openapi: 3.2.0 info: title: Gateway Services Rfi API description: Self onboarding services for merchants to register on the platform, create wallets, and perform withdrawals or payouts to their designated settlement and external beneficiary accounts. contact: name: Standards & Developer Hub url: https://tts.sandbox.developer.citi.com/citiconnect/ email: developer-support@citi.com version: 1.0.0 servers: - url: https://b2b.api.icg.citi.com/citiconnect/prod/gatewayservices description: production gateway url - url: https://sandbox.b2b.api.icg.citi.com/citiconnect/sb/gatewayservices description: sbox url security: - oAuth2: - /authenticationservices/v1 tags: - name: Rfi description: Request for Information operations paths: /merchants/v1/rfi: post: summary: RFI Response description: Allows you to respond to the RFI request with answers. This API allows you to reply to either a single or multiple questions in one call, depending on how you choose to respond. operationId: saveRfiResponse servers: - url: https://b2b.api.icg.citi.com/citiconnect/prod/gatewayservices tags: - Rfi parameters: - $ref: '#/components/parameters/Client-Id' - $ref: '#/components/parameters/Country-Code' - $ref: '#/components/parameters/Merchant-Id' - $ref: '#/components/parameters/Idempotency-Id' requestBody: description: This section holds the request parameters for RFI. required: true content: application/json: schema: $ref: '#/components/schemas/Rfi-Save-Request' examples: Rfi-Response: $ref: '#/components/examples/Rfi-Response' responses: '200': description: RFI response accepted for processing. headers: apim-guid: $ref: '#/components/headers/Apim-Guid' content: application/json: schema: $ref: '#/components/schemas/Rfi-Save-Response' examples: Rfi-Response-Acknowledgement: $ref: '#/components/examples/Rfi-Response-Acknowledgement' '400': $ref: '#/components/responses/Bad-Request' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/Not-Found' '405': $ref: '#/components/responses/Method-Not-Allowed' '409': $ref: '#/components/responses/Conflict' '415': $ref: '#/components/responses/Unsupported-Media-Type' '429': $ref: '#/components/responses/Too-Many-Requests' '500': $ref: '#/components/responses/Internal-Server-Error' '503': $ref: '#/components/responses/Service-Unavailable' '504': $ref: '#/components/responses/Gateway-Timeout' security: - oAuth2: - /authenticationservices/v1 get: summary: RFI Query description: Retrieves details of single RFI using the given RFI ID or returns a list of RFIs raised for your account. operationId: queryRfi servers: - url: https://b2b.api.icg.citi.com/citiconnect/prod/gatewayservices tags: - Rfi parameters: - $ref: '#/components/parameters/Client-Id' - $ref: '#/components/parameters/Country-Code' - $ref: '#/components/parameters/Merchant-Id' - $ref: '#/components/parameters/Rfi-Id' - $ref: '#/components/parameters/Type' - $ref: '#/components/parameters/From-Date' - $ref: '#/components/parameters/To-Date' - $ref: '#/components/parameters/Page-No' - $ref: '#/components/parameters/Limit' - $ref: '#/components/parameters/Rfi-Status' responses: '200': description: RFI details retrieved successfully. headers: apim-guid: $ref: '#/components/headers/Apim-Guid' Pagination-Metadata: description: This header contains a JSON object with details about the response. The full schema is available in the 'Pagination-Metadata' schema section below schema: $ref: '#/components/schemas/Pagination-Metadata' content: application/json: schema: $ref: '#/components/schemas/Rfi-Query-Response' examples: Get-Rfi: $ref: '#/components/examples/Get-Rfi' '400': $ref: '#/components/responses/Bad-Request' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/Not-Found' '405': $ref: '#/components/responses/Method-Not-Allowed' '429': $ref: '#/components/responses/Too-Many-Requests' '500': $ref: '#/components/responses/Internal-Server-Error' '503': $ref: '#/components/responses/Service-Unavailable' '504': $ref: '#/components/responses/Gateway-Timeout' security: - oAuth2: - /authenticationservices/v1 /merchants/v1/rfi/submit: post: summary: RFI Submit description: Allows you to submit an RFI. After submitting status will be updated to CLOSED. CLOSED means the submission of replies is now disabled. operationId: submitRfiResponse servers: - url: https://b2b.api.icg.citi.com/citiconnect/prod/gatewayservices tags: - Rfi parameters: - $ref: '#/components/parameters/Client-Id' - $ref: '#/components/parameters/Country-Code' - $ref: '#/components/parameters/Idempotency-Id' - $ref: '#/components/parameters/Merchant-Id' requestBody: description: This section holds the request parameters for RFI Submit. required: true content: application/json: schema: $ref: '#/components/schemas/Rfi-Submit-Request' examples: Rfi-Submit: $ref: '#/components/examples/Rfi-Submit' responses: '200': description: RFI submitted successfully for processing. headers: apim-guid: $ref: '#/components/headers/Apim-Guid' content: application/json: schema: $ref: '#/components/schemas/Rfi-Submit-Response' examples: Rfi-Submit-Acknowledgement: $ref: '#/components/examples/Rfi-Submit-Acknowledgement' '400': $ref: '#/components/responses/Bad-Request' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/Not-Found' '405': $ref: '#/components/responses/Method-Not-Allowed' '409': $ref: '#/components/responses/Conflict' '415': $ref: '#/components/responses/Unsupported-Media-Type' '429': $ref: '#/components/responses/Too-Many-Requests' '500': $ref: '#/components/responses/Internal-Server-Error' '503': $ref: '#/components/responses/Service-Unavailable' '504': $ref: '#/components/responses/Gateway-Timeout' security: - oAuth2: - /authenticationservices/v1 components: examples: Get-Rfi: value: - rfi_id: string type: string status: string created_time: '2026-03-02T17:46:10.833Z' expiry_time: '2026-03-02T17:46:10.833Z' creditor_id: string questions: - question_id: Q123456789 description_code: string description_english: string description_chinese: string information_request: - information_name: id_doc_front information_type: text answer: string certification_source: merchant_type: ENTERPRISE role: UBO first_name: string middle_name: string last_name: string first_name_in_local_language: string middle_name_in_local_language: string last_name_in_local_language: string Service-Unavailable-Gateway-Example: value: httpCode: '503' httpMessage: Service is temporarily unavailable moreInformation: Retry the request after some time Rfi-Response: value: rfi_id: RFI1234 questions: - question_id: Q123456789 information_request: - information_name: id_doc_front answer: string Not-Found-Gateway-Error-Example: value: httpCode: '404' httpMessage: Not Found moreInformation: No resources match requested URI Rfi-Response-Acknowledgement: value: rfi_id: RFI1234 rfi_status: OPEN questions: - question_id: Q123456789 information_request: - information_name: id_doc_front answer: string Method-Not-Allowed-Service-Error-Example: value: ref_id: ec689822-9864-4c4d-9d68-222467627901 error_details: - issue: Method not supported action: Method not supported for this endpoint, please use valid http verb code: CC00001 Method-Not-Allowed-Gateway-Error-Example: value: httpCode: '405' httpMessage: Method Not Allowed moreInformation: The method is not allowed for the requested URL Un-Supported-Media-Type-Service-Error-Example: value: ref_id: ec689822-9864-4c4d-9d68-222467627902 error_details: - issue: Media type not supported action: please use valid content-type in header code: CC00002 Bad-Request-Gateway-Error-Example: value: httpCode: '400' httpMessage: Bad Request moreInformation: please provide valid value for request Rfi-Submit-Acknowledgement: value: status: CLOSED Rfi-Submit: value: rfi_id: RFI1234 Internal-Server-Gateway-Error-Example: value: httpCode: '500' httpMessage: Internal Server Error moreInformation: Internal Server Error Bad-Request-Service-Error-Example: value: ref_id: ec689822-9864-4c4d-9d68-222467627901 error_details: - issue: record that you are searching is not found action: resend the request with valid values code: VC00003 Unauthorized-Gateway-Error-Example: value: httpCode: '401' httpMessage: Unauthorized moreInformation: The server could not verify that you are authorized to access the URL Internal-Server-Service-Error-Example: value: ref_id: ec689822-9864-4c4d-9d68-222467627902 error_details: - issue: unable to serve your request at this moment action: Please refer to documentation provided or contact support team code: CC00004 Unauthorized-Service-Error-Example: value: ref_id: ec689822-9864-4c4d-9d68-222467627902 error_details: - issue: User not authorized for this functionality action: please use valid credentials to access this functionality code: CC00007 Un-Supported-Media-Type-Gateway-Error-Example: value: httpCode: '415' httpMessage: Unsupported Media Type moreInformation: Unsupported Content-Type application/octet-stream Forbidden-Service-Example: value: ref_id: ec689822-9864-4c4d-9d68-222467627902 error_details: - code: CC00008 issue: User does not have privilege to access this functionality. action: Please reach out to support team to enable this feature. Too-Many-Requests-Gateway-Example: value: httpCode: '429' httpMessage: Too Many Requests moreInformation: Rate Limit exceeded parameters: From-Date: name: from_date in: query required: false description: 'The start date for the requested period. Pattern: YYYY-MM-DD' schema: type: string title: from_date format: date example: '2024-03-17' Rfi-Status: name: status in: query required: false description: List of RFI status values to filter by. schema: type: string title: status minLength: 1 maxLength: 64 Type: name: type in: query required: false description: List of RFI types. Currently supports KYC, RECIPIENT. schema: type: string title: type minLength: 1 maxLength: 64 Merchant-Id: in: header name: Merchant-Id description: CITI generated Merchant ID during merchant creation. schema: type: string title: Merchant-Id minLength: 1 maxLength: 36 example: ec689822-9864-4c4d-9d68-22246762901 required: true Country-Code: in: header name: Country-Code description: Marketplace's country code. schema: pattern: ^[A-Z]{2,2}$ type: string title: Country-Code example: US required: true To-Date: name: to_date in: query required: false description: 'The end date for the requested period. Pattern: YYYY-MM-DD' schema: type: string title: to_date format: date example: '2024-03-17' Page-No: name: page_no in: query required: false description: Page number (default- 1). schema: type: integer title: page_no minimum: 1 maximum: 5000 default: 1 Rfi-Id: name: rfi_id in: query required: false description: RFI unique id. schema: type: string title: rfi_id minLength: 1 maxLength: 128 Idempotency-Id: in: header name: Idempotency-Id description: "Your unique identification for a POST request \n - Maximum length is 128. \n-CitiConnect API responds with an error (HTTP status 4XX) if your POST request idempotency identification value is a duplicate across a recent history of idempotency identifications in Citi's database. \n- If you don't receive any response (HTTP status 2XX, 4XX or 5XX) from Citi to your POST request and you wish to retry, reinitiate your request with the same idempotency identification to prevent accidental duplicate payment." schema: type: string title: Idempotency-Id minLength: 1 maxLength: 128 example: a44cbb606de4edb9a7a123414bba3bb required: true Limit: name: limit in: query required: false description: Number of results per page (default- 50). schema: type: integer title: limit minimum: 1 maximum: 100 default: 50 Client-Id: in: query name: client_id description: Your unique identification, same as the identification you use for OAuth token generation, Citi shared with you during your CitiConnect API onboarding. schema: type: string title: Client-Id example: 6d3cf821-db6d-496d-bec0-064a362e9c31 minimum: 1 maximum: 128 required: true responses: Unauthorized: description: Unauthorized content: application/json: schema: title: Unauthorized-Response oneOf: - $ref: '#/components/schemas/Service-Error-Response' - $ref: '#/components/schemas/Gateway-Error-Response' examples: Unauthorized-Service-Error-Example: $ref: '#/components/examples/Unauthorized-Service-Error-Example' Unauthorized-Gateway-Error-Example: $ref: '#/components/examples/Unauthorized-Gateway-Error-Example' Too-Many-Requests: description: Too Many Requests - Rate limit exceeded. Retry after the specified time. content: application/json: schema: $ref: '#/components/schemas/Gateway-Error-Response' examples: Too-Many-Requests-Gateway-Example: $ref: '#/components/examples/Too-Many-Requests-Gateway-Example' Gateway-Timeout: description: Gateway Timeout content: application/json: schema: $ref: '#/components/schemas/Gateway-Error-Response' Not-Found: description: Not Found content: application/json: schema: $ref: '#/components/schemas/Gateway-Error-Response' examples: Not-Found-Gateway-Error-Example: $ref: '#/components/examples/Not-Found-Gateway-Error-Example' Service-Unavailable: description: Service Unavailable - The server is temporarily unable to handle the request. content: application/json: schema: $ref: '#/components/schemas/Gateway-Error-Response' examples: Service-Unavailable-Gateway-Example: $ref: '#/components/examples/Service-Unavailable-Gateway-Example' Forbidden: description: Forbidden content: application/json: schema: $ref: '#/components/schemas/Service-Error-Response' examples: Forbidden-Service-Example: $ref: '#/components/examples/Forbidden-Service-Example' Unsupported-Media-Type: description: Unsupported Media Type content: application/json: schema: title: Unsupported-Media-Type-Response oneOf: - $ref: '#/components/schemas/Gateway-Error-Response' - $ref: '#/components/schemas/Service-Error-Response' examples: Un-Supported-Media-Type-Gateway-Error-Example: $ref: '#/components/examples/Un-Supported-Media-Type-Gateway-Error-Example' Un-Supported-Media-Type-Service-Error-Example: $ref: '#/components/examples/Un-Supported-Media-Type-Service-Error-Example' Internal-Server-Error: description: Internal Server Error content: application/json: schema: title: Internal-Server-Error-Response oneOf: - $ref: '#/components/schemas/Gateway-Error-Response' - $ref: '#/components/schemas/Service-Error-Response' examples: Internal-Server-Service-Error-Example: $ref: '#/components/examples/Internal-Server-Service-Error-Example' Internal-Server-Gateway-Error-Example: $ref: '#/components/examples/Internal-Server-Gateway-Error-Example' Method-Not-Allowed: description: Method Not Allowed content: application/json: schema: title: Method-Not-Allowed-Response oneOf: - $ref: '#/components/schemas/Gateway-Error-Response' - $ref: '#/components/schemas/Service-Error-Response' examples: Method-Not-Allowed-Gateway-Error-Example: $ref: '#/components/examples/Method-Not-Allowed-Gateway-Error-Example' Method-Not-Allowed-Service-Error-Example: $ref: '#/components/examples/Method-Not-Allowed-Service-Error-Example' Conflict: description: Conflict content: application/json: schema: $ref: '#/components/schemas/Service-Error-Response' Bad-Request: description: Bad Request content: application/json: schema: title: Bad-Request-Response oneOf: - $ref: '#/components/schemas/Gateway-Error-Response' - $ref: '#/components/schemas/Service-Error-Response' examples: Bad-Request-Service-Error-Example: $ref: '#/components/examples/Bad-Request-Service-Error-Example' Bad-Request-Gateway-Error-Example: $ref: '#/components/examples/Bad-Request-Gateway-Error-Example' headers: Apim-Guid: description: Unique system generated reference number generated by Citi. Refer to this number in case of any discrepancy reporting to a Citi representative. schema: type: string maxLength: 128 minLength: 1 title: Apim-Guid required: true example: na-apimgwgtds04~4a98cbc5-d813-4e65-bc81-d70f0f87f6ec schemas: Get-Information-Request: title: GetInformationRequest description: Information item that needs to be responded to in an RFI. allOf: - $ref: '#/components/schemas/Common-Information-Request' - type: object title: Get-Information-Request properties: information_type: $ref: '#/components/schemas/Information-Type' Rfi-Submit-Response: title: RfiSubmitResponse type: object description: Response body for RFI Submit. properties: status: allOf: - $ref: '#/components/schemas/Status' title: status description: 'RFI submit status. Possible values: OPEN, CLOSED.' Service-Error-Response: title: ServiceErrorResponse type: object required: - ref_id - error_details properties: ref_id: type: string maxLength: 120 description: Unique ID for the Transaction title: ref_id example: 444d0f3f-4x55-7g99-8b2c-0cf2a921a5ab error_details: type: array description: List of error details title: error_details items: $ref: '#/components/schemas/Error-Detail' Created-Time: type: string format: date-time description: Date and time of the file created. Pattern YYYY-MM-DDTHH:mm:ssZ title: created_time example: '2026-01-06T10:56:25Z' Information-Request: title: InformationRequest description: Information item that needs to be responded to in an RFI. allOf: - $ref: '#/components/schemas/Common-Information-Request' - type: object title: Information-Request required: - information_name Error-Detail: type: object title: ErrorDetail properties: issue: type: string minLength: 1 maxLength: 200 description: more details about the issue title: issue example: property emailAddress is mandatory and it cannot be empty action: type: string maxLength: 350 description: corrective action to be taken to resolve above issue title: action example: please provide valid value for property emailAddress code: type: string minLength: 1 maxLength: 64 description: unique code representing the issue title: code example: VC00010 Information-Request-Response: title: InformationRequestResponse description: Information item that needs to be responded to in an RFI. allOf: - $ref: '#/components/schemas/Common-Information-Request' - type: object title: Information-Request-Response Questions-Request: title: QuestionRequest type: object description: A question with response information for RFI submission. required: - question_id - information_request properties: question_id: $ref: '#/components/schemas/Question-Id' information_request: type: array title: information_request description: The information to be responded to. minItems: 1 maxItems: 100 items: $ref: '#/components/schemas/Information-Request' Rfi-Id: type: string title: rfi_id minLength: 1 maxLength: 128 description: RFI unique id. Creditor-Id: type: string title: creditor_id description: The unique creditor identifier assigned by payment service provider. minLength: 1 maxLength: 36 example: R202501080950209789 Rfi-Submit-Request: title: RfiSubmitRequest type: object description: Request body for submitting an RFI for review. required: - rfi_id properties: rfi_id: $ref: '#/components/schemas/Rfi-Id' Personal-Details: title: Personal-Details type: object description: This section contains the name details. properties: first_name: type: string title: first_name minLength: 1 maxLength: 64 description: Business person's first name in English. Required for CN and HK. example: Hongbo first_name_in_local_language: type: string title: first_name_in_local_language minLength: 1 maxLength: 64 description: Business person's first name in local language. Required for CN and HK. example: first name middle_name: type: string title: middle_name minLength: 1 maxLength: 64 description: Business person's middle name in English. Optional for CN and HK. example: s middle_name_in_local_language: type: string title: middle_name_in_local_language minLength: 1 maxLength: 64 description: Business person's middle name in local language. Optional for CN and HK. example: middle name last_name: type: string title: last_name minLength: 1 maxLength: 64 description: Business person's last name in English. Required for CN and HK. example: Lin last_name_in_local_language: type: string title: last_name_in_local_language minLength: 1 maxLength: 64 description: Business person's full name in local language. Required for CN and HK. example: last name Answer: type: string title: answer minLength: 1 maxLength: 2048 description: The answer for the information request. Certification-Source: title: CertificationSource description: Information related to the KYC source. allOf: - $ref: '#/components/schemas/Personal-Details' - type: object properties: role: type: string title: role description: Role of business person. Supported values are OWNER_OR_OPERATOR, PARTNER, UBO, DIRECTOR_CONTROL_PERSON_OR_LEGAL_REP, AGENT_OR_AUTHORISED_PERSON. example: AGENT_OR_AUTHORISED_PERSON merchant_type: $ref: '#/components/schemas/Merchant-Type' Rfi-Query-Response: type: array title: RfiQueryResponse description: The information to be responded to. items: $ref: '#/components/schemas/Rfi-Query-Item' Pagination-Metadata: description: '
current_page: Current page number
total_pages: Total number of pages available for this request
page_size: The number of records to display per page
has_more: Any more messages or records expected' type: object title: Pagination Metadata properties: current_page: description: Current page number type: integer minimum: 1 maximum: 1000 example: 1 title: current_page total_pages: description: Total number of pages available for this request type: integer minimum: 1 maximum: 1000 example: 1 title: total_pages page_size: description: Number of records to display per page type: integer minimum: 1 maximum: 10000 example: 1 title: page_size has_more: description: Any more messages or records expected type: boolean example: true title: has_more example: current_page: 1 total_pages: 10 page_size: 100 has_more: true Questions-Response: title: QuestionResponse type: object description: A question with response information for RFI submission. properties: question_id: $ref: '#/components/schemas/Question-Id' information_request: type: array title: information_request description: The information to be responded to. items: $ref: '#/components/schemas/Information-Request-Response' Question-Id: type: string title: question_id minLength: 1 maxLength: 64 description: The unique id for specific question. example: Q123456789 Rfi-Save-Request: title: RfiSaveRequest type: object description: Request body for responding to an RFI. required: - rfi_id - questions properties: rfi_id: $ref: '#/components/schemas/Rfi-Id' questions: type: array title: questions description: An array of questions to respond to. minItems: 1 maxItems: 100 items: $ref: '#/components/schemas/Questions-Request' Information-Type: type: string title: information_type minLength: 1 maxLength: 32 description: 'Information type: text or file.' Rfi-Query-Item: title: Rfi-Query-Item description: Response containing RFI list and details. allOf: - $ref: '#/components/schemas/Common-Rfi' - type: object properties: questions: type: array title: questions description: List of questions for the RFI. items: $ref: '#/components/schemas/Question' Rfi-Save-Response: title: RfiSaveResponse type: object description: Response body for responding to an RFI. properties: rfi_id: $ref: '#/components/schemas/Rfi-Id' status: allOf: - $ref: '#/components/schemas/Status' title: status description: 'RFI status. Possible values: OPEN, CLOSED.' example: OPEN questions: type: array title: questions description: An array of questions to respond to. items: $ref: '#/components/schemas/Questions-Response' Common-Question: title: Common-Question type: object description: An individual RFI question. properties: question_id: type: string title: question_id minLength: 1 maxLength: 64 description: The unique id for specific question. example: Q123456789 description_code: type: string title: description_code minLength: 1 maxLength: 64 description: The code for question's description. description_english: type: string title: description_english minLength: 1 maxLength: 2048 description: Question description in English. description_chinese: type: string title: description_chinese minLength: 1 maxLength: 2048 description: Question description in Chinese. certification_source: $ref: '#/components/schemas/Certification-Source' Information-Name: type: string title: information_name minLength: 1 maxLength: 64 description: Information name. example: id_doc_front Common-Rfi: title: Common-Rfi type: object description: Response containing RFI list and details. properties: rfi_id: $ref: '#/components/schemas/Rfi-Id' type: type: string title: type minLength: 1 maxLength: 64 description: RFI type. Currently supports KYC, RECIPIENT. status: allOf: - $ref: '#/components/schemas/Status' title: status description: 'RFI status. Possible values: OPEN, CLOSED.' created_time: allOf: - $ref: '#/components/schemas/Created-Time' description: RFI Creation date time in ISO 8601 format. title: created_time expiry_time: allOf: - $ref: '#/components/schemas/Created-Time' description: RFI expiration time in ISO 8601 format. title: expiry_time creditor_id: allOf: - $ref: '#/components/schemas/Creditor-Id' title: creditor_id description: Recipient id (use for RECIPIENT RFI type). Status: type: string description: Status of the request. title: status minLength: 1 maxLength: 64 Common-Information-Request: title: CommonInformationRequest type: object description: Information item that needs to be responded to in an RFI. properties: information_name: $ref: '#/components/schemas/Information-Name' answer: $ref: '#/components/schemas/Answer' Gateway-Error-Response: type: object title: GatewayErrorResponse required: - httpCode - httpMessage - moreInformation properties: httpCode: type: string maxLength: 3 description: Numeric HTTP Staus code title: httpCode httpMessage: type: string maxLength: 128 description: HTTP error message title: httpMessage example: Bad Request moreInformation: type: string maxLength: 128 description: HTTP error message title: moreInformation example: please provide valid value for request Merchant-Type: type: string title: merchant_type description: Type of merchant. enum: - INDIVIDUAL - ENTERPRISE Question: title: Questions description: An individual RFI question. allOf: - $ref: '#/components/schemas/Common-Question' - type: object properties: information_request: type: array title: information_request description: The information that needs to be responded to. items: $ref: '#/components/schemas/Get-Information-Request' securitySchemes: oAuth2: type: oauth2 flows: clientCredentials: tokenUrl: https://b2b.api.icg.citi.com/authenticationservices/v3/oauth/token scopes: /authenticationservices/v1: Access to marketplace management APIs