openapi: 3.2.0 info: title: Payment Acceptance Tokens API description: 'Payment Acceptance API Update - April 28, 2026' contact: name: Standards & Developer Hub url: https://tts.sandbox.developer.citi.com/citiconnect/ email: developer-support@citi.com version: 1.0.0 servers: - url: https://tts.apib2b.citi.com/citiconnect/prod description: production gateway URL - url: https://tts.sandbox.apib2b.citi.com/citiconnect/sb description: sbox URL - url: https://tts.sit.apib2b.citi.com/citiconnect/uat description: uat URL tags: - name: Tokens description: Tokens API paths: /digitalpayments/v1/payment-acceptance/tokens: post: tags: - Tokens summary: Create a Tokenization request description: This endpoint validates your request and synchronously responds with HTTP status 202 (accepted) after successful validation. If validation fails, the endpoint synchronously responds with error (HTTP status 4XX / 5XX and any applicable reason code), indicating Citi couldn't accept your tokenization creation request. operationId: tokenize parameters: - $ref: '#/components/parameters/Client-Id' - $ref: '#/components/parameters/Idempotency-Id' - $ref: '#/components/parameters/Merchant-Token-Id' - $ref: '#/components/parameters/Value-Added-Services' requestBody: description: Create Tokenization request required: true content: application/json: schema: $ref: '#/components/schemas/Tokenization-Create-Request' examples: Citi_Token_Create_Request: $ref: '#/components/examples/Citi-Token-Create-Request-Example' Network_Token_Create_Request: $ref: '#/components/examples/Network-Token-Create-Request-Example' Account_Updater_Create_Request: $ref: '#/components/examples/Account-Updater-Token-Create-Request-Example' security: - clientCredentials: [] callbacks: tokenization-create-request-status: $ref: '#/components/callbacks/Tokenization-Create-Request-Status' responses: '202': $ref: '#/components/responses/Request-Accepted' '400': $ref: '#/components/responses/Bad-Request' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/Not-Found' '405': $ref: '#/components/responses/Method-Not-Allowed' '409': $ref: '#/components/responses/Conflict' '415': $ref: '#/components/responses/Unsupported-Media-Type' '429': $ref: '#/components/responses/Rate-Limit-Exceeded' '500': $ref: '#/components/responses/Internal-Server-Error' '504': $ref: '#/components/responses/Gateway-Timeout' default: $ref: '#/components/responses/Internal-Server-Error' get: tags: - Tokens summary: Retrieve token details description: Get the latest statuses of tokenization using matching criteria. Currently, you can get the latest tokenization statuses up to 90 days from the token creation date. If the tokenization statuses date is 90+ days old, the endpoint responds with HTTP status 404 (not found). operationId: getToken parameters: - $ref: '#/components/parameters/Client-Id' - $ref: '#/components/parameters/Get-Token-Id' - $ref: '#/components/parameters/Merchant-Id' security: - clientCredentials: [] responses: '200': description: Token status headers: apim-guid: schema: type: string description: Citi's unique identification for your request result: schema: type: integer minimum: 1 maximum: 1000 default: 100 description: Number of transaction status matching your request content: application/json: schema: $ref: '#/components/schemas/Token-Response' examples: Token-Status: $ref: '#/components/examples/Token-Retrieve-Status' '400': $ref: '#/components/responses/Bad-Get-Request2' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/Not-Found' '405': $ref: '#/components/responses/Method-Not-Allowed' '429': $ref: '#/components/responses/Rate-Limit-Exceeded' '500': $ref: '#/components/responses/Internal-Server-Error' '504': $ref: '#/components/responses/Gateway-Timeout' patch: tags: - Tokens summary: Token Update Request description: This endpoint validates your request and synchronously responds with HTTP status 202 (accepted) after successful validation. If validation fails, the endpoint synchronously responds with error (HTTP status 4XX / 5XX and any applicable reason code), indicating Citi couldn't accept your tokenization update request. operationId: updateToken parameters: - $ref: '#/components/parameters/Client-Id' - $ref: '#/components/parameters/Idempotency-Id' - $ref: '#/components/parameters/Merchant-Token-Id' requestBody: description: Token Update Request. required: true content: application/json: schema: $ref: '#/components/schemas/Token-Update-Request' examples: Token_Update_Request: $ref: '#/components/examples/Token-Delete-Request-Example' security: - clientCredentials: [] callbacks: token-update-request-status: $ref: '#/components/callbacks/Token-Update-Request-Status' responses: '202': $ref: '#/components/responses/Request-Accepted' '400': $ref: '#/components/responses/Bad-Request' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/Not-Found' '405': $ref: '#/components/responses/Method-Not-Allowed' '409': $ref: '#/components/responses/Conflict' '415': $ref: '#/components/responses/Unsupported-Media-Type' '429': $ref: '#/components/responses/Rate-Limit-Exceeded' '500': $ref: '#/components/responses/Internal-Server-Error' '504': $ref: '#/components/responses/Gateway-Timeout' delete: tags: - Tokens summary: Token Delete Request description: This endpoint validates your request and synchronously responds with HTTP status 202 (accepted) after successful validation. If validation fails, the endpoint synchronously responds with error (HTTP status 4XX / 5XX and any applicable reason code), indicating Citi couldn't accept your tokenization update request. operationId: deleteToken parameters: - $ref: '#/components/parameters/Client-Id' - $ref: '#/components/parameters/Get-Token-Id' - $ref: '#/components/parameters/Merchant-Id' - $ref: '#/components/parameters/Value-Added-Services' security: - clientCredentials: [] callbacks: token-delete-request-status: $ref: '#/components/callbacks/Token-Delete-Request-Status' responses: '202': $ref: '#/components/responses/Request-Accepted' '400': $ref: '#/components/responses/Bad-Request' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/Not-Found' '405': $ref: '#/components/responses/Method-Not-Allowed' '409': $ref: '#/components/responses/Conflict' '415': $ref: '#/components/responses/Unsupported-Media-Type' '429': $ref: '#/components/responses/Rate-Limit-Exceeded' '500': $ref: '#/components/responses/Internal-Server-Error' '504': $ref: '#/components/responses/Gateway-Timeout' components: examples: Method-Not-Allowed-Example: value: ref_id: ec689822-9864-4c4d-9d68-222467627902 error_details: - issue: HTTP method is not supported action: Provide valid HTTP method code: CC00001 Token-Delete-Request-Status-Example: value: id: TRNX12345 customer: id: CITI202402040111 status: SUCCESS description: Token is succesfully deleted method: type: CARD id_type: CARD_NUMBER token_id: TOKEN123456 Rate-Limit-Exceeded-Gateway-Error-Example: value: httpCode: '429' httpMessage: Too Many Requests moreInformation: Rate Limit exceeded Token-Retrieve-Status: value: - id: TRNX12345 customer: id: CITI202402040111 card: token_id: Create0618token02 number: '4012000033330026' name_on_card: Clive expiry_month: '04' expiry_year: '25' Tokenization-Create-Request-Notification-Example: value: id: TRNX06181 customer: id: CITI202402040111 status: SUCCESS description: Citi Token Created method: type: CARD id_type: CARD_NUMBER card: token_id: Create0618token02 number: '4012000033330026' name_on_card: Peter Kemp expiry_month: 09 expiry_year: '25' Not-Found-Gateway-Error-Example: value: httpCode: '404' httpMessage: Not Found moreInformation: No resources match requested URI Method-Not-Allowed-Gateway-Error-Example: value: httpCode: '405' httpMessage: Method Not Allowed moreInformation: The method is not allowed for the requested URL Network-Token-Create-Request-Example: value: id: NETWORKRNX06181 customer: id: CITI202402040155 method: type: CARD id_type: CARD_NUMBER token_id: '456789001122' Bad-Request-Gateway-Error-Example: value: httpCode: '400' httpMessage: Bad Request moreInformation: please provide valid value for property emailAddress Unsupported-Media-Type-Example: value: ref_id: ec689822-9864-4c4d-9d68-222467627902 error_details: - issue: Media type not supported action: please use valid content-type in header code: CC00002 Account-Updater-Token-Create-Request-Example: value: id: ACCTUPDRNX06181 customer: id: CITI202402040155 method: type: CARD id_type: CARD_NUMBER token_id: '456789001122' Internal-Server-Gateway-Error-Example: value: httpCode: '500' httpMessage: Internal Server Error moreInformation: unable to serve your request at this moment Not-Found-Example: value: ref_id: ec689822-9864-4c4d-9d68-222467627702 error_details: - issue: Resource that you are searching is not found action: Please use valid resource details code: CC00006 Idempotency-Id-Conflict-Example: value: ref_id: ec689822-9864-4c4d-9d68-222467627902 error_details: - issue: Idempotency-Id provided is currently being used in another request action: please do not repeat the same request again code: VC00016 Unauthorized-Gateway-Error-Example: value: httpCode: '401' httpMessage: Unauthorized moreInformation: This server could not verify that you are authorized to access the URL Unauthorized-Example: value: ref_id: ec689822-9864-4c4d-9d68-222467627902 error_details: - issue: User not authorized for this functionality action: please use valid credentials to access this functionality code: CC00007 Bad-Request-Example: value: ref_id: 444d0f3f-4x55-7g99-8b2c-0cf2a921a5ab error_details: - issue: property method.type is mandatory and it cannot be empty action: please provide valid value for property method.type code: VC00010 Internal-Server-Error-Example: value: ref_id: ec689822-9864-4c4d-9d68-222467627902 error_details: - issue: unable to serve your request at this moment action: Please refer to documentation provided or contact support team code: CC00004 Gateway-Timeout-Gateway-Error-Example: value: httpCode: '504' httpMessage: GATEWAY_TIMEOUT moreInformation: 'Response took longer than timeout: PT50S' Un-Supported-Media-Type-Gateway-Error-Example: value: httpCode: '415' httpMessage: Unsupported Media Type moreInformation: Unsupported Content-Type Bad-Request-Get2-Example: value: ref_id: 444d0f3f-4x55-7g99-8b2c-0cf2b921a5ab error_details: - issue: provided value is not within the range for query-param reference action: please provide valid value for query-param reference, size must be between 1 and 128 code: VC00012 Citi-Token-Create-Request-Example: value: id: CITITRNX06181 customer: id: CITI202402040111 method: type: CARD id_type: CARD_NUMBER card: number: '4012000033330026' name_on_card: Peter Kemp expiry_month: 09 expiry_year: '25' Token-Delete-Request-Example: value: id: TRNX06181 customer: id: CITI202402040111 method: type: CARD id_type: CARD_NUMBER token_id: Create0618token02 schemas: Tokenization-Create-Status-Customer-Notification: title: customer type: object required: - id properties: id: description: Customer ID minLength: 1 maxLength: 40 type: string example: ABC12345 title: id first_name: description: Customer's first name minLength: 1 maxLength: 50 type: string example: John title: Customer first name last_name: description: Customer's last name minLength: 1 maxLength: 50 type: string example: Karl title: Customer last name Token-Update-Request-Customer-Notification: title: Customer Update type: object required: - id properties: id: description: Customer ID minLength: 1 maxLength: 40 type: string example: ABC12345 title: id first_name: description: Customer's first name minLength: 1 maxLength: 50 type: string example: John title: Customer first name last_name: description: Customer's last name minLength: 1 maxLength: 50 type: string example: Karl title: Customer last name Tokenization-Create-Request: title: Create Token Request type: object required: - customer - method - id properties: customer: $ref: '#/components/schemas/Tokenization-Create-Request-Customer' method: $ref: '#/components/schemas/Tokenization-Create-Request-Method' id: description: Request Id type: string minLength: 1 maxLength: 128 example: ABC123456 title: id card: $ref: '#/components/schemas/Tokenization-Create-Request-Card' billing_address: $ref: '#/components/schemas/Tokenization-Create-Request-Billing_Address' Error-Response: type: object title: Error Response properties: ref_id: type: string maxLength: 60 description: Unique ID for the Transaction title: ref_id error_details: type: array uniqueItems: true items: $ref: '#/components/schemas/Error-Detail' Error-Detail: type: object title: Error Detail properties: issue: type: string maxLength: 150 description: more details about the issue title: issue action: type: string maxLength: 150 description: corrective action to be taken to resolve above issue title: action code: type: string maxLength: 10 description: unique code representing the issue title: code Tokens-Response: type: object title: Tokens Response properties: id: type: string maxLength: 128 description: Unique reference number example: pay02052023456r title: id status: type: string maxLength: 10 description: The request has successfully been created. enum: - CREATED example: CREATED title: status description: type: string maxLength: 200 description: more information about the status example: The request has successfully been created title: description Token-Update-Request: type: object title: Token Update request required: - method - id properties: customer: $ref: '#/components/schemas/Token-Update-Request-Customer' method: $ref: '#/components/schemas/Token-Update-Request-Method' id: description: Request_Id type: string minLength: 1 maxLength: 128 example: ABC123456 title: id billing_address: $ref: '#/components/schemas/Tokenization-Update-Request-Billing_Address' Token-Update-Request-Method: title: method type: object required: - type - id_type - token_id properties: type: description: Payment Method Type type: string enum: - CARD - ACH - SEPA example: CARD title: type id_type: description: Personally Identifiable Information type: string enum: - CARD_NUMBER - ACCOUNT_NUMBER - IBAN - CITI_TOKEN example: IBAN title: id_type token_id: description: Token id type: string minLength: 1 maxLength: 50 example: Create0618token02 title: token_id Tokenization-Create-Request-Billing_Address: title: billing_address type: object properties: company: description: Company Name type: string minLength: 1 maxLength: 100 example: ABC Inc title: company city: description: Customer City Name type: string minLength: 1 maxLength: 100 example: New York title: city state: description: Customer State Name type: string minLength: 1 maxLength: 35 example: California title: state postal_code: description: Customer Postal code type: string minLength: 1 maxLength: 16 example: '33610' title: postal_code country_code: description: Customer Country code type: string pattern: ^[A-Z]{2,2}$ example: US title: country_code email: description: "Customer Email \n- Email address must be longer than 3 characters and adheres to a generous subset of valid RFC 2822 email addresses" example: customer.raj2024@gmail.com type: string pattern: '[a-z0-9._%+-]+@[a-z0-9.-]+\.[a-z]{2,4}$' title: email phone: description: "Customer Phone number \n- Data consists of '+', country code (1, 2 or 3 digits), 'space', and national number (which may embed single space characters for readability)" example: '+919962125789' pattern: \+[0-9]{1,3}[-\ ][0-9()+\-]{1,30} type: string title: phone lines: type: array minItems: 1 maxItems: 7 items: $ref: '#/components/schemas/Token_Lines' Tokenization-Create-Request-Customer: title: Customer type: object required: - id properties: id: description: Customer ID minLength: 1 maxLength: 40 type: string example: ABC12345 title: id first_name: description: Customer's first name minLength: 1 maxLength: 50 type: string example: John title: Customer first name last_name: description: Customer's last name minLength: 1 maxLength: 50 type: string example: Karl title: Customer last name Tokenization-Request-Customer: title: Customer Get type: object required: - id properties: id: description: Customer ID minLength: 1 maxLength: 40 type: string example: ABC12345 title: id first_name: description: Customer's first name minLength: 1 maxLength: 50 type: string example: John title: Customer first name last_name: description: Customer's last name minLength: 1 maxLength: 50 type: string example: Karl title: Customer last name Tokenization-Update-Request-Billing_Address: title: billing address Update type: object properties: company: description: "Company Name \n- For token id update request, billing_address.company parameter becomes mandatory when customer_id parameters was not provided by client in the payload request." type: string minLength: 1 maxLength: 100 example: ABC Inc title: company city: description: "Customer City Name \n- For token id update request, billing_address.city parameter becomes mandatory when customer_id parameters was not provided by client in the payload request." type: string minLength: 1 maxLength: 100 example: New York title: city state: description: "Customer State Name \n- For token id update request, billing_address.state parameter becomes mandatory when customer_id parameters was not provided by client in the payload request." type: string minLength: 1 maxLength: 35 example: California title: state postal_code: description: "Customer Postal code \n- For token id update request, billing_address.postal_code parameter becomes mandatory when customer_id parameters was not provided by client in the payload request." type: string minLength: 1 maxLength: 16 example: '33610' title: postal_code country_code: description: "Customer Country code \n- For token id update request, billing_address.country_code parameter becomes mandatory when customer_id parameters was not provided by client in the payload request." type: string pattern: ^[A-Z]{2,2}$ example: US title: country_code email: description: "Customer Email \n- Email address must be longer than 3 characters and adheres to a generous subset of valid RFC 2822 email addresses \n- For token id update request, billing_address.email parameter becomes mandatory when customer_id parameters was not provided by client in the payload request." example: customer.raj2024@gmail.com type: string pattern: '[a-z0-9._%+-]+@[a-z0-9.-]+\.[a-z]{2,4}$' title: email phone: description: "Customer Phone number \n- Data consists of '+', country code (1, 2 or 3 digits), 'space', and national number (which may embed single space characters for readability) \n- For token id update request, billing_address.phone parameter becomes mandatory when customer_id parameters was not provided by client in the payload request." example: '+919962125789' pattern: \+[0-9]{1,3}[-\ ][0-9()+\-]{1,30} type: string title: phone lines: type: array minItems: 1 maxItems: 7 items: $ref: '#/components/schemas/Token_Lines' Token_Lines: type: string maxLength: 70 minLength: 1 description: Address Lines title: lines Token-Delete-Request-Customer-Notification: title: Customer Update type: object required: - id properties: id: description: Customer ID minLength: 1 maxLength: 40 type: string example: ABC12345 title: id Token-Update-Request-Notification: type: object title: Tokenization-Create-Request-Notification required: - id - customer - status - description - method properties: id: description: Request Id type: string minLength: 1 maxLength: 128 example: ABC123456 title: id customer: $ref: '#/components/schemas/Token-Update-Request-Customer-Notification' status: type: string enum: - SUCCESS - FAILED description: Transaction Status title: status description: type: string minLength: 1 maxLength: 200 description: "Status Description \n- SUCCESS - Token is succesfully deleted \n- FAILED - Token deletion request is failed" title: description reason_code: description: Tokenization rejection Code example: SC0020 maxLength: 100 minLength: 1 type: string title: reason_code method: $ref: '#/components/schemas/Token-Delete-Request-Method-Notification' billing_address: $ref: '#/components/schemas/Tokenization-Update-Request-Billing_Address' card: $ref: '#/components/schemas/Tokenization-Create-Status-Card-Notification' Tokenization-Create-Status-Card-Notification: title: card type: object properties: number: description: Card Number that needs to be tokenized type: string minLength: 9 maxLength: 23 example: '4012000033330026' title: number name_on_card: description: Payer's name as given on the card type: string minLength: 1 maxLength: 50 example: ROGER WOOD title: name_on_card expiry_month: description: Two-digit month in which the payment card expires example: '01' type: string pattern: ^(0?[1-9]|1[0-2])$ title: expiry_month expiry_year: description: Two-digit year in which the payment card expires type: string pattern: ^[0-9]{2,2}$ example: '25' title: expiry_year Tokenization-Create-Status-Billing_Address-Notification: title: Billing Address type: object properties: company: description: Company Name type: string minLength: 1 maxLength: 100 example: ABC Inc title: company city: description: Customer City Name type: string minLength: 1 maxLength: 100 example: New York title: city state: description: Customer State Name type: string minLength: 1 maxLength: 20 example: California title: state postal_code: description: Customer Postal code type: string minLength: 1 maxLength: 10 example: '33610' title: postal_code country_code: description: Customer Country code type: string pattern: ^[A-Z]{3,3}$ example: USA title: country_code email: description: "Customer Email \n- Email address must be longer than 3 characters and adheres to a generous subset of valid RFC 2822 email addresses" type: string minLength: 3 example: sca@citi.com title: email phone: description: "Customer Phone number \n- Data consists of '+', country code (1, 2 or 3 digits), 'space', and national number (which may embed single space characters for readability)" example: '+919962125789' pattern: \+[0-9]{1,3}[-\ ][0-9()+\-]{1,30} type: string title: phone lines: description: Billing Addres details type: array minItems: 1 maxItems: 7 items: $ref: '#/components/schemas/Token_Lines' title: lines Token-Response: type: array items: $ref: '#/components/schemas/Tokenization' Tokenization: type: object title: Tokenization properties: customer: $ref: '#/components/schemas/Tokenization-Request-Customer' id: description: Request Id type: string minLength: 1 maxLength: 128 example: ABC123456 title: id status: type: string enum: - SUCCESS - FAILED description: Transaction Status title: status value_added_services: type: array items: type: string description: Value added services like CITI_TOKEN, NETWORK_TOKEN and ACCOUNT_UPDATER title: value_added_services description: type: string minLength: 1 maxLength: 200 description: "Status Description \n- SUCCESS - Network Token Activated \n- FAILED - Network Token Creation Failed" title: description reason_code: description: Tokenization rejection Code example: SC0020 maxLength: 100 minLength: 1 type: string title: reason_code method: $ref: '#/components/schemas/Tokenization-Create-Status-Method-Notification' card: $ref: '#/components/schemas/Tokenization-Create-Status-Card-Notification' billing_address: $ref: '#/components/schemas/Tokenization-Create-Status-Billing_Address-Notification' Tokenization-Create-Request-Card: title: card type: object description: Card object is mandatory for Citi token ID creation, if method.type is selected as CARD properties: number: description: "Card Number that needs to be tokenized \n- For Network token ID creation, card.number parameter becomes mandatory when client is not provided method.token_id parameter in the payload request." type: string minLength: 9 maxLength: 23 example: '4012000033330026' title: number name_on_card: description: "Payer's name as given on the card \n- For Network token ID creation, card.name_on_card parameter becomes mandatory when client is not provided method.token_id parameter in the payload request." type: string minLength: 1 maxLength: 50 example: ROGER WOOD title: name_on_card expiry_month: description: "Two-digit month in which the payment card expires \n- For Network token ID creation, card.expiry_month parameter becomes mandatory when client is not provided method.token_id parameter in the payload request." example: '01' type: string pattern: ^(0?[1-9]|1[0-2])$ title: expriry_month expiry_year: description: "Two-digit year in which the payment card expires \n- For Network token ID creation, card.expiry_year parameter becomes mandatory when client is not provided method.token_id parameter in the payload request." type: string pattern: ^[0-9]{2,2}$ example: '25' title: expiry_year Tokenization-Create-Request-Method: title: method type: object required: - type - id_type properties: type: description: Payment Method Type type: string enum: - CARD - ACH - SEPA example: CARD title: type id_type: description: Personally Identifiable Information type: string enum: - CARD_NUMBER - ACCOUNT_NUMBER - IBAN - CITI_TOKEN example: IBAN title: id_type token_id: description: "Token id. \n- For Network token ID creation, method.token_id parameter becomes mandatory when client is not provided card related information in the payload request." type: string minLength: 1 maxLength: 50 example: Create0618token02 title: token_id session_id: description: Session identification number type: string minLength: 36 maxLength: 37 example: SES1234567890123456789012345678 title: session_id Token-Update-Request-Customer: title: Customer Update type: object required: - id properties: id: description: "Customer ID \n- For token id update request, customer_id parameter becomes mandatory when billing_address parameters was not provided by client in the payload request." minLength: 1 maxLength: 40 type: string example: ABC12345 title: id first_name: description: Customer's first name minLength: 1 maxLength: 50 type: string example: John title: Customer first name last_name: description: Customer's last name minLength: 1 maxLength: 50 type: string example: Karl title: Customer last name Gateway-Error-Response: type: object title: GatewayErrorResponse properties: httpCode: type: string maxLength: 3 description: Numeric HTTP Staus code title: httpCode httpMessage: type: string maxLength: 128 description: HTTP error message title: httpMessage moreInformation: type: string maxLength: 128 description: HTTP error message title: httpMessage Tokenization-Create-Status-Notification: type: object title: Tokenization-Create-Status-Notification required: - id - customer - status - description - method properties: id: description: Request Id type: string minLength: 1 maxLength: 128 example: ABC123456 title: id customer: $ref: '#/components/schemas/Tokenization-Create-Status-Customer-Notification' status: type: string enum: - SUCCESS - FAILED description: Transaction Status title: status description: type: string minLength: 1 maxLength: 200 description: "Status Description \n- SUCCESS - Citi Token Created \n- FAILED - Citi Token Creation Failed" title: description reason_code: description: Tokenization rejection Code example: SC0020 maxLength: 100 minLength: 1 type: string title: reason_code billing_address: $ref: '#/components/schemas/Tokenization-Create-Status-Billing_Address-Notification' method: $ref: '#/components/schemas/Tokenization-Create-Status-Method-Notification' card: $ref: '#/components/schemas/Tokenization-Create-Status-Card-Notification' card_old: $ref: '#/components/schemas/Tokenization-Create-Status-Card-Notification' Token-Delete-Request-Method-Notification: title: method type: object required: - type - id_type - token_id properties: type: description: Payment Method Type type: string enum: - CARD - ACH - SEPA example: CARD title: type id_type: description: Personally Identifiable Information type: string enum: - CARD_NUMBER - ACCOUNT_NUMBER - IBAN - CITI_TOKEN example: IBAN title: id_type token_id: description: Token id generated/updated by VGS type: string minLength: 1 maxLength: 50 example: Create0618token02 title: token_id session_id: description: Session identification number type: string minLength: 36 maxLength: 37 example: SES1234567890123456789012345678 title: session_id Token-Delete-Request-Notification: type: object title: Tokenization-Create-Request-Notification required: - customer - status - description - method properties: customer: $ref: '#/components/schemas/Token-Delete-Request-Customer-Notification' status: type: string enum: - SUCCESS - FAILED description: Transaction Status title: status description: type: string minLength: 1 maxLength: 200 description: "Status Description \n- SUCCESS - Token is succesfully deleted \n- FAILED - Token deletion request is failed" title: description reason_code: description: Tokenization rejection Code example: SC0020 maxLength: 100 minLength: 1 type: string title: reason_code method: $ref: '#/components/schemas/Token-Delete-Request-Method-Notification' card: $ref: '#/components/schemas/Tokenization-Create-Status-Card-Notification' Tokenization-Create-Status-Method-Notification: title: method type: object required: - type - id_type - token_id properties: type: description: Payment Method Type type: string enum: - CARD - ACH - SEPA example: CARD title: type id_type: description: Personally Identifiable Information type: string enum: - CARD_NUMBER - ACCOUNT_NUMBER - IBAN - CITI_TOKEN example: IBAN title: id_type token_id: description: Token id generated/updated by VGS type: string minLength: 1 maxLength: 50 example: Create0618token02 title: token_id session_id: description: Session identification number type: string minLength: 36 maxLength: 37 example: SES1234567890123456789012345678 title: session_id responses: Unauthorized: description: Unauthorized headers: apim-guid: $ref: '#/components/headers/Request-Id' content: application/json: schema: oneOf: - $ref: '#/components/schemas/Gateway-Error-Response' - $ref: '#/components/schemas/Error-Response' examples: Unauthorized-Service-Error-Example: $ref: '#/components/examples/Unauthorized-Example' Unauthorized-Gateway-Error-Example: $ref: '#/components/examples/Unauthorized-Gateway-Error-Example' Bad-Get-Request2: description: Bad Get Request headers: apim-guid: $ref: '#/components/headers/Request-Id' content: application/json: schema: $ref: '#/components/schemas/Error-Response' examples: Bad-Request-Example: $ref: '#/components/examples/Bad-Request-Get2-Example' Gateway-Timeout: description: Gateway Timeout headers: apim-guid: $ref: '#/components/headers/Request-Id' content: application/json: schema: oneOf: - $ref: '#/components/schemas/Gateway-Error-Response' examples: Gateway-Timeout-Gateway-Error-Example: $ref: '#/components/examples/Gateway-Timeout-Gateway-Error-Example' Request-Accepted: description: Accepted headers: apim-guid: $ref: '#/components/headers/Request-Id' Merchant-Id: schema: type: string description: The unique identifier issued to you by your payment provider content: application/json: schema: $ref: '#/components/schemas/Tokens-Response' Rate-Limit-Exceeded: description: Rate Limit Exceeded headers: apim-guid: $ref: '#/components/headers/Request-Id' content: application/json: schema: oneOf: - $ref: '#/components/schemas/Gateway-Error-Response' examples: Rate-Limit-Exceeded-Gateway-Error-Example: $ref: '#/components/examples/Rate-Limit-Exceeded-Gateway-Error-Example' Not-Found: description: Not Found headers: apim-guid: $ref: '#/components/headers/Request-Id' content: application/json: schema: oneOf: - $ref: '#/components/schemas/Gateway-Error-Response' - $ref: '#/components/schemas/Error-Response' examples: Not-Found-Service-Error-Example: $ref: '#/components/examples/Not-Found-Example' Not-Found-Gateway-Error-Example: $ref: '#/components/examples/Not-Found-Gateway-Error-Example' Unsupported-Media-Type: description: Unsupported Media Type headers: apim-guid: $ref: '#/components/headers/Request-Id' content: application/json: schema: oneOf: - $ref: '#/components/schemas/Gateway-Error-Response' - $ref: '#/components/schemas/Error-Response' examples: Unsupported-Media-Type-Service-Error-Example: $ref: '#/components/examples/Unsupported-Media-Type-Example' Unsupported-Media-Type-Gateway-Error-Example: $ref: '#/components/examples/Un-Supported-Media-Type-Gateway-Error-Example' Internal-Server-Error: description: Internal Server Error headers: apim-guid: $ref: '#/components/headers/Request-Id' content: application/json: schema: oneOf: - $ref: '#/components/schemas/Gateway-Error-Response' - $ref: '#/components/schemas/Error-Response' examples: Internal-Server-Error-Example: $ref: '#/components/examples/Internal-Server-Error-Example' Internal-Server-Gateway-Error-Example: $ref: '#/components/examples/Internal-Server-Gateway-Error-Example' Method-Not-Allowed: description: Method Not Allowed headers: apim-guid: $ref: '#/components/headers/Request-Id' content: application/json: schema: oneOf: - $ref: '#/components/schemas/Gateway-Error-Response' - $ref: '#/components/schemas/Error-Response' examples: Method-Not-Allowed-Service-Error-Example: $ref: '#/components/examples/Method-Not-Allowed-Example' Method-Not-Allowed-Gateway-Error-Example: $ref: '#/components/examples/Method-Not-Allowed-Gateway-Error-Example' Conflict: description: Conflict headers: apim-guid: $ref: '#/components/headers/Request-Id' content: application/json: schema: $ref: '#/components/schemas/Error-Response' examples: Idempotency-Id-Conflict-Example: $ref: '#/components/examples/Idempotency-Id-Conflict-Example' Bad-Request: description: Bad Request headers: apim-guid: $ref: '#/components/headers/Request-Id' content: application/json: schema: oneOf: - $ref: '#/components/schemas/Gateway-Error-Response' - $ref: '#/components/schemas/Error-Response' examples: Bad-Request-Service-Error-Example: $ref: '#/components/examples/Bad-Request-Example' Bad-Request-Gateway-Error-Example: $ref: '#/components/examples/Bad-Request-Gateway-Error-Example' parameters: Merchant-Token-Id: name: Merchant-Id in: header required: true description: Your unique Merchant Identification number schema: type: string maxLength: 40 minLength: 1 description: Your unique Merchant Identification number example: M123456987 Merchant-Id: name: Merchant-Id in: header required: true description: Your unique Merchant Identification number schema: type: string maxLength: 40 minLength: 1 description: Your unique Merchant Identification number example: M123456987 Get-Token-Id: name: token-id in: query required: true description: Token ID schema: type: string Event-Name: name: Event-Name in: header required: true description: Event Type schema: type: string Idempotency-Id: name: Idempotency-Id in: header required: true description: "Your unique identification for a POST request \n - Maximum length is 128. \n- CitiConnect API responds with an error (HTTP status 4XX) if your POST request idempotency identification value is a duplicate across a recent history of idempotency identifications in Citi's database." schema: type: string maxLength: 128 description: "Your unique identification for a POST request \n - Maximum length is 128. \n- CitiConnect API responds with an error (HTTP status 4XX) if your POST request idempotency identification value is a duplicate across a recent history of idempotency identifications in Citi's database. \n- If you don't receive any response (HTTP status 2XX, 4XX or 5XX) from Citi to your POST request and you wish to retry, reinitiate your request with the same idempotency identification to prevent accidental duplicate payment." example: a44cbb60-6de4-4edb-9a7a-123414bba3bb Value-Added-Services: name: Value-Added-Services in: header required: true description: Event Type schema: type: string enum: - NETWORK_TOKEN - CITI_TOKEN - ACCOUNT_UPDATER Event-Type: name: Event-Type in: header required: true description: Event Type schema: type: string Client-Id: in: query name: client_id required: true description: Your unique identification, same as the identification you use for OAuth token generation, Citi shared with you during your CitiConnect API onboarding schema: type: string description: Your unique identification, same as the identification you use for OAuth token generation, Citi shared with you during your CitiConnect API onboarding example: 9a10a5d6-63d4-4885-b6bd-19e79629496d Apim-Guid: name: Apim-Guid in: header required: true description: Your unique Apim-Guid schema: type: string maxLength: 52 minLength: 1 description: Your unique Apim-Guid example: na-apimgwgtds04~4a98cbc5-d813-4e65-bc81-d70f0f87f6ec callbacks: Token-Delete-Request-Status: /token-delete-request-status: delete: parameters: - $ref: '#/components/parameters/Apim-Guid' - $ref: '#/components/parameters/Event-Type' - $ref: '#/components/parameters/Event-Name' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/Token-Delete-Request-Notification' examples: Token-Update-Request-Notification: $ref: '#/components/examples/Token-Delete-Request-Status-Example' responses: '202': description: Accepted content: application/json: schema: type: object Tokenization-Create-Request-Status: /tokenization-create-request-status: post: parameters: - $ref: '#/components/parameters/Apim-Guid' - $ref: '#/components/parameters/Event-Type' - $ref: '#/components/parameters/Event-Name' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/Tokenization-Create-Status-Notification' examples: Tokenization-Create-Request-Notification: $ref: '#/components/examples/Tokenization-Create-Request-Notification-Example' responses: '202': description: Accepted content: application/json: schema: type: object Token-Update-Request-Status: /token-update-request-status: patch: parameters: - $ref: '#/components/parameters/Apim-Guid' - $ref: '#/components/parameters/Event-Type' - $ref: '#/components/parameters/Event-Name' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/Token-Update-Request-Notification' examples: Token-Update-Request-Notification: $ref: '#/components/examples/Token-Delete-Request-Status-Example' responses: '202': description: Accepted content: application/json: schema: type: object headers: Request-Id: schema: type: string description: Citi's unique identification for your request securitySchemes: clientCredentials: description: 'All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. ' oAuth2: type: oauth2 flows: authorizationCode: authorizationUrl: /authenticationservices/v3/oauth/token tokenUrl: /authenticationservices/v3/oauth/token scopes: authenticationservices/v1: Grant read-only access to payment initation service