openapi: 3.0.3 info: title: Lithic 3DS Management Operations API description: The Lithic API is a card issuing and issuer-processor platform for issuing virtual and physical cards, authorizing and clearing transactions, moving money across ledgered financial accounts, and managing the full card lifecycle - KYC/KYB account holder onboarding, authorization rules and real-time Auth Stream Access (ASA) decisioning, disputes, tokenization into digital wallets, 3DS authentication, ACH payments, book transfers, external payments, settlement reporting, and fraud/transaction monitoring. This document curates the real, published Lithic OpenAPI 3.1 definitions (https://github.com/lithic-com/lithic-openapi) into the endpoint surface referenced by this apis.yml, expressed as OpenAPI 3.0.3 with lightweight response schemas. Requests are authenticated with an API key sent as the raw value of the Authorization header (not a Bearer token). version: 1.0.0 contact: name: Lithic url: https://www.lithic.com license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0.txt servers: - url: https://api.lithic.com description: Production - url: https://sandbox.lithic.com description: Sandbox (mirrors production functionality) security: - ApiKeyAuth: [] tags: - name: Management Operations description: Manual ledger adjustments and corrections. paths: /v1/management_operations: get: operationId: getManagementOperations tags: - Management Operations summary: List management operations description: List management operations responses: '200': description: Successful response. content: application/json: schema: $ref: '#/components/schemas/ManagementOperations' '401': $ref: '#/components/responses/Unauthorized' '422': $ref: '#/components/responses/ValidationError' post: operationId: postManagementOperations tags: - Management Operations summary: Create management operation description: Create management operation requestBody: required: true content: application/json: schema: type: object additionalProperties: true responses: '200': description: Successful response. content: application/json: schema: $ref: '#/components/schemas/ManagementOperations' '401': $ref: '#/components/responses/Unauthorized' '422': $ref: '#/components/responses/ValidationError' /v1/management_operations/{management_operation_token}: get: operationId: getManagementOperation tags: - Management Operations summary: Get management operation description: Get management operation parameters: - name: management_operation_token in: path required: true description: Globally unique identifier for the management operation schema: type: string responses: '200': description: Successful response. content: application/json: schema: $ref: '#/components/schemas/ManagementOperations' '401': $ref: '#/components/responses/Unauthorized' '422': $ref: '#/components/responses/ValidationError' /v1/management_operations/{management_operation_token}/reverse: post: operationId: reverseManagementOperation tags: - Management Operations summary: Reverse management operation description: Reverse a management operation parameters: - name: management_operation_token in: path required: true description: Globally unique identifier for the management operation schema: type: string requestBody: required: true content: application/json: schema: type: object additionalProperties: true responses: '200': description: Successful response. content: application/json: schema: $ref: '#/components/schemas/ManagementOperations' '401': $ref: '#/components/responses/Unauthorized' '422': $ref: '#/components/responses/ValidationError' components: schemas: ManagementOperations: type: object description: Manual ledger adjustments and corrections. properties: token: type: string format: uuid description: Globally unique identifier for the object. created: type: string format: date-time additionalProperties: true responses: ValidationError: description: The request failed validation. Unauthorized: description: Missing or invalid API key. securitySchemes: ApiKeyAuth: type: apiKey in: header name: Authorization description: Raw API secret key value (not prefixed with "Bearer").