# Ask the merchant to authorise the debit

Raises the merchant's permission to debit this schedule — the signed authorisation a debit needs to be legal. Body: `expiresAt` is REQUIRED as an RFC3339 time, because an authorisation with no end never lapses; plus `contactChannel` (email, sms, in_person, phone) and `contactTarget` for where the request goes, `amountMinor` (MINOR UNITS, the ceiling per debit), `frequency` (daily_ach, daily, weekly, bi_weekly, monthly), `currency`, `authorizationText` — the exact words the customer is shown, stored so they cannot be edited out from under the consent — `sourceReference` for the funding source as the provider names it, and the `facilityId` / `counterpartyId` links. It opens pending and moves on with `post_servicing_authorizations_id_accept`. This authorises money; it does not move any.

Access class: `workspace`.

## Endpoint

`POST /v1/payment-schedules/{id}/servicing-authorizations`

## Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| id | path | string | Yes |

## Request body

Content type: `application/json`.

```json
{
  "body": {
    "amountMinor": 1,
    "authorizationText": "string",
    "contactChannel": "string",
    "contactTarget": "string",
    "counterpartyId": 1,
    "currency": "string",
    "expiresAt": "string",
    "facilityId": 1,
    "frequency": "string",
    "sourceReference": "string"
  },
  "params": {
    ":id": "string"
  },
  "query": {}
}
```

## Responses

### 201

the action's answer

Content type: `application/json`.

```json
{
  "data": {
    "acceptedAt": "string",
    "acceptedIp": "string",
    "acceptedUserAgent": "string",
    "achAuthorizationAccepted": true,
    "amountMinor": 1,
    "authorizationText": "string",
    "cancelledAt": "string",
    "closedReason": "string",
    "consentToDebit": true,
    "contactChannel": "string",
    "contactTarget": "string",
    "counterpartyId": 1,
    "createdAt": "string",
    "currency": "string",
    "detail": {},
    "expiresAt": "string",
    "facilityId": 1,
    "frequency": "string",
    "id": 1,
    "revokedAt": "string",
    "scheduleId": 1,
    "sourceReference": "string",
    "status": "string",
    "termsAccepted": true,
    "updatedAt": "string"
  }
}
```

### default

a refusal: `{"error": "<what a person needs to read>"}`. 401 no credential, 402 the plan does not include this, 403 the seat does not, 404 the thing does not exist or is not yours to see.

Content type: `application/json`.

```json
{
  "error": "string"
}
```
