# Record the merchant's consent to debit

Records that the customer agreed: the authorisation becomes live permission to debit this schedule. Body: `consentToDebit`, `achAuthorizationAccepted` and `termsAccepted` must ALL be true and `sourceReference` must name the funding source, or the database refuses it — an acceptance missing one of those is not an acceptance. The caller's IP and user agent are stamped from the request as the evidence of who agreed and from where. Legal from pending and not yet expired, so a second acceptance or a late one changes nothing and answers not found. Accepting is permission only: collecting the money is `post_payments_id_collect`, and recording money that arrived is `post_payments_id_record`.

Access class: `workspace`.

## Endpoint

`POST /v1/servicing-authorizations/{id}/accept`

## Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| id | path | string | Yes |

## Request body

Content type: `application/json`.

```json
{
  "body": {
    "achAuthorizationAccepted": true,
    "consentToDebit": true,
    "sourceReference": "string",
    "termsAccepted": true
  },
  "params": {
    ":id": "string"
  },
  "query": {}
}
```

## Responses

### 201

the action's answer

Content type: `application/json`.

```json
{
  "data": {
    "acceptedAt": "string",
    "acceptedIp": "string",
    "acceptedUserAgent": "string",
    "achAuthorizationAccepted": true,
    "amountMinor": 1,
    "authorizationText": "string",
    "cancelledAt": "string",
    "closedReason": "string",
    "consentToDebit": true,
    "contactChannel": "string",
    "contactTarget": "string",
    "counterpartyId": 1,
    "createdAt": "string",
    "currency": "string",
    "detail": {},
    "expiresAt": "string",
    "facilityId": 1,
    "frequency": "string",
    "id": 1,
    "revokedAt": "string",
    "scheduleId": 1,
    "sourceReference": "string",
    "status": "string",
    "termsAccepted": true,
    "updatedAt": "string"
  }
}
```

### default

a refusal: `{"error": "<what a person needs to read>"}`. 401 no credential, 402 the plan does not include this, 403 the seat does not, 404 the thing does not exist or is not yours to see.

Content type: `application/json`.

```json
{
  "error": "string"
}
```
