> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# List fraud rules

> Use this endpoint to list fraud rules with cursor-based pagination and optional filters. DELETED rules are not returned in listings.



## OpenAPI

````yaml /en/openapi/v3-current/tracer.yaml get /v1/rules
openapi: 3.1.0
info:
  title: Midaz Tracer API
  description: >-
    Reference for Midaz Tracer transaction validation, fraud rules, spending
    limits, reservations, and audit events.
  version: 4.0.0
servers:
  - url: https://tracer.sandbox.lerian.net
security: []
tags:
  - name: Validations API
  - name: Rules API
  - name: Limits API
  - name: Reservations API
  - name: Audit Events API
paths:
  /v1/rules:
    get:
      tags:
        - Rules API
      summary: List fraud rules
      description: >-
        Use this endpoint to list fraud rules with cursor-based pagination and
        optional filters. DELETED rules are not returned in listings.
      operationId: listRules
      parameters:
        - description: Filter by name (case-insensitive partial match)
          explode: false
          in: query
          name: name
          schema:
            description: Filter by name (case-insensitive partial match)
            type: string
        - description: Filter by status (DRAFT, ACTIVE, INACTIVE; DELETED not allowed)
          explode: false
          in: query
          name: status
          schema:
            description: Filter by status (DRAFT, ACTIVE, INACTIVE; DELETED not allowed)
            type: string
        - description: Filter by action (ALLOW, DENY, REVIEW)
          explode: false
          in: query
          name: action
          schema:
            description: Filter by action (ALLOW, DENY, REVIEW)
            type: string
        - description: Filter by scope account_id (UUID)
          explode: false
          in: query
          name: account_id
          schema:
            description: Filter by scope account_id (UUID)
            type: string
        - description: Filter by scope segment_id (UUID)
          explode: false
          in: query
          name: segment_id
          schema:
            description: Filter by scope segment_id (UUID)
            type: string
        - description: Filter by scope portfolio_id (UUID)
          explode: false
          in: query
          name: portfolio_id
          schema:
            description: Filter by scope portfolio_id (UUID)
            type: string
        - description: Filter by scope merchant_id (UUID)
          explode: false
          in: query
          name: merchant_id
          schema:
            description: Filter by scope merchant_id (UUID)
            type: string
        - description: Filter by scope transaction_type (CARD, WIRE, PIX, CRYPTO)
          explode: false
          in: query
          name: transaction_type
          schema:
            description: Filter by scope transaction_type (CARD, WIRE, PIX, CRYPTO)
            type: string
        - description: Filter by scope sub_type (case-insensitive; max 50 chars)
          explode: false
          in: query
          name: sub_type
          schema:
            description: Filter by scope sub_type (case-insensitive; max 50 chars)
            type: string
        - description: 'Max items per page (1-100, default: 10)'
          explode: false
          in: query
          name: limit
          schema:
            description: 'Max items per page (1-100, default: 10)'
            type: string
        - description: Pagination cursor (empty for first page)
          explode: false
          in: query
          name: cursor
          schema:
            description: Pagination cursor (empty for first page)
            type: string
        - description: Sort field (created_at, updated_at, name, status)
          explode: false
          in: query
          name: sort_by
          schema:
            description: Sort field (created_at, updated_at, name, status)
            type: string
        - description: Sort direction (ASC, DESC)
          explode: false
          in: query
          name: sort_order
          schema:
            description: Sort direction (ASC, DESC)
            type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListRulesResponse'
          description: OK
        default:
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Error'
          description: Error
      security:
        - BearerAuth: []
        - ApiKeyAuth: []
components:
  schemas:
    ListRulesResponse:
      additionalProperties: false
      properties:
        hasMore:
          examples:
            - true
          type: boolean
        nextCursor:
          examples:
            - eyJpZCI6IjAxOTI4In0=
          type: string
        rules:
          items:
            $ref: '#/components/schemas/Rule'
          type:
            - array
            - 'null'
      required:
        - rules
        - hasMore
      type: object
    Error:
      additionalProperties: false
      properties:
        code:
          description: >-
            Stable, machine-readable domain error code scoped to the emitting
            service (format: <SERVICE>-NNNN).
          examples:
            - ERR-0001
          type: string
        detail:
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          examples:
            - Property foo is required but is missing.
          type: string
        errors:
          description: Optional list of individual error details
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type:
            - array
            - 'null'
        instance:
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          examples:
            - https://example.com/error-log/abc123
          format: uri
          type: string
        status:
          description: HTTP status code
          examples:
            - 400
          format: int64
          type: integer
        title:
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          examples:
            - Bad Request
          type: string
        type:
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          examples:
            - https://example.com/errors/example
          format: uri
          type: string
        upstream:
          $ref: '#/components/schemas/Upstream'
          description: >-
            RFC 9457 extension member: the error a proxied third-party provider
            reported. Absent unless the emitting service explicitly surfaced
            one.
      type: object
    Rule:
      additionalProperties: false
      properties:
        action:
          examples:
            - DENY
          type: string
        activatedAt:
          examples:
            - '2021-01-01T00:00:00Z'
          format: date-time
          type: string
        createdAt:
          examples:
            - '2021-01-01T00:00:00Z'
          format: date-time
          type: string
        deactivatedAt:
          examples:
            - '2021-01-01T00:00:00Z'
          format: date-time
          type: string
        deletedAt:
          examples:
            - '2021-01-01T00:00:00Z'
          format: date-time
          type: string
        description:
          examples:
            - Denies transactions over $1000 from checking accounts
          type: string
        expression:
          examples:
            - transaction.amount > 1000 && account.type == 'checking'
          type: string
        name:
          examples:
            - Block high-value checking transactions
          maxLength: 255
          type: string
        ruleId:
          examples:
            - 00000000-0000-0000-0000-000000000000
          format: uuid
          type: string
        scopes:
          items:
            $ref: '#/components/schemas/Scope'
          type:
            - array
            - 'null'
        status:
          examples:
            - ACTIVE
          type: string
        updatedAt:
          examples:
            - '2021-01-01T00:00:00Z'
          format: date-time
          type: string
      required:
        - ruleId
        - name
        - expression
        - action
        - scopes
        - status
        - createdAt
        - updatedAt
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
    Upstream:
      additionalProperties: false
      properties:
        code:
          description: The upstream provider's own error code, verbatim.
          examples:
            - E4001
          type: string
        message:
          description: >-
            The upstream provider's own error message, verbatim (bounded, never
            its raw response body).
          examples:
            - account not found at provider
          type: string
      type: object
    Scope:
      additionalProperties: false
      properties:
        accountId:
          examples:
            - 00000000-0000-0000-0000-000000000000
          format: uuid
          type: string
        merchantId:
          examples:
            - 00000000-0000-0000-0000-000000000000
          format: uuid
          type: string
        portfolioId:
          examples:
            - 00000000-0000-0000-0000-000000000000
          format: uuid
          type: string
        segmentId:
          examples:
            - 00000000-0000-0000-0000-000000000000
          format: uuid
          type: string
        subType:
          examples:
            - purchase
          maxLength: 50
          type: string
        transactionType:
          examples:
            - CARD
          type: string
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT bearer token issued by the identity provider.
      scheme: bearer
      type: http
    ApiKeyAuth:
      description: Static API key presented in the X-API-Key header.
      in: header
      name: X-API-Key
      type: apiKey

````