# Discover > Discover Financial Services is a US consumer bank and payments network, and through Discover Global Network one of the four global card acceptance networks (alongside the Diners Club International and PULSE brands). Its developer-facing business is the network side: issuers, acquirers, processors, wallet providers and token requestors integrate for tokenization, account updating, IIN/BIN lookup, fraud alerts, enhanced decisioning and a set of travel and acceptance tools. Generated by API Evangelist on 2026-09-06 from apis.yml and the artifacts in this repository. Discover does not publish an llms.txt of its own (/llms.txt returns 404 on www.discover.com, www.discoverglobalnetwork.com, partner.discoverglobalnetwork.com, developer.discover.com, apis.discover.com and sandbox.apis.discover.com, probed 2026-09-06). ## What an agent needs to know first - There is **no OpenAPI**, no AsyncAPI, no GraphQL SDL and no MCP server. The rebuilt Discover Developer Center advertises "interactive OpenAPI documentation", but every API page is behind an invitation-only login (HTTP 403 on developer.discover.com/api/*/documentation). - Access is **not self-serve**. "Currently, portal access is by invitation only." A partner is invited or applies through the Contact Us form, signs a service agreement, and is then issued client credentials, API scopes, an API Plan and certificates, per environment. - The API documentation that *is* public lives on the Discover Partner Product Portal product pages, rendered client-side from a server-delivered payload. It carries real endpoints, headers, request/response examples, field tables and a 113-entry error registry. - Reads are mostly POST. The IIN Data Lookup Service is the exception with real GET operations. - There is **no idempotency key**, so writes are not safe to retry. ## APIs - [Discover Stored Token Services](https://partner.discoverglobalnetwork.com/products/discover-stored-token-services?tab=overview): PAN-to-token replacement, token requestor boarding, token lifecycle, cryptogram generation, Account Notification webhooks - [Discover Payment Account Reference](https://partner.discoverglobalnetwork.com/products/payment-account-reference?tab=overview): EMVCo PAR correlation across tokenized and untokenized transactions - [Discover IIN Data Lookup Service](https://partner.discoverglobalnetwork.com/products/iin-data-lookup?tab=overview): IIN/BIN range data - issuer, card product, network - [Discover Network Account Updater](https://partner.discoverglobalnetwork.com/products/discover-network-account-updater?tab=overview): keeps recurring and card-on-file credentials current - [Discover Issuer Card Account Services](https://partner.discoverglobalnetwork.com/products/issuer-card-account-services?tab=overview): bulk card account enrollment and card product code management (iCAS) - [Discover HCE Wallet Services](https://partner.discoverglobalnetwork.com/products/hce-wallet-services?tab=overview): host card emulation wallet tokenization - [Discover SE Wallet Services](https://partner.discoverglobalnetwork.com/products/se-wallet-services?tab=overview): secure element wallet tokenization - [Discover Side-by-Side Token Services](https://partner.discoverglobalnetwork.com/products/sxs-token-services?tab=overview): alternate SXS tokens for debit routing and security enforcement - [Discover Enhanced Decisioning](https://partner.discoverglobalnetwork.com/products/discover-enhanced-decisioning?tab=overview): risk and decisioning signals - [Discover Fraud Alerts](https://partner.discoverglobalnetwork.com/products/fraud-alerts?tab=overview): near real-time fraudulent-activity notifications - [Diners Club International Customer Service](https://partner.discoverglobalnetwork.com/products/diners-club-international-customer-service?tab=overview) - [Discover Airport Lounge & Travel Program](https://partner.discoverglobalnetwork.com/products/airport-lounge-locator?tab=overview) - [Discover ATM Locator](https://partner.discoverglobalnetwork.com/products/atm-locator?tab=overview) - [Discover Country Acceptance](https://partner.discoverglobalnetwork.com/products/country-acceptance?tab=overview) - [Discover Currency Converter](https://partner.discoverglobalnetwork.com/products/currency-converter?tab=overview) - [Discover Tip Etiquette](https://partner.discoverglobalnetwork.com/products/tip-etiquette?tab=overview) - [Discover Travel Guides](https://partner.discoverglobalnetwork.com/products/travel-guides?tab=overview) ## Hosts - `https://apis.discover.com` - production API gateway - `https://sandbox.apis.discover.com` - sandbox and certification, selected by the X-DFS-API-PLAN header - `https://rangerx-api.discoverfinancial.com/epp/rangerx/v1` - production host documented for the IIN Data Lookup Service - `https://identity.discoverglobalnetwork.com` - Okta tenant that signs humans into the partner portal and Developer Center ## Authentication - Token endpoint: `POST https://apis.discover.com/auth/oauth/v2/token`, `grant_type=client_credentials`, HTTP Basic client authentication, `scope=`, Bearer token, `expires_in` 3600. - `X-DFS-API-PLAN` is mandatory on every call *including* the token request. - Second factor per API: a signed JWS in `X-DFS-C-APP-JWT`, or a consumer application certificate in `X-DFS-C-APP-CERT`. - mTLS where the API requires it, and on Discover's outgoing webhook calls. - Payloads may be JWE-encrypted, JWS-signed, or nested JWS-in-JWE. TLS 1.2 or 1.3 required. - Anonymous JWKS: `https://apis.discover.com/dfs/jwk/v1/public-keys` (keys rotate every 90 days). ## Specs - [Well-known probe index](well-known/discover-well-known.yml) - only identity.discoverglobalnetwork.com serves real documents - [OIDC discovery](well-known/discover-identity-openid-configuration.json) - [OAuth authorization server metadata](well-known/discover-identity-oauth-authorization-server.json) - [JWKS](authentication/discover-jwks.json) - [Authentication profile](authentication/discover-authentication.yml) - [OAuth scopes](scopes/discover-scopes.yml) - [API conventions](conventions/discover-conventions.yml) - [Gateway problem types](errors/discover-problem-types.yml) - [Error code registry, 113 codes](errors/discover-error-codes.yml) - [Lifecycle](lifecycle/discover-lifecycle.yml) - [Conformance](conformance/discover-conformance.yml) - [Sandbox](sandbox/discover-sandbox.yml) - [Webhooks](asyncapi/discover-webhooks.yml) - [Rate limits](rate-limits/discover-rate-limits.yml) - [Plans and pricing](plans/discover-plans-pricing.yml) - [Packages](packages/discover-packages.yml) - [Domain security](security/discover-domain-security.yml) - [Vulnerability disclosure](security/discover-vulnerability-disclosure.yml) ## Docs - [Discover Partner Product Portal](https://partner.discoverglobalnetwork.com/) - [Going Live with Discover - developer guide](https://partner.discoverglobalnetwork.com/going-live-with-discover?tab=developer-guide) - [Discover Developer Center](https://developer.discover.com/home) - [Explore our APIs](https://developer.discover.com/explore-apis) - [Partner resources](https://partner.discoverglobalnetwork.com/partner-resources) - [FAQs](https://partner.discoverglobalnetwork.com/faq) - [Contact us](https://partner.discoverglobalnetwork.com/contact-us) - [Responsible disclosure](https://www.discover.com/responsible-disclosure) - [Scope and rules of engagement](https://www.discover.com/responsible-disclosure/scope-and-roe/) - [Terms of use](https://www.discoverglobalnetwork.com/terms-of-use/) - [Privacy](https://www.discoverglobalnetwork.com/privacy-policy/) - [GitHub](https://github.com/discoverfinancial) - eight repositories, all archived and unsupported ## Not published - No OpenAPI, AsyncAPI, GraphQL SDL, gRPC .proto or WSDL. - No MCP server and no A2A agent card. - No SDK or client library for any Discover API. - No changelog, release notes, status page or SLA. - No deprecation or sunset policy. - No pricing, no plans, no free tier and no self-serve sign-up. - No published rate-limit numbers and no rate-limit response headers. - No /.well-known/security.txt, despite a real responsible-disclosure programme. - No idempotency key on any write.