---
title: "Get Merchant Controls"
method: POST
path: "/getMerchantControls"
tags: ["Account-Level Controls"]
---

# Get Merchant Controls

`POST /getMerchantControls`

Use the Get Merchant Controls endpoint to retrieve merchant ID (MID) controls for either the product ID or the specified account. See <a href="doc:set-merchant-id-controls" target="_blank">Set Merchant ID Controls</a> for instructions on using this endpoint.

## Response `default`

- object
  - `status_code` integer, nullable, required — The response status code. May return a string for some statuses.
  - `status` string, nullable, required — The condition of a process or response
  - `processing_time` number, float, nullable, required — The time elapsed in processing the transaction
  - `echo` object, nullable, required — A structure that contains transaction ID information
    - `transaction_id` string, nullable, required — An ID that represents an API transaction
    - `provider_timestamp` string, date-time, nullable, required — Store a related timestamp for reporting and troubleshooting purposes
    - `provider_transaction_id` string, nullable, required — Secondary transaction identifier (generated by a provider)
  - `system_timestamp` string, date-time, nullable, required — A system generated timestamp
  - `rtoken` string, nullable, required — A system-generated ID used for tracking
  - `errors` string[] — A list of errors generated while the request was processed
  - `response_data` object, nullable, required — A structure for the response data. It can be empty but usually will contain information.
    - `pmt_ref_no` string — The PRN of the account. Returned only when `accountNo` was passed in the original call.
    - `product_id` integer — The product ID. Returned only when `prodId` was passed in the original call.
    - `merchant_controls` object[], required — List of MCC controls
      - `merchant_id` string, required — Merchant ID. If the value passed has fewer than 15 characters, the system adds spaces at the end until it has 15 characters.
      - `start_date` string, date-time — Starting date-time of the account-level control. Not populated for product-level controls.
      - `end_date` string, date-time — Ending date-time of the account-level control. Not populated for product-level controls.
      - `deny_allow_flag` string, required — Whether the control is DENY (`d`) or ALLOW (`a`).

---

[API](https://skmtc.net/galileo-ft/apis/program-api.md) · [All operations](https://skmtc.net/galileo-ft/apis/program-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/galileo-ft/program-api/revisions/bcd728f97a18/schema)
