> ## Documentation Index
> Fetch the complete documentation index at: https://docs.heyrafiki.space/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a pre-authorization

> Reserves one covered synthetic Session against an eligible Benefit. Requires `benefits:write`.



## OpenAPI

````yaml /openapi/heyrafiki.openapi.yaml post /preauthorizations
openapi: 3.1.0
info:
  title: Heyrafiki API
  version: 1.0.0
  description: Build Care, Cover and Payment workflows on Heyrafiki.
  contact:
    name: Heyrafiki
    url: https://heyrafiki.space
    email: developers@heyrafiki.space
  license:
    name: All rights reserved
    identifier: LicenseRef-Heyrafiki-Proprietary
servers:
  - url: https://api.heyrafiki.space/v1
security:
  - bearerAuth: []
  - apiKeyAuth: []
paths:
  /preauthorizations:
    post:
      summary: Create a pre-authorization
      description: >-
        Reserves one covered synthetic Session against an eligible Benefit.
        Requires `benefits:write`.
      operationId: createPreauthorization
      parameters:
        - $ref: '#/components/parameters/IdempotencyKey'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PreauthorizationInput'
      responses:
        '200':
          description: The original pre-authorization for an idempotent replay
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Preauthorization'
        '201':
          description: An approved pre-authorization
          headers:
            X-RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/RateLimitReset'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Preauthorization'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          $ref: '#/components/responses/Conflict'
        '422':
          $ref: '#/components/responses/Unprocessable'
        '429':
          $ref: '#/components/responses/TooManyRequests'
        '503':
          $ref: '#/components/responses/ServiceUnavailable'
components:
  parameters:
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      required: true
      description: A caller-owned key for safely retrying one write.
      schema:
        type: string
        minLength: 8
        maxLength: 255
  schemas:
    PreauthorizationInput:
      type: object
      additionalProperties: false
      required:
        - eligibility_check_id
        - booking_id
      properties:
        eligibility_check_id:
          type: string
          maxLength: 100
          pattern: ^elig_[A-Za-z0-9_-]+$
        booking_id:
          type: string
          maxLength: 100
          pattern: ^bkg_[A-Za-z0-9_-]+$
    Preauthorization:
      type: object
      additionalProperties: false
      required:
        - id
        - object
        - eligibility_check_id
        - booking_id
        - status
        - reason_codes
        - amount
        - valid_until
        - created_at
      properties:
        id:
          type: string
          maxLength: 100
          pattern: ^preauth_[A-Za-z0-9_-]+$
        object:
          type: string
          const: preauthorization
        eligibility_check_id:
          type: string
          maxLength: 100
          pattern: ^elig_[A-Za-z0-9_-]+$
        booking_id:
          type: string
          maxLength: 100
          pattern: ^bkg_[A-Za-z0-9_-]+$
        status:
          type: string
          enum:
            - pending
            - approved
            - denied
            - expired
            - cancelled
        reason_codes:
          type: array
          items:
            type: string
        amount:
          type: object
          additionalProperties: false
          required:
            - requested
            - approved
            - currency
          properties:
            requested:
              type: integer
              minimum: 1
            approved:
              type:
                - integer
                - 'null'
              minimum: 1
            currency:
              type: string
              pattern: ^[A-Z]{3}$
        valid_until:
          type:
            - string
            - 'null'
          format: date-time
        created_at:
          type: string
          format: date-time
    ErrorEnvelope:
      type: object
      additionalProperties: false
      required:
        - error
      properties:
        error:
          type: object
          additionalProperties: false
          required:
            - code
            - message
            - docs
          properties:
            code:
              type: string
            message:
              type: string
            docs:
              type: string
              format: uri
  headers:
    RateLimitLimit:
      description: Maximum requests allowed in the current minute.
      schema:
        type: integer
    RateLimitRemaining:
      description: Requests remaining in the current minute.
      schema:
        type: integer
    RateLimitReset:
      description: Unix timestamp when the current limit resets.
      schema:
        type: integer
  responses:
    BadRequest:
      description: The request failed validation.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
    Unauthorized:
      description: The API key is missing or invalid.
      headers:
        WWW-Authenticate:
          schema:
            type: string
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
    Forbidden:
      description: The API key does not permit this operation.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
    NotFound:
      description: The requested resource does not exist or is not visible to this project.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
    Conflict:
      description: The request conflicts with current state.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
    Unprocessable:
      description: The request is valid but cannot be completed.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
    TooManyRequests:
      description: The project exceeded its request limit.
      headers:
        Retry-After:
          description: Seconds until another request should be attempted.
          schema:
            type: integer
        X-RateLimit-Limit:
          $ref: '#/components/headers/RateLimitLimit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/RateLimitRemaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/RateLimitReset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
    ServiceUnavailable:
      description: The service is temporarily unavailable.
      headers:
        Retry-After:
          schema:
            type: integer
            example: 5
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: A sandbox or production secret key.
    apiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: An alternative for clients that cannot set Authorization.

````