openapi: 3.2.0
info:
description: Merchant Presented QR is a Service that includes payment or transactions process with tokens.
version: v1
title: Merchant Presented QR Onboarding API
servers:
- description: Sandbox
url: https://sandbox-api.novopayment.com/api/v1/mpqr
security:
- oAuth2ClientCredentials: []
tags:
- name: Onboarding
paths:
/onboarding:
post:
summary: Create Merchant
description: Acquirers use this endpoint to register a Merchant in the MPQR ecosystem
operationId: CreateMerchant
requestBody:
$ref: '#/components/requestBodies/RQCreateMerchant'
responses:
'200':
$ref: '#/components/responses/RSCreateMerchant'
'400':
$ref: '#/components/responses/RSCreateMerchant400'
'401':
$ref: '#/components/responses/RS401'
'500':
$ref: '#/components/responses/RS500'
tags:
- Onboarding
components:
schemas:
RQCreateMerchant:
type: object
required:
- companyPrimaryLegalName
- primaryWebsiteURL
- companyCity
- companyCountryCode
- primaryContactEmail
- acquirerIdentifiers
properties:
serviceContext:
type: string
description: Service context
example: TOKENIZATION
maxLength: 13
enum:
- TOKENIZATION
dunsNumber:
type: number
description: A D&B DUNS number is a nine-digit number that is recognized as the universal standard to track businesses worldwide. It is designed to enhance the credibility of your business and enable potential customers, lenders, and suppliers to learn about your company.
example: 75102765
maxLength: 9
companyPrimaryTradeName:
type: string
description: Trade name of token requestor, such as a doing-business-as(DBA) name. If not specified, the legal name(companyPrimaryLegalName) is used by default.
**Allowed characters**:
Alphanumeric, excepting semi-colon, percent sign, and parentheses.
maxLength: 75
companyPrimaryLegalName:
type: string
description: Legal name of token requestor. Some processors may not support a 75-character legal name. You cannot exceed the limit imposed by your processor.
**Allowed characters**:
Alphanumeric, excepting semi-colon, percent sign, and parentheses
example: Pepito Pizza
maxLength: 75
status:
type: string
primaryWebsiteURL:
type: string
description: The URL for your token requestor’s site for handling VTS transactions.
**Allowed characters**:
Alphanumeric, valid URL
example: www.pepitospizza.com
maxLength: 100
companyAddress1:
type: string
description: 'First line of the token Requestor’s primary address.
**Allowed characters**:
Alphabetic, numeric, or the following characters: spaces, ‘ (single quote), # (pound-sign or hash), , (comma), _ (underscore), :(colon), / (forward slash), and – (hyphen)
'
maxLength: 140
companyAddress2:
type: string
description: 'First line of the token requestor’s primary address.
**Allowed characters**: Alphabetic, numeric, or the following characters: spaces, ‘ (single quote), # (pound-sign or hash), , (comma), _ (underscore), :(colon), / (forward slash), and – (hyphen)
'
maxLength: 140
companyCity:
type: string
description: 'City in the token requestor’s primary address.
**Allowed characters**:
Alphabetic, numeric, or the following characters: spaces, ‘ (single quote), . (period), and – (hyphen)
'
example: Mexico City
maxLength: 100
companyStateProvinceCode:
type: string
description: State or province code associated with the physical address in the specified country. The companyStateProvinceCode for US must be a standard 2-characters code.
maxLength: 2
companyPostalCode:
type: string
description: Postal code associated with the primary address of token requestor, such as a ZIP code.
maxLength: 7
companyCountryCode:
type: string
description: ISO-3166-1 alpha-2 standard country associated with the token requestor’s primary address.
example: MX
maxLength: 2
companyPhone:
type: string
description: Token requestor’s primary phone number.
maxLength: 16
primaryContactFirstName:
type: string
description: First name of token requestor’s primary contact person.
maxLength: 256
primaryContactLastName:
type: string
description: 'Surname of token requestor’s primary contact person.
**Allowed characters**:
Alphabetic or the following characters: spaces, ‘ (single quote), ` (back tick), ~ (tilde), “ (double quote), . (period), and – (hyphen)
'
maxLength: 256
primaryContactEmail:
type: string
description: Email address of token requestor’s primary contact.
example: ventas@pepitospizza.com
maxLength: 256
relationships:
type: object
description: 'Relationship to the token requestor being onboarded, which is by externalClientId. If not specified, Visa creates the externalClientId for you, which is available in the response.
**Allowed characters**:
An array of Relationships structures.
'
properties:
externalClientId:
type: string
description: 'The relationship ID for the entity being onboarded. This is the relationship ID to use when calling TSP APIs.
'
maxLength: 100
acquirerIdentifiers:
type: object
description: Acquirer and merchant identifiers
required:
- acquirerId
- acquirerMerchantId
properties:
acquirerId:
type: string
description: 'Acquirer Id
'
example: 66978068
maxLength: 15
acquirerMerchantId:
type: string
description: 'Unique identifier relation Acquirer and Merchant Id.
This value is mandatory in future request.
'
example: 9655936598
maxLength: 25
tokenizationConfiguration:
type: object
required:
- tokenizationProfiles
- tokenRequestorId
properties:
channelSecurityContext:
type: string
description: 'Channel security context; default is shared secret.
'
maxLength: 100
tokenizationProfiles:
type: object
description: 'List of profiles
'
required:
- profileName
- applicationId
properties:
profileName:
type: string
description: 'Profile name in tokenization services
'
maxLength: 50
applicationId:
type: string
description: 'Unique Identifier same as the wallet provider
'
maxLength: 36
tokenRequestorId:
type: string
description: 'Identification to use for payments
'
maxLength: 20
RS500:
type: object
properties:
code:
type: string
example: 500.22.999
description: Operation response code
minLength: 10
maxLength: 10
message:
type: string
example: Internal Server Error
description: Response code description
maxLength: 140
datetime:
type: string
example: '2020-01-03T16:05:56.517Z'
format: date-time
RS401:
type: object
properties:
code:
type: string
example: 401.22.990
description: Operation response code
minLength: 10
maxLength: 10
message:
type: string
example: Invalid Access Token
description: Response code description
maxLength: 140
datetime:
type: string
example: '2020-01-03T16:05:56.517Z'
format: date-time
RSCreateMerchant:
type: object
properties:
code:
type: string
example: 200.22.000
description: Operation response code
maxLength: 10
message:
type: string
example: Process Ok
description: Response code description
maxLength: 140
datetime:
type: string
example: '2020-01-03T16:05:56.517Z'
description: Operation Time Stamp in ISO 8601 format
format: date-time
data:
type: object
properties:
id:
type: string
description: 'VISA''s identification response Id
'
acquirerIdentifiers:
type: object
required:
- acquirerId
- acquirerMerchantId
properties:
acquirerId:
type: string
description: 'Acquirer ID
'
acquirerMerchantId:
type: string
description: 'Unique identifier relation Acquirer and Merchant Id
'
tokenizationConfiguration:
type: object
required:
- tokenizationProfiles
- tokenRequestorId
properties:
channelSecurityContext:
type: string
description: 'Channel security context; default is shared secret.
'
maxLength: 100
tokenizationProfiles:
type: object
description: 'List of profiles
'
required:
- profileName
- applicationId
properties:
profileName:
type: string
description: 'Profile name in tokenization services
'
maxLength: 50
applicationId:
type: string
description: 'Unique Identifier same as the wallet provider
'
maxLength: 36
tokenRequestorId:
type: string
description: 'Identification to use for payments
'
maxLength: 20
qrData:
type: string
description: 'Raw entire QR code data, from scanning QR. Base64 encoded
'
RSCreateMerchant400:
type: object
properties:
code:
type: string
example: 400.22.003
description: Operation response code
minLength: 10
maxLength: 10
message:
type: string
example: Params required
description: Response code description
maxLength: 140
datetime:
type: string
example: '2020-01-03T16:05:56.517Z'
format: date-time
examples:
InvalidTenantId:
value:
code: 400.22.004
message: Invalid Tenant ID
datetime: '2020-01-03T16:05:56.517Z'
InvalidAccessToken:
value:
code: 401.22.990
message: Invalid Access Token
datetime: '2020-01-03T16:05:56.517Z'
InvalidSignature:
value:
code: 401.22.992
message: Invalid signature
datetime: '2020-01-03T16:05:56.517Z'
ParamsRequired:
value:
code: 400.22.003
message: Params required
datetime: '2020-01-03T16:05:56.517Z'
InvalidParameters:
value:
code: 400.22.396
message: Invalid Parameters
datetime: '2020-01-03T16:05:56.517Z'
ErrorGeneralServices:
value:
code: 400.22.350
message: Error General Services
datetime: '2020-01-03T16:05:56.517Z'
InvalidData:
value:
code: 400.22.089
message: Invalid Data
datetime: '2020-01-03T16:05:56.517Z'
NoResultsFound:
value:
code: 200.22.364
message: No results found
datetime: '2020-01-03T16:05:56.517Z'
data:
status: 401
code: 9159
severity: ERROR
message: TokenValidationFailed
info: ''
CreateMerchantOk:
value:
code: 200.22.000
message: Process Ok
datetime: '2020-01-03T16:05:56.517Z'
data:
id: 8e9ed12e-e4ba-4ad2-ac9d-2bcb1c8fc18a
acquirerIdentifiers:
acquirerId: 66978068
acquirerMerchantId: 9655936598
tokenizationConfiguration:
channelSecurityContext: SHARED_SECRET
tokenizationProfiles:
profileName: Test1
applicationId: Test1
tokenRequestorId: 40000000057
qrData: iVB...YII=
AccessTokenExpired:
value:
code: 401.22.993
message: Access token expired
datetime: '2020-01-03T16:05:56.517Z'
AccessTokenNotApproved:
value:
code: 401.22.991
message: Access Token not approved
datetime: '2020-01-03T16:05:56.517Z'
responses:
RSCreateMerchant:
description: Process Ok
content:
application/json:
schema:
$ref: '#/components/schemas/RSCreateMerchant'
examples:
Process Ok:
$ref: '#/components/examples/CreateMerchantOk'
No Results Found:
$ref: '#/components/examples/NoResultsFound'
RSCreateMerchant400:
description: Bad Request
content:
application/json:
schema:
$ref: '#/components/schemas/RSCreateMerchant400'
examples:
Params Required:
$ref: '#/components/examples/ParamsRequired'
Invalid Tenant Id:
$ref: '#/components/examples/InvalidTenantId'
Invalid Data:
$ref: '#/components/examples/InvalidData'
Invalid Parameters:
$ref: '#/components/examples/InvalidParameters'
Error General Services:
$ref: '#/components/examples/ErrorGeneralServices'
RS401:
description: Unauthorized
content:
application/json:
schema:
$ref: '#/components/schemas/RS401'
examples:
Invalid Access Token:
$ref: '#/components/examples/InvalidAccessToken'
Access Token Not Approved:
$ref: '#/components/examples/AccessTokenNotApproved'
Invalid Signature:
$ref: '#/components/examples/InvalidSignature'
Access Token Expired:
$ref: '#/components/examples/AccessTokenExpired'
RS500:
description: Not Found
content:
application/json:
schema:
$ref: '#/components/schemas/RS500'
requestBodies:
RQCreateMerchant:
content:
application/json:
schema:
$ref: '#/components/schemas/RQCreateMerchant'
required: true
securitySchemes:
oAuth2ClientCredentials:
type: oauth2
description: 'See [Oauth2 API](https://developer.novopayment.com/api/authentication-method-and-encryption/oauth2-api)
'
flows:
clientCredentials:
tokenUrl: https://sandbox-api.novopayment.com/oauth2/token
scopes: {}