_ACCOUNTS` errors from Items with `investments_auth` as an enabled product.

Error handling

recipient_id, reference, and constraints are required, and reference must contain 1 to 18 characters without special characters. type must be SWEEPING or COMMERCIAL; each periodic_amounts entry must include amount, interval, and alignment, and scopes must contain at least one unique deprecated scope when supplied.