swagger: '2.0' info: title: Mastercard Bill Payment Validator Account Opening Scans API description: This service is provided on behalf of the Mastercard Remote Payment and Presentment (RPPS) Bill Payment Processing Network, which supports consumer to business "push" bill payments (i.e. those which are not funded by debit/credit card transactions) in the U.S. version: '1.0' x-artifactId: billpay-api contact: name: Bill Pay Development Support email: Bill_Pay_Development_Support@mastercard.com host: sandbox.api.mastercard.com basePath: /billpayAPI/v1 schemes: - https consumes: - application/json produces: - application/json tags: - name: Scans paths: /authentication-decisions/scans/{scan_id}: put: tags: - Scans responses: '200': $ref: '#/components/responses/AuthenticationDecisionsResponse' '400': $ref: '#/components/responses/BadRequestError' '401': $ref: '#/components/responses/UnauthorizedError' '403': $ref: '#/components/responses/ForbiddenError' '404': $ref: '#/components/responses/NotFoundError' description: "Authenticate user identity and retrieve identity attributes without updating selfie. \n**This API is mandatory.**\n" summary: Retrieve an outcome for an authentication. operationId: authenticationdecisions parameters: - $ref: '#/components/parameters/ScanIdPathParameter' - $ref: '#/components/parameters/XEncryptedPayload' requestBody: $ref: '#/components/requestBodies/AuthenticationDecisionRequest' /data-extractions/scans/{scan_id}: get: x-mastercard-api-encrypted: true summary: Returns the status of the document verification. tags: - Scans responses: '200': $ref: '#/components/responses/DataExtractionSuccessResponse' '400': $ref: '#/components/responses/BadRequestError_2' '403': $ref: '#/components/responses/ForbiddenError_2' '404': $ref: '#/components/responses/NotFoundError_2' description: Returns the status of the document verification as it's being processed by the vendor. operationId: extractScannedDocumentData parameters: - $ref: '#/components/parameters/ScanIdParameter' - $ref: '#/components/parameters/UserConsentParameter' - $ref: '#/components/parameters/RetrieveSelfieParameter' - $ref: '#/components/parameters/RetrieveDocumentImagesParameter' - $ref: '#/components/parameters/RetrieveFacemapParameter' - $ref: '#/components/parameters/DocumentTypeParameter' - $ref: '#/components/parameters/CountryParameter' - $ref: '#/components/parameters/EncryptedPayloadParameter' components: responses: UnauthorizedError: description: Unauthorized request. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' examples: UnauthorizedExample: $ref: '#/components/examples/UnauthorizedExample' AuthenticationDecisionsResponse: description: Success. headers: X-Transaction-ID: schema: type: string description: A random 128-bit UUID represents the transaction. X-User-Identity: schema: type: string description: JWT token for session validation in subsequent API calls. content: application/json: schema: $ref: '#/components/schemas/AuthenticationDecisions' examples: AuthenticationDecisionsUnencryptedResponse: $ref: '#/components/examples/AuthenticationDecisionsExample' AuthenticationDecisionsEncryptedResponse: $ref: '#/components/examples/EncryptedPayloadWithRotatedPDSExample' NotFoundError: description: The request didn't match an existing resource. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' examples: NotFoundExample: $ref: '#/components/examples/NotFoundExample' ForbiddenError: description: Consent not given. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' examples: ForbiddenExample: $ref: '#/components/examples/ForbiddenExample' ForbiddenExampleUnauthorizedScopedFields: $ref: '#/components/examples/ForbiddenExampleUnauthorizedScopedFields' BadRequestError: description: Something was wrong with the request. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' examples: UserProfileDeletedErrorExample: $ref: '#/components/examples/UserProfileDeletedErrorExample' DataExtractionSuccessResponse: description: Success. headers: X-Transaction-ID: $ref: '#/components/headers/X-Transaction-ID' content: application/json: schema: $ref: '#/components/schemas/DocumentVerificationExtractedData' examples: DocumentDataDriverLicense: $ref: '#/components/examples/DocumentDataExampleDriverLicense' DocumentDataPassaport: $ref: '#/components/examples/DocumentDataExamplePassport' DocumentDataExampleIDCard: $ref: '#/components/examples/DocumentDataExampleIDCard' NotFoundError_2: description: Request didn't match an existing resource. content: application/json: schema: $ref: '#/components/schemas/ApiError' examples: NotFoundExample: $ref: '#/components/examples/NotFoundExample_2' ForbiddenError_2: description: Consent not given. content: application/json: schema: $ref: '#/components/schemas/ApiError' examples: ForbiddenExample: $ref: '#/components/examples/ForbiddenExample' ForbiddenExampleUnauthorizedScopedFields: $ref: '#/components/examples/ForbiddenExampleUnauthorizedScopedFields_2' BadRequestError_2: description: Something was wrong with the request. content: application/json: schema: $ref: '#/components/schemas/ApiError' examples: BadRequestExampleUserConsent: $ref: '#/components/examples/BadRequestExampleUserConsent' BadRequestExampleCountryCode: $ref: '#/components/examples/BadRequestExampleCountryCode' BadRequestExamplePhoneNumber: $ref: '#/components/examples/BadRequestExamplePhoneNumber' BadRequestExampleIVPConnectionTimeout: $ref: '#/components/examples/BadRequestExampleIVPConnectionTimeout' BadRequestExampleIVPSystemError: $ref: '#/components/examples/BadRequestExampleIVPSystemError' BadRequestExampleMedicareExpireDate: $ref: '#/components/examples/BadRequestExampleMedicareExpireDate' BadRequestExampleMedicareName: $ref: '#/components/examples/BadRequestExampleMedicareName' BadRequestExampleMedicareIndividualReferenceNo: $ref: '#/components/examples/BadRequestExampleMedicareIndividualReferenceNo' BadRequestExampleMedicareMedicareNumber: $ref: '#/components/examples/BadRequestExampleMedicareMedicareNumber' BadRequestExampleMedicareCountryCode: $ref: '#/components/examples/BadRequestExampleMedicareCountryCode' BadRequestExampleMedicareUserConsent: $ref: '#/components/examples/BadRequestExampleMedicareUserConsent' BadRequestExampleDocumentMismatch: $ref: '#/components/examples/BadRequestExampleDocumentMismatch' examples: AuthenticationDecisionsExample: value: transactionId: 1ec14310-e85c-11ea-adc1-0242ac120002 status: SUCCESS attributes: legalName: aa6dee5a-6e4d-4932-8189-2ecb7ad6f676: value: SMITH, JOHN lastVerifiedDate: '2022-04-04T02:49:27.915Z' rotatedPds: ZGZnZGVmZ2RnZGVnZXJnZXJncmRnZXJ5aGdld3J0eWJld3J5dHdleXd5d3l3cmFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFh UnauthorizedExample: value: Errors: Error: - Source: mids ReasonCode: UNAUTHORIZED_REQUEST Description: Unauthorized request. Recoverable: false EncryptedPayloadWithRotatedPDSExample: value: encryptedData: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IoxNTE2MjM5MDIyf rotatedPds: ZGZnZGVmZ2RnZGVnZXJnZXJncmRnZXJ5aGdld3J0eWJld3J5dHdleXd5d3l3cmFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFh ForbiddenExampleUnauthorizedScopedFields: value: Errors: Error: - Source: mids ReasonCode: UNAUTHORIZED_SCOPED_FIELDS Description: 'UNAUTHORIZED_SCOPED_FIELDS: Requested scoped fields are not part of whitelisted fields.' Recoverable: false UserProfileDeletedErrorExample: value: Errors: Error: - Source: mids ReasonCode: USER_PROFILE_DELETED Description: 'USER_PROFILE_DELETED: ID of the deleted profile.' Recoverable: false redirectUri: https://sample-rp-redirect-uri.com?error=server_error&state=AJahbadinvjbdvdnvljkdnvdfhsrbghrtiu4w NotFoundExample: value: Errors: Error: - Source: mids ReasonCode: USER_PROFILE_ID_NOT_FOUND Description: The provided user profile ID does not exist. Recoverable: false ForbiddenExample: value: Errors: Error: - Source: mids ReasonCode: CONSENT_NOT_GIVEN Description: User Consent Not Given. Recoverable: false DocumentDataExamplePassport: value: status: PENDING transactionId: 1ec14310-e85c-11ea-adc1-0242ac120002 documentData: documentNumber: N1234567 documentStatus: PENDING documentType: PASSPORT dateOfBirth: '2020-09-09' firstName: John lastName: Smith expiryDate: '2020-10-10' gender: F issuingCountry: USA issuingDate: '2020-09-09' issuingPlace: New York issuingAuthority: United States placeOfBirth: Boston addressLine1: 123 Main St. addressLine2: New York addressZipCode: '10021' addressCity: New York addressCountry: Users Country addressSubdivision: MO issuingState: MO formattedAddress: 220 BLVD O FALLON selfie: /mJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanq......................... documentImageFront: /mJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanq......................... documentImageBack: /mJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanq......................... facemap: /mJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanq......................... DocumentDataExampleDriverLicense: value: status: SUCCESS transactionId: 1ec14310-e85c-11ea-adc1-0242ac120002 documentData: documentNumber: AB001234567 documentStatus: SUCCESS documentType: DRIVER_LICENSE dateOfBirth: '2020-09-09' firstName: MIRIAM lastName: Smith expiryDate: '2020-10-10' gender: F cardNumber: '1234567890' issuingCountry: AUS issuingDate: '2020-09-09' issuingPlace: Sydney issuingAuthority: Australia placeOfBirth: Sydney addressLine1: 10 Boronia Street addressLine2: 09 Boronia Street addressZipCode: '10021' addressCity: SYDNEY addressCountry: Users Country addressSubdivision: NSW issuingState: NSW formattedAddress: 22 Melville Street, Hobart 7000 selfie: /mJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanq......................... documentImageFront: /mJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanq......................... documentImageBack: /mJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanq......................... facemap: /mJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanq......................... BadRequestExampleIVPConnectionTimeout: value: Errors: Error: - Source: mids ReasonCode: IVP_CONNECTION_TIMEOUT Description: Connection timeout when trying to connect with the Identity Verification Provider. Please look at 'details' for additional information. Recoverable: false Details: Received Connection TimeOut Exception BadRequestExampleCountryCode: value: Errors: Error: - Source: mids ReasonCode: VALIDATION_ERROR Description: Invalid value US4 for 'countryCode'. Recoverable: false Details: null BadRequestExampleIVPSystemError: value: Errors: Error: - Source: mids ReasonCode: IVP_SYSTEM_ERROR Description: Received system error from the Identity Verification Provider. Please look at 'details' for additional information. Recoverable: false Details: System Error Received BadRequestExampleMedicareName: value: Errors: Error: - Source: mids ReasonCode: VALIDATION_ERROR Description: Invalid value for 'nameLine' field OR value exceeds allowed max characters. Recoverable: false Details: null BadRequestExampleUserConsent: value: Errors: Error: - Source: mids ReasonCode: VALIDATION_ERROR Description: Unexpected value 'Invalid' for enumerate field. Recoverable: false Details: null BadRequestExampleMedicareCountryCode: value: Errors: Error: - Source: mids ReasonCode: VALIDATION_ERROR Description: Invalid value for 'Country code'. Recoverable: false Details: null ForbiddenExampleUnauthorizedScopedFields_2: value: Errors: Error: - Source: mids ReasonCode: UNAUTHORIZED_SCOPED_FIELDS Description: 'UNAUTHORIZED_SCOPED_FIELDS: Requested scoped fields are not part of whitelisted fields.' Recoverable: false Details: null BadRequestExampleDocumentMismatch: value: Errors: Error: - Source: mids ReasonCode: BAD_REQUEST Description: The document uploaded by the User does not comply to the document type/country specified by the client in the originating access-token request. Recoverable: false Details: null BadRequestExampleMedicareIndividualReferenceNo: value: Errors: Error: - Source: mids ReasonCode: VALIDATION_ERROR Description: Invalid value for 'INDIVIDUAL_REFERENCE_NO'. Recoverable: false Details: null BadRequestExampleMedicareExpireDate: value: Errors: Error: - Source: mids ReasonCode: VALIDATION_ERROR Description: Invalid value for 'expiry date'. Recoverable: false Details: null BadRequestExampleMedicareUserConsent: value: Errors: Error: - Source: mids ReasonCode: VALIDATION_ERROR Description: User consent not given. Recoverable: false Details: null NotFoundExample_2: value: Errors: Error: - Source: mids ReasonCode: USER_PROFILE_ID_NOT_FOUND Description: The provided userProfileId does not exist. Recoverable: false BadRequestExampleMedicareMedicareNumber: value: Errors: Error: - Source: mids ReasonCode: VALIDATION_ERROR Description: Invalid value for 'Medicare card number'. Recoverable: false Details: null BadRequestExamplePhoneNumber: value: Errors: Error: - Source: mids ReasonCode: VALIDATION_ERROR Description: Invalid value ASD for 'phoneNumber'. Recoverable: false Details: null DocumentDataExampleIDCard: value: status: SUCCESS transactionId: 5f4b0b79-8f7a-4731-b828-5e9db6e39e5a documentData: lastName: SMITH gender: M fathersName: WILLIAM SMITH documentType: ID_CARD issuingDate: '2010-01-01' documentNumber: C204050123 expiryDate: '2030-12-31T00:00:00.000Z' issuingPlace: null formattedAddress: null cpf: 000.000.000-00 addressLine1: null documentStatus: SUCCESS addressLine2: null addressCity: null addressZipCode: null addressCountry: null placeOfBirth: null dateOfBirth: '1980-01-01' issuingState: null firstName: JOHN issuingAuthority: null issuingCountry: BRA mothersName: JANE SMITH addressSubdivision: null rgNumber: F204050123 selfie: /mJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanq......................... documentImageFront: /mJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanq......................... documentImageBack: /mJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanq......................... facemap: /mJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanq......................... schemas: PDS: type: string description: Encrypted Personal Device Storage (PDS) which hosts the users identity attributes. The PDS can be retrieved from the MIDS Core SDK, please refer to the SDK guide for details on how to retrieve this. pattern: ^(?:[A-Za-z0-9+\/]{4})*(?:[A-Za-z0-9+\/]{2}==|[A-Za-z0-9+\/]{3}=)?$ minLength: 1 example: ZGZnZGVmZ2RnZGVnZXJnZXJncmRnZXJ5aGdld3J0eWJld3J5dHdleXd5d3l3cmFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFh FraudDetection: type: object description: Object containing the signals from the device to be used for fraud detection. properties: nuDetectMeta: description: The data retrieved from the MIDS Fraud Detection SDK which will be used to determine whether the device is trusted. required: - behaviourData - remoteIp - sessionId - requestUrl - userAgent - xForwardedFor type: object properties: behaviourData: type: string description: base64 encoded JSON generated by MIDS (nuDetect) SDK. pattern: ^(?:[A-Za-z0-9+\/]{4})*(?:[A-Za-z0-9+\/]{2}==|[A-Za-z0-9+\/]{3}=)?$ example: ewogICJuZHMtcG1kIiA6ICJ7XCJmdnFcIjpcIjBONjROOVAzLVBPM1ItNDcyNi04MDBPLTNQMzM2Mzg2Tk5RT1wiLFwianZxdHJnUW5nblwiOntcInp2cXNpXCI6XCJRUTYzOTc5Ny1OUFAyLTQ0OVItOVA0MS04UTM0NDdOODU5UzdcIixcInpjdlwiOlwidmJmXCIsXCJ6b3pzXCI6XCJOY2N5clwiLFwiemZ6XCI6MTcxNzk4NjkxODQsXCJqeGVcIjo0OTcwLFwiem9vXCI6XCJOY2N5clwiLFwienVmXCI6W1wienZ6Z1wiXSxcInF2cWdtXCI6NDIwLFwidmNlXCI6XCJhcHZjLDAsNXM5bzg0MXAsMywxO2ZnLDAsYXF2Y2V2YWNoZzAsMCxhcXZjZXZhY2hnMSwwO3NzLDAsYXF2Y2V2YWNoZzA7eHEsc3A7eHEsNG47eHEsNW87eHEsNjY7eHEsMjUzO3hxLDg1O3hxLHBxO3hxLDM4O3hxLDVuO3hxLDcyO3hxLDU2O3hxLDUyO3hxLDJwO3NvLG45LGFxdmNldmFjaGcwO3NzLDEsYXF2Y2V2YWNoZzE7eHEsMTI1O3hxLDQwO3hxLG82O3hxLDRyO3hxLG87Z3IscXMsNzcsMjM0LGFxdmNlcGJhZ2VieTBcIixcInpjemlcIjoxMixcInpvelwiOlwidkN1YmFyXCIsXCJ6Y3p2aVwiOjIsXCJ6ZmZcIjo0OTk5NjMxNzQ5MTIsXCJ6dW9wZlwiOi0xLFwiem9jXCI6XCJ2Q3ViYXIgS8qAXCIsXCJ6dmh2XCI6XCJjdWJhclwiLFwiZmVcIjpcIjE3OTJrODI4XCIsXCJoblwiOlwiMi4yLjEzODA2NVwiLFwiemh5XCI6XCJIRlwifSxcImpnXCI6XCIxLmotNDUxNjgwLjEuMi56U0dVQk56cHZNeUFoQjBOR2h2ZlRqLCwuM3hCRWhxSGhKZFREb1ZYY0hjYXJOSDUzVWFFS2t2amxNVF9RQTl5dUlYcWUwbV9iX0k0WWtBWGExUExTVXJzS1R4c0NFWHB2bkJjNkpEajhNTzhGZFVXMEcyaE9BWXZDRWZ5NXRLOHdJdVN4MzBnZmszZDF0MWhnc2NJODdFTG9MVlozNi1BcjhhV0pFSjJ1Ungza3RJYW5teDktOExZZmZsMWlFbVhSd1pqQ3FaQTVVMUZ1dzYzUERKZ2lIYzFUendFVjN3ak8yZDBrbUZIWUJaZTAxd0hnajVKQThTM0R6Z3FydE9pN1d3Q0VqZldZMHFITXFGT1g1d2RBYkl5LVNmOGVkYXBaeHNxaTItc0N6ejhRN2osLFwifSIsCiAgInNpZCIgOiAiMEE2NEE5QzMtQ0IzRS00NzI2LTgwMEItM0MzMzYzODZBQURCIgp9 remoteIp: type: string description: The IP of user app to TP backend. minLength: 1 maxLength: 255 example: 127.0.0.1 sessionId: type: string description: UUID which uniquely identifies a set of transactions being executed within the same authentication session. minLength: 36 maxLength: 36 example: da3fe5be-2a8e-11eb-adc1-0242ac120002 userAgent: type: string description: The user-agent sent by the app to the TP backend. minLength: 1 maxLength: 255 example: 'Mozilla: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.3 Mozilla/5.0 (Macintosh; Intel Mac OS X x.y; rv:42.0) Gecko/20100101 Firefox/43.4.' xForwardedFor: type: string description: X-Forwarded-For header sent by the app to TP backend. minLength: 1 maxLength: 255 example: 203.0.113.195,70.41.3.18,150.172.238.178 requestUrl: type: string description: The requested URL is hit by the app to the TP backend. pattern: ^(https?:\/\/(?:www\.|(?!www))[a-zA-Z0-9][a-zA-Z0-9-]+[a-zA-Z0-9]\.[^\s]{2,}|www\.[a-zA-Z0-9][a-zA-Z0-9-]+[a-zA-Z0-9]\.[^\s]{2,}|https?:\/\/(?:www\.|(?!www))[a-zA-Z0-9]+\.[^\s]{2,}|www\.[a-zA-Z0-9]+\.[^\s]{2,})$ example: http://tp-backend.com/api/path ErrorResponse: required: - Errors type: object description: The error response model used by all the API endpoints. properties: Errors: required: - Error type: object description: The error response model used by all the API endpoints. properties: Error: type: array description: A list of Error objects. minItems: 1 items: type: object properties: Source: type: string description: The source of the problem. That is where the error occurred. example: mids ReasonCode: type: string description: A code defining the error, as defined in documentation. example: USER_PROFILE_ID_NOT_FOUND Description: type: string description: A description of this specific occurrence of the Reason code. example: The provided user profile ID does not exist. Recoverable: type: boolean description: Whether or not retrying this request could result in a successful response. example: false Details: type: string description: More details of this specific error. This is an optional field and is sometimes used to give a more comprehensive description of the error that has occurred, when required. example: User X was not found redirectUri: type: string description: TP will use this URI to redirect to RP. pattern: ^(https?:\/\/(?:www\.|(?!www))[a-zA-Z0-9][a-zA-Z0-9-]+[a-zA-Z0-9]\.[^\s]{2,}|www\.[a-zA-Z0-9][a-zA-Z0-9-]+[a-zA-Z0-9]\.[^\s]{2,}|https?:\/\/(?:www\.|(?!www))[a-zA-Z0-9]+\.[^\s]{2,}|www\.[a-zA-Z0-9]+\.[^\s]{2,})$ example: https://sample-rp-redirect-uri.com/?error=invalid_scope&state=AJahbadinvjbdvdnvljkdnvdfhsrbghrtiu4w&ARID=1234&error_description=claim_not_satisfied SdkVersion: type: string description: Mastercard SDK version integrated with TP App, it is a constant extracted from MIDS SDK Configurations (generated while bundling SDK artifacts). If the TP app supports split PDS, this attribute MUST be specified. pattern: ^[0-9]{1,5}\.[0-9]{1,5}\.[0-9]{1,5}$ minLength: 5 maxLength: 255 example: 2.3.0 UserConsent: enum: - ACCEPT - DECLINE - REVOKE - EXPIRE type: string description: Confirmation provided by the TP that the user has consented that the ID-Network can have access to their identity for the purposes of the API call. Should be ACCEPT, a forbidden exception will be thrown if it is any other value. pattern: ^(ACCEPT|DECLINE|REVOKE|EXPIRE)$ minLength: 6 maxLength: 7 example: ACCEPT VerifyAuthenticationDecisions: required: - countryCode - sdkVersion - pds - userProfileId - userConsent - privacyPolicyVersion type: object properties: countryCode: $ref: '#/components/schemas/CountryCode' sdkVersion: $ref: '#/components/schemas/SdkVersion' pds: $ref: '#/components/schemas/PDS' userProfileId: type: string description: UUID identifying the user, which the TP App generates using the MIDS Core SDK. pattern: ^[0-9a-fA-F]{8}\-[0-9a-fA-F]{4}\-[0-9a-fA-F]{4}\-[0-9a-fA-F]{4}\-[0-9a-fA-F]{12}$ example: df52649e-4096-456a-bca0-751ee470009f sdkAuthenticationDecision: type: boolean description: Flag indicating the result of Liveness detection conducted by the SDK. This can be retrieved from the MIDS Verification SDK. example: false userConsent: $ref: '#/components/schemas/UserConsent' scopedFields: type: array description: 'Array of enums representing the identity attributes which the TP is requesting access to. The acceptable values are any/all of: ''all'', ''legalName'', ''email'', ''phone'', ''dateOfBirth'', ''driverLicense'', ''passport'', ''address'' ' minItems: 1 items: enum: - all - legalName - email - phone - dateOfBirth - selfie - address - ageOver - ageUnder - city - postalCode - subDivision - govtId - govtIdDetails - govtIdImage - passportIdentity - passportDetails - passportImage - driverLicenseIdentity - driverLicenseCardNumber - driverLicenseDetails - driverLicenseImage - driverLicenseIssuingState - visaMatched - cpf - rgNumber - cnh - mothersName - fathersName type: string example: all privacyPolicyVersion: type: string description: The version of the privacy policy which the API call is being conducted under, this can be retrieved from the MIDS Core SDK. minLength: 1 maxLength: 20 example: 1.0.0 deviceInfo: $ref: '#/components/schemas/DeviceInfo' fraudDetection: $ref: '#/components/schemas/FraudDetection' arid: $ref: '#/components/schemas/ARID' AuthenticationDecisions: required: - transactionId - status - attributes - rotatedPds type: object properties: transactionId: type: string description: A random 128-bit UUID represents the MIDS transaction. minLength: 36 maxLength: 36 example: 1ec14310-e85c-11ea-adc1-0242ac120002 status: type: string description: Status of the authentication. pattern: ^(SUCCESS|FAILURE)$ minLength: 1 maxLength: 50 example: SUCCESS attributes: type: object description: Keys will be in RetrieveIdentities.scopedFields and data structure will be the data object named after the key. example: legalName: aa6dee5a-6e4d-4932-8189-2ecb7ad6f676: value: SMITH, JOHN lastVerifiedDate: '2022-04-04T02:49:27.915Z' additionalProperties: {} minLength: 1 rotatedPds: type: string description: A rotated PDS is created and returned when the encryption key expires and a new key is generated. pattern: ^(?:[A-Za-z0-9+\/]{4})*(?:[A-Za-z0-9+\/]{2}==|[A-Za-z0-9+\/]{3}=)?$ minLength: 1 example: ZGZnZGVmZ2RnZGVnZXJnZXJncmRnZXJ5aGdld3J0eWJld3J5dHdleXd5d3l3cmFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFhYWFh ARID: type: string description: A unique identifier for any activity being executed arising out of a Claim Share request. This value is passed as a parameter in the URL redirecting a User to the TP Flow during a Claim Share. format: uuid pattern: ^[0-9a-fA-F]{8}\-[0-9a-fA-F]{4}\-[0-9a-fA-F]{4}\-[0-9a-fA-F]{4}\-[0-9a-fA-F]{12}$ minLength: 36 maxLength: 36 example: a15fa6de-b199-11eb-8529-0242ac130003 DeviceInfo: description: Object containing the details of the device from which the enrollment is being conducted. required: - deviceAppId - make - model type: object properties: deviceAppId: type: string description: The device application ID is retrieved from the mobile SDK. minLength: 1 maxLength: 255 example: 599F9C00-92DC-4B5C-9464-7971F01F8370 make: type: string description: The make of the mobile device. minLength: 1 maxLength: 255 example: Samsung model: type: string description: The model of the mobile device. minLength: 1 maxLength: 255 example: S8 CountryCode: type: string description: The country code of the country where the transaction originates from. pattern: ^[a-zA-Z]{2}$ example: US ApiError: required: - Errors type: object properties: Errors: $ref: '#/components/schemas/Errors' Error: type: object properties: Source: type: string description: Source of where the error occured. example: mids ReasonCode: type: string description: Code of the error. example: USER_PROFILE_ID_NOT_FOUND Description: type: string description: The cause of the error example: The provided userProfileId does not exist Recoverable: type: boolean description: Indiciates if the error can be recovered from. example: false Details: type: string description: Contains information about the error. example: IOException Occured DocumentVerificationExtractedDataDocumentData: description: Document Data. required: - dateOfBirth - documentNumber - documentStatus - documentType - expiryDate - firstName - gender - issuingCountry - issuingDate - lastName type: object properties: documentNumber: description: Document Number. example: N1234567 type: string minLength: 1 maxLength: 255 documentStatus: description: Document Status. SUCCESS OR PENDING. example: SUCCESS type: string minLength: 1 maxLength: 7 documentType: description: Document Type. PASSPORT OR DRIVER_LICENSE OR ID_CARD. example: PASSPORT type: string minLength: 1 maxLength: 50 pattern: ^(DRIVING_LICENSE|PASSPORT|ID_CARD)$ dateOfBirth: description: YYYY-MM-DD format. example: '2020-09-09' type: string minLength: 10 maxLength: 10 firstName: description: Users First Name. example: John type: string minLength: 1 maxLength: 255 lastName: description: Users Last Name. example: Smith type: string minLength: 1 maxLength: 255 expiryDate: description: Document expiration date in YYYY-MM-DD format. example: '2020-10-10' type: string format: date minLength: 10 maxLength: 10 gender: description: M/F. example: M type: string minLength: 1 maxLength: 1 issuingCountry: description: Document issuing country. example: AUS type: string minLength: 3 maxLength: 3 issuingDate: description: Document issuing date. example: '2020-09-09' type: string format: date minLength: 10 maxLength: 10 issuingPlace: description: Document issuing place. example: New York type: string minLength: 1 maxLength: 50 issuingAuthority: description: Document issuing authority. example: United States type: string minLength: 1 maxLength: 50 placeOfBirth: description: Users place of birth. example: Boston type: string minLength: 1 maxLength: 255 addressLine1: description: Users Address Line 1. example: 123 Main St. type: string minLength: 1 maxLength: 255 addressLine2: description: Users Address Line 2. example: New York type: string minLength: 1 maxLength: 255 addressZipCode: description: Users zip code. example: '10021' type: string minLength: 1 maxLength: 50 addressCity: description: Users City. example: New York type: string minLength: 1 maxLength: 100 addressCountry: description: Users Country. example: USA type: string minLength: 2 maxLength: 3 addressSubdivision: description: Users Subdivision. example: MO type: string minLength: 2 maxLength: 100 issuingState: description: Users State. example: MO type: string minLength: 2 maxLength: 100 formattedAddress: description: Users formatted Address. example: 220 BLVD O FALLON MO type: string minLength: 1 maxLength: 200 selfie: description: Users Selfie Binary data, Base64 encoded. example: /mJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanq......................... type: string minLength: 1 documentImageFront: description: Users document front binary data, Base64 encoded. example: /mJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanq......................... type: string minLength: 1 documentImageBack: description: Users document back binary data, Base64 encoded. example: /mJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanq......................... type: string minLength: 1 facemap: description: Users document facemap binary data, Base64 encoded. example: /mJygpKjU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanq......................... type: string minLength: 1 rgNumber: type: string minLength: 1 maxLength: 255 description: RG Number. example: 12345 cpf: type: string minLength: 1 maxLength: 255 description: CPF Number. example: 12345 fathersName: type: string minLength: 1 maxLength: 255 description: Father's Name. example: John Smith mothersName: type: string minLength: 1 maxLength: 255 description: Mother's Name. example: Paula Smith DocumentVerificationExtractedData: required: - status - transactionId type: object properties: documentData: $ref: '#/components/schemas/DocumentVerificationExtractedDataDocumentData' status: description: The status of the Status API, possible values are SUCCESS / PENDING. example: SUCCESS type: string minLength: 1 maxLength: 7 transactionId: description: The transaction ID provided in the API response must be logged by the Relying Party. The Relying Party is required to provide the transaction ID when contacting the Mastercard customer support team. example: 1ec14310-e85c-11ea-adc1-0242ac120002 type: string minLength: 36 maxLength: 36 Errors: description: List of Errors. example: $ref: '#/components/examples/NotFoundExample_2' required: - Error type: object properties: Error: $ref: '#/components/schemas/ErrorList' ErrorList: description: Error Details. type: array minItems: 1 items: $ref: '#/components/schemas/Error' requestBodies: AuthenticationDecisionRequest: content: application/json: schema: $ref: '#/components/schemas/VerifyAuthenticationDecisions' required: true parameters: XEncryptedPayload: in: header name: X-Encrypted-Payload type: boolean description: 'An indicator that the request is encrypted or indicates that the client is able to receive an encrypted response. If not set, the payload will be treated as plaintext. ' example: true schema: null ScanIdPathParameter: name: scan_id in: path description: Scan ID. example: 1234 required: true schema: type: string pattern: ^[0-9a-fA-F]{8}\-[0-9a-fA-F]{4}\-[0-9a-fA-F]{4}\-[0-9a-fA-F]{4}\-[0-9a-fA-F]{12}$ RetrieveFacemapParameter: name: retrieve_facemap in: query description: Flag indicating if the facemap needs to be retrieved. example: 'true' required: true schema: type: string pattern: ^(true|false)$ RetrieveDocumentImagesParameter: name: retrieve_document_images in: query description: Flag indicating if the document images needs to be retrieved. example: 'true' required: true schema: type: string pattern: ^(true|false)$ CountryParameter: name: user_selected_country in: query description: The ISO 3166-1 alpha3 code which corresponds to the country from where the request to ID is originating from. example: USA nullable: true schema: type: string pattern: ^[A-Z]{3} DocumentTypeParameter: name: document_type in: query description: The type of document scanned (DRIVING_LICENSE, PASSPORT, ID_CARD). example: DRIVING_LICENSE nullable: true schema: type: string pattern: ^(DRIVING_LICENSE|PASSPORT|ID_CARD)$ ScanIdParameter: name: scan_id in: path description: UUID returned to the application/webpage on completion of the users interactions with the ID-V SDK. example: 5226539e-78e7-45ac-a924-072d1301c24c required: true schema: maxLength: 36 minLength: 36 type: string pattern: ^[0-9a-fA-F]{8}\-[0-9a-fA-F]{4}\-[0-9a-fA-F]{4}\-[0-9a-fA-F]{4}\-[0-9a-fA-F]{12}$ RetrieveSelfieParameter: name: retrieve_selfie in: query description: Flag indicating if the selfie needs to be retrieved. example: 'true' required: true schema: type: string pattern: ^(true|false)$ UserConsentParameter: name: user_consent in: query description: The value which best reflects the input of the User with regard to Consent to use their data (ACCEPT, DECLINE, REVOKE, EXPIRE). example: ACCEPT required: true schema: type: string pattern: ^(ACCEPT|DECLINE|REVOKE|EXPIRE)$ EncryptedPayloadParameter: name: X-Encrypted-Payload in: header description: Whether the request payload is encrypted with the Encyption Key generated from the Developer Zone Portal. example: true required: false schema: type: boolean headers: X-Transaction-ID: schema: type: string example: 2d077b9c-3c06-44ac-b00e-d78fe8cce606 description: A random 128-bit UUID representing the transaction.