openapi: 3.0.3 info: title: Lithic 3DS Hold API description: The Lithic API is a card issuing and issuer-processor platform for issuing virtual and physical cards, authorizing and clearing transactions, moving money across ledgered financial accounts, and managing the full card lifecycle - KYC/KYB account holder onboarding, authorization rules and real-time Auth Stream Access (ASA) decisioning, disputes, tokenization into digital wallets, 3DS authentication, ACH payments, book transfers, external payments, settlement reporting, and fraud/transaction monitoring. This document curates the real, published Lithic OpenAPI 3.1 definitions (https://github.com/lithic-com/lithic-openapi) into the endpoint surface referenced by this apis.yml, expressed as OpenAPI 3.0.3 with lightweight response schemas. Requests are authenticated with an API key sent as the raw value of the Authorization header (not a Bearer token). version: 1.0.0 contact: name: Lithic url: https://www.lithic.com license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0.txt servers: - url: https://api.lithic.com description: Production - url: https://sandbox.lithic.com description: Sandbox (mirrors production functionality) security: - ApiKeyAuth: [] tags: - name: Hold description: Holds placed against financial account balances. paths: /v1/financial_accounts/{financial_account_token}/holds: get: operationId: getFinancialAccountHolds tags: - Hold summary: List holds description: List holds for a financial account. parameters: - name: financial_account_token in: path required: true description: Globally unique identifier for the financial account. schema: type: string responses: '200': description: Successful response. content: application/json: schema: $ref: '#/components/schemas/Hold' '401': $ref: '#/components/responses/Unauthorized' '422': $ref: '#/components/responses/ValidationError' post: operationId: createHold tags: - Hold summary: Create hold description: Create a hold on a financial account. Holds reserve funds by moving them from available to pending balance. They can be resolved via settlement (linked to a payment or book transfer), voiding, or expiration. parameters: - name: financial_account_token in: path required: true description: Globally unique identifier for the financial account. schema: type: string requestBody: required: true content: application/json: schema: type: object additionalProperties: true responses: '200': description: Successful response. content: application/json: schema: $ref: '#/components/schemas/Hold' '401': $ref: '#/components/responses/Unauthorized' '422': $ref: '#/components/responses/ValidationError' /v1/holds/{hold_token}: get: operationId: getHold tags: - Hold summary: Get hold description: Get hold by token. parameters: - name: hold_token in: path required: true description: Globally unique identifier for the hold. schema: type: string responses: '200': description: Successful response. content: application/json: schema: $ref: '#/components/schemas/Hold' '401': $ref: '#/components/responses/Unauthorized' '422': $ref: '#/components/responses/ValidationError' /v1/holds/{hold_token}/void: post: operationId: voidHold tags: - Hold summary: Void hold description: Void an active hold. This returns the held funds from pending back to available balance. Only holds in PENDING status can be voided. parameters: - name: hold_token in: path required: true description: Globally unique identifier for the hold. schema: type: string requestBody: required: true content: application/json: schema: type: object additionalProperties: true responses: '200': description: Successful response. content: application/json: schema: $ref: '#/components/schemas/Hold' '401': $ref: '#/components/responses/Unauthorized' '422': $ref: '#/components/responses/ValidationError' components: responses: ValidationError: description: The request failed validation. Unauthorized: description: Missing or invalid API key. schemas: Hold: type: object description: Holds placed against financial account balances. properties: token: type: string format: uuid description: Globally unique identifier for the object. created: type: string format: date-time additionalProperties: true securitySchemes: ApiKeyAuth: type: apiKey in: header name: Authorization description: Raw API secret key value (not prefixed with "Bearer").