swagger: '2.0' info: title: Bill Payment Validator Account Opening Mastercard API description: This service is provided on behalf of the Mastercard Remote Payment and Presentment (RPPS) Bill Payment Processing Network, which supports consumer to business "push" bill payments (i.e. those which are not funded by debit/credit card transactions) in the U.S. version: '1.0' x-artifactId: billpay-api contact: name: Bill Pay Development Support email: Bill_Pay_Development_Support@mastercard.com host: sandbox.api.mastercard.com basePath: /billpayAPI/v1 schemes: - https consumes: - application/json produces: - application/json tags: - name: Mastercard paths: /mastercard-frauds: post: tags: - Mastercard operationId: submitMastercardFraud description: This endpoint allows the initiator to add a new fraud record using minimal input parameters for Mastercard built transactions. To submit a transaction as fraud, a match has to be found in the Mastercard transaction data repository(Data Warehouse). summary: Add a New Fraud Record Using Minimal Input Parameters for Mastercard Built Transactions. x-mastercard-api-encrypted: true requestBody: $ref: '#/components/requestBodies/FraudMastercardRequest' responses: '200': $ref: '#/components/responses/FraudAdditionException' '201': $ref: '#/components/responses/FraudAddition' '202': $ref: '#/components/responses/FraudAddAccepted' '400': $ref: '#/components/responses/BadRequestError' '401': $ref: '#/components/responses/UnauthorizedError' '403': $ref: '#/components/responses/ForbiddenError' '429': $ref: '#/components/responses/RateLimitExceededError' x-microcks-operation: delay: 0 dispatcher: FALLBACK put: tags: - Mastercard operationId: updateMastercardFraud description: This endpoint allows the initiator to change an existing fraud record using minimal input parameters for Mastercard built transactions. The initiator can modify both successful and rejected fraud transactions and also modify transactions which are submitted via other channels such as GFT, file upload, and online. summary: Change an Existing Fraud Record Using Minimal Input Parameters for Mastercard Built Transactions. x-mastercard-api-encrypted: true requestBody: $ref: '#/components/requestBodies/FraudRequestChange' responses: '200': $ref: '#/components/responses/FraudDataChanged' '400': $ref: '#/components/responses/BadRequestError' '401': $ref: '#/components/responses/UnauthorizedError' '403': $ref: '#/components/responses/ForbiddenError' '429': $ref: '#/components/responses/RateLimitExceededError' x-microcks-operation: delay: 0 dispatcher: FALLBACK components: responses: UnauthorizedError: description: Unauthorized request. content: application/json: schema: $ref: '#/components/schemas/ErrorWrapper' examples: UnauthorizedExample: $ref: '#/components/examples/UnauthorizedExample' FraudAddition: description: Fraud submitted successfully. headers: Location: schema: type: string description: Refers to the created resource location. content: application/json: schema: $ref: '#/components/schemas/Fraud' examples: FraudAdditionExample: $ref: '#/components/examples/FraudAdditionExample' FraudDataChanged: description: Fraud data changed successfully. content: application/json: schema: $ref: '#/components/schemas/Fraud' examples: FraudDataChanged: $ref: '#/components/examples/FraudDataChanged' FraudDataChangedError: $ref: '#/components/examples/FraudDataChangedError' RateLimitExceededError: description: Too Many Requests. content: application/json: schema: $ref: '#/components/schemas/ErrorWrapper' examples: RateLimitExceededExample: $ref: '#/components/examples/RateLimitExceededExample' FraudAdditionException: description: Exception occurred while Fraud submission. content: application/json: schema: $ref: '#/components/schemas/Fraud' examples: FraudAdditionRejectExample: $ref: '#/components/examples/FraudAdditionRejectExample' FraudAdditionSuspendExample: $ref: '#/components/examples/FraudAdditionSuspendExample' ForbiddenError: description: Consent not given. content: application/json: schema: $ref: '#/components/schemas/ErrorWrapper' examples: ForbiddenExample: $ref: '#/components/examples/ForbiddenExample' BadRequestError: description: Something was wrong with the request. content: application/json: schema: $ref: '#/components/schemas/ErrorWrapper' examples: BadRequestRefIdMissing: $ref: '#/components/examples/BadRequestRefIdMissing' FraudAddAccepted: description: Fraud submission accepted successfully. headers: Location: schema: type: string description: Refers to the created resource location. content: application/json: schema: $ref: '#/components/schemas/Fraud' examples: FraudAddAcceptedExample: $ref: '#/components/examples/FraudAddAcceptedExample' schemas: FraudBase: type: object properties: refId: description: Unique identification generated by the transaction originator using UUID logic to unambiguously link a request and response message. example: ecb2d942-eabd-42b6-87fd-69c19692bdc6 maxLength: 36 minLength: 36 type: string timestamp: description: Timestamp of the request initiation by the originator in the format 'YYYY-MM-DDThh:mm:ss:mmm+hh:mm'. The value of '+hh:mm' portion should always be '-05:00' or '-06:00' reflecting CST time. example: '2022-05-24T20:34:37+6:00' maxLength: 25 minLength: 25 type: string icaNumber: description: ICA number of the Issuer or Acquirer or Provider initiating the fraud submission request. example: '1076' maxLength: 7 minLength: 3 type: string SafeFraudProvider: description: Indicates the originator of the request. Value 10 is for Issuer and 20 for Acquirer. type: string example: '10' pattern: ^(10|20) minLength: 2 maxLength: 2 UpdatedMastercardFraud: allOf: - $ref: '#/components/schemas/APIDataElement' - type: object required: - providerId - auditControlNumber properties: providerId: $ref: '#/components/schemas/SafeFraudProvider' auditControlNumber: description: Unique number generated by FLD application and provided in the response message for a successful fraud record submission (FDA event). This is used as a reference to subsequently modify, delete or convert a suspended to a confirmed fraud record. type: string minLength: 15 maxLength: 15 example: '418142102142002' fraudPostedDate: description: Date on which the fraud is posted in FLD by the originator. Format is 'YYYYMMDD'. type: string minLength: 8 maxLength: 8 pattern: ^\d{4}(0[1-9]|1[012])(0[1-9]|[12][0-9]|3[01])$ example: '20210120' fraudTypeCode: description: Code identifying the reason the originator submitted the transaction as fraud in FLD. Please refer to [Table 1](https://developer.mastercard.com/fld-fraud-submission/documentation/parameters/annexure-1/#table-1-fraud-type-codes) for possible values. type: string minLength: 2 maxLength: 2 example: '04' fraudSubTypeCode: description: Code to further identify the reason why the originator submitted the transaction as fraud in FLD. This attribute is mandatory for Issuer but optional for Acquirer. Please refer to [Table 2](https://developer.mastercard.com/fld-fraud-submission/documentation/parameters/annexure-1/#table-2-fraud-sub-type-codes) for possible values. type: string minLength: 1 maxLength: 1 example: U accountDeviceType: description: Indicates if the account uses a magnetic stripe, chip, pin, contactless or any combination thereof. Please refer to [Table 3](https://developer.mastercard.com/fld-fraud-submission/documentation/parameters/annexure-1/#table-3-account-device-type-codes) for possible values. type: string minLength: 1 maxLength: 1 example: '1' cardholderReportedDate: description: Date on which the cardholder had reported the fraud. Format is 'YYYYMMDD'. type: string minLength: 8 maxLength: 8 pattern: ^\d{4}(0[1-9]|1[012])(0[1-9]|[12][0-9]|3[01])$ example: '20210118' cardInPossession: description: Flag to indicate if the card holder was in possession of the card at the time the fraud occurred. Possible values are 'Y', 'N' and 'U' (for Unknown). type: string minLength: 1 maxLength: 1 example: N memo: description: Brief description by the originator providing some comment supporting the action. type: string minLength: 1 maxLength: 1000 example: This is a sample FDC minimal request. ErrorWrapper: description: Object containing the list of combination of error reason codes and their corresponding description (can provide up to 5 errors for a record). It will be absent if the request is processed by FLD application successfully. title: Error Response required: - Errors type: object properties: Errors: $ref: '#/components/schemas/Errors' CfcIndicator: description: Flag to indicate a single or dual message transaction. Possible values are - - 'ARN' for Acquirer Reference Number - 'BRN' for Banknet Reference Number - 'TRC' for Trace ID - 'SER' for Serial ID type: string enum: - ARN - BRN - TRC - SER Errors: title: Errors required: - Error type: object properties: Error: type: array description: Errors array wrapped in an error object items: $ref: '#/components/schemas/Error' example: [] Fraud: allOf: - $ref: '#/components/schemas/FraudBase' - type: object required: - responseCode - responseMessage properties: responseCode: description: Response code indicating success or failure of the transaction at an API level. Errors at a record level will be handled through 'errorDetails' element associated with each record. type: string minLength: 3 maxLength: 3 example: '000' responseMessage: description: Transaction response description corresponding to the response code. type: string minLength: 1 maxLength: 100 example: Success icaNumber: description: ICA number of the originator provided in the request API which is echoed back. This attribute will be absent if the request is not processed by FLD application. type: string minLength: 3 maxLength: 7 example: '1076' auditControlNumber: description: Unique number generated by FLD application and provided in the response message for a successful fraud record submission ('FDA' event). This is used as a reference in the request API to subsequently modify, delete or convert a suspended to a confirmed fraud record and is echoed back. This attribute will be absent if the request is not processed by FLD application. type: string minLength: 15 maxLength: 15 example: '418142102142002' duplicateAuditControlNumbers: description: List of existing Audit Control Number which matches the request submitted for Mastercard-built or Issuer-built. This attribute will appear in case of the records already present while trying to submit or update the existing record. type: array items: type: string minItems: 1 maxItems: 5 uniqueItems: true matchLevelIndicator: description: Indicates if it is a Mastercard-built or Issuer-built record. Possible values are 'M' for Mastercard built record and 'I' for Issuer built record. This attribute will be absent if the request is not processed by FLD application. type: string minLength: 1 maxLength: 1 example: M financialTransactionIndicator: description: Indicates if the fraud record is being submitted against a financial transaction (having a clearing record) or a declined auth transaction (without a clearing record). Possible values are 'APPROVED' for financial transactions (having a clearing record) and 'DECLINED' for declined auth transactions (without a clearing record). This attribute will be absent if the request is not processed by FLD application. type: string minLength: 1 maxLength: 20 example: DECLINED authorizationResponse: description: Provides the 'Auth Response Code' and 'Auth Response Code Description' combination if 'Financial Transaction Indicator' value is 'DECLINED'. This attribute will be absent for all other scenarios. type: string minLength: 1 maxLength: 200 example: 05 - Do not honor previousStatus: description: Previous status of the transaction in terms of an FDC, FDD and FDE event. type: string minLength: 1 maxLength: 50 example: CONFIRMED-REJECTED currentStatus: description: Current status of the transaction in terms of an FDA, FDC, FDD and FDE event. type: string minLength: 1 maxLength: 50 example: CONFIRMED-SUCCESS channel: description: Fraud request submission fld channel name. type: string minLength: 1 maxLength: 50 example: Online errorDetails: $ref: '#/components/schemas/ErrorWrapper' MastercardFraud: allOf: - $ref: '#/components/schemas/APIDataElement' - type: object required: - providerId - transactionIdentifiers - cardNumber - transactionAmount - transactionDate - fraudTypeCode - accountDeviceType - cardInPossession properties: providerId: $ref: '#/components/schemas/SafeFraudProvider' transactionIdentifiers: type: array items: $ref: '#/components/schemas/TransactionIdentifier' cardNumber: description: Cardholder account number used in the fraudulent transaction. Card number to be verified through Luhn's algorithm. type: string minLength: 12 maxLength: 19 example: '5505135664572870000' transactionAmount: description: Transaction amount at the merchant location (without any decimals). type: string minLength: 1 maxLength: 12 example: '10350' transactionDate: description: Local date at the merchant location when the transaction occurred. Format is 'YYYYMMDD'. type: string minLength: 8 maxLength: 8 pattern: ^\d{4}(0[1-9]|1[012])(0[1-9]|[12][0-9]|3[01])$ example: '20210115' fraudPostedDate: description: Date on which the fraud is posted in FLD by the originator. Format is 'YYYYMMDD'.It is optional field, if not provided FLD System will save it as System date. type: string minLength: 8 maxLength: 8 pattern: ^\d{4}(0[1-9]|1[012])(0[1-9]|[12][0-9]|3[01])$ example: '20210120' fraudTypeCode: description: Code identifying the reason the originator submitted the transaction as fraud in FLD. Please refer to [Table 1](https://developer.mastercard.com/fld-fraud-submission/documentation/parameters/annexure-1/#table-1-fraud-type-codes) for possible values. type: string minLength: 2 maxLength: 2 example: '04' fraudSubTypeCode: description: Code to further identify the reason that the originator submitted the transaction as a fraud in FLD. This attribute is mandatory for the Issuer but optional for the Acquirer. Please refer to [Table 2](https://developer.mastercard.com/fld-fraud-submission/documentation/parameters/annexure-1/#table-2-fraud-sub-type-codes) for possible values. type: string minLength: 1 maxLength: 1 example: U accountDeviceType: description: Indicates if the account uses a magnetic stripe, chip, pin, contactless or any combination thereof. Please refer to [Table 3](https://developer.mastercard.com/fld-fraud-submission/documentation/parameters/annexure-1/#table-3-account-device-type-codes) for possible values. type: string minLength: 1 maxLength: 1 example: '1' cardholderReportedDate: description: Date on which the cardholder had reported the fraud. Format is 'YYYYMMDD'. type: string minLength: 8 maxLength: 8 pattern: ^\d{4}(0[1-9]|1[012])(0[1-9]|[12][0-9]|3[01])$ example: '20210118' cardInPossession: description: Flag to indicate if the card holder was in possession of the card at the time the fraud occurred. Possible values are 'Y', 'N' and 'U' (for Unknown). type: string minLength: 1 maxLength: 1 example: N avsResponseCode: description: The Address Verification Service response code in the Authorization Request Response. Please refer to [Table 4](https://developer.mastercard.com/fld-fraud-submission/documentation/parameters/annexure-1/#table-4-avs-response-codes) for possible values. type: string minLength: 1 maxLength: 1 example: U authResponseCode: description: Indicates the result of the authorization request. Please refer to [Table 5](https://developer.mastercard.com/fld-fraud-submission/documentation/parameters/annexure-1/#table-5-authorization-response-codes) for possible values. type: string minLength: 2 maxLength: 2 example: '01' memo: description: Brief description by the originator providing some comment supporting the action. type: string minLength: 1 maxLength: 1000 example: This is a sample FDA minimal request. TransactionIdentifier: description: Transaction Identifier containing CFC Indicator the key and value pair. type: object properties: cfcKey: $ref: '#/components/schemas/CfcIndicator' cfcValue: description: Actual value depending on the 'CFC Indicator' subject to the following validations 1. For ARN, Min Length is 23, Max Length is 23 and Data Type is N. 2. For BRN, Min Length is 6, Max Length is 9 and Data Type is AN. 3. For TRC, Min Length is 6, Max Length is 6 and Data Type is N. 4. For SER, Min Length is 9, Max Length is 9 and Data Type is N. type: string minLength: 6 maxLength: 23 example: 0111111111999999999999 APIDataElement: required: - refId - timestamp - icaNumber type: object properties: refId: description: Unique identification generated by the transaction originator using UUID logic to unambiguously link a request and response message. type: string minLength: 36 maxLength: 36 example: ecb2d942-eabd-42b6-87fd-69c19692bdc6 timestamp: type: string description: Timestamp of the request initiation by the originator in the format 'YYYY-MM-DDThh:mm:ss:mmm+hh:mm'. The value of '+hh:mm' portion should always be '-05:00' or '-06:00' reflecting CST time. minLength: 25 maxLength: 25 example: '2021-02-02T02:34:37-06:00' icaNumber: description: ICA number of the Issuer or Acquirer initiating the fraud submission request. type: string minLength: 3 maxLength: 7 example: '1076' issuerSCAExemption: description: Issuer SCA (Strong Customer Authentication) Exemption value. Please refer to [Table 16](https://developer.mastercard.com/fld-fraud-submission/documentation/parameters/annexure-1/#table-16-issuer-sca-strong-customer-authentication-exemption) for possible values. type: string minLength: 1 maxLength: 2 example: 09 Error: title: ErrorMessage required: - Description - ReasonCode type: object properties: Source: type: string description: The application or component that generated this error. minLength: 3 maxLength: 50 example: FLD ReasonCode: type: string description: Reason code is a unique constant identifying the error case encountered during request processing. minLength: 5 maxLength: 100 example: VALIDATION_ERROR Description: type: string description: Human-readable short description of the reasonCode minLength: 10 maxLength: 250 example: Reference Id is not provided Details: type: string description: Optional detailed description provides information about data received and calculated during request processing. This helps the user to diagnose errors. minLength: 0 maxLength: 1000 example: This is mandatory field while requesting for fraud submission. Recoverable: type: boolean description: Recoverable flag indicates whether this error is always returned for this request, or retrying could change the outcome. For example, 'true' or 'false'. example: false examples: UnauthorizedExample: value: Errors: Error: - Source: fld ReasonCode: UNAUTHORIZED_REQUEST Description: Unauthorized request Recoverable: false FraudAdditionRejectExample: value: refId: ecb2d942-eabd-42b6-87fd-69c19692bdc6 timestamp: '2021-03-16T20:34:40-06:00' responseCode: '100' responseMessage: Failure errorDetails: Errors: Error: - ReasonCode: '60004' Description: 'CardNumber attribute value length not in range. Minimum Length:12 and Maximum Length: 19.' RateLimitExceededExample: value: Errors: Error: - Source: fld ReasonCode: RATE_LIMIT_EXCEEDED Description: You have exceeded the service rate limit. Maximum allowed 10 TPS. Recoverable: true details: null FraudDataChanged: value: refId: ecb2d942-eabd-42b6-87fd-69c19692bdc6 timestamp: '2021-03-16T20:34:40-06:00' responseCode: '000' responseMessage: Success icaNumber: '1076' auditControlNumber: '123111111000025' previousStatus: CONFIRMED-REJECTED currentStatus: CONFIRMED-SUCCESS matchLevelIndicator: M financialTransactionIndicator: DECLINED authorizationResponse: 05 - Do not honor FraudChangeExample: value: refId: ecb2d942-eabd-42b6-87fd-69c19692bdc6 timestamp: '2021-03-16T20:34:37-06:00' icaNumber: '1076' providerId: '10' auditControlNumber: '123111111000025' fraudPostedDate: '20210316' fraudTypeCode: '01' fraudSubTypeCode: N accountDeviceType: '1' cardholderReportedDate: '20210314' cardInPossession: Y memo: This is a sample FDC minimal request. issuerSCAExemption: 09 FraudDataChangedError: value: refId: ecb2d942-eabd-42b6-87fd-69c19692bdc6 timestamp: '2021-03-16T20:34:40-06:00' responseCode: '100' responseMessage: Failure errorDetails: Errors: Error: - ReasonCode: '60003' Description: icaNumber incorrect datatype of attribute value. BadRequestRefIdMissing: value: Errors: Error: - Source: fld ReasonCode: VALIDATION_ERROR Description: Reference Id is not provided Recoverable: false FraudAdditionExample: value: refId: ecb2d942-eabd-42b6-87fd-69c19692bdc6 timestamp: '2021-03-16T20:34:40-06:00' responseCode: '000' responseMessage: Success icaNumber: '1076' auditControlNumber: '123111111000025' currentStatus: CONFIRMED-SUCCESS matchLevelIndicator: M financialTransactionIndicator: DECLINED authorizationResponse: 05 - Do not honor MastercardFraudExample: value: refId: ecb2d942-eabd-42b6-87fd-69c19692bdc6 timestamp: '2021-03-16T20:34:37-06:00' icaNumber: '1076' providerId: '10' transactionIdentifiers: - cfcKey: ARN cfcValue: 0712141161891099999900 - cfcKey: BRN cfcValue: 999RRR cardNumber: '5505135664572870008' transactionAmount: '5505' transactionDate: '20200713' fraudPostedDate: '20210316' fraudTypeCode: '01' fraudSubTypeCode: N accountDeviceType: '1' cardholderReportedDate: '20210314' cardInPossession: Y avsResponseCode: U authResponseCode: '00' memo: This is a sample FDA minimal request. issuerSCAExemption: 09 FraudAddAcceptedExample: value: refId: ecb2d942-eabd-42b6-87fd-69c19692bdc6 timestamp: '2021-03-16T20:34:40-06:00' responseCode: '001' responseMessage: Pending icaNumber: '1076' auditControlNumber: '123111111000025' FraudAdditionSuspendExample: value: refId: ecb2d942-eabd-42b6-87fd-69c19692bdc6 timestamp: '2021-03-16T20:34:40-06:00' responseCode: '201' responseMessage: Failure icaNumber: '1076' auditControlNumber: '123111111000025' matchLevelIndicator: M currentStatus: CONFIRMED-SUSPENDED duplicateAuditControlNumbers: - 000222520077829 - 000222520077830 - 000222520077831 - 000222520077832 - 000222520077833 errorDetails: Errors: Error: - ReasonCode: '30100' Description: Potential Duplicate Data Found, Record is suspended. ForbiddenExample: value: Errors: Error: - Source: fld ReasonCode: CONSENT_NOT_GIVEN Description: User Consent Not Given Recoverable: false requestBodies: FraudRequestChange: description: Change an existing fraud record using minimal input parameters for Mastercard built transactions. This endpoint uses [ payload encryption](https://developer.mastercard.com/platform/documentation/security-and-authentication/securing-sensitive-data-using-payload-encryption/). Please refer to the [reference application](https://developer.mastercard.com/fld-fraud-submission/documentation/api-reference/) page for implementation details. required: true content: application/json: schema: $ref: '#/components/schemas/UpdatedMastercardFraud' examples: FraudChangeExample: $ref: '#/components/examples/FraudChangeExample' FraudMastercardRequest: description: Add a new fraud record using minimal input parameters for Mastercard built transactions. This endpoint uses [payload encryption](https://developer.mastercard.com/platform/documentation/security-and-authentication/securing-sensitive-data-using-payload-encryption/). Please refer to the [reference application](https://developer.mastercard.com/fld-fraud-submission/documentation/api-reference/) page for implementation details. required: true content: application/json: schema: $ref: '#/components/schemas/MastercardFraud' examples: MastercardFraudExample: $ref: '#/components/examples/MastercardFraudExample'