openapi: 3.2.0
info:
title: DN Online & Mobile SEPA Credit Transfer Instant API
description: Diebold Nixdorf Online & Mobile API.
version: 3.2.1
contact:
name: Diebold Nixdorf
email: info.de@dieboldnixdorf.com
servers:
- url: http://localhost:8080/tm-om-api/v4
description: Transaction Middleware (VTE) 3.0+
- url: https://localhost:8080/tm-om-api/v4
description: Transaction Middleware (VTE) 3.0+
security:
- bearerAuth: []
tags:
- name: SEPA Credit Transfer Instant API
paths:
/sepa-instant/pushPayment:
get:
tags:
- SEPA Credit Transfer Instant API
summary: Get the status of a SEPA Instant credit transfer
description: Get the status of a SEPA instant credit transfer inititated by the payer
operationId: getPushPayment
parameters:
- $ref: '#/components/parameters/clientSecretParam'
- $ref: '#/components/parameters/sessionTokenParam'
- $ref: '#/components/parameters/consumerIdParam'
- $ref: '#/components/parameters/referenceIdParam'
responses:
'200':
$ref: '#/components/responses/getPushPaymentResponse'
'400':
$ref: '#/components/responses/badRequestResponse'
'401':
$ref: '#/components/responses/unauthorizedResponse'
'404':
$ref: '#/components/responses/notFoundResponse'
default:
$ref: '#/components/responses/defaultResponse'
post:
tags:
- SEPA Credit Transfer Instant API
summary: Create a SEPA instant payment request
description: Create a push payment to transfer credits.
operationId: createPushPayment
parameters:
- $ref: '#/components/parameters/clientSecretParam'
- $ref: '#/components/parameters/sessionTokenParam'
- $ref: '#/components/parameters/consumerIdParam'
requestBody:
$ref: '#/components/requestBodies/createPushPaymentRequestBody'
responses:
'200':
$ref: '#/components/responses/createPushPaymentResponse'
'400':
$ref: '#/components/responses/badRequestResponse'
'401':
$ref: '#/components/responses/unauthorizedResponse'
'404':
$ref: '#/components/responses/notFoundResponse'
default:
$ref: '#/components/responses/defaultResponse'
delete:
tags:
- SEPA Credit Transfer Instant API
summary: Cancel a SEPA instant payment request
description: Cancel a push payment.
operationId: cancelPushPayment
parameters:
- $ref: '#/components/parameters/clientSecretParam'
- $ref: '#/components/parameters/sessionTokenParam'
- $ref: '#/components/parameters/consumerIdParam'
responses:
'200':
$ref: '#/components/responses/cancelPushPaymentResponse'
'400':
$ref: '#/components/responses/badRequestResponse'
'401':
$ref: '#/components/responses/unauthorizedResponse'
'404':
$ref: '#/components/responses/notFoundResponse'
default:
$ref: '#/components/responses/defaultResponse'
/sepa-instant/pullPayment:
get:
tags:
- SEPA Credit Transfer Instant API
summary: Get the status of a SEPA instant pull payment
description: When a merchant (payee) issues a payment on the clients (payer) behalf a notification is sent to the client. By using a HTTP GET the client can review the status and details of the (pending) transaction.
operationId: getPullPayment
parameters:
- $ref: '#/components/parameters/clientSecretParam'
- $ref: '#/components/parameters/sessionTokenParam'
- $ref: '#/components/parameters/consumerIdParam'
responses:
'200':
$ref: '#/components/responses/getPullPaymentResponse'
'400':
$ref: '#/components/responses/badRequestResponse'
'401':
$ref: '#/components/responses/unauthorizedResponse'
'404':
$ref: '#/components/responses/notFoundResponse'
default:
$ref: '#/components/responses/defaultResponse'
post:
tags:
- SEPA Credit Transfer Instant API
summary: Authorize a pending SEPA instant payment request (pull payment)
description: When a merchant (payee) issues a payment on the clients (payer) behalf a notification is sent to the client. By unsing a HTTP POST the client authorizes the pending transaction for further processing.
operationId: authorizePullPayment
parameters:
- $ref: '#/components/parameters/clientSecretParam'
- $ref: '#/components/parameters/sessionTokenParam'
- $ref: '#/components/parameters/consumerIdParam'
requestBody:
$ref: '#/components/requestBodies/authorizePullPaymentRequestBody'
responses:
'200':
$ref: '#/components/responses/authorizePullPaymentResponse'
'400':
$ref: '#/components/responses/badRequestResponse'
'401':
$ref: '#/components/responses/unauthorizedResponse'
'404':
$ref: '#/components/responses/notFoundResponse'
default:
$ref: '#/components/responses/defaultResponse'
delete:
tags:
- SEPA Credit Transfer Instant API
summary: Cancel a pending SEPA instant payment request (pull payment)
description: When a merchant (payee) issues a payment on the clients (payer) behalf a notification is sent to the client. By unsing a HTTP DELETE the client cancels the pending transaction.
operationId: cancelPullPayment
parameters:
- $ref: '#/components/parameters/clientSecretParam'
- $ref: '#/components/parameters/sessionTokenParam'
- $ref: '#/components/parameters/consumerIdParam'
responses:
'200':
$ref: '#/components/responses/cancelPullPaymentResponse'
'400':
$ref: '#/components/responses/badRequestResponse'
'401':
$ref: '#/components/responses/unauthorizedResponse'
'404':
$ref: '#/components/responses/notFoundResponse'
default:
$ref: '#/components/responses/defaultResponse'
components:
responses:
unauthorizedResponse:
description: Unauthorized
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
defaultResponse:
description: Unexpected error. Please see/inspect 'code' and 'message' properties of the error for more/detailed informations.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
badRequestResponse:
description: Bad Request
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
cancelPushPaymentResponse:
description: Returns the response status.
content:
application/json:
schema:
$ref: '#/components/schemas/CancelPushPaymentResponse'
authorizePullPaymentResponse:
description: Returns the response status.
content:
application/json:
schema:
$ref: '#/components/schemas/AuthorizePullPaymentResponse'
createPushPaymentResponse:
description: Returns the response status.
content:
application/json:
schema:
$ref: '#/components/schemas/CreatePushPaymentResponse'
notFoundResponse:
description: Not found
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
getPushPaymentResponse:
description: Returns the response status.
content:
application/json:
schema:
$ref: '#/components/schemas/GetPushPaymentResponse'
getPullPaymentResponse:
description: Returns the response status.
content:
application/json:
schema:
$ref: '#/components/schemas/GetPullPaymentResponse'
cancelPullPaymentResponse:
description: Returns the response status.
content:
application/json:
schema:
$ref: '#/components/schemas/CancelPullPaymentResponse'
schemas:
ResponseBase:
description: "Every number used by OM-API is within a certain number range.
The OM-API V4 number range is 2870000 - 2879999.
Within that range, every requests group has its number range of 1000:
\n | Request Group | Number Range |\n |---------------|------------------------------------|\n | Account Management API | 2870000-2870999 |\n | Standing Order API | 2871000-2871999 |\n | Prestaged Transaction API | 2872000-2872999 |\n | Miscellaneous API | 2873000-2873999 |\n | Accessibility API | 2874000-2874999 |\nWithin each group range, every belonging request has its number range of 100:\n
\n | Request Name | Number Range |\n |---------------|------------------------------------|\n | *Account Management API*\n | getAccounts | 2870000-2870099 |\n | getAccountTypes | 2870100-2870199 |\n | getAccountDetails | 2870200-2870299 |\n | getTransactions | 2870300-2870399 |\n | getScheduledTransactions | 2870400-2870499 |\n | checkAccount | 2870500-2870599 |\n | createTransfer | 2870600-2870699 |\n | createDispute | 2870700-2870799 |\n | \n | *Standing Order API*\n | getStandingOrders | 2871000-2871099 |\n | createStandingOrder | 2871100-2871199 |\n | updateStandingOrder | 2871200-2871299 |\n | deleteStandingOrder | 2871300-2871399 |\n | updateAccountNickname | 2871400-2871499 |\n | \n | *Prestaged Transaction API*\n | createCashout4Me | 2872000-2872099 |\n | createCashout2You | 2872100-2872199 |\n | createDeposit | 2872200-2872299 |\n | createBranchDeposit | 2872300-2872399 |\n | deletePrestagedTransaction | 2872400-2872499 |\n | getPrestagedTransactions | 2872500-2872599 |\n | executePrestagedTransaction | 2872600-2872699 |\n | \n | *Miscellaneous API*\n | getCreditors | 2874000-2874099 |\n | getSinglePaymentOrderData | 2874100-2874199 |\n | getPreferences | 2874200-2874299 |\n | setPreferences | 2874300-2874399 |\n | getClientBranding | 2874400-2874499 |\n | getGenericTransactionOrders | 2874500-2874599 |\n | performGenericTransactionOrder | 2874600-2874699 |\n | getLocations | 2874700-2874799 |\n | \n | *Accessibility API*\n | getRsaKey | 2875000-2875099 |\n | getEcKey | 2875100-2875199 |\n | getVersion | 2875200-2875299 |\n
\n The numbers in the ranges are used primarily for the error codes (see Error schema)."
type: object
required:
- success
properties:
success:
description: 'Returns True or False to indicate the success of the API call.
The The error property is optional.
It is set only if an error has been detected.
'
type: boolean
example: true
error:
$ref: '#/components/schemas/Error'
GetPushPaymentResponse:
type: object
required:
- responseStatus
description: The response data is contained in the __CryptoEnvelope__'s property __payload__ as encrypted and stringified JSON object using the schema __GetPushPaymentResponsePayload__
properties:
responseStatus:
$ref: '#/components/schemas/ResponseBase'
cryptoEnvelope:
$ref: '#/components/schemas/CryptoEnvelope'
AesKeyParams:
description: A holder object for AES symmetric key params.
required:
- key
- iv
properties:
key:
description: The Base64 encoded (and encrypted) AES key (256bit).
type: string
example: MTI4MzI1Mjc2NTI=
iv:
description: The Base64 encoded (and encrypted) AES iv (128bit).
type: string
example: MTI4MzI1Mjc2NTI=
GetPullPaymentResponse:
type: object
required:
- responseStatus
properties:
responseStatus:
$ref: '#/components/schemas/ResponseBase'
CancelPushPaymentResponse:
type: object
required:
- responseStatus
properties:
responseStatus:
$ref: '#/components/schemas/ResponseBase'
CancelPullPaymentResponse:
type: object
required:
- responseStatus
properties:
responseStatus:
$ref: '#/components/schemas/ResponseBase'
AuthorizePullPaymentRequest:
type: object
required:
- cryptoEnvelope
description: "The request body only holds one property, the __CryptoEnvelope__:\n\n CryptoEnvelope:\n type: object\n required:\n - payload\n description: >-\n Object holding cryptographically secured request/response properties.\n properties:\n payload:\n type: string\n minLength: 1\n example: BB20WIJRTz/T9vkGhETgpehzc6dDoioQ9DJV4lRA6ICaWwLPLDE+\n\nThe __CryptoEnvelope__ has a __payload__ property which represents an encrypted JSON string of the actual request object which is specified by the schema __AuthorizePullPaymentRequestPayload__."
properties:
cryptoEnvelope:
$ref: '#/components/schemas/CryptoEnvelope'
CryptoEnvelope:
type: object
required:
- payload
description: Object holding a cryptographically secured request properties.
properties:
keyParams:
$ref: '#/components/schemas/AesKeyParams'
payload:
type: string
minLength: 1
example: BB20WIJRTz/T9vkGhETgpehzc6dDoioQ9DJV4lRA6ICaWwLPLDE+
Error:
type: object
description: "The error property is optional. It is set only if an error has been detected.
Each request has its number range used for error codes (see ResponseBase schema). This is the list of the actual error codes for each request:
\n | Request Name | Error | Error Code |\n |---------------|-------|-------------|\n | *Account Management API*\n | | | |\n | getAccounts | SERVER_FAILURE | 2870000 |\n | | SYSTEM_ERROR | 2870001 |\n | | REQUEST_DATA_INVALID | 2870002 |\n | | NO_RESULT | 2870003 |\n | | HOST_OFFLINE | 2870004 |\n | | HOST_COMMUNICATION_ERROR | 2870005 |\n | | VERIFICATION_FAILED | 2870015 |\n | | | |\n | getAccountTypes | SERVER_FAILURE | 2870100 |\n | | VERIFICATION_FAILED | 2870115 |\n | | | |\n | getAccountDetails | SERVER_FAILURE | 2870200 |\n | | SYSTEM_ERROR | 2870201 |\n | | REQUEST_DATA_INVALID | 2870202 |\n | | NO_RESULT | 2870203 |\n | | HOST_OFFLINE | 2870204 |\n | | HOST_COMMUNICATION_ERROR | 2870205 |\n | | VERIFICATION_FAILED | 2870215 |\n | | | |\n | getTransactions | SERVER_FAILURE | 2870300 |\n | | SYSTEM_ERROR | 2870301 |\n | | REQUEST_DATA_INVALID | 2870302 |\n | | NO_RESULT | 2870303 |\n | | HOST_OFFLINE | 2870304 |\n | | HOST_COMMUNICATION_ERROR | 2870305 |\n | | VERIFICATION_FAILED | 2870315 |\n | | | |\n | getScheduledTransactions | SERVER_FAILURE | 2870400 |\n | | SYSTEM_ERROR | 2870401 |\n | | REQUEST_DATA_INVALID | 2870402 |\n | | NO_RESULT | 2870403 |\n | | HOST_OFFLINE | 2870404 |\n | | HOST_COMMUNICATION_ERROR | 2870405 |\n | | VERIFICATION_FAILED | 2870415 |\n | | | |\n | checkAccount | SERVER_FAILURE | 2870500 |\n | | SYSTEM_ERROR | 2870501 |\n | | REQUEST_DATA_INVALID | 2870502 |\n | | NO_RESULT | 2870503 |\n | | HOST_OFFLINE | 2870504 |\n | | HOST_COMMUNICATION_ERROR | 2870505 |\n | | VERIFICATION_FAILED | 2870515 |\n | | | |\n | createTransfer | SERVER_FAILURE | 2870600 |\n | | SYSTEM_ERROR | 2870601 |\n | | REQUEST_DATA_INVALID | 2870602 |\n | | NO_RESULT | 2870603 |\n | | HOST_OFFLINE | 2870604 |\n | | HOST_COMMUNICATION_ERROR | 2870605 |\n | | LIMIT_EXCEEDED | 2870606 |\n | | INSUFFICIENT_FUNDS | 2870607 |\n | | ACCOUNT_TYPE_INVALID | 2870608 |\n | | VERIFICATION_FAILED | 2870615 |\n | | | |\n | createDispute | SERVER_FAILURE | 2870700 |\n | | SYSTEM_ERROR | 2870701 |\n | | MESSAGE_NOT_SENT | 2870700 |\n | | REQUEST_DATA_INVALID | 2870703 |\n | | VERIFICATION_FAILED | 2870715 |\n | | | |\n | *Standing Order API*\n | | | |\n | getStandingOrders | SERVER_FAILURE | 2871000 |\n | | REQUEST_DATA_INVALID | 2871002 |\n | | CONSUMER_NOT_FOUND | 2871012 |\n | | VERIFICATION_FAILED | 2871015 |\n | | | |\n | createStandingOrder | SERVER_FAILURE | 2871100 |\n | | REQUEST_DATA_INVALID | 2871102 |\n | | VERIFICATION_FAILED | 2871115 |\n | | | |\n | updateStandingOrder | SERVER_FAILURE | 2871200 |\n | | SYSTEM_ERROR | 2871201 |\n | | REQUEST_DATA_INVALID | 2871202 |\n | | STANDINGORDER_NOT_FOUND | 2871209 |\n | | VERIFICATION_FAILED | 2871215 |\n | | | |\n | deleteStandingOrder | SERVER_FAILURE | 2871300 |\n | | REQUEST_DATA_INVALID | 2871302 |\n | | STANDINGORDER_NOT_FOUND | 2871309 |\n | | VERIFICATION_FAILED | 2871315 |\n | | | |\n | updateAccountNickname | SERVER_FAILURE | 2871400 |\n | | SYSTEM_ERROR | 2871401 |\n | | REQUEST_DATA_INVALID | 2871402 |\n | | NO_RESULT | 2871403 |\n | | HOST_OFFLINE | 2871404 |\n | | HOST_COMMUNICATION_ERROR | 2871405 |\n | | SERVICE_NOT_SUPPORTED | 2871413 |\n | | EXT_RESPONSE_NO_MATCHING_RECORD_FOUND | 2871414 |\n | | VERIFICATION_FAILED | 2871415 |\n | | | |\n | *Prestaged Transaction API*\n | | | |\n | createCashout4Me | SERVER_FAILURE | 2872000 |\n | | SYSTEM_ERROR | 2872001 |\n | | REQUEST_DATA_INVALID | 2872002 |\n | | NO_RESULT | 2872003 |\n | | HOST_OFFLINE | 2872004 |\n | | HOST_COMMUNICATION_ERROR | 2872005 |\n | | VERIFICATION_FAILED | 2872015 |\n | | | |\n | createCashout2You | SERVER_FAILURE | 2872100 |\n | | SYSTEM_ERROR | 2872101 |\n | | REQUEST_DATA_INVALID | 2872102 |\n | | NO_RESULT | 2872103 |\n | | HOST_OFFLINE | 2872104 |\n | | HOST_COMMUNICATION_ERROR | 2872105 |\n | | VERIFICATION_FAILED | 2872115 |\n | | | |\n | createDeposit | SERVER_FAILURE | 2872200 |\n | | SYSTEM_ERROR | 2872201 |\n | | REQUEST_DATA_INVALID | 2872202 |\n | | NO_RESULT | 2872203 |\n | | HOST_OFFLINE | 2872204 |\n | | HOST_COMMUNICATION_ERROR | 2872205 |\n | | VERIFICATION_FAILED | 2872215 |\n | | | |\n | createBranchDeposit | SERVER_FAILURE | 2872300 |\n | | SYSTEM_ERROR | 2872301 |\n | | REQUEST_DATA_INVALID | 2872302 |\n | | NO_RESULT | 2872303 |\n | | HOST_OFFLINE | 2872304 |\n | | HOST_COMMUNICATION_ERROR | 2872305 |\n | | VERIFICATION_FAILED | 2872315 |\n | | | |\n | deletePrestagedTransaction | SERVER_FAILURE | 2872400 |\n | | RESERVED | 2872400 |\n | | REQUEST_DATA_INVALID | 2872402 |\n | | VERIFICATION_FAILED | 2872415 |\n | | | |\n | getPrestagedTransactions | SERVER_FAILURE | 2872500 |\n | | SYSTEM_ERROR | 2872501 |\n | | REQUEST_DATA_INVALID | 2872502 |\n | | NO_RESULT | 2872503 |\n | | HOST_OFFLINE | 2872504 |\n | | HOST_COMMUNICATION_ERROR | 2872505 |\n | | VERIFICATION_FAILED | 2872515 |\n | | | |\n | executePrestagedTransaction | SERVER_FAILURE | 2872600 |\n | | SYSTEM_ERROR | 2872601 |\n | | REQUEST_DATA_INVALID | 2872602 |\n | | VERIFICATION_FAILED | 2872615 |\n | | | |\n | *Miscellaneous API*\n | | | |\n | getCreditors | SERVER_FAILURE | 2874000 |\n | | SYSTEM_ERROR | 2874001 |\n | | REQUEST_DATA_INVALID | 2874002 |\n | | VERIFICATION_FAILED | 2874015 |\n | | | |\n | getSinglePaymentOrderData | SERVER_FAILURE | 2874100 |\n | | RESERVED | 2874100 |\n | | REQUEST_DATA_INVALID | 2874102 |\n | | CONSUMER_NOT_FOUND | 2874112 |\n | | VERIFICATION_FAILED | 2874115 |\n | | | |\n | getPreferences | SERVER_FAILURE | 2874200 |\n | | RESERVED | 2874200 |\n | | REQUEST_DATA_INVALID | 2874202 |\n | | RESPONSE_NO_CONSUMER_ID_AVAILABLE | 2874210 |\n | | RESPONSE_NO_PREFERENCES_AVAILABLE | 2874211 |\n | | VERIFICATION_FAILED | 2874215 |\n | | | |\n | setPreferences | SERVER_FAILURE | 2874300 |\n | | RESERVED | 2874300 |\n | | REQUEST_DATA_INVALID | 2874302 |\n | | VERIFICATION_FAILED | 2874315 |\n | | | |\n | getClientBranding | SERVER_FAILURE | 2874400 |\n | | RESERVED | 2874400 |\n | | REQUEST_DATA_INVALID | 2874402 |\n | | VERIFICATION_FAILED | 2874415 |\n | | | |\n | getGenericTransactionOrders | SERVER_FAILURE | 2874500 |\n | | RESERVED | 2874500 |\n | | REQUEST_DATA_INVALID | 2874502 |\n | | VERIFICATION_FAILED | 2874515 |\n | | | |\n | executeGenericTransactionOrder | SERVER_FAILURE | 2874600 |\n | | RESERVED | 2874600 |\n | | REQUEST_DATA_INVALID | 2874602 |\n | | VERIFICATION_FAILED | 2874615 |\n | | | |\n | getLocations | SERVER_FAILURE | 2873000 |\n | | SYSTEM_ERROR | 2873001 |\n | | REQUEST_DATA_INVALID | 2873002 |\n | | NO_RESULT | 2873003 |\n | | VERIFICATION_FAILED | 2873015 |\n | | | |\n | *Accessibility API*\n | | | |\n | getRsaKey | SERVER_FAILURE | 2875000 |\n | | VERIFICATION_FAILED | 2875015 |\n | | | |\n | getEcKey | SERVER_FAILURE | 2875100 |\n | | VERIFICATION_FAILED | 2875115 |\n | | | |\n | getVersion | SERVER_FAILURE | 2875200 |\n | | VERIFICATION_FAILED | 2875215 |"
required:
- code
properties:
code:
description: An error code as outlined in the PC/E documentation.
type: integer
format: int32
minimum: 0
example: 850004
message:
description: An optional, additional message which describes the error.
type: string
maxLength: 255
example: Internal server error. A database connection could not be established.
CreatePushPaymentRequest:
type: object
required:
- cryptoEnvelope
description: "The request body only holds one property, the __CryptoEnvelope__:\n\n CryptoEnvelope:\n type: object\n required:\n - payload\n description: >-\n Object holding cryptographically secured request/response properties.\n properties:\n payload:\n type: string\n minLength: 1\n example: BB20WIJRTz/T9vkGhETgpehzc6dDoioQ9DJV4lRA6ICaWwLPLDE+\n\nThe __CryptoEnvelope__ has a __payload__ property which represents an encrypted JSON string of the actual request object which is specified by the schema __CreatePushPaymentRequestPayload__."
properties:
cryptoEnvelope:
$ref: '#/components/schemas/CryptoEnvelope'
AuthorizePullPaymentResponse:
type: object
required:
- responseStatus
properties:
responseStatus:
$ref: '#/components/schemas/ResponseBase'
CreatePushPaymentResponse:
type: object
required:
- responseStatus
properties:
responseStatus:
$ref: '#/components/schemas/ResponseBase'
requestBodies:
authorizePullPaymentRequestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/AuthorizePullPaymentRequest'
description: The request body used for AuthorizePullPaymentRequest
required: true
createPushPaymentRequestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/CreatePushPaymentRequest'
description: The request body used for CreatePushPaymentRequest
required: true
parameters:
referenceIdParam:
name: Dn-Tm-Omapi-Reference-Id
in: header
description: A unique identifier referring to a transaction in TM. This parameter should be encrypted and encoded in base64.
required: true
schema:
type: string
minLength: 1
sessionTokenParam:
name: Dn-Tm-Omapi-Session-Token
in: header
description: A unique identifier of a consumer session (within an external system), which is required to validate the consumer session. The default implementation expects in the sessionToken parameter a valid openId Connect id_token. Moreover, the default implementation expects in the authorization header of the http request the authorization schema "Bearer" followed by a valid openId Connect access token. This parameter should be encrypted and encoded in base64.
required: true
schema:
type: string
minLength: 1
clientSecretParam:
name: Dn-Tm-Omapi-Client-Secret
in: header
required: true
description: "Depending on the crypto scheme (RSA/AES or ECIES) the client intends to use the corresponding properties of the __CryptoParams__ schema defined by OM-API should be filled accordingly and sent back to the server as stringified JSON. For example:\n\n__Using RSA/AES:__\n\n cryptoParams: {\n aesKeyParams: {\n key: \"uMSlxHYT+ttxz0T+nL+A344iP6ujJdodCn6k5MmjWDC0T+MFCXcs1OjXK1DaYFaP3v1mqN9+uh58FE0VxcwFGaRSp6uDfbl9Oaji7v0vDS9mMFa4hzMoiiYBmRKUemTNkJOcgCpDi7kDNHPB+gpqYyc4dMFfPvSCG/SYv7CFXTA=\",\n iv: \"FgZ/HdtOhroVzRd802X3NgHCuiqBjCM+6Q/6PS0lUrROBe8T+me444KpKt112gLwHck7nmOVkZJPznWf7bpX6dh+mcIQ/3B7PJ3xGEsHbmSXEAK10C+AKwXpI9Sdig8feP2QT+Hd0d1qGk0X93OFaJ/zfqs/MNIesNTVAY2YBIw=\"\n },\n rsaPublicKey:\"-----BEGIN PUBLIC KEY-----\\nMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCeB05D31/zFICpf9JJWDo1ZVXt\\npYwvJa6ka0g0EHN95C8fvMguNDmprslmsOqaJYplmknWpWjbHAtIPpqrtY3H6eWP\\nELkBN2hitJlQQjf1y2jsWHsSH7BsVY5z1hCzJySFE7Q1ae9WuYj3RTsq+4ZZpEk7\\nCjRdjA26emVkCR3vWwIDAQAB\\n-----END PUBLIC KEY-----\"\n }\n\nThe property __rsaPublicKey__ is used to send the client's public key to the server in order to create encrypted responses. It is recommended to use __rsaPublicKey__ key size of - at least - 1024 bit.\nThe property __aesKeyParams__ is used to send the client's AES key (256bit) and iv (128bit) to the server. Both values __must__ be encrypted with the servers public RSA key (see __/getRsaKey__).\n\n__Using ECIES:__\n\n cryptoParams: {\n \"ecPublicKey\":{\n \"publicKeyPem\":\"-----BEGIN PUBLIC KEY-----\\nMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEHPMaBu6d0BR6QFw3VKwPipuAdDPL\\nG36/aoyTx7iTK1xgoi7X9aMmT1x3Qh1+S1zVhBh2LDDEljHkkVyHrl4bOg==\\n-----END PUBLIC KEY-----\\n\"\n }\n }\n\nThe property __ecPublicKey__ is used to send the client's public key to the server in order to create encrypted responses."
schema:
type: string
minLength: 1
consumerIdParam:
name: Dn-Tm-Omapi-Consumer-Id
in: header
description: A unique identifier of a consumer (within an external system), which is required to identify the consumer. Maybe the consumerId is moreover/also used to authorize the consumer against an external system. This parameter should be encrypted and encoded in base64.
required: true
schema:
type: string
minLength: 1
securitySchemes:
bearerAuth:
description: When using the bearer authentication method an access token has to be provided in the HTTP authorization header. When using openIdConnect as security scheme the access token has to be provided in the Authorization header with the bearer scheme while the id token has to be provided in the __consumerIdParam__ which must also be encrypted.
type: http
scheme: bearer
externalDocs:
description: Find out more about Swagger
url: http://swagger.io