Page expense evidence for the current authorized business organization
/cards/spend/expensesVerified bank-bound customer PERSON identity with customer scope, session/device and online account organization membership required. Writes require authentication within five minutes; API keys, staff and service impersonation refused. Existing maker/approver/admin roles and amount limits apply. Expense review requires distinct users AND person customer IDs. Pending/approved allocations reserve exact bank-source and receipt totals; duplicate bytes cannot be relabeled. Actual unreversed committed card journals are revalidated. Pre-export coding corrections preserve source/receipt/amount. Immutable customer-expense-json-1 exports contain balanced customer-book entries, exact review/source proofs and unique expense membership. Preparation/download never claims provider delivery/import, and never posts customer expense codes to bank GLs. See services/cards/spend/README.md. account_id is required; optional after_id pages up to 200 immutable records ascending with more for continuation.
Returns
200 OK
expensesarray of objectsRequired10 child attributes
amountintegerRequiredcontent_sha256stringRequiredcreated_atstring · date-timeRequiredexport_idstringOptionalidstringRequiredreplaced_by_expense_idstringOptionalrequestobjectRequired7 child attributes
allocationsarray of objectsRequired4 child attributes
amountintegerRequiredcost_centerstringRequiredexternal_account_codestringRequiredmemostringRequiredauthorization_idstringRequiredExample auth_2tVh8nqLxq4GbDe0K1F6S9zRcWm
coding_evidenceobjectRequired2 child attributes
referencestringRequiredsha256stringRequiredreasonstringRequiredreceiptobjectRequiredReceipt identity is scoped to the organization and the exact processor merchant. A source document can support several partial bank payments, but only up to its declared total. Evidence is retained customer-supplied documentation, not OCR proof.
6 child attributes
currency_codestringRequiredevidenceobjectRequiredexternal_referencestringRequiredissued_datestring · dateRequiredA business date, YYYY-MM-DD
merchant_idstringRequiredtotal_amountintegerRequiredreplaces_expense_idstringOptionalsettlement_account_codestringRequiredreviewobject or nullOptional6 child attributes
approvebooleanRequiredatstring · date-timeRequiredauthorityobjectRequiredAuthority is the observed current organization membership and separately bank- verified person identity. Neither the request body nor a receipt supplies it.
12 child attributes
account_idstringRequiredExample acct_2tVh8nqLxq4GbDe0K1F6S9zRcWm
device_sha256stringRequiredmembership_changed_bystringRequiredmembership_updated_atstring · date-timeRequiredobserved_atstring · date-timeRequiredorganization_customer_idstringRequiredExample cust_2tVh8nqLxq4GbDe0K1F6S9zRcWm
payment_limit_amountintegerRequiredperson_customer_idstringRequiredExample cust_2tVh8nqLxq4GbDe0K1F6S9zRcWm
rolestringRequiredsession_sha256stringRequiredstep_up_atstring · date-timeRequireduser_idstringRequiredExample user_2tVh8nqLxq4GbDe0K1F6S9zRcWm
content_sha256stringRequiredevidenceobjectRequired2 child attributes
referencestringRequiredsha256stringRequiredreasonstringRequiredsourceobjectRequired15 child attributes
account_idstringRequiredExample acct_2tVh8nqLxq4GbDe0K1F6S9zRcWm
amountintegerRequiredauthorization_idstringRequiredExample auth_2tVh8nqLxq4GbDe0K1F6S9zRcWm
card_idstringRequiredExample card_2tVh8nqLxq4GbDe0K1F6S9zRcWm
card_kindstringRequiredcurrency_codestringRequiredjournalobjectRequired18 child attributes
adjusts_periodstringOptionalA sealed period this journal corrects, YYYY-MM
approved_bystringOptionalbackdatedbooleanOptionalEffective_date is before posting_date (read only)
committed_atstring · date-timeOptionaleffective_datestring · dateRequiredA business date, YYYY-MM-DD
entriesarray of objectsRequiredfx_legsarray of objectsOptionalFXLegs is read only: the legs of a cross-currency journal the ledger's own conversion and close commands posted. A caller's posting never carries them.
idstringOptionalkindstringRequiredposted_bystringOptionalposting_datestring · dateOptionalA business date, YYYY-MM-DD
protected_command_idstringOptionalreasonstringOptionalRequired on a backdated journal
release_hold_idstringOptionalExample hold_2tVh8nqLxq4GbDe0K1F6S9zRcWm
require_availablebooleanOptionalreversal_ofstringOptionalsource_refstringRequiredsource_servicestringRequiredjournal_keystringRequiredjournal_sha256stringRequiredkindstringRequiredPurchase or refund, derived from actual bank source
merchant_idstringRequiredmerchant_namestringRequirednetwork_referencestringRequiredorganization_customer_idstringRequiredExample cust_2tVh8nqLxq4GbDe0K1F6S9zRcWm
original_authorization_idstringOptionalExample auth_2tVh8nqLxq4GbDe0K1F6S9zRcWm
submitted_byobjectRequiredAuthority is the observed current organization membership and separately bank- verified person identity. Neither the request body nor a receipt supplies it.
12 child attributes
account_idstringRequiredExample acct_2tVh8nqLxq4GbDe0K1F6S9zRcWm
device_sha256stringRequiredmembership_changed_bystringRequiredmembership_updated_atstring · date-timeRequiredobserved_atstring · date-timeRequiredorganization_customer_idstringRequiredExample cust_2tVh8nqLxq4GbDe0K1F6S9zRcWm
payment_limit_amountintegerRequiredperson_customer_idstringRequiredExample cust_2tVh8nqLxq4GbDe0K1F6S9zRcWm
rolestringRequiredsession_sha256stringRequiredstep_up_atstring · date-timeRequireduser_idstringRequiredExample user_2tVh8nqLxq4GbDe0K1F6S9zRcWm
morebooleanRequiredErrors
Every error is a problem document with a stable code. See Errors.
400401403404409412413422424429500503