openapi: 3.2.0 info: title: DN Online & Mobile Standing Order API description: Diebold Nixdorf Online & Mobile API. version: 3.2.1 contact: name: Diebold Nixdorf email: info.de@dieboldnixdorf.com servers: - url: http://localhost:8080/tm-om-api/v4 description: Transaction Middleware (VTE) 3.0+ - url: https://localhost:8080/tm-om-api/v4 description: Transaction Middleware (VTE) 3.0+ security: - bearerAuth: [] tags: - name: Standing Order API paths: /getStandingOrders: get: tags: - Standing Order API summary: Returns a list of standing orders for the given consumerId description: 'Returns a list of standing orders for the given consumerId (see __GetStandingOrdersResponsePayload__). ### Example Response: { "responseStatus": { "success": true, "error": null }, "cryptoEnvelope": { "keyParams": null, "payload": "1Dbp80MYqQ/z3+dzIVqxBhHXg6Awu/S1XVbK7OcbHZCw5ubyMrv4TjZLq5+U6bvtiRBWFeitgcWWb8Ng+TjOWQ==" } } __Using RSA/AES:__ The server generates an AES key (256 bit) and iv (128 bit) to encrypt the response payload. After the payload encryption the key parameters are encrypted with the client''s public RSA key (see __clientSecretparam__). The encrypted key parameters and payload are stored in a __CryptoEnvelope__ entity that is attached to the response body. __Using ECIES:__ The server uses the client''s EC public key (see __clientSecretParam__) to encrypt the response payload. The encrypted payload is stored in a __CryptoEnvelope__ entity that is attached to the response body.' operationId: getStandingOrders parameters: - $ref: '#/components/parameters/clientSecretParam' - $ref: '#/components/parameters/sessionTokenParam' - $ref: '#/components/parameters/consumerIdParam' responses: '200': $ref: '#/components/responses/getStandingOrdersResponse' '400': $ref: '#/components/responses/badRequestResponse' '401': $ref: '#/components/responses/unauthorizedResponse' '404': $ref: '#/components/responses/notFoundResponse' default: $ref: '#/components/responses/defaultResponse' /createStandingOrder: post: tags: - Standing Order API summary: Create a standing order for the given account and consumerId description: 'Create a standing order (recurring transfer) for the given account and consumerId. Returns a referenceId if the transfer was created successfully (see __CreateTransferResponsePayload__). The transfer''s source account must be owned by the customer with the given consumerId. Additionally a period for the recurring transaction must be specified (see __StandingOrderRequestPayload__). ### Example Response: { "responseStatus": { "success": true, "error": null }, "cryptoEnvelope": { "keyParams": null, "payload": "1Dbp80MYqQ/z3+dzIVqxBhHXg6Awu/S1XVbK7OcbHZCw5ubyMrv4TjZLq5+U6bvtiRBWFeitgcWWb8Ng+TjOWQ==" } } __Using RSA/AES:__ The server generates an AES key (256 bit) and iv (128 bit) to encrypt the response payload. After the payload encryption the key parameters are encrypted with the client''s public RSA key (see __clientSecretparam__). The encrypted key parameters and payload are stored in a __CryptoEnvelope__ entity that is attached to the response body. __Using ECIES:__ The server uses the client''s EC public key (see __clientSecretParam__) to encrypt the response payload. The encrypted payload is stored in a __CryptoEnvelope__ entity that is attached to the response body.' operationId: createStandingOrder parameters: - $ref: '#/components/parameters/clientSecretParam' - $ref: '#/components/parameters/sessionTokenParam' - $ref: '#/components/parameters/consumerIdParam' requestBody: $ref: '#/components/requestBodies/standingOrderRequestBody' responses: '200': $ref: '#/components/responses/createStandingOrderResponse' '400': $ref: '#/components/responses/badRequestResponse' '401': $ref: '#/components/responses/unauthorizedResponse' '404': $ref: '#/components/responses/notFoundResponse' default: $ref: '#/components/responses/defaultResponse' /updateStandingOrder: post: tags: - Standing Order API summary: Update an existing standing order by the given referenceId description: 'Update a standing order with the given __referenceId__ (see __CreateTransferResponsePayload__). The request body''s __CryptoEnvelope__ carries the same payload as in a __/createStandingOrder__ request. The __referenceId__ parameter is used to identify and update the stored standing order. ### Example Response: { "responseStatus": { "success": true, "error": null }, "cryptoEnvelope": { "keyParams": null, "payload": "1Dbp80MYqQ/z3+dzIVqxBhHXg6Awu/S1XVbK7OcbHZCw5ubyMrv4TjZLq5+U6bvtiRBWFeitgcWWb8Ng+TjOWQ==" } } __Using RSA/AES:__ The server generates an AES key (256 bit) and iv (128 bit) to encrypt the response payload. After the payload encryption the key parameters are encrypted with the client''s public RSA key (see __clientSecretparam__). The encrypted key parameters and payload are stored in a __CryptoEnvelope__ entity that is attached to the response body. __Using ECIES:__ The server uses the client''s EC public key (see __clientSecretParam__) to encrypt the response payload. The encrypted payload is stored in a __CryptoEnvelope__ entity that is attached to the response body.' operationId: updateStandingOrder parameters: - $ref: '#/components/parameters/clientSecretParam' - $ref: '#/components/parameters/sessionTokenParam' - $ref: '#/components/parameters/consumerIdParam' - $ref: '#/components/parameters/referenceIdParam' requestBody: $ref: '#/components/requestBodies/standingOrderRequestBody' responses: '200': $ref: '#/components/responses/updateStandingOrderResponse' '400': $ref: '#/components/responses/badRequestResponse' '401': $ref: '#/components/responses/unauthorizedResponse' '404': $ref: '#/components/responses/notFoundResponse' default: $ref: '#/components/responses/defaultResponse' /deleteStandingOrder: post: tags: - Standing Order API summary: Delete an existing standing order description: 'Delete a standing order with the given __referenceID__ (see __referenceIdParam__). ### Example Response: { "responseStatus": { "success": true, "error": null } }' operationId: deleteStandingOrder parameters: - $ref: '#/components/parameters/clientSecretParam' - $ref: '#/components/parameters/sessionTokenParam' - $ref: '#/components/parameters/consumerIdParam' - $ref: '#/components/parameters/referenceIdParam' responses: '200': $ref: '#/components/responses/deleteStandingOrderResponse' '400': $ref: '#/components/responses/badRequestResponse' '401': $ref: '#/components/responses/unauthorizedResponse' '404': $ref: '#/components/responses/notFoundResponse' default: $ref: '#/components/responses/defaultResponse' components: responses: unauthorizedResponse: description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/Error' defaultResponse: description: Unexpected error. Please see/inspect 'code' and 'message' properties of the error for more/detailed informations. content: application/json: schema: $ref: '#/components/schemas/Error' updateStandingOrderResponse: description: No further data are returned in case of a successful call. content: application/json: schema: $ref: '#/components/schemas/CreateTransferResponse' badRequestResponse: description: Bad Request content: application/json: schema: $ref: '#/components/schemas/Error' getStandingOrdersResponse: description: Returns a list of standing orders. content: application/json: schema: $ref: '#/components/schemas/GetStandingOrdersResponse' createStandingOrderResponse: description: Returns the response status. content: application/json: schema: $ref: '#/components/schemas/CreateTransferResponse' notFoundResponse: description: Not found content: application/json: schema: $ref: '#/components/schemas/Error' deleteStandingOrderResponse: description: Returns the response status. content: application/json: schema: $ref: '#/components/schemas/DeleteStandingOrderResponse' schemas: ResponseBase: description: "Every number used by OM-API is within a certain number range.
The OM-API V4 number range is 2870000 - 2879999.
Within that range, every requests group has its number range of 1000:
\n | Request Group | Number Range |\n |---------------|------------------------------------|\n | Account Management API | 2870000-2870999 |\n | Standing Order API | 2871000-2871999 |\n | Prestaged Transaction API | 2872000-2872999 |\n | Miscellaneous API | 2873000-2873999 |\n | Accessibility API | 2874000-2874999 |\nWithin each group range, every belonging request has its number range of 100:\n
\n | Request Name | Number Range |\n |---------------|------------------------------------|\n | *Account Management API*\n | getAccounts | 2870000-2870099 |\n | getAccountTypes | 2870100-2870199 |\n | getAccountDetails | 2870200-2870299 |\n | getTransactions | 2870300-2870399 |\n | getScheduledTransactions | 2870400-2870499 |\n | checkAccount | 2870500-2870599 |\n | createTransfer | 2870600-2870699 |\n | createDispute | 2870700-2870799 |\n |  \n | *Standing Order API*\n | getStandingOrders | 2871000-2871099 |\n | createStandingOrder | 2871100-2871199 |\n | updateStandingOrder | 2871200-2871299 |\n | deleteStandingOrder | 2871300-2871399 |\n | updateAccountNickname | 2871400-2871499 |\n |  \n | *Prestaged Transaction API*\n | createCashout4Me | 2872000-2872099 |\n | createCashout2You | 2872100-2872199 |\n | createDeposit | 2872200-2872299 |\n | createBranchDeposit | 2872300-2872399 |\n | deletePrestagedTransaction | 2872400-2872499 |\n | getPrestagedTransactions | 2872500-2872599 |\n | executePrestagedTransaction | 2872600-2872699 |\n |  \n | *Miscellaneous API*\n | getCreditors | 2874000-2874099 |\n | getSinglePaymentOrderData | 2874100-2874199 |\n | getPreferences | 2874200-2874299 |\n | setPreferences | 2874300-2874399 |\n | getClientBranding | 2874400-2874499 |\n | getGenericTransactionOrders | 2874500-2874599 |\n | performGenericTransactionOrder | 2874600-2874699 |\n | getLocations | 2874700-2874799 |\n |  \n | *Accessibility API*\n | getRsaKey | 2875000-2875099 |\n | getEcKey | 2875100-2875199 |\n | getVersion | 2875200-2875299 |\n
\n The numbers in the ranges are used primarily for the error codes (see Error schema)." type: object required: - success properties: success: description: 'Returns True or False to indicate the success of the API call. The The error property is optional. It is set only if an error has been detected. ' type: boolean example: true error: $ref: '#/components/schemas/Error' CreateTransferResponse: type: object required: - responseStatus description: The response data is contained in the __CryptoEnvelope__'s property __payload__ as encrypted and stringified JSON object using the schema __CreateTransferResponsePayload__ properties: responseStatus: $ref: '#/components/schemas/ResponseBase' cryptoEnvelope: $ref: '#/components/schemas/CryptoEnvelope' AesKeyParams: description: A holder object for AES symmetric key params. required: - key - iv properties: key: description: The Base64 encoded (and encrypted) AES key (256bit). type: string example: MTI4MzI1Mjc2NTI= iv: description: The Base64 encoded (and encrypted) AES iv (128bit). type: string example: MTI4MzI1Mjc2NTI= GetStandingOrdersResponse: type: object required: - responseStatus description: The response data is contained in the __CryptoEnvelope__'s property __payload__ as encrypted and stringified JSON object using the schema __GetStandingOrdersResponsePayload__ properties: responseStatus: $ref: '#/components/schemas/ResponseBase' cryptoEnvelope: $ref: '#/components/schemas/CryptoEnvelope' StandingOrderRequest: type: object required: - cryptoEnvelope description: "With OM-API v3 encryption is used for all endpoints. The request body is therefore specified to contain only on property, the __CryptoEnvelope__:\n\n CryptoEnvelope:\n type: object\n required:\n - payload\n description: >-\n Object holding cryptographically secured request properties.\n properties:\n payload:\n type: string\n minLength: 1\n example: BB20WIJRTz/T9vkGhETgpehzc6dDoioQ9DJV4lRA6ICaWwLPLDE+\n\nThe __CryptoEnvelope__ has a __payload__ property which represents an encrypted JSON string of the actual request object which is specified by the schema __StandingOrderRequestPayload__." properties: cryptoEnvelope: $ref: '#/components/schemas/CryptoEnvelope' CryptoEnvelope: type: object required: - payload description: Object holding a cryptographically secured request properties. properties: keyParams: $ref: '#/components/schemas/AesKeyParams' payload: type: string minLength: 1 example: BB20WIJRTz/T9vkGhETgpehzc6dDoioQ9DJV4lRA6ICaWwLPLDE+ DeleteStandingOrderResponse: type: object required: - responseStatus properties: responseStatus: $ref: '#/components/schemas/ResponseBase' Error: type: object description: "The error property is optional. It is set only if an error has been detected.

Each request has its number range used for error codes (see ResponseBase schema). This is the list of the actual error codes for each request:
\n | Request Name | Error | Error Code |\n |---------------|-------|-------------|\n | *Account Management API*\n |   | | |\n | getAccounts | SERVER_FAILURE | 2870000 |\n | | SYSTEM_ERROR | 2870001 |\n | | REQUEST_DATA_INVALID | 2870002 |\n | | NO_RESULT | 2870003 |\n | | HOST_OFFLINE | 2870004 |\n | | HOST_COMMUNICATION_ERROR | 2870005 |\n | | VERIFICATION_FAILED | 2870015 |\n |   | | |\n | getAccountTypes | SERVER_FAILURE | 2870100 |\n | | VERIFICATION_FAILED | 2870115 |\n |   | | |\n | getAccountDetails | SERVER_FAILURE | 2870200 |\n | | SYSTEM_ERROR | 2870201 |\n | | REQUEST_DATA_INVALID | 2870202 |\n | | NO_RESULT | 2870203 |\n | | HOST_OFFLINE | 2870204 |\n | | HOST_COMMUNICATION_ERROR | 2870205 |\n | | VERIFICATION_FAILED | 2870215 |\n |   | | |\n | getTransactions | SERVER_FAILURE | 2870300 |\n | | SYSTEM_ERROR | 2870301 |\n | | REQUEST_DATA_INVALID | 2870302 |\n | | NO_RESULT | 2870303 |\n | | HOST_OFFLINE | 2870304 |\n | | HOST_COMMUNICATION_ERROR | 2870305 |\n | | VERIFICATION_FAILED | 2870315 |\n |   | | |\n | getScheduledTransactions | SERVER_FAILURE | 2870400 |\n | | SYSTEM_ERROR | 2870401 |\n | | REQUEST_DATA_INVALID | 2870402 |\n | | NO_RESULT | 2870403 |\n | | HOST_OFFLINE | 2870404 |\n | | HOST_COMMUNICATION_ERROR | 2870405 |\n | | VERIFICATION_FAILED | 2870415 |\n |   | | |\n | checkAccount | SERVER_FAILURE | 2870500 |\n | | SYSTEM_ERROR | 2870501 |\n | | REQUEST_DATA_INVALID | 2870502 |\n | | NO_RESULT | 2870503 |\n | | HOST_OFFLINE | 2870504 |\n | | HOST_COMMUNICATION_ERROR | 2870505 |\n | | VERIFICATION_FAILED | 2870515 |\n |   | | |\n | createTransfer | SERVER_FAILURE | 2870600 |\n | | SYSTEM_ERROR | 2870601 |\n | | REQUEST_DATA_INVALID | 2870602 |\n | | NO_RESULT | 2870603 |\n | | HOST_OFFLINE | 2870604 |\n | | HOST_COMMUNICATION_ERROR | 2870605 |\n | | LIMIT_EXCEEDED | 2870606 |\n | | INSUFFICIENT_FUNDS | 2870607 |\n | | ACCOUNT_TYPE_INVALID | 2870608 |\n | | VERIFICATION_FAILED | 2870615 |\n |   | | |\n | createDispute | SERVER_FAILURE | 2870700 |\n | | SYSTEM_ERROR | 2870701 |\n | | MESSAGE_NOT_SENT | 2870700 |\n | | REQUEST_DATA_INVALID | 2870703 |\n | | VERIFICATION_FAILED | 2870715 |\n |   | | |\n | *Standing Order API*\n |   | | |\n | getStandingOrders | SERVER_FAILURE | 2871000 |\n | | REQUEST_DATA_INVALID | 2871002 |\n | | CONSUMER_NOT_FOUND | 2871012 |\n | | VERIFICATION_FAILED | 2871015 |\n |   | | |\n | createStandingOrder | SERVER_FAILURE | 2871100 |\n | | REQUEST_DATA_INVALID | 2871102 |\n | | VERIFICATION_FAILED | 2871115 |\n |   | | |\n | updateStandingOrder | SERVER_FAILURE | 2871200 |\n | | SYSTEM_ERROR | 2871201 |\n | | REQUEST_DATA_INVALID | 2871202 |\n | | STANDINGORDER_NOT_FOUND | 2871209 |\n | | VERIFICATION_FAILED | 2871215 |\n |   | | |\n | deleteStandingOrder | SERVER_FAILURE | 2871300 |\n | | REQUEST_DATA_INVALID | 2871302 |\n | | STANDINGORDER_NOT_FOUND | 2871309 |\n | | VERIFICATION_FAILED | 2871315 |\n |   | | |\n | updateAccountNickname | SERVER_FAILURE | 2871400 |\n | | SYSTEM_ERROR | 2871401 |\n | | REQUEST_DATA_INVALID | 2871402 |\n | | NO_RESULT | 2871403 |\n | | HOST_OFFLINE | 2871404 |\n | | HOST_COMMUNICATION_ERROR | 2871405 |\n | | SERVICE_NOT_SUPPORTED | 2871413 |\n | | EXT_RESPONSE_NO_MATCHING_RECORD_FOUND | 2871414 |\n | | VERIFICATION_FAILED | 2871415 |\n |   | | |\n | *Prestaged Transaction API*\n |   | | |\n | createCashout4Me | SERVER_FAILURE | 2872000 |\n | | SYSTEM_ERROR | 2872001 |\n | | REQUEST_DATA_INVALID | 2872002 |\n | | NO_RESULT | 2872003 |\n | | HOST_OFFLINE | 2872004 |\n | | HOST_COMMUNICATION_ERROR | 2872005 |\n | | VERIFICATION_FAILED | 2872015 |\n |   | | |\n | createCashout2You | SERVER_FAILURE | 2872100 |\n | | SYSTEM_ERROR | 2872101 |\n | | REQUEST_DATA_INVALID | 2872102 |\n | | NO_RESULT | 2872103 |\n | | HOST_OFFLINE | 2872104 |\n | | HOST_COMMUNICATION_ERROR | 2872105 |\n | | VERIFICATION_FAILED | 2872115 |\n |   | | |\n | createDeposit | SERVER_FAILURE | 2872200 |\n | | SYSTEM_ERROR | 2872201 |\n | | REQUEST_DATA_INVALID | 2872202 |\n | | NO_RESULT | 2872203 |\n | | HOST_OFFLINE | 2872204 |\n | | HOST_COMMUNICATION_ERROR | 2872205 |\n | | VERIFICATION_FAILED | 2872215 |\n |   | | |\n | createBranchDeposit | SERVER_FAILURE | 2872300 |\n | | SYSTEM_ERROR | 2872301 |\n | | REQUEST_DATA_INVALID | 2872302 |\n | | NO_RESULT | 2872303 |\n | | HOST_OFFLINE | 2872304 |\n | | HOST_COMMUNICATION_ERROR | 2872305 |\n | | VERIFICATION_FAILED | 2872315 |\n |   | | |\n | deletePrestagedTransaction | SERVER_FAILURE | 2872400 |\n | | RESERVED | 2872400 |\n | | REQUEST_DATA_INVALID | 2872402 |\n | | VERIFICATION_FAILED | 2872415 |\n |   | | |\n | getPrestagedTransactions | SERVER_FAILURE | 2872500 |\n | | SYSTEM_ERROR | 2872501 |\n | | REQUEST_DATA_INVALID | 2872502 |\n | | NO_RESULT | 2872503 |\n | | HOST_OFFLINE | 2872504 |\n | | HOST_COMMUNICATION_ERROR | 2872505 |\n | | VERIFICATION_FAILED | 2872515 |\n |   | | |\n | executePrestagedTransaction | SERVER_FAILURE | 2872600 |\n | | SYSTEM_ERROR | 2872601 |\n | | REQUEST_DATA_INVALID | 2872602 |\n | | VERIFICATION_FAILED | 2872615 |\n |   | | |\n | *Miscellaneous API*\n |   | | |\n | getCreditors | SERVER_FAILURE | 2874000 |\n | | SYSTEM_ERROR | 2874001 |\n | | REQUEST_DATA_INVALID | 2874002 |\n | | VERIFICATION_FAILED | 2874015 |\n |   | | |\n | getSinglePaymentOrderData | SERVER_FAILURE | 2874100 |\n | | RESERVED | 2874100 |\n | | REQUEST_DATA_INVALID | 2874102 |\n | | CONSUMER_NOT_FOUND | 2874112 |\n | | VERIFICATION_FAILED | 2874115 |\n |   | | |\n | getPreferences | SERVER_FAILURE | 2874200 |\n | | RESERVED | 2874200 |\n | | REQUEST_DATA_INVALID | 2874202 |\n | | RESPONSE_NO_CONSUMER_ID_AVAILABLE | 2874210 |\n | | RESPONSE_NO_PREFERENCES_AVAILABLE | 2874211 |\n | | VERIFICATION_FAILED | 2874215 |\n |   | | |\n | setPreferences | SERVER_FAILURE | 2874300 |\n | | RESERVED | 2874300 |\n | | REQUEST_DATA_INVALID | 2874302 |\n | | VERIFICATION_FAILED | 2874315 |\n |   | | |\n | getClientBranding | SERVER_FAILURE | 2874400 |\n | | RESERVED | 2874400 |\n | | REQUEST_DATA_INVALID | 2874402 |\n | | VERIFICATION_FAILED | 2874415 |\n |   | | |\n | getGenericTransactionOrders | SERVER_FAILURE | 2874500 |\n | | RESERVED | 2874500 |\n | | REQUEST_DATA_INVALID | 2874502 |\n | | VERIFICATION_FAILED | 2874515 |\n |   | | |\n | executeGenericTransactionOrder | SERVER_FAILURE | 2874600 |\n | | RESERVED | 2874600 |\n | | REQUEST_DATA_INVALID | 2874602 |\n | | VERIFICATION_FAILED | 2874615 |\n |   | | |\n | getLocations | SERVER_FAILURE | 2873000 |\n | | SYSTEM_ERROR | 2873001 |\n | | REQUEST_DATA_INVALID | 2873002 |\n | | NO_RESULT | 2873003 |\n | | VERIFICATION_FAILED | 2873015 |\n |   | | |\n | *Accessibility API*\n |   | | |\n | getRsaKey | SERVER_FAILURE | 2875000 |\n | | VERIFICATION_FAILED | 2875015 |\n |   | | |\n | getEcKey | SERVER_FAILURE | 2875100 |\n | | VERIFICATION_FAILED | 2875115 |\n |   | | |\n | getVersion | SERVER_FAILURE | 2875200 |\n | | VERIFICATION_FAILED | 2875215 |" required: - code properties: code: description: An error code as outlined in the PC/E documentation. type: integer format: int32 minimum: 0 example: 850004 message: description: An optional, additional message which describes the error. type: string maxLength: 255 example: Internal server error. A database connection could not be established. requestBodies: standingOrderRequestBody: content: application/json: schema: $ref: '#/components/schemas/StandingOrderRequest' description: The request body used for /createStandingOrder and /updateStandingOrder requests required: true parameters: referenceIdParam: name: Dn-Tm-Omapi-Reference-Id in: header description: A unique identifier referring to a transaction in TM. This parameter should be encrypted and encoded in base64. required: true schema: type: string minLength: 1 sessionTokenParam: name: Dn-Tm-Omapi-Session-Token in: header description: A unique identifier of a consumer session (within an external system), which is required to validate the consumer session. The default implementation expects in the sessionToken parameter a valid openId Connect id_token. Moreover, the default implementation expects in the authorization header of the http request the authorization schema "Bearer" followed by a valid openId Connect access token. This parameter should be encrypted and encoded in base64. required: true schema: type: string minLength: 1 clientSecretParam: name: Dn-Tm-Omapi-Client-Secret in: header required: true description: "Depending on the crypto scheme (RSA/AES or ECIES) the client intends to use the corresponding properties of the __CryptoParams__ schema defined by OM-API should be filled accordingly and sent back to the server as stringified JSON. For example:\n\n__Using RSA/AES:__\n\n cryptoParams: {\n aesKeyParams: {\n key: \"uMSlxHYT+ttxz0T+nL+A344iP6ujJdodCn6k5MmjWDC0T+MFCXcs1OjXK1DaYFaP3v1mqN9+uh58FE0VxcwFGaRSp6uDfbl9Oaji7v0vDS9mMFa4hzMoiiYBmRKUemTNkJOcgCpDi7kDNHPB+gpqYyc4dMFfPvSCG/SYv7CFXTA=\",\n iv: \"FgZ/HdtOhroVzRd802X3NgHCuiqBjCM+6Q/6PS0lUrROBe8T+me444KpKt112gLwHck7nmOVkZJPznWf7bpX6dh+mcIQ/3B7PJ3xGEsHbmSXEAK10C+AKwXpI9Sdig8feP2QT+Hd0d1qGk0X93OFaJ/zfqs/MNIesNTVAY2YBIw=\"\n },\n rsaPublicKey:\"-----BEGIN PUBLIC KEY-----\\nMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCeB05D31/zFICpf9JJWDo1ZVXt\\npYwvJa6ka0g0EHN95C8fvMguNDmprslmsOqaJYplmknWpWjbHAtIPpqrtY3H6eWP\\nELkBN2hitJlQQjf1y2jsWHsSH7BsVY5z1hCzJySFE7Q1ae9WuYj3RTsq+4ZZpEk7\\nCjRdjA26emVkCR3vWwIDAQAB\\n-----END PUBLIC KEY-----\"\n }\n\nThe property __rsaPublicKey__ is used to send the client's public key to the server in order to create encrypted responses. It is recommended to use __rsaPublicKey__ key size of - at least - 1024 bit.\nThe property __aesKeyParams__ is used to send the client's AES key (256bit) and iv (128bit) to the server. Both values __must__ be encrypted with the servers public RSA key (see __/getRsaKey__).\n\n__Using ECIES:__\n\n cryptoParams: {\n \"ecPublicKey\":{\n \"publicKeyPem\":\"-----BEGIN PUBLIC KEY-----\\nMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEHPMaBu6d0BR6QFw3VKwPipuAdDPL\\nG36/aoyTx7iTK1xgoi7X9aMmT1x3Qh1+S1zVhBh2LDDEljHkkVyHrl4bOg==\\n-----END PUBLIC KEY-----\\n\"\n }\n }\n\nThe property __ecPublicKey__ is used to send the client's public key to the server in order to create encrypted responses." schema: type: string minLength: 1 consumerIdParam: name: Dn-Tm-Omapi-Consumer-Id in: header description: A unique identifier of a consumer (within an external system), which is required to identify the consumer. Maybe the consumerId is moreover/also used to authorize the consumer against an external system. This parameter should be encrypted and encoded in base64. required: true schema: type: string minLength: 1 securitySchemes: bearerAuth: description: When using the bearer authentication method an access token has to be provided in the HTTP authorization header. When using openIdConnect as security scheme the access token has to be provided in the Authorization header with the bearer scheme while the id token has to be provided in the __consumerIdParam__ which must also be encrypted. type: http scheme: bearer externalDocs: description: Find out more about Swagger url: http://swagger.io