openapi: 3.2.0 info: title: ACES ETF OrderApproval Submit Action API version: '1.0' description: The ACES ETF Order Approval API receives order action requests from Citi ETF Sponsor clients. x-ibm-name: aces-order-approval contact: name: ACES L2 Support Team email: funds.l2productionsupport@imceu.eu.ssmb.com servers: - url: https://sit.b2b.tts.icgservices.citi.com/tts description: SIT Environment URL - url: https://qa.b2b.tts.icgservices.citi.com/tts description: QA Environment URL - url: https://uat.b2b.tts.icgservices.citi.com/tts description: UAT Environment URL - url: https://tts.sandbox.apib2b.citi.com/tts description: CTE Environment URL security: - Authorization: [] tags: - name: submitAction description: Operations related to ETF Order Approval processing paths: /etf/api/v1/order/submitAction: post: tags: - submitAction description: Posts an action request - Approve, Reject, or Cancel, allowing a PM/CM/D to approve or reject orders on the ACES Dealing Portal. operationId: submitAction summary: Request action on an order parameters: - name: Content-Type in: header description: Supports \"application/json\". required: true schema: type: string - name: Authorization in: header description: The OAuth Token prefixed with "Bearer" and space in between. required: true schema: type: string - name: client_id in: query required: true description: This is your unique identifier shared during your CitiConnect API onboarding. This is the same `client_id` used for oauth token generation schema: type: string requestBody: description: Order Submit Action Object content: application/json: schema: $ref: '#/components/schemas/submitAction' responses: '200': description: OK. Returns a confirmation of the action submission. content: application/json: schema: $ref: '#/components/schemas/ackResponse' '400': description: Bad Request Error content: application/json: schema: $ref: '#/components/schemas/nackResponse' examples: InvalidOrderId: summary: Invalid Order ID value: orderResponse: clientRefId: ABC1234 orderId: '100021822' responseTimeStamp: 2025-07-26 10:30:10EST respStatus: Failed respCode: '400' error: Invalid Order ID. InvalidAction: summary: Invalid Order ID value: orderResponse: clientRefId: ABC1234 orderId: '100021822' responseTimeStamp: 2025-07-26 10:30:10EST respStatus: Failed respCode: '400' error: Invalid action performed for the order. InvalidRole: summary: Invalid Role value: orderResponse: clientRefId: ABC1234 orderId: '100021822' responseTimeStamp: 2025-07-26 10:30:10EST respStatus: Failed respCode: '400' error: Invalid Role. '500': description: Internal Server Error content: application/json: schema: $ref: '#/components/schemas/nackResponse' example: orderResponse: clientRefId: ABC1234 orderId: '100021822' responseTimeStamp: 2025-07-26 10:30:10EST respStatus: Failed respCode: '500' error: Unable to serve your request at this moment. Please try again later. components: schemas: nackResponse: title: Order Action NACK Response Object type: object properties: orderResponse: type: object properties: clientRefId: title: Client Reference ID type: string description: Unique Client assigned identifier for each api request and response.. example: ABC1234 orderId: title: Order ID type: string description: ACES Dealing Portal Order ID for which action is submitted. example: '100021822' responseTimeStamp: title: Response Timestamp type: string description: Timestamp of the response in EST (Format:-"yyyy-MM-dd HH:mm:ssEST").. example: 2025-07-26 10:30:10EST respStatus: title: Response Status type: string description: Status of the request (e.g.,"Failed" for any failures). example: Failed respCode: title: Response Code type: string description: Error response Code. example: '400' error: type: string description: Description of the error encountered. example: Invalid Order ID. submitAction: title: Order Action Request Object type: object properties: orderRequest: type: object required: - clientRefId - orderId - citiVelocityUserId - requestTimestamp - role - statusUpdate - basketType properties: clientRefId: title: Client Reference ID type: string description: Unique Client assigned identifier for each api request and response. example: ABC1234 orderId: title: Order ID type: string description: ACES Dealing Portal Order Id for which action is being submitted. example: '100021822' citiVelocityUserId: title: Citi Velocity User ID type: string description: ACES User Id for authentication. example: ps90033 requestTimestamp: title: Request Timestamp type: string description: Timestamp of the request in EST (Format:-"yyyy-MM-dd HH:mm:ssEST"). role: title: User Role type: string description: Role of the user submitting the action. enum: - PM - CMD example: PM statusUpdate: title: Status Update description: The action to be applied to the order (for example "APPROVED", REJECTED", "CANCEL_APPROVED", "CANCEL_REJECTED"). type: string format: date basketType: title: Basket Type type: string enum: - STANDARD - CUSTOM description: Specifies the BasketType of the order. Can be applied by PM. example: STANDARD comments: title: Comments type: string description: Optional comments regarding the action. example: Portfolio Manager ok with the order. ackResponse: title: Order Action ACK Response Object type: object properties: orderResponse: type: object properties: clientRefId: title: Client Reference ID type: string description: Unique Client assigned identifier for each api request and response.. example: ABC1234 orderId: title: Order ID type: string description: ACES Dealing Portal Order ID for which action is submitted. example: '100021822' responseTimeStamp: title: Response Timestamp type: string description: Timestamp of the response in EST (Format:-"yyyy-MM-dd HH:mm:ssEST").. example: 2025-07-26 10:30:10EST respStatus: title: Response Status type: string description: Status of the request (e.g., "Success" for successfully processed). example: Success respCode: title: Response Code type: string description: Successful response Code. example: '200' securitySchemes: Authorization: description: "Client applications must supply an\n authentication token with every request, and therefore must first\n authenticate before it can proceed. A client can use the OAuth 2 client\n credential grant flow to obtain a time limited access token. To get an\n access token send a HTTP Post request to the token endpoint using basic\n authentication with the client key and secret.

**Request**

```POST {baseURL}/tts/api/v1/oauth2/token HTTPS/1.1\n Authorization: Basic base64(key:secret) \n Content-Type:application/x-www-form-urlencoded\n {\n scope=/api&grant_type=client_credentials\n }```

\n **Response**

```\n {\n \"token_type\": \"bearer\", \n \"access_token\": , \n \"expires_in\": , \n \"consented_on\":, \n \"scope\": \"api\"\n }```

The bearer token is valid for 1800 seconds (30 minutes) after which it will expire. At this point, you would need to re-authenticate.

\n" type: oauth2 flows: clientCredentials: tokenUrl: /tts/api/v1/oauth2/token scopes: /api: Access to ETF Order API