generated: '2026-09-05' method: derived source: openapi/ — 118 first-party Citi OpenAPI/Swagger specifications harvested from https://developer.citi.com/apidocs/redocusaurus/.yaml on 2026-09-05; plus https://developer.citi.com/apidocs/authentication/authentication-only-guide versioning: style: path segment example: https://tts.apib2b.citi.com/citiconnect/prod/paymentservices/v3 note: Major version is carried in the base path. Citi runs multiple major versions concurrently and publishes each as its own contract, so version selection is contract selection. concurrent_versions: - product: Authentication versions: - V1 - V2 - V3 - V4 note: All four are live simultaneously. Each product contract names the version it requires; V4 drops the payload signing and encryption requirement. specs: - openapi/citi-authentication-api-1-openapi.yaml - openapi/citi-authentication-api-2-openapi.yaml - openapi/citi-authentication-api-3-openapi.yaml - openapi/citi-authentication-api-4-openapi.yaml - product: Account Services versions: - V1.4.2 (accountsservices/v4) - V5 (accountsservices/v5) - product: WorldLink versions: - V1 - V2.4 - V3.3 - V5.1 - product: Statements versions: - v1 - v2 - product: Virtual Card Account lifecycle versions: - v1 - 2.0.0 - product: VCA for payment intermediaries versions: - v1 - v2.0.0 - product: e-Mandate versions: - v1 - v2 - product: Payment enhanced inquiry versions: - JSON v3.0.3 - XML v3.0.1 deprecation: policy_published: partial mechanism: RFC 8594 Deprecation and Sunset response headers, plus a Link header naming the successor URL headers: - name: Deprecation semantics: '"The date when the API was stopped or will be stopped by the system owner. ISO 8601-1:2019 format."' - name: Sunset semantics: '"The date when the API will no longer be Supported by the system owner. The API will no longer be responsive and all REQUESTS will generate an error. ISO 8601-1:2019 format."' - name: Link semantics: '"Latest working url that can be used for the same purpose."' declared_on: - openapi/citi-addonservice-openapi.yaml - openapi/citi-entityid-openapi.yaml - openapi/citi-vamanagement-openapi.yaml coverage_note: Three of 118 contracts declare these headers. The mechanism is real and correctly specified where it appears, but it is not fleet-wide, and no dated deprecation calendar is published anywhere on developer.citi.com. deprecated_operations: [] sla: published: false note: No public SLA or uptime commitment is published on developer.citi.com or partner.citi.com. Availability terms are set in the client contract negotiated during onboarding. status_page: published: false probed: - url: https://status.citi.com status: DNS NXDOMAIN - url: https://partner.citi.com/outages status: 500 note: The Citi Partner Portal ships an /outages route in its Angular route table, but the page returned HTTP 500 when probed on 2026-09-05, and there is no status host. No StatusPage pointer is emitted. support: email: devsupport@citi.com source: https://developer.citi.com/apidocs/authentication/authentication-only-guide note: Named in the published Authentication Guide as the developer support contact. onboarding_lifecycle: stages: - SIGN UP — register and browse the API catalog - CREATE — register an app and call the sandbox - SUBMIT — submit the idea through contact sales for fit assessment - ONBOARDING — work with a Citi Relationship Manager to complete official onboarding - GO LIVE — move to production source: https://partner.citi.com/assets/json/pre-login/developers-page.json note: Production access is relationship-managed, not self-service. This is the governing lifecycle fact for anyone planning an integration.