generated: '2026-09-05' method: derived source: openapi/citi-account-balance-inquiry-api-openapi.yaml, openapi/citi-account-notifications-api-openapi.yaml, openapi/citi-accounts-openapi.yaml, openapi/citi-accountsv5-openapi.yaml, openapi/citi-add-on-service-openapi.yaml, openapi/citi-addonservice-openapi.yaml, openapi/citi-balances-api-openapi.yaml, openapi/citi-beneficiary-search-openapi.yaml, openapi/citi-blocksandfilters-openapi.yaml, openapi/citi-brazillocalmandate-openapi.yaml, openapi/citi-bulk-payments-openapi.yaml, openapi/citi-card-disputes-openapi.yaml, openapi/citi-cash-balances-openapi.yaml, openapi/citi-cash-transactions-openapi.yaml, openapi/citi-clearing-exception-report-openapi.yaml, openapi/citi-contractstatusinquiry-openapi.yaml, openapi/citi-custody-billing-openapi.yaml, openapi/citi-custody-fx-transactions-openapi.yaml, openapi/citi-custody-penalties-openapi.yaml, openapi/citi-digitalpaymentscollectionsv12-openapi.yaml, openapi/citi-direct-debit-api-openapi.yaml, openapi/citi-due-date-openapi.yaml, openapi/citi-e-mandate-api-v1-openapi.yaml, openapi/citi-e-mandate-api-v2-openapi.yaml, openapi/citi-entityid-openapi.yaml, openapi/citi-express-payments-api-openapi.yaml, openapi/citi-express-payments-webhooks-openapi.yaml, openapi/citi-finance-undertaking-api-openapi.yaml, openapi/citi-fx-benchmark-async-api-openapi.yaml, openapi/citi-fx-benchmark-sync-api-openapi.yaml, openapi/citi-fx-cancel-async-api-openapi.yaml, openapi/citi-fx-cancel-sync-api-openapi.yaml, openapi/citi-fx-ecommerce-api-openapi.yaml, openapi/citi-fx-gateway-reporting-async-api-openapi.yaml, openapi/citi-fx-gateway-reporting-sync-api-openapi.yaml, openapi/citi-fx-market-async-api-openapi.yaml, openapi/citi-fx-market-sync-api-openapi.yaml, openapi/citi-fx-orders-async-api-openapi.yaml, openapi/citi-fx-orders-sync-api-openapi.yaml, openapi/citi-fx-quote-async-api-openapi.yaml, openapi/citi-fx-quote-sync-api-openapi.yaml, openapi/citi-fx-reporting-async-api-openapi.yaml, openapi/citi-fx-reporting-sync-api-openapi.yaml, openapi/citi-grace-iva-openapi.yaml, openapi/citi-id-provisioning-openapi.yaml, openapi/citi-idd-openapi.yaml, openapi/citi-immediate-openapi.yaml, openapi/citi-marketplace-management-openapi.yaml, openapi/citi-marqueta-openapi.yaml, openapi/citi-mobile-wallets-openapi.yaml, openapi/citi-mobilecardonboarding-openapi.yaml, openapi/citi-mobilevirtuallifecycle-openapi.yaml, openapi/citi-online-payment-acceptance-api-openapi.yaml, openapi/citi-order-approval-openapi.yaml, openapi/citi-payerid-api-openapi.yaml, openapi/citi-payment-reconfirmation-openapi.yaml, openapi/citi-payment-refund-openapi.yaml, openapi/citi-payment-status-openapi.yaml, openapi/citi-paymentcancellation-json-openapi.yaml, openapi/citi-paymentcancellation-xml-openapi.yaml, openapi/citi-paymentenhancedinquiry-json-openapi.yaml, openapi/citi-paymentenhancedinquiry-xml-openapi.yaml, openapi/citi-paymentinitiation-pacs008-openapi.yaml, openapi/citi-paymentinitiation-pacs009-openapi.yaml, openapi/citi-paymentinitiation-pain102-openapi.yaml, openapi/citi-paymentinitiation-pain103-openapi.yaml, openapi/citi-payto-openapi.yaml, openapi/citi-portfolio-listing-openapi.yaml, openapi/citi-proof-of-payment-openapi.yaml, openapi/citi-purchase-openapi.yaml, openapi/citi-reporting-get-2-openapi.yaml, openapi/citi-request-to-pay-openapi.yaml, openapi/citi-safekeeping-accounts-openapi.yaml, openapi/citi-safekeeping-positions-openapi.yaml, openapi/citi-securitytransactionsaccounts-openapi.yaml, openapi/citi-self-service-api-openapi.yaml, openapi/citi-statement-transactions-openapi.yaml, openapi/citi-statements-api-openapi.yaml, openapi/citi-statementsv2-api-openapi.yaml, openapi/citi-static-openapi.yaml, openapi/citi-submit-action-openapi.yaml, openapi/citi-tax-reclaims-openapi.yaml, openapi/citi-trade-api-openapi.yaml, openapi/citi-transfer-agency-accounts-openapi.yaml, openapi/citi-transfer-agency-holding-openapi.yaml, openapi/citi-transfer-agency-investors-openapi.yaml, openapi/citi-transfer-agency-transactions-openapi.yaml, openapi/citi-ukraine-bank-data-sharing-api-openapi.yaml, openapi/citi-ukraine-payment-service-initiation-api-openapi.yaml, openapi/citi-vamanagement-openapi.yaml, openapi/citi-vca-api-openapi.yaml, openapi/citi-vcaeventssubscriptions-openapi.yaml, openapi/citi-vcagetnotifications-openapi.yaml, openapi/citi-virtual-cards-lifecycle-v1-openapi.yaml, openapi/citi-virtual-cards-lifecycle-v4-openapi.yaml, openapi/citi-virtual-cards-notifications-openapi.yaml, openapi/citi-virtual-cards-pi-openapi.yaml, openapi/citi-virtual-cards-pi-v2-openapi.yaml, openapi/citi-virtual-cards-pi-webhooks-openapi.yaml, openapi/citi-virtual-cards-reporting-openapi.yaml, openapi/citi-virtual-cards-reporting-v1-openapi.yaml, openapi/citi-worldlink-ir-api-openapi.yaml, openapi/citi-worldlink-v1-api-openapi.yaml, openapi/citi-worldlink-v2-api-openapi.yaml, openapi/citi-worldlink-v3-api-openapi.yaml, openapi/citi-worldlink-v5-api-openapi.yaml schemes: - name: clientCredentials source: openapi/citi-account-balance-inquiry-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/tts/cards/api/v1/oauth2/token - name: clientCredentials source: openapi/citi-account-notifications-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-accounts-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: oAuth source: openapi/citi-accountsv5-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token - name: clientCredentials source: openapi/citi-add-on-service-openapi.yaml flows: - flow: authorizationCode authorizationUrl: /authenticationservices/v3/oauth/token tokenUrl: /authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: Client Credentials source: openapi/citi-addonservice-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-balances-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-beneficiary-search-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/tts/cards/api/v1/oauth2/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-blocksandfilters-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token - name: OAuth2 source: openapi/citi-brazillocalmandate-openapi.yaml flows: - flow: authorizationCode authorizationUrl: /authenticationservices/v3/oauth/token tokenUrl: /authenticationservices/v3/oauth/token - name: clientCredentials source: openapi/citi-bulk-payments-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token - name: ClientCredentials source: openapi/citi-card-disputes-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/api/oauth2/token - name: client-Credential-Oauth-Security-Schema source: openapi/citi-cash-balances-openapi.yaml flows: - flow: clientCredentials tokenUrl: /markets/api/oauth2/token description: This API uses OAuth 2 with the client credentials flow - name: client-Credential-Oauth-Security-Schema source: openapi/citi-cash-transactions-openapi.yaml flows: - flow: clientCredentials tokenUrl: /markets/api/oauth2/token description: This API uses OAuth 2 with the client credentials flow - name: clientCredentials source: openapi/citi-clearing-exception-report-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/tts/cards/api/v1/oauth2/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-contractstatusinquiry-openapi.yaml flows: - flow: authorizationCode authorizationUrl: /authenticationservices/v3/oauth/token tokenUrl: /authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: client-Credential-Oauth-Security-Schema source: openapi/citi-custody-billing-openapi.yaml flows: - flow: clientCredentials tokenUrl: /markets/api/oauth2/token description: This API uses OAuth 2 with the client credentials flow - name: client-Credential-Oauth-Security-Schema source: openapi/citi-custody-fx-transactions-openapi.yaml flows: - flow: clientCredentials tokenUrl: /markets/api/oauth2/token description: This API uses OAuth 2 with the client credentials flow - name: client-Credential-Oauth-Security-Schema source: openapi/citi-custody-penalties-openapi.yaml flows: - flow: clientCredentials tokenUrl: /markets/api/oauth2/token description: This API uses OAuth 2 with the client credentials flow - name: oAuth2 source: openapi/citi-digitalpaymentscollectionsv12-openapi.yaml flows: - flow: authorizationCode authorizationUrl: /authenticationservices/v3/oauth/token tokenUrl: /authenticationservices/v3/oauth/token - name: clientCredentials source: openapi/citi-direct-debit-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.sandbox.apib2b.citi.com/citiconnect/sb/authenticationservices/v1/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: cobVWriteSample source: openapi/citi-due-date-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token - name: cobVReadSample source: openapi/citi-due-date-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token - name: clientCredentials source: openapi/citi-e-mandate-api-v1-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.sit.apib2b.citi.com/citiconnect/sit5/authenticationservices/v1/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-e-mandate-api-v2-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.sandbox.apib2b.citi.com/citiconnect/sb/authenticationservices/v1/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: Client Credentials source: openapi/citi-entityid-openapi.yaml flows: - flow: authorizationCode authorizationUrl: /authenticationservices/v3/oauth/token tokenUrl: /authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: oAuth2 source: openapi/citi-express-payments-api-openapi.yaml flows: - flow: authorizationCode authorizationUrl: /authenticationservices/v3/oauth/token tokenUrl: /authenticationservices/v3/oauth/token - name: oAuth2 source: openapi/citi-express-payments-webhooks-openapi.yaml flows: - flow: authorizationCode authorizationUrl: /authenticationservices/v3/oauth/token tokenUrl: /authenticationservices/v3/oauth/token - name: oAuth2 source: openapi/citi-finance-undertaking-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: /v1/oauth2/token description: This API uses OAuth2 with the client credentials grant type for service provider API gateway integration. - name: OAuth2 source: openapi/citi-fx-benchmark-async-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://api.citivelocity.com/markets/cv/api/fx/oauth2/token description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. See the Citi Authentication API reference for information on requesting a token. - name: OAuth2 source: openapi/citi-fx-benchmark-sync-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://api.citivelocity.com/markets/cv/api/fx/oauth2/token description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. See the Citi Authentication API reference for information on requesting a token. - name: OAuth2 source: openapi/citi-fx-cancel-async-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://sandbox.api.citivelocity.com/markets/cv/api/fx/oauth2/token description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. See the Citi Authentication API reference for information on requesting a token. - name: OAuth2 source: openapi/citi-fx-cancel-sync-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://sandbox.api.citivelocity.com/markets/cv/api/fx/oauth2/token description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. See the Citi Authentication API reference for information on requesting a token. - name: client_credential source: openapi/citi-fx-ecommerce-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://icg.api.citigroup.net/markets/internal/cv/api/fx/oauth2/token description: client_credential - name: OAuth2 source: openapi/citi-fx-gateway-reporting-async-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://sandbox.api.citivelocity.com/markets/cv/api/fx/oauth2/token description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. See the Citi Authentication API reference for information on requesting a token. - name: OAuth2 source: openapi/citi-fx-gateway-reporting-sync-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://sandbox.api.citivelocity.com/markets/cv/api/fx/oauth2/token description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. See the Citi Authentication API reference for information on requesting a token. - name: OAuth2 source: openapi/citi-fx-market-async-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://sandbox.api.citivelocity.com/markets/cv/api/fx/oauth2/token description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. See the Citi Authentication API reference for information on requesting a token. - name: OAuth2 source: openapi/citi-fx-market-sync-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://sandbox.api.citivelocity.com/markets/cv/api/fx/oauth2/token description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. See the Citi Authentication API reference for information on requesting a token. - name: OAuth2 source: openapi/citi-fx-orders-async-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://api.citivelocity.com/markets/cv/api/fx/oauth2/token description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. See the Citi Authentication API reference for information on requesting a token. - name: OAuth2 source: openapi/citi-fx-orders-sync-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://sandbox.api.citivelocity.com/markets/cv/api/fx/oauth2/token description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. See the Citi Authentication API reference for information on requesting a token. - name: OAuth2 source: openapi/citi-fx-quote-async-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://api.citivelocity.com/markets/cv/api/fx/oauth2/token description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. See the Citi Authentication API reference for information on requesting a token. - name: OAuth2 source: openapi/citi-fx-quote-sync-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://api.citivelocity.com/markets/cv/api/fx/oauth2/token description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. See the Citi Authentication API reference for information on requesting a token. - name: OAuth2 source: openapi/citi-fx-reporting-async-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://api.citivelocity.com/markets/cv/api/fx/oauth2/token description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. See the Citi Authentication API reference for information on requesting a token. - name: OAuth2 source: openapi/citi-fx-reporting-sync-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://api.citivelocity.com/markets/cv/api/fx/oauth2/token description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-grace-iva-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/tts/cards/api/v1/oauth2/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-id-provisioning-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/tts/cards/api/oauth2/token description: 'All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token.

Sandbox Token URL: https://tts.sandbox.apib2b.citi.com/tts/api/oauth2/token
' - name: clientCredentials source: openapi/citi-idd-openapi.yaml flows: - flow: authorizationCode authorizationUrl: /authenticationservices/v3/oauth/token tokenUrl: /authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: cobWriteSample source: openapi/citi-immediate-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token - name: cobReadSample source: openapi/citi-immediate-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token - name: oAuth2 source: openapi/citi-marketplace-management-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://b2b.api.icg.citi.com/authenticationservices/v3/oauth/token - name: clientCredentials source: openapi/citi-marqueta-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/tts/cards/api/v1/oauth2/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-mobile-wallets-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/tts/cards/mvca/v1/token-lifecycle-events/cv/api/oauth2/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-mobilecardonboarding-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/tts/api/v1/oauth2/token - name: clientCredentials source: openapi/citi-mobilevirtuallifecycle-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/tts/api/v1/oauth2/token - name: Client Credentials source: openapi/citi-online-payment-acceptance-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: Authorization source: openapi/citi-order-approval-openapi.yaml flows: - flow: clientCredentials tokenUrl: /tts/api/v1/oauth2/token description: "Client applications must supply an\n authentication token with every request,\ \ and therefore must first\n authenticate before it can proceed. A client can use the OAuth\ \ 2 client\n credential grant flow to obtain a time limited access token. To get an\n access\ \ token send a HTTP Post request to the token endpoint using basic\n authentication with\ \ the client key and secret.

**Request**

```POST {baseURL}/tts/api/v1/oauth2/token\ \ HTTPS/1.1\n Authorization: Basic base64(key:secret) \n Content-Type:application/x-www-form-urlencoded\n\ \ {\n scope=/api&grant_type=client_credentials\n }```

\n **Response**

```\n\ \ {\n \"token_type\": \"bearer\", \n \"access_token\": , \n \ \ \"expires_in\": , \n \"consented_on\":, \n \"\ scope\": \"api\"\n }```

The bearer token is valid for 1800 seconds (30 minutes)\ \ after which it will expire. At this point, you would need to re-authenticate.

" - name: oAuth2 source: openapi/citi-payerid-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: authenticationservices/v3/oauth/token - name: clientCredentials source: openapi/citi-payment-reconfirmation-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v1/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API Reference for information on requesting a token. - name: clientCredentials source: openapi/citi-payment-refund-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v1/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API Reference for information on requesting a token. - name: clientCredentials source: openapi/citi-payment-status-openapi.yaml flows: - flow: clientCredentials tokenUrl: $(catalog.url)/authenticationservices/v1/oauth/token description: All CitiConnect APIs use the OAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API Reference for information on requesting a token. - name: clientCredentials source: openapi/citi-paymentcancellation-json-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.sit.apib2b.citi.com/citiconnect/sit5/authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-paymentcancellation-xml-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.sit.apib2b.citi.com/citiconnect/sit5/authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-paymentenhancedinquiry-json-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-paymentenhancedinquiry-xml-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-paymentinitiation-pacs008-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-paymentinitiation-pacs009-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-paymentinitiation-pain102-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-paymentinitiation-pain103-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-payto-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: Authentication source: openapi/citi-portfolio-listing-openapi.yaml flows: - flow: clientCredentials tokenUrl: /tts/api/v1/oauth2/token description: "Client applications must supply an authentication token with every request,\ \ and therefore must first authenticate before it can proceed. A client can use the OAuth\ \ 2 client credential grant flow to obtain a time limited access token. To get an access\ \ token send a HTTP Post request to the token endpoint using basic authentication with the\ \ client key and secret.

**Request**

```POST {baseURL}/tts/api/v1/oauth2/token\ \ HTTPS/1.1 Authorization: Basic base64(key:secret) Content-Type:application/x-www-form-urlencoded\ \ {\n scope=/api&grant_type=client_credentials\n}```

**Response**

```\n \ \ {\n \"token_type\": \"bearer\", \n \"access_token\": , \n \"expires_in\"\ : , \n \"consented_on\":, \n \"scope\": \"api\"\n\ \ }```

The bearer token is valid for 1800 seconds (30 minutes) after which it\ \ will expire. At this point, you would need to re-authenticate.

" - name: oAuth2 source: openapi/citi-proof-of-payment-openapi.yaml flows: - flow: authorizationCode authorizationUrl: /authenticationservices/v3/oauth/token tokenUrl: /authenticationservices/v3/oauth/token description: OAuth2 Authorization Code Flow - name: clientCredentials source: openapi/citi-purchase-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/tts/cards/api/v1/oauth2/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-reporting-get-2-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/tts/cards/api/oauth2/token description: 'All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token.

Sandbox Token URL: https://tts.sandbox.apib2b.citi.com/tts/api/oauth2/token
' - name: clientCredentials source: openapi/citi-request-to-pay-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/citiconnect/prod/requesttopayservice/v1/validate/address/authenticationservices/v1/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: client-Credential-Oauth-Security-Schema source: openapi/citi-safekeeping-accounts-openapi.yaml flows: - flow: clientCredentials tokenUrl: /markets/api/oauth2/token description: This API uses OAuth 2 with the client credentials flow - name: client-Credential-Oauth-Security-Schema source: openapi/citi-safekeeping-positions-openapi.yaml flows: - flow: clientCredentials tokenUrl: /markets/api/oauth2/token description: This API uses OAuth 2 with the client credentials flow - name: client-Credential-Oauth-Security-Schema source: openapi/citi-securitytransactionsaccounts-openapi.yaml flows: - flow: clientCredentials tokenUrl: /markets/api/oauth2/token description: This API uses OAuth 2 with the client credentials flow - name: clientCredentials source: openapi/citi-self-service-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.sandbox.apib2b.citi.com/citiconnect/sb/authenticationservices/v1/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-statement-transactions-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/api/v1/oauth2/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-statements-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v1/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: oAuth2 source: openapi/citi-statementsv2-api-openapi.yaml flows: - flow: authorizationCode authorizationUrl: /authenticationservices/v2/oauth/token tokenUrl: authenticationservices/v2/oauth/token - name: clientCredentials source: openapi/citi-static-openapi.yaml flows: - flow: authorizationCode authorizationUrl: /authenticationservices/v3/oauth/token tokenUrl: /authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-submit-action-openapi.yaml flows: - flow: clientCredentials tokenUrl: /tts/internal/api/oauth2 description: All APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: client-Credential-Oauth-Security-Schema source: openapi/citi-tax-reclaims-openapi.yaml flows: - flow: clientCredentials tokenUrl: /markets/api/oauth2/token description: This API uses OAuth 2 with the client credentials flow - name: clientCredentials source: openapi/citi-trade-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/tts/cards/api/v1/oauth2/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: oAuth2 source: openapi/citi-transfer-agency-accounts-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token - name: oAuth2 source: openapi/citi-transfer-agency-holding-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token - name: oAuth2 source: openapi/citi-transfer-agency-investors-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token - name: oAuth2 source: openapi/citi-transfer-agency-transactions-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token - name: oAuth source: openapi/citi-ukraine-bank-data-sharing-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token - name: auth source: openapi/citi-ukraine-bank-data-sharing-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://secure.api-preprod.bkm.com.tr/oauth-provider/oauth2/token - name: oAuth source: openapi/citi-ukraine-payment-service-initiation-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token - name: auth source: openapi/citi-ukraine-payment-service-initiation-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://secure.api-preprod.bkm.com.tr/oauth-provider/oauth2/token - name: clientCredentials source: openapi/citi-vamanagement-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-vca-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: ClientCredentials source: openapi/citi-vcaeventssubscriptions-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.sandbox.apib2b.citi.com/tts/cards/api/oauth2/token description: OAuth2 Client Credentials flow - name: ClientCredentials source: openapi/citi-vcagetnotifications-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/tts/api/v1/oauth2/token - name: clientCredentials source: openapi/citi-virtual-cards-lifecycle-v1-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/tts/api/v1/oauth2/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: ClientCredentials source: openapi/citi-virtual-cards-lifecycle-v4-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/tts/api/v1/oauth2/token - name: clientCredentials source: openapi/citi-virtual-cards-notifications-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/tts/cards/api/v1/oauth2/token - name: clientCredentials source: openapi/citi-virtual-cards-pi-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.sandbox.apib2b.citi.com/citiconnect/sb/authenticationservices/v1/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: ClientCredentials source: openapi/citi-virtual-cards-pi-v2-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/tts/api/v1/oauth2/token description: OAuth 2.0 Client Credentials flow for API authentication - name: OAuth2 source: openapi/citi-virtual-cards-pi-webhooks-openapi.yaml flows: - flow: authorizationCode authorizationUrl: https://tts.apib2b.citi.com/tts/api/v1/oauth2/authorize tokenUrl: https://tts.apib2b.citi.com/tts/api/v1/oauth2/token - name: clientCredentials source: openapi/citi-virtual-cards-reporting-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/tts/api/v1/oauth2/token description: 'All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token.

Sandbox Token URL: https://tts.sandbox.apib2b.citi.com/tts/api/v1/oauth2/token
' - name: clientCredentials source: openapi/citi-virtual-cards-reporting-v1-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.apib2b.citi.com/tts/api/v1/oauth2/token description: 'All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token.

Sandbox Token URL: https://tts.sandbox.apib2b.citi.com/tts/api/v1/oauth2/token
' - name: oAuth2 source: openapi/citi-worldlink-ir-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token - name: clientCredentials source: openapi/citi-worldlink-v1-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-worldlink-v2-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-worldlink-v3-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: /authenticationservices/v3/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. - name: clientCredentials source: openapi/citi-worldlink-v5-api-openapi.yaml flows: - flow: clientCredentials tokenUrl: https://tts.sandbox.apib2b.citi.com/citiconnect/sb/authenticationservices/v1/oauth/token description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See the Citi Authentication API reference for information on requesting a token. scopes: - scope: /api description: Access to ETF Order API flows: - clientCredentials sources: - openapi/citi-card-disputes-openapi.yaml - openapi/citi-id-provisioning-openapi.yaml - openapi/citi-mobilecardonboarding-openapi.yaml - openapi/citi-mobilevirtuallifecycle-openapi.yaml - openapi/citi-order-approval-openapi.yaml - openapi/citi-portfolio-listing-openapi.yaml - openapi/citi-reporting-get-2-openapi.yaml - openapi/citi-vcaeventssubscriptions-openapi.yaml - openapi/citi-vcagetnotifications-openapi.yaml - openapi/citi-virtual-cards-lifecycle-v4-openapi.yaml - openapi/citi-virtual-cards-pi-v2-openapi.yaml - openapi/citi-virtual-cards-reporting-openapi.yaml - openapi/citi-virtual-cards-reporting-v1-openapi.yaml - scope: /authenticationservices/v1 description: Access to Accounts, Balances, Transactions Information flows: - clientCredentials sources: - openapi/citi-accounts-openapi.yaml - openapi/citi-accountsv5-openapi.yaml - openapi/citi-blocksandfilters-openapi.yaml - openapi/citi-bulk-payments-openapi.yaml - openapi/citi-marketplace-management-openapi.yaml - openapi/citi-payerid-api-openapi.yaml - openapi/citi-request-to-pay-openapi.yaml - openapi/citi-transfer-agency-accounts-openapi.yaml - openapi/citi-transfer-agency-holding-openapi.yaml - openapi/citi-transfer-agency-investors-openapi.yaml - openapi/citi-transfer-agency-transactions-openapi.yaml - scope: /dod description: Access to Cash Balances Information flows: - clientCredentials sources: - openapi/citi-cash-balances-openapi.yaml - openapi/citi-cash-transactions-openapi.yaml - openapi/citi-custody-billing-openapi.yaml - openapi/citi-custody-fx-transactions-openapi.yaml - openapi/citi-custody-penalties-openapi.yaml - openapi/citi-safekeeping-accounts-openapi.yaml - openapi/citi-safekeeping-positions-openapi.yaml - openapi/citi-securitytransactionsaccounts-openapi.yaml - openapi/citi-tax-reclaims-openapi.yaml - scope: /fxapi flows: - clientCredentials sources: - openapi/citi-fx-ecommerce-api-openapi.yaml - scope: account_information description: Account Information flows: - clientCredentials sources: - openapi/citi-ukraine-bank-data-sharing-api-openapi.yaml - openapi/citi-ukraine-payment-service-initiation-api-openapi.yaml - scope: addonservices description: Grant read-only access to add-on services flows: - authorizationCode sources: - openapi/citi-entityid-openapi.yaml - scope: admin description: Grants read and write access to administrative information flows: - authorizationCode sources: - openapi/citi-virtual-cards-pi-webhooks-openapi.yaml - scope: authenticationservices/v1 description: Grant read-only access to payment initation service flows: - authorizationCode - clientCredentials sources: - openapi/citi-accountsv5-openapi.yaml - openapi/citi-brazillocalmandate-openapi.yaml - openapi/citi-digitalpaymentscollectionsv12-openapi.yaml - openapi/citi-ukraine-bank-data-sharing-api-openapi.yaml - openapi/citi-ukraine-payment-service-initiation-api-openapi.yaml - openapi/citi-worldlink-ir-api-openapi.yaml - scope: authenticationservices/v2 description: API Access for flows: - authorizationCode sources: - openapi/citi-statementsv2-api-openapi.yaml - scope: authenticationservices/v3 description: Grant read-only access to WorldLink FX service flows: - authorizationCode sources: - openapi/citi-contractstatusinquiry-openapi.yaml - scope: cob.read description: Permission to consult Immediate collection flows: - clientCredentials sources: - openapi/citi-immediate-openapi.yaml - scope: cob.write description: Permission to change Immediate collection flows: - clientCredentials sources: - openapi/citi-immediate-openapi.yaml - scope: cobv.read description: Authenticates to retrieve collection item with due date flows: - clientCredentials sources: - openapi/citi-due-date-openapi.yaml - scope: cobv.write description: Authenticates to update collection with due date flows: - clientCredentials sources: - openapi/citi-due-date-openapi.yaml - scope: directDebitService description: Grant read-only access to emandate initation service flows: - authorizationCode sources: - openapi/citi-idd-openapi.yaml - scope: emandateservices description: Grant read-only access to emandate initation service flows: - clientCredentials sources: - openapi/citi-payto-openapi.yaml - scope: fxapi flows: - clientCredentials sources: - openapi/citi-fx-benchmark-async-api-openapi.yaml - openapi/citi-fx-benchmark-sync-api-openapi.yaml - openapi/citi-fx-cancel-async-api-openapi.yaml - openapi/citi-fx-cancel-sync-api-openapi.yaml - openapi/citi-fx-gateway-reporting-async-api-openapi.yaml - openapi/citi-fx-gateway-reporting-sync-api-openapi.yaml - openapi/citi-fx-market-async-api-openapi.yaml - openapi/citi-fx-market-sync-api-openapi.yaml - openapi/citi-fx-orders-async-api-openapi.yaml - openapi/citi-fx-orders-sync-api-openapi.yaml - openapi/citi-fx-quote-async-api-openapi.yaml - openapi/citi-fx-quote-sync-api-openapi.yaml - openapi/citi-fx-reporting-async-api-openapi.yaml - openapi/citi-fx-reporting-sync-api-openapi.yaml - scope: payment_order description: Payment Order flows: - clientCredentials sources: - openapi/citi-ukraine-payment-service-initiation-api-openapi.yaml - scope: paymentservices description: Grant read-only access to payment initiation service flows: - authorizationCode sources: - openapi/citi-add-on-service-openapi.yaml - openapi/citi-express-payments-api-openapi.yaml - openapi/citi-express-payments-webhooks-openapi.yaml - openapi/citi-static-openapi.yaml - scope: read description: Grants read access flows: - authorizationCode - clientCredentials sources: - openapi/citi-submit-action-openapi.yaml - openapi/citi-virtual-cards-pi-webhooks-openapi.yaml - scope: selfservices description: Grant read-only access to beneficiary validation flows: - authorizationCode sources: - openapi/citi-add-on-service-openapi.yaml - openapi/citi-express-payments-api-openapi.yaml - openapi/citi-express-payments-webhooks-openapi.yaml - openapi/citi-proof-of-payment-openapi.yaml - scope: webhook.write sources: - openapi/citi-brazillocalmandate-openapi.yaml - scope: webhookcobr.write sources: - openapi/citi-brazillocalmandate-openapi.yaml - scope: write description: Grants write access flows: - authorizationCode - clientCredentials sources: - openapi/citi-submit-action-openapi.yaml - openapi/citi-virtual-cards-pi-webhooks-openapi.yaml