REST APIPolicyWallet Policy

PUT

Updates whitelist policy rules across multiple wallets in a single request. Only advancedWhitelist rules are supported.

Body Params

object

  • updates array of objects required
    updates object
    • walletId string required
      The ID of the wallet to update
    • coin string required
      The coin type for this rule
    • id string required
      The id of the rule
    • type string enum required
      Must be advancedWhitelist
      advancedWhitelist
    • action object required
      The action to take when the rule is triggered
      action object
      • type string required
      • userIds array of strings
    • condition object required
      The condition for the rule (add/remove address)
      condition object
      • add object
        Entry to add to the whitelist
        add object
        • item string required
        • type string required
        • metaData map of strings
      • remove object
        Entry to remove from the whitelist
        remove object
        • item string required
        • type string
      • verifyItems object
        verifyItems object
        • items array of strings required
    • lockDate string
      ISO date string for when the whitelist policy locks. Omit to auto-lock after ~48h.
    • generatePolicy boolean
      When true, creates the wallet whitelist policy in the Policy Service if it doesn't exist

Responses

200
OK

Response Body

object

Response for bulk policy rule update
  • successes array of objects
  • failures array of objects
    failures object
    • walletId string required
    • error string required
  • pendingAdminApproval object
    Pending approval created for multi-wallet updates requiring admin approval
    pendingAdminApproval object
    • id string required

      matches ^[0-9a-f]{32}$

    • coin string
      A cryptocurrency or token ticker symbol.
    • wallet string

      matches ^[0-9a-f]{32}$

    • walletType string
    • walletSubType string
      The subtype of the wallet (e.g., custodialHot)
    • wallets array of strings
    • enterprise string

      matches ^[0-9a-f]{32}$

    • organization string

      matches ^[0-9a-f]{32}$

    • organizationName string
      The organization name
    • bitgoOrg string
      The BitGo organization
    • creator string required

      matches ^[0-9a-f]{32}$

    • createDate string date-time required
      The creation date of the pending approval
    • approvedDate string date-time
      The date when the approval was granted
    • updatedAt string date-time
      The date when the approval was last updated (any update, not just processing)
    • keyCurve string enum
      The key curve of the coin attached to this pending approval
      secp256k1ed25519bls12_381
    • info object required
      Information about the pending approval
      info object
      • type string enum required
        userChangeRequesttransactionRequesttransactionRequestFullpolicyRuleRequestupdateApprovalsRequiredRequestupdateEnterpriseRequestupdateOrganizationRequestgenericRequestenterpriseInviteRequestupdateWalletSettingRequestupdateWalletTagsRequest
      • userChangeRequest object
        userChangeRequest object
        • action string
          The action taken
        • permissions array of strings
        • userChanged string
          The user that changed
      • transactionRequest object
        transactionRequest object
        • buildParams object
          The build parameters for the transaction
        • coinSpecific object
          Coin-specific details
        • comment string nullable
          The comment for the transaction request
        • fee object
          The fee for the transaction
        • isUnsigned boolean nullable
          Indicates if the transaction is unsigned
        • policyUniqueId object
          The unique ID for the policy
        • recipients array of objects
          recipients object
          • address string
            The address of the recipient

            up to 250 characters

          • amount object
            The amount to be transferred
          • data string
            Additional data for the transaction
        • requestedAmount object
          The requested amount
        • sourceWallet object
          The source wallet
        • triggeredPolicy object
          The triggered policy for the transaction
        • validTransaction string
          Indicates if the transaction is valid
        • validTransactionHash string
          The hash of the valid transaction
        • verificationItems array of strings nullable
          The verification items for the transaction
        • verificationRuleId string nullable
          The ID of the verification rule
        • videoApprovers array of objects
      • transactionRequestFull object
        transactionRequestFull object
        • intent object
          The intent of the transaction request

          ONE OF

          • sequenceId string
            Client-assigned sequence identifier for idempotency.
          • comment string
            Human-readable memo attached to the transaction.
          • nonce string or number
            Override the on-chain nonce for this transaction.
          • recipients array of objects required
            recipients object
            • address object required
              address object
              • address string
              • option map of objects
                option object
                • <key> object
            • amount object required
              amount object
              • value string required
              • symbol string required
            • data string
          • intentType string enum required
            Must be "payment".
            payment
        • policyUniqueId string
          The unique ID for the policy
        • txRequest object
          The transaction request details

          ONE OF

          • intent object
            The intent of the transaction request

            ONE OF

            • unspents array of strings
            • intentType string enum required
              Must be "consolidate".
              consolidate
            • receiveAddress string required
              Destination address for consolidated funds. Must be a wallet-owned address.
            • senderAddressIndex number
              Index of the wallet address to use as the sender.
            • consolidateId string
              Opaque identifier used to correlate consolidation requests.
            • recipients array of objects
              recipients object
              • tokenData object
                tokenData object
                • tokenQuantity string required
                • tokenType string required
                • tokenId string
                • tokenName string required
                • tokenContractAddress string
                • decimals number
              • address object required
                address object
                • Same shape as Address.
              • amount object required
                amount object
                • Same shape as Amount.
              • data string
            • keepAlive boolean
              When true, leaves a small amount in the source address to keep it alive.
            • nonce string or number
              Override the on-chain nonce for this transaction.
          • unsignedTxs array of objects
            unsignedTxs object
            • parsedTx object required
              parsedTx object
              • inputs array of objects required
                inputs object
                • valueString string required
                • _id string
                • address string
                • chain number
                • derivationIndex number
                • index number
                • value number
              • minerFee string or number required
              • outputs array of objects required
                outputs object
                • valueString string required
                • address string
                • change boolean
                • coinName string
                • data string
                • isPayGo boolean
                • value number
                • wallet string
                • walletV1 string
                • baseAddress string
                • enterprise string
              • spendAmount string or number required
              • gasPrice number
              • hasUnvalidatedData boolean
              • payGoFee string or number
              • spendAmounts array of objects
                spendAmounts object
                • <key> object
              • type string
            • serializedTxHex string required
              The unsigned transaction as a hex string.
            • signableHex string required
              The portion of a transaction used to generate a signature (may or may not be the same as serializedTxHex) as a hex string.
            • derivationPath string
              A bip32 path.
            • coinSpecific object
              Coin specific information.
              coinSpecific object
              • nonceAddress string
              • stakingAddress string
              • signature string
              • <key> object
            • feeInfo object
              feeInfo object
              • fee string or number required
              • feeString string required
          • signatureShares array of objects
            signatureShares object
            • vssProof string
              The VSS proof of the signature share
            • privateShareProof string
              The private share proof
            • publicShare string
              The public share
            • from string enum required
              The source of the signature share.
              userbackupbitgo
            • to string enum required
              The recipient of the signature share.
              userbackupbitgo
            • share string required
              The signature share
          • commitmentShares array of objects
            commitmentShares object
            • type string enum required
              The type of the commitment share
              commitment
            • from string enum required
              The source of the commitment share
              userbackupbitgo
            • to string enum required
              The recipient of the commitment share.
              userbackupbitgo
            • share string required
              The commitment share.
          • txHashes array of strings
          • apiVersion string enum
            The API version of the transaction request
            litefull
          • txRequestId string uuid required
            A unique ID for the TxRequest document across all wallets. The combination of the txRequestId and version will always be unique.
          • idempotencyKey string
            The idempotency key of the transaction request
          • walletId string required
            The id of the Wallet the TxRequest is for.
          • walletType string enum
            The type describes who owns the keys to the wallet associated to the TxRequest.
            backingcoldcustodialcustodialPairedhotadvancedtrading
          • version number required
            The version of the transaction request
          • enterpriseId string
            If the wallet that owns the TxRequest is owned by an enterprise then this is the Id of said enterprise.

            matches ^[0-9a-f]{32}$

          • state string enum required
            pendingApprovalcanceledrejectedinitializedpendingDeliverydeliveredpendingUserSignaturependingUserCommitmentpendingUserRSharependingUserGSharereadyToSendsignedfailed
          • date string date-time required
            The date and time this version of the TxRequest document was created.
          • createdDate string date-time required
            The date and time the version 1 TxRequest document was created.
          • userId string required
            The Id of the User that produced this version of the TxRequest document. Could have created a new document or updated an existing document.
          • initiatedBy string required
            The Id of the User that originally created the TxRequest document (initiated the TxRequest).
          • updatedBy string required
            The Id of the User that last updated the TxRequest document. This is an alias for the userId field.
          • intent object
            The intent of the transaction request
          • intents array of objects required
          • pendingApprovalId string
            The id of the Pending Approval that was created for the TxRequest if one was required.
          • policiesChecked boolean
          • latest boolean required
            Indicates if this is the latest transaction request
          • isCanceled boolean
            True, if the transaction request is canceled.
          • initiatedByDAppClient boolean
            True when the txRequest was initiated by a dApp OAuth client (e.g. Narval).
          • txChannel object
            Immutable DeFi / marketplace channel classification (DEFI-300).
            txChannel object
            • clientId string
              OAuth dApp client id (Narval).
            • connector string enum
              External entry connector (narval, walletconnect). Omitted for internal BitGo flows.
              narvalwalletconnect
            • defiAction string enum
              approvedepositwithdraw
            • protocol string enum
              DeFi protocol (morpho, aave, concrete).
              morphoaaveconcrete
            • source string enum required
              internalexternal
            • type string enum required
              defi
            • vaultId string
            • walletConnectRequestId string
              defi-service walletconnect_requests.id when supplied on the intent.
        • txRequestId string uuid required
          The ID of the transaction request
        • verificationItems array of strings
        • verificationRuleId string
          The ID of the verification rule
        • videoApprovers array of strings
        • walletRebalanceEventId string
          The ID of the wallet rebalance event
      • policyRuleRequest object
        policyRuleRequest object
        • action string
          The action of the policy rule request
        • update object
          The update details of the policy rule request (single-wallet)
          update object
          • action object
            The action of the policy rule
            action object
            • type string enum required
              The type of the action
              denygetApprovalgetEnterpriseUserApprovalgetUserRoleApprovalgetAnyApprovalgetFinalApprovalgetVideoApprovalgetIdVerificationverifyWalletRebalancegetCustodianApprovalgetCustodialSignaturetriggerWebhookNotificationperformLivenessVerificationrecommendBackingWalletRoutinggetManualTrustReviewgetManualSupportReviewgetSupportManagerApprovalgetVideoApprovalFromSupport
            • userIds array of strings
          • coin string
            A cryptocurrency symbol or token ticker symbol
          • condition object
            The condition of the policy rule

            ONE OF

            • add string
            • remove string
            • metaData map of objects
              metaData object
              • <key> map of objects
                value object
                • <key> object
          • generatePolicy boolean
            Should generate new whitelist policy when generatePolicy is undefined *
          • id string
            The ID of the policy rule
          • lockDate string date
          • type string enum
            The type of the API rule
            advancedWhitelistcoinAddressWhitelistcoinAddressBlacklist
          • walletId string
            Optional walletId field for multi-wallet updates
        • updates array of objects
          updates object
          • action object
            The action of the policy rule
            action object
            • type string enum required
              The type of the action
              denygetApprovalgetEnterpriseUserApprovalgetUserRoleApprovalgetAnyApprovalgetFinalApprovalgetVideoApprovalgetIdVerificationverifyWalletRebalancegetCustodianApprovalgetCustodialSignaturetriggerWebhookNotificationperformLivenessVerificationrecommendBackingWalletRoutinggetManualTrustReviewgetManualSupportReviewgetSupportManagerApprovalgetVideoApprovalFromSupport
            • userIds array of strings
          • coin string
            A cryptocurrency symbol or token ticker symbol
          • condition object
            The condition of the policy rule

            ONE OF

            • add string
            • remove string
            • metaData map of objects
              metaData object
              • <key> map of objects
                value object
                • <key> object
          • generatePolicy boolean
            Should generate new whitelist policy when generatePolicy is undefined *
          • id string
            The ID of the policy rule
          • lockDate string date
          • type string enum
            The type of the API rule
            advancedWhitelistcoinAddressWhitelistcoinAddressBlacklist
          • walletId string
            Optional walletId field for multi-wallet updates
      • updateApprovalsRequiredRequest object
        updateApprovalsRequiredRequest object
        • requestedApprovalsRequired number
          The number of requested approvals required
      • updateEnterpriseRequest object
        updateEnterpriseRequest object
        • action string enum
          addupdateremove
        • email string
          The email of the user
        • isVideoIdUser boolean
          Indicates if the user is a video ID user
        • permissions string enum
          The permissions associated with the update
          adminauditorwallet.create
        • userId string
          The ID of the user
      • updateOrganizationRequest object
        updateOrganizationRequest object
        • action string enum
          addupdateremove
        • email string
          The email of the user
        • inviterInfo object
          CaaS org add-invite only (POST /api/v2/organization/{orgId}/user); UMS org user changes use genericRequest.
          inviterInfo object
          • email string required
          • fullName string required
          • id string required
        • role string enum
          The role of the user in the organization
          serviceUseradminmembercustomer
        • userId string
          The ID of the user
      • genericRequest object
        genericRequest object
        • anchors array of objects
          anchors object
          • anchorType string enum required
            The type of the anchor
            policyRuleIdsettlementIdcrossChainRecoveryId
          • key string required
            The key of the anchor
          • value string required
            The value of the anchor
        • changeType string enum
          The type of change requested
          createupdatedeleteunlockbulkUnlockbulkArchiveduplicate
        • currentId string
          The current ID associated with the request
        • description string
          The description of the request
        • metadata map of objects
          The metadata of the request
          metadata object
          • <key> string or number or boolean or array of strings
        • proposedId string
          The proposed ID associated with the request
        • resources array of objects
          resources object
          • currentId string
          • metadata map of objects
            metadata object
            • <key> string or number or boolean or array of strings
          • proposedId string
        • resourceType string
          The resource type of the request
      • enterpriseInviteRequest object
        enterpriseInviteRequest object
        • action string enum
          addupdateremove
        • email string
          The email of the user
        • enterpriseInfo object
          Additional info used by the client accepting the invite
          enterpriseInfo object
          • id string required
          • invitedBy object required
            Inviter snapshot on CaaS org add-invite inviterInfo and enterprise invite invitedBy. Not used for UMS genericRequest.
            invitedBy object
            • id string required
            • email string required
            • fullName string required
          • name string required
          • requiredVerificationStep string required
          • userKycState string
        • isVideoIdUser boolean
          Indicates if the user is a video ID user
        • permissions string enum
          The permissions associated with the invite
          adminauditorwallet.create
        • userId string
          The ID of the user
      • updateWalletSettingRequest object
        updateWalletSettingRequest object
        • userKeySigningRequired object
          userKeySigningRequired object
          • newValue boolean required
          • oldValue boolean required
      • updateWalletTagsRequest object
        updateWalletTagsRequest object
        • action string enum required
          Whether to add or remove the specified tags
          addremove
        • customTags array of strings required
    • state string required
      The state of the pending approval

      ONE OF

      string enum

    • scope string enum required
      What kind of entity the Pending Approval is tied to
      enterprisewalletorganizationglobal
    • userIds array of strings
    • approvalsRequired number

      >= 1

    • walletLabel string
      Label for the wallet
    • addressLabels array of objects
      addressLabels object
      • address string required

        up to 250 characters

      • label string required
        The label
      • walletLabel string
        The wallet label
    • resolvers array of objects
      resolvers object
      • autoApproved boolean
        Whether the resolution was auto approved
      • date string date-time
        The date of resolution
      • resolutionAction string enum
        Action taken during resolution
        approverejectskipfail
      • resolutionMemo string
        Memo regarding the resolution
      • resolutionType string enum required
        The type of resolution
        pendingawaitingSignaturependingFinalApprovalpendingCustodianApprovalpendingVideoApprovalpendingIdVerificationpendingLivenessVerificationpendingManualTrustReviewpendingManualSupportReviewpendingVideoApprovalFromSupport
      • user string
        The user who resolved the approval
      • videoApprover string
        The approver of the video resolution
      • videoException string
        Exception details for the video
      • videoLink string
        Link to the resolution video
    • approvers array of strings
    • singleRunResults array of objects
      singleRunResults object
      • ruleId string
        The rule ID
      • triggered boolean
        Whether the rule was triggered
    • txRequestId string uuid
      Transaction request ID
    • videoId object
      ID for the video related to the approval
      videoId object
      • date string date-time
        The date of the video ID
      • user string
        The user associated with the video ID
      • videoApprover string
        The approver of the video
      • videoException string
        The exception related to the video
      • videoLink string
        The link to the video
    • version number
      Version of the pending approval
    • policyEvaluationId string
      ID for the policy evaluation
    • actions array of objects
      actions object
      • approvers array of strings
      • excludedApprovers array of strings
      • id string required
        The ID of the action
      • name string required
        The name of the action
      • operator string enum
        The operator of the action
        ANDOR
      • parameters object required
        The parameters of the action
        parameters object
        • minRequired string or number
        • userIds array of strings
        • initiatorIsAllowedToApprove boolean
        • webhookURL string

          at least 1 characters

        • livenessCheckUser string enum
          transactionInitiatorwalletAdminsvideoIdUsersenterpriseAdmin
        • isFallback boolean
        • walletSubtype string enum
          custodialColdcustodialHotlightningCustody
        • userRoleIds array of strings
      • resolvers array of objects
        resolvers object
        • autoApproved boolean
          Whether the resolution was auto approved
        • date string date-time
          The date of resolution
        • resolutionAction string enum
          Action taken during resolution
          approverejectskipfail
        • resolutionMemo string
          Memo regarding the resolution
        • resolutionType string enum required
          The type of resolution
          pendingawaitingSignaturependingFinalApprovalpendingCustodianApprovalpendingVideoApprovalpendingIdVerificationpendingLivenessVerificationpendingManualTrustReviewpendingManualSupportReviewpendingVideoApprovalFromSupport
        • user string
          The user who resolved the approval
        • videoApprover string
          The approver of the video resolution
        • videoException string
          Exception details for the video
        • videoLink string
          Link to the resolution video
      • status string enum required
        The status of the action
        SKIPPEDPENDINGNOT_NEEDEDCOMPLETECANCELLEDFAILEDAUTO_CANCELLED
    • resolutionOrder array of objects
      resolutionOrder object
      • actions array of strings required
    • useLegacyPolicyEngine boolean
      Flag to use legacy policy engine
    • videoCallId string
      ID for the video call
    • lastUpdated string date-time
      The last date the approval was processing
    • freeze object
      The freeze state
      freeze object
      • actions array of objects
        actions object
        • reason string
        • state string enum
          frozenunFrozen
        • time string date-time
        • userId string
        • username string
      • state string enum
        frozenunFrozen
    • memo array of objects
      memo object
      • text string required
        The text of the memo
      • time string date-time required
        The time the memo was created
      • userId string required
        The user ID of the admin who created the memo
      • username string required
        The username of the admin who created the memo
    • associatedInquiries array of objects
      associatedInquiries object
      • inquiryId string required
      • inquiryStatus string enum required
        completedfailed
      • inquirySubType string enum required
        withdrawalLivenessCheckmanagePolicyLivenessCheckgovIdSelfie
      • inquiryType string enum required
        livenessCheck
    • securityControlEvents array of objects
      securityControlEvents object
      • control string
        The security control that was evaluated
      • date string date-time required
        The date the event was recorded
      • ip string
        The IP address of the user
      • message string
        Message from the security control
      • result string enum required
        Whether the user was allowed or blocked
        allowedblocked
      • user string required
        The user who triggered the security control check
  • travelRulePendingApprovals array of objects
400
Bad Request

Response Body

object

  • name string
    Error code
  • context map of objects required
    Properties that apply to a specific error name
    context object
    • <key> object
  • error string required
    Human-readable error message
  • requestId string required
    Client request id
403
Forbidden

Response Body

object

  • name string
    Error code
  • context map of objects required
    Properties that apply to a specific error name
    context object
    • <key> object
  • error string required
    Human-readable error message
  • requestId string required
    Client request id