# Authorise a card payment (any issuer)

Source: https://immiscible.fly.dev/docs/api/post-issuing-wid-generic-authorize

`POST /issuing/:wid/generic/authorize`

Signed with `immiscible-signature`. Approved only against an unused receipt for the same payee and currency covering the amount.

## Authentication

Issuer signature. No bearer credential: the caller proves itself by signing the raw request body. Anything that does not verify is refused (or, on the card rail, declined) before the body is read. The `immiscible-signature: t=<unix seconds>,v1=<hex>` header: an HMAC-SHA256 of `<t>.<raw body>` with the workspace's issuer secret. Five minute window.

## Path parameters

- `wid` (string, required): Workspace id

## Request

curl:

```bash
curl -X POST "https://immiscible.fly.dev/issuing/$IMMISCIBLE_WORKSPACE/generic/authorize" \
  -H "immiscible-signature: $SIGNATURE" \
  -H "content-type: application/json" \
  -d '{
    "authRef": "auth_881",
    "cardRef": "card_19",
    "amount": 4200,
    "currency": "GBP",
    "merchant": {
      "name": "Grocer",
      "domain": "grocer.example",
      "mcc": "5411"
    },
    "eventId": "evt_77"
  }'
```

Node:

```ts
// signature: computed over the raw body, see the authentication note above
const res = await fetch('https://immiscible.fly.dev/issuing/$IMMISCIBLE_WORKSPACE/generic/authorize', {
  method: 'POST',
  headers: {
    'immiscible-signature': signature,
    'content-type': 'application/json',
  },
  body: JSON.stringify({
    authRef: 'auth_881',
    cardRef: 'card_19',
    amount: 4200,
    currency: 'GBP',
    merchant: {
      name: 'Grocer',
      domain: 'grocer.example',
      mcc: '5411',
    },
    eventId: 'evt_77',
  }),
});
const data = await res.json();
console.log(res.status, data);
```

Python:

```python
import requests

# signature: computed over the raw body, see the authentication note above
res = requests.post(
    "https://immiscible.fly.dev/issuing/$IMMISCIBLE_WORKSPACE/generic/authorize",
    headers={
        "immiscible-signature": signature,
        "content-type": "application/json",
    },
    json={
        "authRef": "auth_881",
        "cardRef": "card_19",
        "amount": 4200,
        "currency": "GBP",
        "merchant": {
            "name": "Grocer",
            "domain": "grocer.example",
            "mcc": "5411",
        },
        "eventId": "evt_77",
    },
)
print(res.status_code, res.json())
```

## Response

```json
{ "approved": true }
```
