Blacklist or whitelist a customer
- Paymish
- Customer
Blacklist or whitelist a customer
Update the blacklist status of a customer.
Purpose
Use this endpoint to blacklist or whitelist a customer. It belongs to the Customer collection and is designed for backend integrations.
Request shape
0 parameters and
2 documented body fields
using application/json.
Recommended workflow
Authenticate first and inject a valid bearer token or secret key before calling the endpoint.
Validate the input data, identifiers, and account state in your application before making the request.
Send the PUT request from your backend using the required headers and the expected content type (application/json).
Persist the important identifiers returned in the response so later lookups, webhooks, or support actions can be linked correctly.
Implementation notes
- Validate the request payload on your backend before sending it, especially the 2 documented body fields.
- Protect state-changing operations with strong validation, logging, and retry rules to avoid duplicate mutations.
Request Body
Content type: application/json
customerReference
required
CUST_49089e7a-5000-4ab1-b107-f921feec0468
isBlackListed
required
True
Responses
Expected Outcomes
Success example
Customer status updated successfully
{
"message": "Update customer status successfully."
}
Failure example
Bad request
{
"error": "Bad request"
}
- Log the Paymish reference or request context returned by the API so support teams can trace the call later.
- Retry only when the failure is safe to repeat; otherwise correct the payload or auth state first.
- Store enough internal metadata to match the API response back to your order, payout, case, or checkout record.
Language Notes
Python
Use `requests` from a backend worker, service, or Django/Flask app and centralize headers in a reusable helper.
Node.js
Use `axios` or `fetch` from Node.js services only; do not place secret credentials in frontend bundles.
PHP
Wrap cURL usage in a small client class so auth headers, error handling, and logging stay consistent.
cURL
Use cURL for smoke testing and debugging, then move the final logic into your backend service code.
Code Examples
import requests
headers = {
"Authorization": "Bearer YOUR_SECRET_KEY",
"Content-Type": "application/json",
}
payload = {
"customerReference": "CUST_49089e7a-5000-4ab1-b107-f921feec0468",
"isBlackListed": true
}
response = requests.put(
"https://api.paymish.com/api/customer-service/external/v1/black-listed",
headers=headers,
json=payload,
)
data = response.json()
print(data)
const axios = require("axios");
const response = await axios({
method: "put",
url: "https://api.paymish.com/api/customer-service/external/v1/black-listed",
headers: {
Authorization: "Bearer YOUR_SECRET_KEY",
"Content-Type": "application/json",
},
data: {
"customerReference": "CUST_49089e7a-5000-4ab1-b107-f921feec0468",
"isBlackListed": true
}
});
console.log(response.data);
curl https://api.paymish.com/api/customer-service/external/v1/black-listed \
-X PUT \
-H "Authorization: Bearer YOUR_SECRET_KEY" \
-H "Content-Type: application/json" \
-d '{ "customerReference": "CUST_49089e7a-5000-4ab1-b107-f921feec0468", "isBlackListed": true }'
<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://api.paymish.com/api/customer-service/external/v1/black-listed");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "PUT");
curl_setopt($ch, CURLOPT_HTTPHEADER, [
"Authorization: Bearer YOUR_SECRET_KEY",
"Content-Type: application/json",
]);
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode([
"customerReference" => "CUST_49089e7a-5000-4ab1-b107-f921feec0468",
"isBlackListed" => true,
]));
$response = curl_exec($ch);
curl_close($ch);
$data = json_decode($response, true);
print_r($data);