openapi: 3.2.0 info: title: DN Online & Mobile SEPA Credit Transfer Instant API description: Diebold Nixdorf Online & Mobile API. version: 3.2.1 contact: name: Diebold Nixdorf email: info.de@dieboldnixdorf.com servers: - url: http://localhost:8080/tm-om-api/v4 description: Transaction Middleware (VTE) 3.0+ - url: https://localhost:8080/tm-om-api/v4 description: Transaction Middleware (VTE) 3.0+ security: - bearerAuth: [] tags: - name: SEPA Credit Transfer Instant API paths: /sepa-instant/pushPayment: get: tags: - SEPA Credit Transfer Instant API summary: Get the status of a SEPA Instant credit transfer description: Get the status of a SEPA instant credit transfer inititated by the payer operationId: getPushPayment parameters: - $ref: '#/components/parameters/clientSecretParam' - $ref: '#/components/parameters/sessionTokenParam' - $ref: '#/components/parameters/consumerIdParam' - $ref: '#/components/parameters/referenceIdParam' responses: '200': $ref: '#/components/responses/getPushPaymentResponse' '400': $ref: '#/components/responses/badRequestResponse' '401': $ref: '#/components/responses/unauthorizedResponse' '404': $ref: '#/components/responses/notFoundResponse' default: $ref: '#/components/responses/defaultResponse' post: tags: - SEPA Credit Transfer Instant API summary: Create a SEPA instant payment request description: Create a push payment to transfer credits. operationId: createPushPayment parameters: - $ref: '#/components/parameters/clientSecretParam' - $ref: '#/components/parameters/sessionTokenParam' - $ref: '#/components/parameters/consumerIdParam' requestBody: $ref: '#/components/requestBodies/createPushPaymentRequestBody' responses: '200': $ref: '#/components/responses/createPushPaymentResponse' '400': $ref: '#/components/responses/badRequestResponse' '401': $ref: '#/components/responses/unauthorizedResponse' '404': $ref: '#/components/responses/notFoundResponse' default: $ref: '#/components/responses/defaultResponse' delete: tags: - SEPA Credit Transfer Instant API summary: Cancel a SEPA instant payment request description: Cancel a push payment. operationId: cancelPushPayment parameters: - $ref: '#/components/parameters/clientSecretParam' - $ref: '#/components/parameters/sessionTokenParam' - $ref: '#/components/parameters/consumerIdParam' responses: '200': $ref: '#/components/responses/cancelPushPaymentResponse' '400': $ref: '#/components/responses/badRequestResponse' '401': $ref: '#/components/responses/unauthorizedResponse' '404': $ref: '#/components/responses/notFoundResponse' default: $ref: '#/components/responses/defaultResponse' /sepa-instant/pullPayment: get: tags: - SEPA Credit Transfer Instant API summary: Get the status of a SEPA instant pull payment description: When a merchant (payee) issues a payment on the clients (payer) behalf a notification is sent to the client. By using a HTTP GET the client can review the status and details of the (pending) transaction. operationId: getPullPayment parameters: - $ref: '#/components/parameters/clientSecretParam' - $ref: '#/components/parameters/sessionTokenParam' - $ref: '#/components/parameters/consumerIdParam' responses: '200': $ref: '#/components/responses/getPullPaymentResponse' '400': $ref: '#/components/responses/badRequestResponse' '401': $ref: '#/components/responses/unauthorizedResponse' '404': $ref: '#/components/responses/notFoundResponse' default: $ref: '#/components/responses/defaultResponse' post: tags: - SEPA Credit Transfer Instant API summary: Authorize a pending SEPA instant payment request (pull payment) description: When a merchant (payee) issues a payment on the clients (payer) behalf a notification is sent to the client. By unsing a HTTP POST the client authorizes the pending transaction for further processing. operationId: authorizePullPayment parameters: - $ref: '#/components/parameters/clientSecretParam' - $ref: '#/components/parameters/sessionTokenParam' - $ref: '#/components/parameters/consumerIdParam' requestBody: $ref: '#/components/requestBodies/authorizePullPaymentRequestBody' responses: '200': $ref: '#/components/responses/authorizePullPaymentResponse' '400': $ref: '#/components/responses/badRequestResponse' '401': $ref: '#/components/responses/unauthorizedResponse' '404': $ref: '#/components/responses/notFoundResponse' default: $ref: '#/components/responses/defaultResponse' delete: tags: - SEPA Credit Transfer Instant API summary: Cancel a pending SEPA instant payment request (pull payment) description: When a merchant (payee) issues a payment on the clients (payer) behalf a notification is sent to the client. By unsing a HTTP DELETE the client cancels the pending transaction. operationId: cancelPullPayment parameters: - $ref: '#/components/parameters/clientSecretParam' - $ref: '#/components/parameters/sessionTokenParam' - $ref: '#/components/parameters/consumerIdParam' responses: '200': $ref: '#/components/responses/cancelPullPaymentResponse' '400': $ref: '#/components/responses/badRequestResponse' '401': $ref: '#/components/responses/unauthorizedResponse' '404': $ref: '#/components/responses/notFoundResponse' default: $ref: '#/components/responses/defaultResponse' components: responses: unauthorizedResponse: description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/Error' defaultResponse: description: Unexpected error. Please see/inspect 'code' and 'message' properties of the error for more/detailed informations. content: application/json: schema: $ref: '#/components/schemas/Error' badRequestResponse: description: Bad Request content: application/json: schema: $ref: '#/components/schemas/Error' cancelPushPaymentResponse: description: Returns the response status. content: application/json: schema: $ref: '#/components/schemas/CancelPushPaymentResponse' authorizePullPaymentResponse: description: Returns the response status. content: application/json: schema: $ref: '#/components/schemas/AuthorizePullPaymentResponse' createPushPaymentResponse: description: Returns the response status. content: application/json: schema: $ref: '#/components/schemas/CreatePushPaymentResponse' notFoundResponse: description: Not found content: application/json: schema: $ref: '#/components/schemas/Error' getPushPaymentResponse: description: Returns the response status. content: application/json: schema: $ref: '#/components/schemas/GetPushPaymentResponse' getPullPaymentResponse: description: Returns the response status. content: application/json: schema: $ref: '#/components/schemas/GetPullPaymentResponse' cancelPullPaymentResponse: description: Returns the response status. content: application/json: schema: $ref: '#/components/schemas/CancelPullPaymentResponse' schemas: ResponseBase: description: "Every number used by OM-API is within a certain number range.
The OM-API V4 number range is 2870000 - 2879999.
Within that range, every requests group has its number range of 1000:
\n | Request Group | Number Range |\n |---------------|------------------------------------|\n | Account Management API | 2870000-2870999 |\n | Standing Order API | 2871000-2871999 |\n | Prestaged Transaction API | 2872000-2872999 |\n | Miscellaneous API | 2873000-2873999 |\n | Accessibility API | 2874000-2874999 |\nWithin each group range, every belonging request has its number range of 100:\n
\n | Request Name | Number Range |\n |---------------|------------------------------------|\n | *Account Management API*\n | getAccounts | 2870000-2870099 |\n | getAccountTypes | 2870100-2870199 |\n | getAccountDetails | 2870200-2870299 |\n | getTransactions | 2870300-2870399 |\n | getScheduledTransactions | 2870400-2870499 |\n | checkAccount | 2870500-2870599 |\n | createTransfer | 2870600-2870699 |\n | createDispute | 2870700-2870799 |\n |  \n | *Standing Order API*\n | getStandingOrders | 2871000-2871099 |\n | createStandingOrder | 2871100-2871199 |\n | updateStandingOrder | 2871200-2871299 |\n | deleteStandingOrder | 2871300-2871399 |\n | updateAccountNickname | 2871400-2871499 |\n |  \n | *Prestaged Transaction API*\n | createCashout4Me | 2872000-2872099 |\n | createCashout2You | 2872100-2872199 |\n | createDeposit | 2872200-2872299 |\n | createBranchDeposit | 2872300-2872399 |\n | deletePrestagedTransaction | 2872400-2872499 |\n | getPrestagedTransactions | 2872500-2872599 |\n | executePrestagedTransaction | 2872600-2872699 |\n |  \n | *Miscellaneous API*\n | getCreditors | 2874000-2874099 |\n | getSinglePaymentOrderData | 2874100-2874199 |\n | getPreferences | 2874200-2874299 |\n | setPreferences | 2874300-2874399 |\n | getClientBranding | 2874400-2874499 |\n | getGenericTransactionOrders | 2874500-2874599 |\n | performGenericTransactionOrder | 2874600-2874699 |\n | getLocations | 2874700-2874799 |\n |  \n | *Accessibility API*\n | getRsaKey | 2875000-2875099 |\n | getEcKey | 2875100-2875199 |\n | getVersion | 2875200-2875299 |\n
\n The numbers in the ranges are used primarily for the error codes (see Error schema)." type: object required: - success properties: success: description: 'Returns True or False to indicate the success of the API call. The The error property is optional. It is set only if an error has been detected. ' type: boolean example: true error: $ref: '#/components/schemas/Error' GetPushPaymentResponse: type: object required: - responseStatus description: The response data is contained in the __CryptoEnvelope__'s property __payload__ as encrypted and stringified JSON object using the schema __GetPushPaymentResponsePayload__ properties: responseStatus: $ref: '#/components/schemas/ResponseBase' cryptoEnvelope: $ref: '#/components/schemas/CryptoEnvelope' AesKeyParams: description: A holder object for AES symmetric key params. required: - key - iv properties: key: description: The Base64 encoded (and encrypted) AES key (256bit). type: string example: MTI4MzI1Mjc2NTI= iv: description: The Base64 encoded (and encrypted) AES iv (128bit). type: string example: MTI4MzI1Mjc2NTI= GetPullPaymentResponse: type: object required: - responseStatus properties: responseStatus: $ref: '#/components/schemas/ResponseBase' CancelPushPaymentResponse: type: object required: - responseStatus properties: responseStatus: $ref: '#/components/schemas/ResponseBase' CancelPullPaymentResponse: type: object required: - responseStatus properties: responseStatus: $ref: '#/components/schemas/ResponseBase' AuthorizePullPaymentRequest: type: object required: - cryptoEnvelope description: "The request body only holds one property, the __CryptoEnvelope__:\n\n CryptoEnvelope:\n type: object\n required:\n - payload\n description: >-\n Object holding cryptographically secured request/response properties.\n properties:\n payload:\n type: string\n minLength: 1\n example: BB20WIJRTz/T9vkGhETgpehzc6dDoioQ9DJV4lRA6ICaWwLPLDE+\n\nThe __CryptoEnvelope__ has a __payload__ property which represents an encrypted JSON string of the actual request object which is specified by the schema __AuthorizePullPaymentRequestPayload__." properties: cryptoEnvelope: $ref: '#/components/schemas/CryptoEnvelope' CryptoEnvelope: type: object required: - payload description: Object holding a cryptographically secured request properties. properties: keyParams: $ref: '#/components/schemas/AesKeyParams' payload: type: string minLength: 1 example: BB20WIJRTz/T9vkGhETgpehzc6dDoioQ9DJV4lRA6ICaWwLPLDE+ Error: type: object description: "The error property is optional. It is set only if an error has been detected.

Each request has its number range used for error codes (see ResponseBase schema). This is the list of the actual error codes for each request:
\n | Request Name | Error | Error Code |\n |---------------|-------|-------------|\n | *Account Management API*\n |   | | |\n | getAccounts | SERVER_FAILURE | 2870000 |\n | | SYSTEM_ERROR | 2870001 |\n | | REQUEST_DATA_INVALID | 2870002 |\n | | NO_RESULT | 2870003 |\n | | HOST_OFFLINE | 2870004 |\n | | HOST_COMMUNICATION_ERROR | 2870005 |\n | | VERIFICATION_FAILED | 2870015 |\n |   | | |\n | getAccountTypes | SERVER_FAILURE | 2870100 |\n | | VERIFICATION_FAILED | 2870115 |\n |   | | |\n | getAccountDetails | SERVER_FAILURE | 2870200 |\n | | SYSTEM_ERROR | 2870201 |\n | | REQUEST_DATA_INVALID | 2870202 |\n | | NO_RESULT | 2870203 |\n | | HOST_OFFLINE | 2870204 |\n | | HOST_COMMUNICATION_ERROR | 2870205 |\n | | VERIFICATION_FAILED | 2870215 |\n |   | | |\n | getTransactions | SERVER_FAILURE | 2870300 |\n | | SYSTEM_ERROR | 2870301 |\n | | REQUEST_DATA_INVALID | 2870302 |\n | | NO_RESULT | 2870303 |\n | | HOST_OFFLINE | 2870304 |\n | | HOST_COMMUNICATION_ERROR | 2870305 |\n | | VERIFICATION_FAILED | 2870315 |\n |   | | |\n | getScheduledTransactions | SERVER_FAILURE | 2870400 |\n | | SYSTEM_ERROR | 2870401 |\n | | REQUEST_DATA_INVALID | 2870402 |\n | | NO_RESULT | 2870403 |\n | | HOST_OFFLINE | 2870404 |\n | | HOST_COMMUNICATION_ERROR | 2870405 |\n | | VERIFICATION_FAILED | 2870415 |\n |   | | |\n | checkAccount | SERVER_FAILURE | 2870500 |\n | | SYSTEM_ERROR | 2870501 |\n | | REQUEST_DATA_INVALID | 2870502 |\n | | NO_RESULT | 2870503 |\n | | HOST_OFFLINE | 2870504 |\n | | HOST_COMMUNICATION_ERROR | 2870505 |\n | | VERIFICATION_FAILED | 2870515 |\n |   | | |\n | createTransfer | SERVER_FAILURE | 2870600 |\n | | SYSTEM_ERROR | 2870601 |\n | | REQUEST_DATA_INVALID | 2870602 |\n | | NO_RESULT | 2870603 |\n | | HOST_OFFLINE | 2870604 |\n | | HOST_COMMUNICATION_ERROR | 2870605 |\n | | LIMIT_EXCEEDED | 2870606 |\n | | INSUFFICIENT_FUNDS | 2870607 |\n | | ACCOUNT_TYPE_INVALID | 2870608 |\n | | VERIFICATION_FAILED | 2870615 |\n |   | | |\n | createDispute | SERVER_FAILURE | 2870700 |\n | | SYSTEM_ERROR | 2870701 |\n | | MESSAGE_NOT_SENT | 2870700 |\n | | REQUEST_DATA_INVALID | 2870703 |\n | | VERIFICATION_FAILED | 2870715 |\n |   | | |\n | *Standing Order API*\n |   | | |\n | getStandingOrders | SERVER_FAILURE | 2871000 |\n | | REQUEST_DATA_INVALID | 2871002 |\n | | CONSUMER_NOT_FOUND | 2871012 |\n | | VERIFICATION_FAILED | 2871015 |\n |   | | |\n | createStandingOrder | SERVER_FAILURE | 2871100 |\n | | REQUEST_DATA_INVALID | 2871102 |\n | | VERIFICATION_FAILED | 2871115 |\n |   | | |\n | updateStandingOrder | SERVER_FAILURE | 2871200 |\n | | SYSTEM_ERROR | 2871201 |\n | | REQUEST_DATA_INVALID | 2871202 |\n | | STANDINGORDER_NOT_FOUND | 2871209 |\n | | VERIFICATION_FAILED | 2871215 |\n |   | | |\n | deleteStandingOrder | SERVER_FAILURE | 2871300 |\n | | REQUEST_DATA_INVALID | 2871302 |\n | | STANDINGORDER_NOT_FOUND | 2871309 |\n | | VERIFICATION_FAILED | 2871315 |\n |   | | |\n | updateAccountNickname | SERVER_FAILURE | 2871400 |\n | | SYSTEM_ERROR | 2871401 |\n | | REQUEST_DATA_INVALID | 2871402 |\n | | NO_RESULT | 2871403 |\n | | HOST_OFFLINE | 2871404 |\n | | HOST_COMMUNICATION_ERROR | 2871405 |\n | | SERVICE_NOT_SUPPORTED | 2871413 |\n | | EXT_RESPONSE_NO_MATCHING_RECORD_FOUND | 2871414 |\n | | VERIFICATION_FAILED | 2871415 |\n |   | | |\n | *Prestaged Transaction API*\n |   | | |\n | createCashout4Me | SERVER_FAILURE | 2872000 |\n | | SYSTEM_ERROR | 2872001 |\n | | REQUEST_DATA_INVALID | 2872002 |\n | | NO_RESULT | 2872003 |\n | | HOST_OFFLINE | 2872004 |\n | | HOST_COMMUNICATION_ERROR | 2872005 |\n | | VERIFICATION_FAILED | 2872015 |\n |   | | |\n | createCashout2You | SERVER_FAILURE | 2872100 |\n | | SYSTEM_ERROR | 2872101 |\n | | REQUEST_DATA_INVALID | 2872102 |\n | | NO_RESULT | 2872103 |\n | | HOST_OFFLINE | 2872104 |\n | | HOST_COMMUNICATION_ERROR | 2872105 |\n | | VERIFICATION_FAILED | 2872115 |\n |   | | |\n | createDeposit | SERVER_FAILURE | 2872200 |\n | | SYSTEM_ERROR | 2872201 |\n | | REQUEST_DATA_INVALID | 2872202 |\n | | NO_RESULT | 2872203 |\n | | HOST_OFFLINE | 2872204 |\n | | HOST_COMMUNICATION_ERROR | 2872205 |\n | | VERIFICATION_FAILED | 2872215 |\n |   | | |\n | createBranchDeposit | SERVER_FAILURE | 2872300 |\n | | SYSTEM_ERROR | 2872301 |\n | | REQUEST_DATA_INVALID | 2872302 |\n | | NO_RESULT | 2872303 |\n | | HOST_OFFLINE | 2872304 |\n | | HOST_COMMUNICATION_ERROR | 2872305 |\n | | VERIFICATION_FAILED | 2872315 |\n |   | | |\n | deletePrestagedTransaction | SERVER_FAILURE | 2872400 |\n | | RESERVED | 2872400 |\n | | REQUEST_DATA_INVALID | 2872402 |\n | | VERIFICATION_FAILED | 2872415 |\n |   | | |\n | getPrestagedTransactions | SERVER_FAILURE | 2872500 |\n | | SYSTEM_ERROR | 2872501 |\n | | REQUEST_DATA_INVALID | 2872502 |\n | | NO_RESULT | 2872503 |\n | | HOST_OFFLINE | 2872504 |\n | | HOST_COMMUNICATION_ERROR | 2872505 |\n | | VERIFICATION_FAILED | 2872515 |\n |   | | |\n | executePrestagedTransaction | SERVER_FAILURE | 2872600 |\n | | SYSTEM_ERROR | 2872601 |\n | | REQUEST_DATA_INVALID | 2872602 |\n | | VERIFICATION_FAILED | 2872615 |\n |   | | |\n | *Miscellaneous API*\n |   | | |\n | getCreditors | SERVER_FAILURE | 2874000 |\n | | SYSTEM_ERROR | 2874001 |\n | | REQUEST_DATA_INVALID | 2874002 |\n | | VERIFICATION_FAILED | 2874015 |\n |   | | |\n | getSinglePaymentOrderData | SERVER_FAILURE | 2874100 |\n | | RESERVED | 2874100 |\n | | REQUEST_DATA_INVALID | 2874102 |\n | | CONSUMER_NOT_FOUND | 2874112 |\n | | VERIFICATION_FAILED | 2874115 |\n |   | | |\n | getPreferences | SERVER_FAILURE | 2874200 |\n | | RESERVED | 2874200 |\n | | REQUEST_DATA_INVALID | 2874202 |\n | | RESPONSE_NO_CONSUMER_ID_AVAILABLE | 2874210 |\n | | RESPONSE_NO_PREFERENCES_AVAILABLE | 2874211 |\n | | VERIFICATION_FAILED | 2874215 |\n |   | | |\n | setPreferences | SERVER_FAILURE | 2874300 |\n | | RESERVED | 2874300 |\n | | REQUEST_DATA_INVALID | 2874302 |\n | | VERIFICATION_FAILED | 2874315 |\n |   | | |\n | getClientBranding | SERVER_FAILURE | 2874400 |\n | | RESERVED | 2874400 |\n | | REQUEST_DATA_INVALID | 2874402 |\n | | VERIFICATION_FAILED | 2874415 |\n |   | | |\n | getGenericTransactionOrders | SERVER_FAILURE | 2874500 |\n | | RESERVED | 2874500 |\n | | REQUEST_DATA_INVALID | 2874502 |\n | | VERIFICATION_FAILED | 2874515 |\n |   | | |\n | executeGenericTransactionOrder | SERVER_FAILURE | 2874600 |\n | | RESERVED | 2874600 |\n | | REQUEST_DATA_INVALID | 2874602 |\n | | VERIFICATION_FAILED | 2874615 |\n |   | | |\n | getLocations | SERVER_FAILURE | 2873000 |\n | | SYSTEM_ERROR | 2873001 |\n | | REQUEST_DATA_INVALID | 2873002 |\n | | NO_RESULT | 2873003 |\n | | VERIFICATION_FAILED | 2873015 |\n |   | | |\n | *Accessibility API*\n |   | | |\n | getRsaKey | SERVER_FAILURE | 2875000 |\n | | VERIFICATION_FAILED | 2875015 |\n |   | | |\n | getEcKey | SERVER_FAILURE | 2875100 |\n | | VERIFICATION_FAILED | 2875115 |\n |   | | |\n | getVersion | SERVER_FAILURE | 2875200 |\n | | VERIFICATION_FAILED | 2875215 |" required: - code properties: code: description: An error code as outlined in the PC/E documentation. type: integer format: int32 minimum: 0 example: 850004 message: description: An optional, additional message which describes the error. type: string maxLength: 255 example: Internal server error. A database connection could not be established. CreatePushPaymentRequest: type: object required: - cryptoEnvelope description: "The request body only holds one property, the __CryptoEnvelope__:\n\n CryptoEnvelope:\n type: object\n required:\n - payload\n description: >-\n Object holding cryptographically secured request/response properties.\n properties:\n payload:\n type: string\n minLength: 1\n example: BB20WIJRTz/T9vkGhETgpehzc6dDoioQ9DJV4lRA6ICaWwLPLDE+\n\nThe __CryptoEnvelope__ has a __payload__ property which represents an encrypted JSON string of the actual request object which is specified by the schema __CreatePushPaymentRequestPayload__." properties: cryptoEnvelope: $ref: '#/components/schemas/CryptoEnvelope' AuthorizePullPaymentResponse: type: object required: - responseStatus properties: responseStatus: $ref: '#/components/schemas/ResponseBase' CreatePushPaymentResponse: type: object required: - responseStatus properties: responseStatus: $ref: '#/components/schemas/ResponseBase' requestBodies: authorizePullPaymentRequestBody: content: application/json: schema: $ref: '#/components/schemas/AuthorizePullPaymentRequest' description: The request body used for AuthorizePullPaymentRequest required: true createPushPaymentRequestBody: content: application/json: schema: $ref: '#/components/schemas/CreatePushPaymentRequest' description: The request body used for CreatePushPaymentRequest required: true parameters: referenceIdParam: name: Dn-Tm-Omapi-Reference-Id in: header description: A unique identifier referring to a transaction in TM. This parameter should be encrypted and encoded in base64. required: true schema: type: string minLength: 1 sessionTokenParam: name: Dn-Tm-Omapi-Session-Token in: header description: A unique identifier of a consumer session (within an external system), which is required to validate the consumer session. The default implementation expects in the sessionToken parameter a valid openId Connect id_token. Moreover, the default implementation expects in the authorization header of the http request the authorization schema "Bearer" followed by a valid openId Connect access token. This parameter should be encrypted and encoded in base64. required: true schema: type: string minLength: 1 clientSecretParam: name: Dn-Tm-Omapi-Client-Secret in: header required: true description: "Depending on the crypto scheme (RSA/AES or ECIES) the client intends to use the corresponding properties of the __CryptoParams__ schema defined by OM-API should be filled accordingly and sent back to the server as stringified JSON. For example:\n\n__Using RSA/AES:__\n\n cryptoParams: {\n aesKeyParams: {\n key: \"uMSlxHYT+ttxz0T+nL+A344iP6ujJdodCn6k5MmjWDC0T+MFCXcs1OjXK1DaYFaP3v1mqN9+uh58FE0VxcwFGaRSp6uDfbl9Oaji7v0vDS9mMFa4hzMoiiYBmRKUemTNkJOcgCpDi7kDNHPB+gpqYyc4dMFfPvSCG/SYv7CFXTA=\",\n iv: \"FgZ/HdtOhroVzRd802X3NgHCuiqBjCM+6Q/6PS0lUrROBe8T+me444KpKt112gLwHck7nmOVkZJPznWf7bpX6dh+mcIQ/3B7PJ3xGEsHbmSXEAK10C+AKwXpI9Sdig8feP2QT+Hd0d1qGk0X93OFaJ/zfqs/MNIesNTVAY2YBIw=\"\n },\n rsaPublicKey:\"-----BEGIN PUBLIC KEY-----\\nMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCeB05D31/zFICpf9JJWDo1ZVXt\\npYwvJa6ka0g0EHN95C8fvMguNDmprslmsOqaJYplmknWpWjbHAtIPpqrtY3H6eWP\\nELkBN2hitJlQQjf1y2jsWHsSH7BsVY5z1hCzJySFE7Q1ae9WuYj3RTsq+4ZZpEk7\\nCjRdjA26emVkCR3vWwIDAQAB\\n-----END PUBLIC KEY-----\"\n }\n\nThe property __rsaPublicKey__ is used to send the client's public key to the server in order to create encrypted responses. It is recommended to use __rsaPublicKey__ key size of - at least - 1024 bit.\nThe property __aesKeyParams__ is used to send the client's AES key (256bit) and iv (128bit) to the server. Both values __must__ be encrypted with the servers public RSA key (see __/getRsaKey__).\n\n__Using ECIES:__\n\n cryptoParams: {\n \"ecPublicKey\":{\n \"publicKeyPem\":\"-----BEGIN PUBLIC KEY-----\\nMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEHPMaBu6d0BR6QFw3VKwPipuAdDPL\\nG36/aoyTx7iTK1xgoi7X9aMmT1x3Qh1+S1zVhBh2LDDEljHkkVyHrl4bOg==\\n-----END PUBLIC KEY-----\\n\"\n }\n }\n\nThe property __ecPublicKey__ is used to send the client's public key to the server in order to create encrypted responses." schema: type: string minLength: 1 consumerIdParam: name: Dn-Tm-Omapi-Consumer-Id in: header description: A unique identifier of a consumer (within an external system), which is required to identify the consumer. Maybe the consumerId is moreover/also used to authorize the consumer against an external system. This parameter should be encrypted and encoded in base64. required: true schema: type: string minLength: 1 securitySchemes: bearerAuth: description: When using the bearer authentication method an access token has to be provided in the HTTP authorization header. When using openIdConnect as security scheme the access token has to be provided in the Authorization header with the bearer scheme while the id token has to be provided in the __consumerIdParam__ which must also be encrypted. type: http scheme: bearer externalDocs: description: Find out more about Swagger url: http://swagger.io