# POST /api/merchants/{merchantId}/screening-provider-profiles

Adds a screening provider profile to the merchant.

Example body:
```
{
  "isActive": true,
  "configuration": {
    "providerId": "example-screening",
    "fieldValues": [ { "key": "apiKey", "value": "…" } ]
  }
}
```
An active profile whose provider declares a conflict with one of the merchant's active processor
profiles is rejected. Optionally send `If-Match: "<concurrencyStamp>"` for optimistic
concurrency (409 on a stale stamp).

**Operation ID:** `POST_api_merchants_merchantId_screening-provider-profiles`

## Authorization

Requires: Merchants.Merchants.Create, merchant scope.

Required permissions:
- `Merchants.Merchants.Create`

## Parameters

| Name | In | Required | Type | Description |
| --- | --- | --- | --- | --- |
| merchantId | path | yes | string(uuid) | The merchant id. |
| suppressNulls | query | no | boolean | If true, omit properties with null values. |

## Request Body

The profile to add. The `screeningProviderProfileId` is server-assigned; any value supplied
on the body is ignored. Discover the provider's field keys via
`GET /api/screening-providers/{providerId}/config-schema`, or fetch a ready-to-fill skeleton
from `.../config-schema/template`.

**Content type:** `application/json`

Schema: `PhoeniXGateMerchantsScreeningProviderProfileDto`

**Content type:** `text/json`

Schema: `PhoeniXGateMerchantsScreeningProviderProfileDto`

**Content type:** `application/*+json`

Schema: `PhoeniXGateMerchantsScreeningProviderProfileDto`

## Responses

### 200

OK

**Content type:** `text/plain`

Schema: `PhoeniXGateMerchantsScreeningProviderProfileDto`

**Content type:** `application/json`

Schema: `PhoeniXGateMerchantsScreeningProviderProfileDto`

**Content type:** `text/json`

Schema: `PhoeniXGateMerchantsScreeningProviderProfileDto`

### 403

Forbidden

**Content type:** `text/plain`

Schema: `WinkPGHttpRemoteServiceErrorResponse`

**Content type:** `application/json`

Schema: `WinkPGHttpRemoteServiceErrorResponse`

**Content type:** `text/json`

Schema: `WinkPGHttpRemoteServiceErrorResponse`

### 401

Unauthorized

**Content type:** `text/plain`

Schema: `WinkPGHttpRemoteServiceErrorResponse`

**Content type:** `application/json`

Schema: `WinkPGHttpRemoteServiceErrorResponse`

**Content type:** `text/json`

Schema: `WinkPGHttpRemoteServiceErrorResponse`

### 400

Bad Request

**Content type:** `text/plain`

Schema: `WinkPGHttpRemoteServiceErrorResponse`

**Content type:** `application/json`

Schema: `WinkPGHttpRemoteServiceErrorResponse`

**Content type:** `text/json`

Schema: `WinkPGHttpRemoteServiceErrorResponse`

### 404

Not Found

**Content type:** `text/plain`

Schema: `WinkPGHttpRemoteServiceErrorResponse`

**Content type:** `application/json`

Schema: `WinkPGHttpRemoteServiceErrorResponse`

**Content type:** `text/json`

Schema: `WinkPGHttpRemoteServiceErrorResponse`

### 501

Not Implemented

**Content type:** `text/plain`

Schema: `WinkPGHttpRemoteServiceErrorResponse`

**Content type:** `application/json`

Schema: `WinkPGHttpRemoteServiceErrorResponse`

**Content type:** `text/json`

Schema: `WinkPGHttpRemoteServiceErrorResponse`

### 500

Internal Server Error

**Content type:** `text/plain`

Schema: `WinkPGHttpRemoteServiceErrorResponse`

**Content type:** `application/json`

Schema: `WinkPGHttpRemoteServiceErrorResponse`

**Content type:** `text/json`

Schema: `WinkPGHttpRemoteServiceErrorResponse`

### default

The request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.

**Content type:** `application/json`

Schema: `WinkPGHttpRemoteServiceErrorResponse`

## See also

- [All documentation](https://docs.winkpg.io/llms.txt): the machine-readable index of every public page on this site.
