URL: /baas/api/reference/financial-operations/create-payment-consent
---
title: 'Create payment consent'
description: 'Create a payment consent and receive a magicLinkToken containing the authentication code for execution.'
---
## Endpoint
`POST /api/v2.1/fintrans/{accountId}/payment-consents/types/{operationType}`
This endpoint requires `X-Forwarded-From` and a device header. The backend accepts any of:
`deviceId`, `X-Device-Id`, `device-id`.
## Sample cURL
```bash
curl --request POST \
--url 'https://sandbox.finhub.cloud/api/v2.1/fintrans/{accountId}/payment-consents/types/{operationType}' \
--header 'Authorization: Bearer ' \
--header 'X-Tenant-Id: ' \
--header 'Content-Type: application/json' \
--header 'Accept: application/json' \
--header 'User-Agent: ' \
--header 'X-Forwarded-From: ' \
--header 'platform: Web' \
--header 'deviceId: ' \
--data '{
"metadata": {
"parameters": {
"validity": {
"endDate": "2027-12-31",
"startDate": "2025-10-01",
"maxUsageCount": 100
},
"beneficiaries": {
"requireBeneficiaryName": true,
"allowedTypes": [
"sepa_transfer_internal"
],
"allowedAccounts": [
"LT213320011000055860"
],
"allowNewBeneficiaries": false
},
"limits": {
"maxTransactionsPerDay": 10,
"maxAmountPerTransaction": {
"currency": "EUR",
"amount": 10000
},
"maxAmountPerDay": {
"currency": "EUR",
"amount": 20000
}
}
},
"paymentType": "TRANSFER",
"questions": {
"question": "I consent to the processing",
"answer": ""
},
"title": "Payment Consent"
},
"verificationData": {
"consentVersion": "1.0",
"scope": "Transfer processing",
"consentPurpose": "Payment Consent"
},
"entityId": "97e7ff29-15f3-49ef-9681-3bbfcce4f6cd",
"verificationStatus": "PENDING",
"entityType": "ORGANIZATION",
"verificationType": "CONSENT",
"tenantId": "97e7ff29-15f3-49ef-9681-3bbfcce4f6cd",
"documentId": "59ddc658-7cfc-4dbe-ac82-c716330b44eb",
"documentType": "PAYMENT_CONSENT"
}'
```
## Response Example
```json
{
"code": 200,
"data": {
"consentId": "f3822ff0-3986-4fef-84eb-7b517e657b6f",
"id": "f3822ff0-3986-4fef-84eb-7b517e657b6f",
"operationType": "transfer",
"status": "APPROVED",
"walletId": "d7d94804-4d8b-45af-862f-77cbcef740f4",
"accountId": "d7d94804-4d8b-45af-862f-77cbcef740f4",
"message": "Consent created successfully",
"magicLinkToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
},
"message": "Success"
}
```
Decode the `magicLinkToken` JWT and extract the `answer` field. That value is the `authenticationCode` required to execute a prepared operation.
## Missing Headers Error Example
```json
{
"code": 500,
"data": {
"deviceId_accepted": [
"deviceId",
"X-Device-Id",
"device-id"
],
"missingHeaders": [
"X-Forwarded-From",
"deviceId"
]
},
"message": "Missing required header(s)"
}
```