openapi: 3.0.1 info: title: Basis Theory 3D Secure Tokenize / Detokenize API description: The Basis Theory API is a PCI Level 1 compliant tokenization and data vault platform. It lets developers tokenize, store, and use sensitive data - cardholder data, PII, PHI, and bank account numbers - without that data touching their own systems. The API exposes Tokens, batch Tokenize / Detokenize, Applications, the detokenizing Proxy (pre-configured and ephemeral), serverless Reactors, 3D Secure, Tenants, Logs, and Webhooks. All requests are authenticated with a `BT-API-KEY` request header. termsOfService: https://basistheory.com/terms contact: name: Basis Theory Support email: support@basistheory.com url: https://developers.basistheory.com version: '1.0' servers: - url: https://api.basistheory.com description: Production environment (PRODUCTION tenants) - url: https://api.test.basistheory.com description: Test environment (TEST tenants) security: - ApiKey: [] tags: - name: Tokenize / Detokenize description: Batch tokenization and detokenization. paths: /tokens/tokenize: post: operationId: tokenize tags: - Tokenize / Detokenize summary: Tokenize description: Batch tokenization. Accepts an arbitrary object graph containing token requests and returns the same shape with each request replaced by the created token. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/TokenizeRequest' responses: '200': description: The tokenized object graph. content: application/json: schema: type: object additionalProperties: true '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '422': $ref: '#/components/responses/ValidationProblem' /tokens/detokenize: post: operationId: detokenize tags: - Tokenize / Detokenize summary: Detokenize description: Batch detokenization. Accepts an object graph containing detokenization expressions and returns the same shape with each expression replaced by the plaintext token data. requestBody: required: true content: application/json: schema: type: object additionalProperties: true responses: '200': description: The detokenized object graph. content: application/json: schema: type: object additionalProperties: true '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '422': $ref: '#/components/responses/ValidationProblem' components: responses: Forbidden: description: The application lacks the required permission. content: application/json: schema: $ref: '#/components/schemas/ProblemDetails' Unauthorized: description: The BT-API-KEY header is missing or invalid. content: application/json: schema: $ref: '#/components/schemas/ProblemDetails' ValidationProblem: description: The request failed validation. content: application/json: schema: $ref: '#/components/schemas/ValidationProblemDetails' schemas: ValidationProblemDetails: type: object properties: title: type: string status: type: integer errors: type: object additionalProperties: type: array items: type: string ProblemDetails: type: object properties: title: type: string status: type: integer detail: type: string TokenizeRequest: type: object additionalProperties: true description: An arbitrary object graph where leaf nodes may be token requests of the form {type, data, ...}. The same shape is returned with each request replaced by its created token. securitySchemes: ApiKey: type: apiKey in: header name: BT-API-KEY description: Authenticate every request with a Basis Theory Application key supplied in the BT-API-KEY request header.