---
title: "Simulate a card financial authorization"
method: POST
path: "/sandbox/cards/{id}/simulate/financial_authorization"
tags: ["Sandbox"]
---

# Simulate a card financial authorization

`POST /sandbox/cards/{id}/simulate/financial_authorization`

Simulate a single-message financial authorization (an authorization that clears in the same message, e.g. an ATM withdrawal or other dual-message-exempt flow) against a card in the sandbox environment. Drives the same internal paths the card issuer would call in production. The resulting card operation is delivered asynchronously via the issuer's events webhook.

As with `simulate/authorization`, the decisioning outcome is controlled by the last three characters of `merchant.descriptor` — see the `simulate/authorization` suffix table.

Production returns `404` on this path.

## Path parameters

- `id` string, required

## Request body

- SandboxCardAuthorizationRequest — Sandbox-only request body shared by the card authorization-family simulate endpoints: `simulate/authorization`, `simulate/credit_authorization`, `simulate/financial_authorization`, `simulate/financial_credit_authorization`, and `simulate/credit_authorization_advice`. Drives the same internal authorization + reconcile paths that the issuer would call in production. The decisioning outcome is controlled by the last three characters of `merchant.descriptor` — see the `simulate/authorization` documentation for the suffix table.
  - `amount` integer, required — Authorization amount in the smallest unit of `currency` (e.g. cents for USD).
  - `currency` Currency, required
    - `code` string — Three-letter currency code (ISO 4217) for fiat currencies. Some cryptocurrencies may use their own ticker symbols (e.g. "BTC" for Bitcoin, "USDC" for USDC, etc.)
    - `name` string — Full name of the currency
    - `symbol` string — Symbol of the currency
    - `decimals` integer — Number of decimal places for the currency
  - `merchant` CardMerchant, required
    - `descriptor` string, required — Merchant descriptor string captured from the card network at authorization time.
    - `mcc` string — Merchant Category Code (ISO 18245) — four-digit numeric string.
    - `country` string — Two-letter ISO 3166-1 alpha-2 country code of the merchant.

## Response `202`

Simulation accepted. The resulting card operation is delivered asynchronously via the issuer's events webhook. Returns the issuer transaction token that correlates the simulated event.

- SandboxCardSimulationResponse — Response body for the sandbox card-event simulators. The simulate call pokes the card issuer's sandbox; the resulting card operation is delivered asynchronously via the issuer's events webhook, never synchronously in this response.
  - `issuerTransactionToken` string, required — The card issuer's transaction token for the simulated event. Correlates the eventual webhook-delivered card operation back to this simulate call.

## Other responses

- `400` — Bad request - Invalid parameters
- `401` — Unauthorized
- `403` — Forbidden - request was made with a production platform token
- `404` — Card not found (also returned in production for this path)
- `500` — Internal service error

---

[API](https://skmtc.net/stainless-api/apis/grid-api.md) · [All operations](https://skmtc.net/stainless-api/apis/grid-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/stainless-api/grid-api/versions/526036c12609/schema)
