openapi: 3.2.0
info:
title: Novopayment Tokenization Process API
version: '1.0'
description: 'Operations tagged Tokenization Process across 2 of this provider''s published API definitions: novopayment-issuer-tokenization-openapi.yml, novopayment-mastercard-issuer-tokenization-openapi.yml. Each path carries the servers of the definition it was published in.'
servers:
- description: UAT
url: https://cert-api.novopayment.com
- description: Certification
url: https://[URLIssuer]/v2
tags:
- name: Tokenization Process
paths:
/v1/checkEligibility:
post:
servers:
- description: 'External
'
url: https://[URLIssuer]
tags:
- Tokenization Process
summary: Check Eligibility
description: 'This endpoint is consumed in the card enrollment flow for VTS, and it
is only valid when the metadata card information is only known by one
entity or an external issuer.
NovoPayment will consume this endpoint when it is required to very if a
card is eligible for the card enrollment flow.'
parameters:
- $ref: '#/components/parameters/ContentType'
requestBody:
$ref: '#/components/requestBodies/RQCheckEligibility'
operationId: CheckEligibility
responses:
'200':
$ref: '#/components/responses/RSCheckEligibility200'
'400':
$ref: '#/components/responses/RS400'
'401':
$ref: '#/components/responses/RS401'
'500':
$ref: '#/components/responses/RS500'
servers:
- description: UAT
url: https://cert-api.novopayment.com
/v1/approveProvision:
post:
servers:
- description: External
url: https://[URLIssuer]
tags:
- Tokenization Process
summary: Approve Provision
description: 'This endpoint is consumed in the card enrollment flow for VTS, and it is
only valid when the metadata card information is only known by one entity
or an external issuer.
NovoPayment will consume this endpoint when it is required to very if a
card is eligible for the card enrollment flow with external Issuers.'
requestBody:
$ref: '#/components/requestBodies/RQApproveProvision'
operationId: ApproveProvision
responses:
'200':
$ref: '#/components/responses/RSApproveProvision200'
'400':
$ref: '#/components/responses/RSErrorCode400'
'401':
$ref: '#/components/responses/RS401'
'500':
$ref: '#/components/responses/RS500'
servers:
- description: UAT
url: https://cert-api.novopayment.com
/v1/notification:
post:
servers:
- description: External
url: https://[URLIssuer]
tags:
- Tokenization Process
summary: Notification
description: 'NovoPayment to Issuer (external and internal).
The I-TSP notification to the issuer is done through a REST request to
the URL previously send by the issuer.
Through this endpoint, the Issuer is going to receive a variety of
different notifications regarding changes to the tokens, PAN, or Card
Metadata lifecycle.
Every notification could have different parameters.'
requestBody:
$ref: '#/components/requestBodies/RQNotification'
operationId: Notification
responses:
'200':
$ref: '#/components/responses/RS200'
'400':
$ref: '#/components/responses/RS400'
'401':
$ref: '#/components/responses/RS401'
'500':
$ref: '#/components/responses/RS500'
servers:
- description: UAT
url: https://cert-api.novopayment.com
/v1/verification/methods:
post:
servers:
- description: External
url: https://[URLIssuer]
tags:
- Tokenization Process
summary: Get Cardholder Verification Methods
description: 'NovoPayment to Issuer (external and internal).
This endpoint allows the issuer to notify the I-TSP the different
cardholder authentication methods such as email, phone number, among
others for the delivery of the One Time Password (OTP). The request
from the I-TSP to the Issuer is sent through a REST request to a URL
previously send by the issuer.'
requestBody:
$ref: '#/components/requestBodies/RQCardholderVerificationMethods'
operationId: CardholderVerificationMethods
responses:
'200':
$ref: '#/components/responses/RSCardholderVerificationMethods200'
'400':
$ref: '#/components/responses/RS400'
'401':
$ref: '#/components/responses/RS401'
'500':
$ref: '#/components/responses/RS500'
servers:
- description: UAT
url: https://cert-api.novopayment.com
/v1/sendPasscode:
post:
servers:
- description: External
url: https://[URLIssuer]
tags:
- Tokenization Process
summary: Send Passcode
description: 'NovoPayment to Issuer (external and internal)
This endpoint allows the issuer to send an OTP or a temporally
verification code to the cardholder that have requested it through the
wallet.'
requestBody:
$ref: '#/components/requestBodies/RQSendPasscode'
operationId: SendPasscode
responses:
'200':
$ref: '#/components/responses/RS200'
'400':
$ref: '#/components/responses/RS400'
'401':
$ref: '#/components/responses/RS401'
'500':
$ref: '#/components/responses/RS500'
servers:
- description: UAT
url: https://cert-api.novopayment.com
/v1/deviceBinding:
post:
servers:
- description: External
url: https://[URLIssuer]
tags:
- Tokenization Process
summary: Device Token Binding
description: 'NovoPayment to External Issuer.
The issuer approves the binding of an e-commerce or Card-On-File token to a device.'
requestBody:
$ref: '#/components/requestBodies/RQDeviceTokenBinding'
operationId: DeviceTokenBinding
responses:
'200':
$ref: '#/components/responses/RSDeviceTokenBinding200'
'400':
$ref: '#/components/responses/RS400'
'401':
$ref: '#/components/responses/RS401'
'500':
$ref: '#/components/responses/RS500'
servers:
- description: UAT
url: https://cert-api.novopayment.com
/v1/cardinfo:
post:
servers:
- description: External
url: https://[URLIssuer]
tags:
- Tokenization Process
summary: Card Info
description: Get card and customer information for a list of card ids.
requestBody:
$ref: '#/components/requestBodies/RQCardInfo'
operationId: CardInfo
responses:
'200':
$ref: '#/components/responses/RSCardInfo200'
'400':
$ref: '#/components/responses/RSCardInfo400'
'500':
$ref: '#/components/responses/RSCardInfo500'
servers:
- description: UAT
url: https://cert-api.novopayment.com
/sendverifycode:
post:
servers:
- description: External
url: https://[URLIssuer]
tags:
- Tokenization Process
summary: Send Verify Code
description: 'Our endpoint empowers issuers to seamlessly receive and deliver a One-Time Password (OTP) to cardholders.
This temporary verification code is essential for cardholders to confirm their identity when registering
their card with merchants, ensuring a secure and smooth transaction experience.'
operationId: SendVerifyCode
requestBody:
$ref: '#/components/requestBodies/RQSendVerifyCode'
responses:
'200':
$ref: '#/components/responses/RSFromIssuer_200'
'400':
$ref: '#/components/responses/RSFromIssuer_400'
'401':
$ref: '#/components/responses/RSInvalidSignature'
'500':
$ref: '#/components/responses/RSInternalServerError'
security:
- oAuth2ClientCredentials: []
servers:
- description: Certification
url: https://[URLIssuer]/v2
/notifications/serviceactivated:
post:
servers:
- description: External
url: https://[URLIssuer]
tags:
- Tokenization Process
summary: Notifications Service Activated
description: The Issuer exposes this endpoint to receive the notifications about token’s creation.
operationId: serviceactivated
requestBody:
$ref: '#/components/requestBodies/RQNotServiceActivated'
responses:
'200':
$ref: '#/components/responses/RSFromIssuer_200'
'400':
$ref: '#/components/responses/RSFromIssuer_400'
'401':
$ref: '#/components/responses/RSInvalidSignature'
'500':
$ref: '#/components/responses/RSInternalServerError'
security:
- oAuth2ClientCredentials: []
servers:
- description: Certification
url: https://[URLIssuer]/v2
/notifications/tokenupdated:
post:
servers:
- description: External
url: https://[URLIssuer]
tags:
- Tokenization Process
summary: Notifications about Token Updated
description: 'The Issuer exposes this endpoint to receive notifications about the token’s status changes.
Available Types:
REDIGITIZATION_COMPLETE
DELETED_FROM_CONSUMER_APP
STATUS_UPDATE'
operationId: tokenupdated
requestBody:
$ref: '#/components/requestBodies/RQNotTokenUpdated'
responses:
'200':
$ref: '#/components/responses/RSFromIssuer_200'
'400':
$ref: '#/components/responses/RSFromIssuer_400'
'401':
$ref: '#/components/responses/RSInvalidSignature'
'500':
$ref: '#/components/responses/RSInternalServerError'
security:
- oAuth2ClientCredentials: []
servers:
- description: Certification
url: https://[URLIssuer]/v2
/notifications/suspiciousevents:
post:
servers:
- description: External
url: https://[URLIssuer]
tags:
- Tokenization Process
summary: Notifications about Suspicious Events
description: 'The Issuer exposes this endpoint to receive notifications
about the token when any suspicious events are detected.'
operationId: suspiciousevents
requestBody:
$ref: '#/components/requestBodies/RQNotSuspiciousEvents'
responses:
'200':
$ref: '#/components/responses/RSFromIssuer_200'
'400':
$ref: '#/components/responses/RSFromIssuer_400'
'401':
$ref: '#/components/responses/RSInvalidSignature'
'500':
$ref: '#/components/responses/RSInternalServerError'
security:
- oAuth2ClientCredentials: []
servers:
- description: Certification
url: https://[URLIssuer]/v2
components:
schemas:
ObjGroupResp:
type: object
properties:
groupType:
type: string
maxLength: 16
description: 'The Group Type Code from the request that is returned in the response.
'
groupID:
type: string
maxLength: 32
description: 'Contains the issuer-supplied group identifier for the specified group type received in request.
'
responseStatus:
type: string
description: 'Response status value.
Available values:
- S
- W
- F
'
enum:
- S
- W
- F
rejectCode:
type: string
maxLength: 2
description: 'Contains the Reject Code for the failure. Present only when the Response Status = F.
'
example: ER
rejectDesc:
type: string
maxLength: 100
description: 'Contains the Reject Reason for the failure. Present only when the Response Status = F.
'
example: ERROR DETAIL
RQCheckEligibility:
type: object
required:
- tokenRequestorID
- tokenReferenceID
- panReferenceID
- panSource
- deviceInfo
- encryptedData
properties:
tokenRequestorID:
type: integer
description: 'Unique ID assigned to the client requesting the token. This value is
assigned by Visa when creating the VTS project.
'
example: 40022358888
tokenReferenceID:
type: string
description: 'Unique ID associating a token with a card. This ID can be used in
future calls to make operations related to the token in the I-TSP.
'
example: DNITHE30194726875288888
panReferenceID:
type: string
description: 'Unique ID representing a card. This ID can be used in future calls
referred to the card in the Tokenization flow.
'
example: V-3019231458906209630635
panSource:
type: string
description: 'Origin of the information of the PAN.
Allowed values:
- KEY_ENTERED
- ON_FILE
- MOBILE_BANKING_APP
- TOKEN
- CHIP_DIP
- CONTACTLESS_TAP
'
enum:
- KEY_ENTERED
- ON_FILE
- MOBILE_BANKING_APP
- TOKEN
- CHIP_DIP
- CONTACTLESS_TAP
example: MOBILE_BANKING_APP
deviceInfo:
description: 'When the token is for an specific device, The object must have deviceID and deviceLanguageCode.
'
$ref: '#/components/schemas/ObjDeviceInformationEligibility'
encryptedData:
type: object
description: Represents the encrypted payload
properties:
cardholderInfo:
$ref: '#/components/schemas/ObjCardHolderInfo_PANExpiryDate'
ObjTokenUserInfo:
type: object
required:
- tokenUserID
properties:
tokenUserID:
type: number
description: 'Unique value that identifies the user token.
The user token is an entity that initiated the payment request.
'
maxLength: 11
example: Novo InApp
tokenUserAppType:
type: string
description: 'Token user application type. It can be a merchant, market or other.
Possible values:
- UNKNOWN
- WEB
- MOBILE_WEB
- MOBILE_APP
- MARKETPLACE
- VOICE_APP
- BIOMETRIC_APP
'
enum:
- UNKNOWN
- WEB
- MOBILE_WEB
- MOBILE_APP
- MARKETPLACE
- VOICE_APP
- BIOMETRIC_APP
example: MOBILE_WEB
RQNotification:
type: object
required:
- eventType
- messageReasonCode
- dateTimeOfEvent
properties:
eventType:
type: string
description: 'Type of event this value is important to recognize the fields that
is going to receive in the notification.
Available values:
- TOKEN_CREATED
- TOKEN_STATUS_UPDATED
- TOKEN_ACTIVATION_STIP
- PAN_UPDATED
- CARD_METADATA_UPDATED
- ACCOUNT_LEVEL_RECORD
- THREE_DS_ACTIVATION
- ACCOUNT_LEVEL_RECORD_UPDATE
- PUSH_PROVISIONING_STATUS
- PUSH_ENROLLMENT_STATUS
- CTP_ENROLLMENT_ATTEMPT
'
enum:
- TOKEN_CREATED
- TOKEN_STATUS_UPDATED
- TOKEN_ACTIVATION_STIP
- PAN_UPDATED
- CARD_METADATA_UPDATED
- ACCOUNT_LEVEL_RECORD
- THREE_DS_ACTIVATION
- ACCOUNT_LEVEL_RECORD_UPDATE
- PUSH_PROVISIONING_STATUS
- PUSH_ENROLLMENT_STATUS
- CTP_ENROLLMENT_ATTEMPT
maxLength: 25
example: TOKEN_CREATED
panReferenceID:
type: string
description: 'Unique ID representing a card. This ID can be used instead of the
PAN number for subsequent calls such as notifications or life cycle
management.
Not present when evenType is CARD_METADATA_UPDATED.
'
maxLength: 32
example: V-3019231458906209630635
tokenReferenceID:
type: string
description: 'Unique ID associating a token with a card. This ID can be used in
future calls to make operations related to the token in the I-TSP
for example events related to the management of the life cycle.
Not present when eventType is PAN_UPDATED or CARD_METADATA_UPDATED
OR ACCOUNT_LEVEL_RECORD.
'
maxLength: 32
example: DNITHE30194726875288888
tokenRequestorID:
type: integer
description: 'Unique ID assigned to the client requesting the token. This value
is assigned by Visa when creating the VTS project.
Not present when eventType is PAN_UPDATED or CARD_METADATA_UPDATED
OR ACCOUNT_LEVEL_RECORD
'
example: 40022358888
messageReasonCode:
type: string
description: 'Message reason code.
The descriptions may vary in previously agreement with the issuer.
Available values:
- TOKEN_CREATED
- TOKEN_DEACTIVATED
- TOKEN_SUSPEND
- TOKEN_RESUME
- DEVICE_PROVISIONING_RESULT
- OTP_VERIFICATION_RESULT
- CALL_CENTER_ACTIVATION
- MOBILE_BANK_APP_ACTIVATION
- LUK_REPLENISHMENT
- DEVICE_PROVISIONING
- REPERSONALIZATION_RESULT
- TOKEN_EXPIRY_DATE_UPDATED
- TOKEN_DEVICE_BINDING_RESULT
- CARDHOLDER_STEPUP_RESULT
- RUSTED_LISTING_ENROLLMENT_RESULT
- TOKEN_DEVICE_BINDING_REMOVED
- ACCOUNT_UPDATE
- EXP_DATE_UPDATE
- CARD_METADATA_UPDATED
- TOKEN_ACTIVATION_STIP
- ACCOUNT_LEVEL_RECORD_UPDATE
- THREE_DS_ACTIVATION
'
enum:
- TOKEN_CREATED
- TOKEN_DEACTIVATED
- TOKEN_SUSPEND
- TOKEN_RESUME
- DEVICE_PROVISIONING_RESULT
- OTP_VERIFICATION_RESULT
- CALL_CENTER_ACTIVATION
- MOBILE_BANK_APP_ACTIVATION
- LUK_REPLENISHMENT
- DEVICE_PROVISIONING
- REPERSONALIZATION_RESULT
- TOKEN_EXPIRY_DATE_UPDATED
- TOKEN_DEVICE_BINDING_RESULT
- CARDHOLDER_STEPUP_RESULT
- RUSTED_LISTING_ENROLLMENT_RESULT
- TOKEN_DEVICE_BINDING_REMOVED
- ACCOUNT_UPDATE
- EXP_DATE_UPDATE
- ACCOUNT_LEVEL_RECORD_UPDATE
- CARD_METADATA_UPDATED
- TOKEN_ACTIVATION_STIP
- THREE_DS_ACTIVATION
example: TOKEN_CREATED
dateTimeOfEvent:
type: string
format: date-time
description: 'Date and time of the event.
Format: yyyy-MM-ddTHH:mm:ss.SSSz The time zone is GMT.
'
encryptedData:
$ref: '#/components/schemas/ObjNotificationEncryptedData'
tokenInfo:
$ref: '#/components/schemas/ObjTokenInfo'
deviceInfo:
$ref: '#/components/schemas/ObjDeviceInformation'
tokenUserInfo:
$ref: '#/components/schemas/ObjTokenUserInfo'
merchantInfo:
$ref: '#/components/schemas/ObjMerchantInfo'
actionCode:
type: string
description: "Action code to indicate Visa for which flow it should go.\nIn case the provisioning of the token is approved, the values are:\n\n- 00 - Green path, indicates that the token is provisioned and\n automatically activated for payments.\n- 85 - Yellow path, indicates that the token is provisioned and the\n client must be authenticated to activate the token. In case the\n provisioning is not approved, the code must be within the following.\n- N7 - incorrect CVV2\n- 14 - Invalid card number\n- 54 - Invalid expiration date\n- 05 - Generic rejection\n- 96 - Internal system error\n"
enum:
- '00'
- '85'
- N7
- '14'
- '54'
- '05'
- '96'
example: '00'
lifeCycleTraceID:
type: number
description: 'Identification of the process.
Present when eventType is TOKEN_STATUS_UPDATED or TOKEN_CREATED
'
maxLength: 15
tokenRequestorTspID:
type: string
description: 'Identification of the token requestor token service provider.
Not present on evenType PAN_UPDATED or CARD_METADATA_UPDATED.
'
maxLength: 11
tokenUpdateChannel:
type: string
description: "Conditional, Token update channel. \nIt is present when the messageReasonCode is TOKEN_EXPIRY_DATE_UPDATED and the date is updated via the Visa Issuer OBO Credential Update Service.\n"
example: ISSUER_OBO_LCM
panUpdateChannel:
type: string
description: "Conditional, PAN update channel.\n It is present when the messageReasonCode is EXP_DATE_UPDATE and the date is updated via the Visa Issuer OBO Credential Update Service.\n"
example: ISSUER_OBO_LCM
accountLevelInfoResp:
$ref: '#/components/schemas/ObjAccountLevelInfoResp'
clientWalletAccountID:
type: string
description: 'Identifier of the wallet that sends the request.
Client provided consumer ID that identifies the wallet account
holder entity
'
maxLength: 32
panSource:
type: string
description: 'Origin of the information of the PAN.
Allowed values:
- KEY_ENTERED
- ON_FILE
- MOBILE_BANKING_APP
- TOKEN
- CHIP_DIP
- CONTACTLESS_TAP
'
enum:
- KEY_ENTERED
- ON_FILE
- MOBILE_BANKING_APP
- TOKEN
- CHIP_DIP
- CONTACTLESS_TAP
example: KEY_ENTERED
cvv2ResultsCode:
type: string
description: "Result code of the validation of CVV2 made by VISA. Present when eventType is TOKEN_CREATED or TOKEN_ACTIVATION_STIP in some cases this value could be null.\nAvailable Values:\n- M: The CVV2 is match.\n- N: The CVV2 enter by the user is incorrect.\n- P: The CVV2 was not validate.\n- S: Indicates that V.I.P. or the issuer was unable to perform CVV2\n verification.\n\n- U: Issuer was not available does not participate in the CVV2\n Service or that STIP has responded to an issuer-unavailable\n response.\n\n- NULL: When the provisioning process occured without CVV\n"
enum:
- M
- N
- P
- S
- U
- null
maxLength: 1
example: M
consumerEntryMode:
type: string
description: 'Method of consumer entry.
Available values:
- KEY_ENTERED
- CAMERA_CAPTURED
- UNKNOWN
Could be present when eventType is TOKEN_CREATED or
TOKEN_ACTIVATION_STIP.
'
enum:
- KEY_ENTERED
- CAMERA_CAPTURED
- UNKNOWN
locale:
type: string
description: 'The language for the app if need a country code should be separated
using a “_“.Example: en_US.
Format: String; ISO language ISO 639-1 and alpha-2 country code ISO
3166-1 alpha-2.
Could be present when eventType is TOKEN_CREATED or
TOKEN_ACTIVATION_STIP.
'
maxLength: 5
example: en_US
termsAndConditions:
$ref: '#/components/schemas/ObjTermsAndConditions'
stipReasonCode:
type: string
description: 'STIP Response code only present when eventType is
TOKEN_ACTIVATION_STIP.
Available Values for VISA:
- 9011: The line to issuer is down.
- 9012: Forced STIP because of N0 (Force STIP) original response from issuer.
- 9020: Issuer Time Out.
- 9027: ECIP RTD Decline. Sent by CVV2 or RTD upon decline.
- 9203: Decline due to Office of Foreign Assets Control (OFAC) embargo.
- 9206: Mod-10 check failure.
- 9208: Declined because issuing identifier and/or routing identifier is blocked.
- 9210: Declined because of issuer participation options.
- 9212: Declined due to fraud condition.
- 9216: Ineligible data for Token Type. Token is not a device-based one.
- 9217: Loyalty personalized data input is incorrect.
- 9061: Switch Detected Error. Sent by Visa by default.
'
enum:
- 9011
- 9012
- 9020
- 9027
- 9203
- 9206
- 9208
- 9210
- 9212
- 9216
- 9217
- 9061
maxLength: 4
example: 9011
activationVerificationResult:
type: string
description: 'Result of the verification this notification is available when de
provisioning is in yellow flow.
Will be present when messageReasonCode is OTP_VERIFICATION_RESULT or
MOBILE_BANK_APP_ACTIVATION.
Available values:
- VERIFICATION_SUCCESS
- VERIFICATION_CODE_EXPIRED
- VERIFICATION_CODE_FAILED
- VERIFICATION_CODE_MISSING
- VERIFICATION_CODE_RETRIES_EXCEEDED
'
enum:
- VERIFICATION_SUCCESS
- VERIFICATION_CODE_EXPIRED
- VERIFICATION_CODE_FAILED
- VERIFICATION_CODE_MISSING
- VERIFICATION_CODE_RETRIES_EXCEEDED
maxLength: 100
statusCode:
type: string
description: "(Conditional) Action status codes. Required for the PUSH_PROVISIONING_STATUS and PUSH_ENROLLMENT_STATUS event types;\n not used with the CTP_ENROLLMENT_ATTEMPT event type..\n\nAvailable values:\n- SUCCESS\n- FAILURE\n- NOTIFICATION_FAILURE\n- PROVISION_FAILURE\n- ENROLLMENT_FAILURE\n- ENROLLMENT_CANCELLED\n"
enum:
- SUCCESS
- FAILURE
- NOTIFICATION_FAILURE
- PROVISION_FAILURE
- ENROLLMENT_FAILURE
- ENROLLMENT_CANCELLED
maxLength: 100
cardHolderStepupResult:
type: string
description: 'Result of the verification about cardholder.
Will be present when messageReasonCode is CARDHOLDER_STEPUP_RESULT.
Available values:
- CARDHOLDER_STEPUP_OTP
- CARDHOLDER_STEPUP_CALL_CENTER
- CARDHOLDER_STEPUP_ISSUER_APP
- CARDHOLDER_STEPUP_APPROVED
- CARDHOLDER_STEPUP_THREE_DS
'
enum:
- CARDHOLDER_STEPUP_OTP
- CARDHOLDER_STEPUP_CALL_CENTER
- CARDHOLDER_STEPUP_ISSUER_APP
- CARDHOLDER_STEPUP_APPROVED
- CARDHOLDER_STEPUP_THREE_DS
maxLength: 100
deviceBindingResult:
type: string
description: 'Result of a token device binding. Will be present when
messageReasonCode is TOKEN_DEVICE_BINDING_RESULT.
Available values:
- DEVICE_BINDING_APPROVED
- DEVICE_BINDING_OTP
- DEVICE_BINDING_CALL_CENTER
- DEVICE_BINDING_ISSUER_APP
- DEVICE_BINDING_REMOVED
- DEVICE_BINDING_THREE_DS
- DEVICE_BINDING_IMPLICITLYAPPROVED
'
enum:
- DEVICE_BINDING_APPROVED
- DEVICE_BINDING_OTP
- DEVICE_BINDING_CALL_CENTER
- DEVICE_BINDING_ISSUER_APP
- DEVICE_BINDING_REMOVED
- DEVICE_BINDING_THREE_DS
- DEVICE_BINDING_IMPLICITLYAPPROVED
maxLength: 100
deviceId:
type: string
description: 'When the provisioning is in a SE wallets providers this value is the
SE ID in hex binary characters.
In an HCE wallet is the device ID determined for the wallet.
Will be present when messageReasonCode is TOKEN_DEVICE_BINDING_RESULT.
'
maxLength: 48
taskID:
type: string
description: 'Present only when messageReasonCode is CARD_METADATA_UPDATED.
This value is an GUID hyphens to identify the task.
'
maxLength: 36
errorCode:
type: string
description: 'Present only when messageReasonCode is CARD_METADATA_UPDATED.
For VISA is the Business error code starts with VSEXXXXX
'
maxLength: 8
cardToken:
type: string
description: 'Unique Card Identifier at NovoPayment’s Issuance Service.
'
maxLength: 40
example: 5DA...27
ObjTokenInfo:
type: object
description: 'Structure with token information, the content available could be different in each API service.
'
properties:
token:
type: string
maxLength: 19
description: The token associated with the PAN.
example: '...'
tokenType:
type: string
maxLength: 32
description: 'Token type.
Available values.
- ECOMMERCE
- SECURE_ELEMENT
- CARD_ON_FILE
- HCE
- QRC
'
enum:
- ECOMMERCE
- SECURE_ELEMENT
- CARD_ON_FILE
- HCE
- QRC
example: ECOMMERCE
tokenStatus:
type: string
description: 'Token status.
Available values:
- INACTIVE : The token was created but the activation process is pending.
- ACTIVE : The token was Activated successfully.
- SUSPENDED : The token was suspended.
- DEACTIVATED : The token was eliminated.
'
enum:
- INACTIVE
- ACTIVE
- SUSPENDED
- DEACTIVATED
example: ACTIVE
tokenExpirationDate:
$ref: '#/components/schemas/ObjExpirationDate'
tokenRequestorName:
type: string
maxLength: 100
description: 'Token requestor name.
'
example: NovoPayment Wallet
tokenAssuranceMethod:
type: string
maxLength: 19
description: "Method of Issuer ID&V that has taken place at time of provisioning,\ndevice binding.\n- 00 Cardholder Verification was Not Performed\n- 10 Card Issuer Account Verification\n- 11 Card Issuer Interactive Cardholder Verification - 1 Factor\n- 12 Card Issuer Interactive Cardholder Verification - 2 Factor\n- 13 Card Issuer Risk Oriented Non-Interactive Cardholder\n Authentication\n- 14 Card Issuer Asserted Authentication\n"
example: '00'
numberOfActiveTokensForPAN:
type: number
maxLength: 4
description: 'Number of device tokens that are currently active for this PAN.
'
example: 2
numberOfInactiveTokensForPAN:
type: number
maxLength: 4
description: 'Number of device tokens that are currently inactive.
(device tokens have not been activated) for this PAN
'
example: 2
numberOfSuspendedTokensForPAN:
type: number
maxLength: 4
description: 'Number of device tokens that were activated but are
suspended for payments for this PAN.
'
example: 0
tokenActivationDate:
type: string
format: date-time
description: 'System date/timestamp, in GMT, of token activation into an active
state. For an inactive state, this field is left empty and populated
only when a token transitions to an active state. If a token
is suspended, this field is populated with the new date/timestamp of
when an active state resumes.
Format: yyy-MM-ddTHH:mm:ss.SSSZ
'
example: '2022-04-25T23:19:12.000Z'
tokenDeactivationDate:
type: string
description: 'Date of token deactivation.
This field is left empty and populated only when a token transitions
to an Inactive state.
'
example: '...'
lastTokenStatusUpdatedTime:
type: string
maxLength: 19
description: 'Original Token account number.
This field is populated only when performing token for token
provisioning, this mean the panSource is equal to TOKEN.
'
example: '...'
originalToken:
type: string
maxLength: 19
description: 'Original Token account number.
This field is populated only when performing token for token
provisioning, this mean the panSource is equal to TOKEN.
'
example: '...'
originalTokenRequestorID:
type: number
maxLength: 4
description: 'Unique ID assigned to the initiator of the OriginalToken request.
This field is populated only when performing token for token
provisioning, this mean the panSource is equal to TOKEN.
'
example: '...'
originalTokenReferenceID:
type: string
maxLength: 32
description: 'Unique ID for the OriginalToken associated with the PAN.
This field is populated only when performing token for token
provisioning, this mean the panSource is equal to TOKEN.
'
example: '...'
originalTokenType:
type: string
description: 'Token type of the original token.
This field is populated only when performing token for token
provisioning, this mean the panSource is equal to TOKEN.
Format: It is one of the following values:
- SECURE_ELEMENT
- HCE
- CARD_ON_FILE
- ECOMMERCE
- QRC
'
enum:
- SECURE_ELEMENT
- HCE
- CARD_ON_FILE
- ECOMMERCE
- QRC
example: SECURE_ELEMENT
originaltokenAssuranceMethod:
type: string
description: 'Original token assurance method.
This field is populated only when performing token for token
provisioning, this mean the panSource is equal to TOKEN.
- 00 ID&V Not Performed
- 10 Card Issuer Account Verification
- 11 Card Issuer Interactive Cardholder Verification - 1 Factor
- 12 Card Issuer Interactive Cardholder Verification - 2 Factor
- 13 Card Issuer Risk Oriented Non-Interactive Cardholder Authentication
- 14 Card Issuer Asserted Authentication
'
enum:
- '00'
- '10'
- '11'
- '12'
- '13'
- '14'
example: '00'
autoFillIndicator:
type: boolean
description: 'Indicates whether the token is for an autofill use case.
This value is populated when eventType is equal to TOKEN_CREATED.
'
example: false
RSCardInfo200:
required:
- code
- message
- datetime
- data
properties:
code:
type: string
description: Operation response code
example: 200.00.000
maxLength: 10
message:
type: string
description: Response code description
example: Process Ok
maxLength: 140
datetime:
type: string
description: 'Operation Time Stamp in ISO 8601 format
date-time - the date-time notation as defined by
[RFC 3339, section 5.6](https://tools.ietf.org/html/rfc3339#section-5.6),
for example, 2017-07-21T17:32:28Z
'
example: '2022-04-25T23:19:12.000Z'
minLength: 24
maxLength: 24
data:
$ref: '#/components/schemas/ObjCardInfoRSData'
ObjCardHolderInfo_PANExpiryDate:
type: object
description: 'Object that contains the related information to the customer cards.
'
required:
- primaryAccountNumber
- expirationDate
properties:
primaryAccountNumber:
type: string
description: 'Card number.
'
maxLength: 19
example: XX25XX25XX25XX25
expirationDate:
type: object
properties:
month:
type: string
example: 08
year:
type: string
example: '2028'
ObjCheckEligibilityCardMetadataInfo:
type: object
required:
- cardIssuer
description: Card metadata information structure
properties:
cardIssuer:
type: string
maxLength: 128
description: 'Card issuer name.
'
foregroundColor:
type: string
maxLength: 32
description: 'Foreground color of the digital wallet home.
Format: rgb.
Sample: 255,122,235
This value is optional because the issuer can configure it through
the Visa Card Art Management (VCMM).
'
example: 255,122,235
backgroundColor:
type: string
maxLength: 32
description: 'Background color of the digital wallet home, for displaying the card.
Format: rgb.
Sample: 255,122,235
This value is optional because the issuer can configure it through
the Visa Card Art Management (VCMM).
'
example: 255,122,235
labelColor:
type: string
maxLength: 32
description: 'Label color of the digital wallet home, for displaying the card.
Format: rgb.
This value is optional because the issuer can configure it through
the Visa Card Art Management (VCMM).
'
example: 255,122,235
shortDescription:
type: string
maxLength: 32
description: 'Short card description. It can be used with block screen notification
'
example: The Bank Card
longDescription:
type: string
maxLength: 64
description: 'Long card description. It can be used in the digital wallet.
'
example: The Bank Card
profileID:
type: string
maxLength: 32
description: 'Profile ID associated to a card.
It is only available to issuers that consume the API Check eligibility.
During the the preload of the card metadata into the Visa system,
either through the Visa Card Art Management (VCMM) user interface or
the batch files, issuers have the option to assign their own unique
profile ID (GUID) to a send of card metadata.
Format: Lowercase, hexadecimal. Hyphens (-) are not allowed.
'
example: The Bank Card
cardArtData:
type: array
$ref: '#/components/schemas/ObjCheckEligibilityCardArtRefID'
termsAndConditionsID:
type: string
maxLength: 64
description: 'Name of the file based on GUID for terms and conditions text.
File used by the issuer when uploading the image in VCMM.
This is a required DWP field. However, it is Optional in this API
because the issuer can configure it through VCM.
'
example: The Bank Card
contactInfo:
$ref: '#/components/schemas/ObjCheckEligibilityContactInfo'
applicationInfo:
$ref: '#/components/schemas/ObjCheckEligibilityApplicationInfo'
privacyPolicyURL:
type: string
maxLength: 128
description: "URL pointing to an issuing bank’s privacy policy. This \nvalue is nott applicable for Check Eligibility; only available for \nUpdate Card Metadata.\n"
example: https://issuer.com/privacyPolicyURL
termsAndConditionsURL:
type: string
maxLength: 128
description: "URL pointing to the issuing bank’s terms and conditions \nfor a card. This value is not applicable for Check Eligibility; only \navailable for Update Card Metadata.\n"
example: https://issuer.com/termsAndConditionsURL
ObjCardInfoRSData:
type: object
required:
- cardInfoList
properties:
cardInfoList:
$ref: '#/components/schemas/ObjCardInfoList'
ObjSendPasscodeCardHolderInfo:
type: object
description: 'PrimaryAccountNumber will be provided in cardholderInfo.
And Otp Destiny when the Issuer have this param active on service
configuration.
'
required:
- primaryAccountNumber
properties:
primaryAccountNumber:
type: string
description: 'Card number to be tokenized.
See the conditionals use cases for this field.
'
maxLength: 19
example: '0000000000000000'
otpDestiny:
type: string
description: 'Phone number or email address to send the OTP value, only If the
Issuer’s configuration have this param available and the Issuer’s
Wallet sent the values in the enroll device and Enroll PAN process
with our SDK.
'
example: '57300800800'
maxLength: 50
ObjCheckEligibilityCardArtRefID:
type: object
properties:
cardArtRefID:
type: string
description: "\tGUID-based file names for the Cart Art Image file used by the issuer\n when uploading the image to VCMM. Required by the DWP field.\n It is optional in this API because the issuer can pre-configure this\n value through VCMM.\n"
maxLength: 32
ObjDeviceInformation:
type: object
description: 'Object that contain the Device Information, the values that coould be present depends on the Token Type and the Device Type.
'
properties:
deviceID:
type: string
description: 'This field represents the device ID.
- For SECURE_ELEMENT this value will be the SE ID in hex binary characters transformed to a 48-character string.
- For ECOMMERCE or CARD_ON_FILE this value may not be available.
- For Host Card Emulation HCE his value is determined by the wallet.
Format: Alphanumeric characters
'
maxLength: 48
example: CTF0000000001
deviceIndex:
type: number
description: 'Visa’s index number where the device ID is stored.
Number between 1 and 99.
This is required for TOKEN DEVICE BINDING
'
maxLength: 2
example: 99
deviceLanguageCode:
type: string
description: ISO 639 Version 3
maxLength: 3
example: eng
deviceType:
type: string
description: 'This field represents the device type.
Allowed values:
- MOBILE_PHONE
- TABLET
- MOBILEPHONE_OR_TABLET
- PC
- WATCH
- TV
- HOME_DEVICE
- WEARABLE_DEVICE
- AUTOMOBILE_DEVICE
'
enum:
- MOBILE_PHONE
- TABLET
- MOBILEPHONE_OR_TABLET
- PC
- WATCH
- TV
- HOME_DEVICE
- WEARABLE_DEVICE
- AUTOMOBILE_DEVICE
maxLength: 32
example: PHONE
deviceName:
type: string
description: 'Device index.
Format: Number between 1 and 99, included.
'
maxLength: 128
example: Novo_Phone
deviceNumber:
type: string
description: Device number
maxLength: 13
example: 6506198963
osType:
type: string
description: 'Operating System from which the request is sent.
Allowed values
- ANDROID
- IOS
- WINDOWS
- BLACKBERRY
- TIZEN
- OTHER
'
maxLength: 32
enum:
- ANDROID
- IOS
- WINDOWS
- BLACKBERRY
- TIZEN
- OTHER
example: ANDROID
osVersion:
type: string
description: 'Operating system version
Sample: 13.1.8
'
maxLength: 256
example: 4.4.4
osBuildID:
type: string
description: OS Compilation version
maxLength: 32
example: 13.1
deviceIDType:
type: string
description: 'Attribute indicating the source of the Device ID value.
Example: The source for Device ID (deviceID)could be SecureElement,
TEE, or Derived,
'
maxLength: 32
example: TEE
deviceManufacturer:
type: string
description: 'Manufacturer of the decive.
Sample: Samsung
'
maxLength: 32
example: Samsung
deviceBrand:
type: string
description: 'Device Brand.
Sample: Galaxy
'
maxLength: 32
example: Galaxy
deviceModel:
type: string
description: Device model
maxLength: 32
example: M05
deviceLocation:
type: string
description: 'Obfuscated geographic location of the device.
Example: +37/-121
'
maxLength: 26
deviceIPAddressV4:
type: string
description: 'The IP address of the device at the time of the provisioning request,
with the value represented in 255.255.255.255 format.
Restriction: Cannot contain any leading zeros
'
maxLength: 15
example: 127.0.0.1
locationSource:
type: string
description: 'Source used to identify consumer location.
Available values:
- WIFI
- CELLULAR
- GPS
- OTHER
'
enum:
- WIFI
- CELLULAR
- GPS
- OTHER
maxLength: 32
example: WIFI
tokenProtectionMethod:
type: string
description: 'Method of token protection.
Available values:
- SOFTWARE
- TRUSTED_EXECUTION_ENVIRONMENT
- SECURE_ELEMENT
- CLOUD
'
enum:
- SOFTWARE
- TRUSTED_EXECUTION_ENVIRONMENT
- SECURE_ELEMENT
- CLOUD
maxLength: 40
example: CLOUD
originalDeviceID:
type: string
description: "Device ID from the original provision. \nThis field is populated only when performing token-for-token provisioning and can be used only in the following APIs: \n- Approve Provisioning\n- Approve Provisioning Stand-In Notification\n- Token Create Notification.\n"
maxLength: 48
example: '...'
originalDeviceType:
type: string
description: "Device type from the original provision. \nThis field is populated only when performing token-for-token provisioning and can be used only in the following APIs: \n- Approve Provisioning\n- Approve Provisioning Stand-In Notification\n- Token Create Notification.\n"
maxLength: 48
example: '...'
RSCheckEligibility200:
type: object
properties:
cardMetadataInfo:
description: 'This object could be empty if VISA is going to provide the metadata detail.
'
$ref: '#/components/schemas/ObjCheckEligibilityCardMetadataInfo'
ObjDeviceInformationEligibility:
type: object
description: 'Object that contain the Device Information, the values that coould be present depends on the Token Type and the Device Type.
'
properties:
deviceID:
type: string
description: 'This field represents the device ID.
- For SECURE_ELEMENT this value will be the SE ID in hex binary characters transformed to a 48-character string.
- For ECOMMERCE or CARD_ON_FILE this value may not be available.
- For Host Card Emulation HCE his value is determined by the wallet.
Format: Alphanumeric characters
'
maxLength: 48
example: CTF0000000001
deviceLanguageCode:
type: string
description: ISO 639 Version 3
maxLength: 3
example: eng
deviceType:
type: string
description: 'This field represents the device type.
Allowed values:
- MOBILE_PHONE
- TABLET
- MOBILEPHONE_OR_TABLET
- PC
- WATCH
- TV
- HOME_DEVICE
- WEARABLE_DEVICE
- AUTOMOBILE_DEVICE
'
enum:
- MOBILE_PHONE
- TABLET
- MOBILEPHONE_OR_TABLET
- PC
- WATCH
- TV
- HOME_DEVICE
- WEARABLE_DEVICE
- AUTOMOBILE_DEVICE
maxLength: 32
example: PHONE
deviceName:
type: string
description: 'Device index.
Format: Number between 1 and 99, included.
'
maxLength: 128
example: Novo_Phone
deviceNumber:
type: string
description: Device number
maxLength: 13
example: 6506198963
osType:
type: string
description: 'Operating System from which the request is sent.
Allowed values
- ANDROID
- IOS
- WINDOWS
- BLACKBERRY
- TIZEN
- OTHER
'
maxLength: 32
enum:
- ANDROID
- IOS
- WINDOWS
- BLACKBERRY
- TIZEN
- OTHER
example: ANDROID
osVersion:
type: string
description: 'Operating system version
Sample: 13.1.8
'
maxLength: 256
example: 4.4.4
osBuildID:
type: string
description: OS Compilation version
maxLength: 32
example: 13.1
deviceIDType:
type: string
description: 'Attribute indicating the source of the Device ID value.
Example: The source for Device ID (deviceID)could be SecureElement,
TEE, or Derived,
'
maxLength: 32
example: TEE
deviceManufacturer:
type: string
description: 'Manufacturer of the decive.
Sample: Samsung
'
maxLength: 32
example: Samsung
deviceBrand:
type: string
description: 'Device Brand.
Sample: Galaxy
'
maxLength: 32
example: Galaxy
deviceModel:
type: string
description: Device model
maxLength: 32
example: M05
deviceLocation:
type: string
description: 'Obfuscated geographic location of the device.
Example: +37/-121
'
maxLength: 26
deviceIPAddressV4:
type: string
description: 'The IP address of the device at the time of the provisioning request,
with the value represented in 255.255.255.255 format.
Restriction: Cannot contain any leading zeros
'
maxLength: 15
example: 127.0.0.1
locationSource:
type: string
description: 'Source used to identify consumer location.
Available values:
- WIFI
- CELLULAR
- GPS
- OTHER
'
enum:
- WIFI
- CELLULAR
- GPS
- OTHER
maxLength: 32
example: WIFI
tokenProtectionMethod:
type: string
description: 'Method of token protection.
Available values:
- SOFTWARE
- TRUSTED_EXECUTION_ENVIRONMENT
- SECURE_ELEMENT
- CLOUD
'
enum:
- SOFTWARE
- TRUSTED_EXECUTION_ENVIRONMENT
- SECURE_ELEMENT
- CLOUD
maxLength: 40
example: CLOUD
ObjMerchantInfo:
type: object
properties:
merchantID:
type: number
description: 'Unique merchant identifiers.
Required for trusted listing enrollment.
'
maxLength: 8
example: Novo InApp
merchantName:
type: string
description: 'Merchant’s name
'
maxLength: 256
example: 10808 Research Boulevard
ObjCardHolderInfo:
type: object
description: 'Object that contains the required information to make the decision
whether the card is eligible or not.
'
required:
- primaryAccountNumber
- expirationDate
properties:
primaryAccountNumber:
type: string
description: 'Card number to be tokenized.
See the conditionals use cases for this field.
'
maxLength: 19
example: XX25XX25XX25XX25
expirationDate:
type: object
properties:
month:
type: string
example: '04'
year:
type: string
example: '2023'
cvv2:
type: string
description: "CVV2 value associated to the card.\nThis field will be NULL when the PAN Source is any of these values:\n- ON_FILE\n- MOBILE_BANKING_APP\n- TOKEN <> OR TokenType is one of any of these values:\n - CARD_ON_FILE\n - ECOMMERCE\n"
enum:
- ON_FILE
- MOBILE_BANKING_APP
- TOKEN
- CARD_ON_FILE
- ECOMMERCE
maxLength: 4
example: '888'
name:
type: string
description: Complete cardholder´s name.
maxLength: 32
example: Jhon Doe
highValueCustomer:
type: boolean
description: 'If available, it will be provided in Check Eligibility.
Authorized values:
- true: Indicates that the customer is high value.
- false: Indicates that the customer is not high value.
'
example: false
riskAssessmentScore:
type: string
description: 'This value shows the risk score of the PAN is calculated by the AA Risk
engine, based on the PAN’s transaction pattern (long-term and shortterm).
Values are 0 through 99, with a higher value indicating higher risk.
'
maxLength: 2
example: 5
BillingAddress:
$ref: '#/components/schemas/ObjBillingAddress'
RQCardholderVerificationMethods:
type: object
required:
- tokenRequestorID
- tokenReferenceID
- panReferenceID
- walletAccountEmailAddressHash
- clientWalletAccountID
properties:
tokenRequestorID:
type: integer
description: 'Unique ID assigned to the client requesting the token. This value is
assigned by Visa when creating the VTS project.
'
example: 40022358888
tokenReferenceID:
type: string
description: 'Unique ID associating a token with a card. This ID can be used in
future calls to make operations related to the token in the I-TSP.
'
example: DNITHE30194726875288888
panReferenceID:
type: string
description: 'Unique ID representing a card. This ID can be used in future calls
referred to the card in the Tokenization flow.
'
example: V-3019231458906209630635
panSource:
type: string
description: 'Origin of the information of the PAN.
Allowed values:
- KEY_ENTERED
- ON_FILE
- MOBILE_BANKING_APP
- TOKEN
- CHIP_DIP
- CONTACTLESS_TAP
'
enum:
- KEY_ENTERED
- ON_FILE
- MOBILE_BANKING_APP
- TOKEN
- CHIP_DIP
- CONTACTLESS_TAP
example: MOBILE_BANKING_APP
otpReason:
type: string
description: "\tOTP reason the descriptions may vary in agreement with the issuer.\n\n Allowed values:\n - PROVISIONING\n - FPAN_NOTIFICATIONS\n - PAYMENT\n - TOKEN_DEVICE_BINDING\n - CARDHOLDER_STEPUP\n - TRUSTED_LISTING_ENROLLMENT\n"
enum:
- PROVISIONING
- FPAN_NOTIFICATIONS
- PAYMENT
- TOKEN_DEVICE_BINDING
- CARDHOLDER_STEPUP
- TRUSTED_LISTING_ENROLLMENT
otpMaxReached:
type: boolean
description: "\tIf this field is active, it means the user with the referenced\n token has exceeded the number of requests for authentication\n methods or OTP requests, thus, the response must not include the\n value when requesting them again.\n"
clientWalletAccountID:
type: string
description: 'Identifier of the wallet that sends the request.
Client provided consumer ID that identifies the wallet account
holder entity
'
maxLength: 32
deviceInfo:
description: 'Device Information containing the device model.
It is required for TOKEN DEVICE BINDING.
'
$ref: '#/components/schemas/ObjDeviceInformation'
tokenInfo:
description: 'Structure with token information - Optional.
'
$ref: '#/components/schemas/ObjTokenInfo'
encryptedData:
type: object
description: 'Encrypted payload data.
Only primaryAccountNumber needs to be provided in CardholderInfo.
'
maxLength: 7000
properties:
cardholderInfo:
$ref: '#/components/schemas/ObjCardHolderInfo'
cardToken:
type: string
description: 'Unique Card Identifier at NovoPayment’s Issuance Service.
'
maxLength: 40
example: 5DA...27
RQDeviceTokenBinding:
type: object
required:
- tokenRequestorID
- tokenReferenceID
- panReferenceID
- walletAccountEmailAddressHash
- clientWalletAccountID
- deviceInfo
properties:
tokenRequestorID:
type: integer
description: 'Unique ID assigned to the client requesting the token. This value is
assigned by Visa when creating the VTS project.
'
example: 40022358888
tokenReferenceID:
type: string
description: 'Unique ID associating a token with a card. This ID can be used in
future calls to make operations related to the token in the I-TSP.
'
example: DNITHE30194726875288888
panReferenceID:
type: string
description: 'Unique ID representing a card. This ID can be used in future calls
referred to the card in the Tokenization flow.
'
example: V-3019231458906209630635
walletAccountEmailAddressHash:
type: string
description: 'Hash of the email from which the account is opened in the wallet
that sends the request.
'
maxLength: 64
clientWalletAccountID:
type: string
description: 'Identifier of the wallet that sends the request.
Client provided consumer ID that identifies the wallet account
holder entity
'
maxLength: 32
deviceInfo:
$ref: '#/components/schemas/ObjDeviceInformation_ForBinding'
tokenUserInfo:
$ref: '#/components/schemas/ObjTokenUserInfo'
merchantInfo:
$ref: '#/components/schemas/ObjMerchantInfo'
ObjCheckEligibilityContactInfo:
type: object
properties:
contactWebsite:
type: string
description: Customer Service website of the issuing bank
maxLength: 128
example: https://issuer.com
contactEmail:
type: string
description: Customer Service email address of the issuing bank
maxLength: 32
example: user@issuer.com
contactNumber:
type: string
description: Customer service phone number of the issuing bank
maxLength: 32
example: 800-000-0000
contactName:
type: string
description: Name of the issuing bank
maxLength: 32
example: Issuer
ObjTermsAndConditions:
type: object
properties:
id:
type: string
maxLength: 36
description: 'ID for Terms and Conditions that were accepted by the consumer.
It is not returned for Card on File.
'
example: 13c5e2ba-eb5c-432d-a027-97ddaf109af1
date:
type: string
description: 'Timestamp when Terms and Conditions are acted upon by consumer.
It is not returned for Card on File.
UTC Format in epoch seconds The UNIX_UTC_timestamp is a UNIX Epoch
timestamp. The value is in seconds
'
example: 111115
RS400Tk:
type: object
properties:
code:
type: string
example: 400.22.001
description: Operation response code
minLength: 10
maxLength: 10
message:
type: string
description: Response code description
example: Header Params Required
maxLength: 140
datetime:
type: string
example: '2022-04-25T23:19:12.000Z'
description: 'Operation Time Stamp in ISO 8601 format
date-time - the date-time notation as defined by [RFC 3339, section 5.6](https://tools.ietf.org/html/rfc3339#section-5.6), for example, 2017-07-21T17:32:28Z
'
minLength: 24
maxLength: 24
RQCardInfo:
type: object
required:
- cardIdList
properties:
cardIdList:
type: array
description: 'List of card ids. Each id corresponds to a card whose information is requested.
'
example:
- 866f4af6-69a8-4c51-9940-95bdd05124c6
- f18eaabb-bdce-43eb-b17a-e5560f36687c
ObjExpirationDate:
type: object
required:
- month
- year
properties:
month:
type: string
description: Month of expiration date
maxLength: 2
example: 7
year:
type: string
description: Year of expiration date
maxLength: 4
example: 2016
ObjCardInfoList:
type: object
required:
- cardId
- cardProduct
- cardProductId
- cardStatus
- cardStatusId
- cardType
- cardTypeId
- customerName
- expirationDate
- maskedNumber
- pan
properties:
cardId:
type: string
description: 'Card Id assocated to card
'
example: 866f4af6-69a8-4c51-9940-95bdd05124c6
cardProduct:
type: string
description: 'Product of card
'
example: Lynk Visa Debit
cardProductId:
type: string
description: 'Product Id of card
'
example: '2'
cardStatus:
type: string
description: 'Status of card
'
example: Active
cardStatusId:
type: string
description: 'Status Id of card
'
example: '1'
cardType:
type: string
description: 'Type of card
'
example: Debit
cardTypeId:
type: string
description: 'Type Id of card
'
example: 1"
customerName:
type: string
description: 'Name of customer
'
example: Gen Lynk
expirationDate:
type: string
description: 'Expiration date of card
'
example: '2810'
maskedNumber:
type: string
description: 'Masked PAN
'
example: '************8603'
pan:
type: string
description: 'PAN of card
'
example: '4537850008998603'
RSApproveProvision200:
type: object
properties:
actionCode:
type: string
description: "Action code to indicate Visa for which flow it should go.\nIn case the provisioning of the token is approved, the values are:\n\n- 00 - Green path, indicates that the token is provisioned and\n automatically activated for payments.\n- 85 - Yellow path, indicates that the token is provisioned and the\n client must be authenticated to activate the token. In case the\n provisioning is not approved, the code must be within the following.\n- N7 - incorrect CVV2\n- 14 - Invalid card number\n- 54 - Invalid expiration date\n- 05 - Generic rejection\n- 96 - Internal system error\n"
enum:
- '00'
- '85'
- N7
- '14'
- '54'
- '05'
- '96'
example: '00'
addressVerificationResultCode:
type: string
description: 'Code that describes the result of an address verification.
'
maxLength: 1
cvv2ResultsCode:
type: string
description: "CVV2 verification from Visa\n\n- M - Visa verified the CVV2 enter by the user in the wallet.\n- N - Visa couldn’t verified the CVV2 enter by the user in the wallet,\n meaning the CVV2 enter is incorrect.\n- P - Visa didn’t verify the CVV2. Is null when cvv is optional\n"
enum:
- M
- N
- P
maxLength: 1
issuerSpecialConditionCodes:
type: string
description: "Supported for issuers participating in 0100 TAR.The issuer can send\nvalues for this element in the 0100 TAR response.\n- If the issuer sends a value in the 0100 TAR, it will be sent in\n this element of the Get CVM.\n- If no value is sent in 0100 TAR or if the issuer does not\n participate in TAR, this element will not be present.\n"
maxLength: 100
issuerDiscretionaryData:
$ref: '#/components/schemas/ObjApproveProvisionIssuerDiscretionaryData'
RSCardholderVerificationMethods200:
type: object
required:
- stepUpMethods
properties:
stepUpMethods:
type: array
$ref: '#/components/schemas/ObjStepUpMethods'
responseCode:
type: string
description: 'This field is present when the field otpReason is:
TOKEN_DEVICE_BINDING, CARDHOLDER_STEPUP o TRUSTED_LISTING_ENROLLMENT
Allowed values:
- APPROVED
- STEPUP
- DECLINED
'
enum:
- APPROVED
- STEPUP
- DECLINED
example: APPROVED
RS500Tk:
type: object
properties:
code:
type: string
example: 500.22.999
description: Operation response code
minLength: 10
maxLength: 10
message:
type: string
example: Internal Server Error
description: Response code description
maxLength: 140
datetime:
type: string
example: '2022-04-25T23:19:12.000Z'
minLength: 24
maxLength: 24
ObjRpinEnrollment:
type: object
properties:
responseStatus:
type: string
description: 'RPIN enrollment response status.
Available values:
- S
- F
'
enum:
- S
- F
rejectCode:
type: string
maxLength: 2
description: 'Contains the Reject Code for the failure. Present only when the Response Status = F.
'
example: ER
rejectDesc:
type: string
maxLength: 100
description: 'Contains the Reject Reason for the failure. Present only when the Response Status = F.
'
example: ERROR DETAIL
RQSendPasscode:
type: object
required:
- tokenRequestorID
- lifeCycleTraceID
- encryptedData
properties:
tokenRequestorID:
type: integer
description: 'Unique ID assigned to the client requesting the token. This value is
assigned by Visa when creating the VTS project.
'
example: 40022358888
tokenReferenceID:
type: string
description: 'Unique ID associating a token with a card. This ID can be used in
future calls to make operations related to the token in the I-TSP.
'
example: DNITHE30194726875288888
panReferenceID:
type: string
description: 'Unique ID representing a card. This ID can be used in future calls
referred to the card in the Tokenization flow.
'
example: V-3019231458906209630635
clientWalletAccountID:
type: string
description: 'Identifier of the wallet that sends the request.
Client provided consumer ID that identifies the wallet account holder entity
'
maxLength: 32
otpMaxReached:
type: boolean
description: "\tIf this field is active, it means the user with the referenced\n token has exceeded the number of requests for authentication\n methods or OTP requests, thus, the response must not include the\n value when requesting them again.\n"
otpMethodIdentifier:
type: string
description: 'Unique ID that allows to associate an OTP action to the cardholder.
This value is delivered by the issuer when the I-TSP calls the
endpoint Cardholder Verification Methods.
'
maxLength: 32
otpValue:
type: string
description: 'OTP Value
'
maxLength: 8
OtpReason:
type: string
description: 'OTP reason The descriptions may vary in agreement with the issuer.
Allowed values:
- PROVISIONING
- FPAN_NOTIFICATIONS
- PAYMENT
- TOKEN_DEVICE_BINDING
- CARDHOLDER_STEPUP
- TRUSTED_LISTING_ENROLLMENT
'
enum:
- PROVISIONING
- FPAN_NOTIFICATIONS
- PAYMENT
- TOKEN_DEVICE_BINDING
- CARDHOLDER_STEPUP
- TRUSTED_LISTING_ENROLLMENT
otpExpirationDate:
type: string
description: 'Token expiration date
Format: yyyy-MM-ddTHH:mm:ss.SSSZ
'
deviceInfo:
$ref: '#/components/schemas/ObjDeviceInformation'
encryptedData:
type: object
description: 'Encrypted payload data Only primaryAccountNumber needs to be
provided in cardholderInfo.
'
properties:
cardholderInfo:
$ref: '#/components/schemas/ObjSendPasscodeCardHolderInfo'
tokenInfo:
$ref: '#/components/schemas/ObjTokenInfo'
RSDeviceTokenBinding200:
type: object
required:
- actionCode
properties:
actionCode:
type: string
description: "Action code to indicate Visa for which flow it should go.\nIn case the provisioning of the token is approved, the values are:\n\n- 00 - Green path, indicates that the token is provisioned and\n automatically activated for payments.\n- 85 - Yellow path, indicates that the token is provisioned and the\n client must be authenticated to activate the token. In case the\n provisioning is not approved, the code must be within the following.\n- N7 - incorrect CVV2\n- 14 - Invalid card number\n- 54 - Invalid expiration date\n- 05 - Generic rejection\n- 96 - Internal system error\n"
enum:
- '00'
- '85'
- N7
- '14'
- '54'
- '05'
- '96'
example: '00'
ObjStepUpMethods:
type: object
required:
- type
- value
- identifier
properties:
type:
type: string
description: 'It is required when the authentication method of the cardholder is
returned.
Allowed values:
- OTPSMS
- OTPEMAIL
- APP_TO_APP
- CUSTOMERSERVICE
- OUTBOUNDCALL
'
enum:
- OTPSMS
- OTPEMAIL
- APP_TO_APP
- CUSTOMERSERVICE
- OUTBOUNDCALL
maxLength: 32
example: OTPSMS
value:
type: string
description: 'Value of the identification method of the cardholder.
'
maxLength: 64
identifier:
type: string
description: 'Identifier of the identification method of the cardholder that can
be used for future calls to send the OTP.
'
maxLength: 32
sourceAddress:
type: string
description: 'Indicates the source address from which the OTP is sent.
'
maxLength: 64
otpMethodPlatform:
type: string
description: 'Used with the APP_TO_APP type, this field contains the appropriate
OS platform for the associated issuer mobile banking application.
Authorized values:
- IOS
- ANDROID
- WINDOWS
- WEB
'
enum:
- IOS
- ANDROID
- WINDOWS
- WEB
maxLength: 64
ObjCardHolderInfo_Provisioning:
type: object
description: "Object that contains the related information to the customer cards, only PAN and Expiry Date are required; \nin some cases CVV is present, please, follow the applicable cases.\n"
required:
- primaryAccountNumber
- expirationDate
properties:
primaryAccountNumber:
type: string
description: 'Card number.
'
maxLength: 19
example: XX25XX25XX25XX25
expirationDate:
type: object
properties:
month:
type: string
example: 08
year:
type: string
example: '2028'
cvv2:
type: string
description: 'CVV2 value associated to the card.
This field could contain value when the PAN Source is KEY_ENTERED
'
maxLength: 4
example: '808'
ObjNotificationEncryptedData:
type: object
description: 'Encrypted payload data. When this value is decrypted the fields are
conditional to the type of the notification consider the
messageReasonCode to be secure about what values could be contained.
When eventType is TOKEN_CREATED the encrypted payload can contain
Cardholder Information Token Information Risk Information.
When eventType is TOKEN_STATUS_UPDATED can contain a Risk
Information Structure.
Not present on evenType PAN_UPDATED or CARD_METADATA_UPDATED.
'
maxLength: 7000
properties:
cardholderInfo:
$ref: '#/components/schemas/ObjCardHolderInfo'
tokenInfo:
$ref: '#/components/schemas/ObjTokenInfo'
deviceInfo:
$ref: '#/components/schemas/ObjDeviceInformation'
riskInfo:
$ref: '#/components/schemas/ObjRiskInfo'
ObjDeviceInformation_ForBinding:
type: object
description: 'Device Information containing the device model.
The object must have:
- deviceID
- deviceIndex
'
anyOf:
- required:
- deviceID
- required:
- deviceIndex
properties:
deviceID:
type: string
description: 'This field represents the device ID.
- For SECURE_ELEMENT this value will be the SE ID in hex binary characters transformed to a 48-character string.
- For ECOMMERCE or CARD_ON_FILE this value may not be available.
- For Host Card Emulation HCE his value is determined by the wallet.
Format: Alphanumeric characters
'
maxLength: 48
example: CTF0000000001
deviceIndex:
type: number
description: 'Visa’s index number where the device ID is stored.
Number between 1 and 99.
This is required for TOKEN DEVICE BINDING
'
maxLength: 2
example: 99
deviceLanguageCode:
type: string
description: ISO 639 Version 3
maxLength: 3
example: eng
deviceType:
type: string
description: 'This field represents the device type.
Allowed values:
- MOBILE_PHONE
- TABLET
- MOBILEPHONE_OR_TABLET
- PC
- WATCH
- TV
- HOME_DEVICE
- WEARABLE_DEVICE
- AUTOMOBILE_DEVICE
'
enum:
- MOBILE_PHONE
- TABLET
- MOBILEPHONE_OR_TABLET
- PC
- WATCH
- TV
- HOME_DEVICE
- WEARABLE_DEVICE
- AUTOMOBILE_DEVICE
maxLength: 32
example: PHONE
deviceName:
type: string
description: 'Device index.
Format: Number between 1 and 99, included.
'
maxLength: 128
example: MyCTFDeviceTEst
deviceNumber:
type: string
description: Device number
maxLength: 13
example: 6506198963
osType:
type: string
description: 'Operating System from which the request is sent.
Allowed values
- ANDROID
- IOS
- WINDOWS
- BLACKBERRY
- TIZEN
- OTHER
'
maxLength: 32
enum:
- ANDROID
- IOS
- WINDOWS
- BLACKBERRY
- TIZEN
- OTHER
example: IOS
osVersion:
type: string
description: 'Operating system version
Sample: 4.4.4
'
maxLength: 256
example: 4.4.4
osBuildID:
type: string
description: OS Compilation version
maxLength: 32
example: 1.6
deviceIDType:
type: string
description: 'Note: There are 9 more optional fields that contain / request the
information of the device from which the request is made.
Attribute indicating the source of the Device ID value.
Example: The source for Device ID (deviceID)could be SecureElement,
TEE, or Derived,
'
maxLength: 32
example: 630635
deviceManufacturer:
type: string
description: 'Manufacturer
Sample: Samsung
'
maxLength: 32
example: Samsung
deviceBrand:
type: string
description: 'Device Brand.
Sample: Galaxy
'
maxLength: 32
example: Galaxy
deviceModel:
type: string
description: Device model
maxLength: 32
example: M05
deviceLocation:
type: string
description: 'Obfuscated geographic location of the device.
Example: +37/-121
'
maxLength: 26
deviceIPAddressV4:
type: string
description: 'The IP address of the device at the time of the provisioning request,
with the value represented in 255.255.255.255 format.
Restriction: Cannot contain any leading zeros
'
maxLength: 15
example: 127.0.0.1
locationSource:
type: string
description: 'Source used to identify consumer location.
Available values:
- WIFI
- CELLULAR
- GPS
- OTHER
'
enum:
- WIFI
- CELLULAR
- GPS
- OTHER
maxLength: 32
example: WIFI
tokenProtectionMethod:
type: string
description: 'Method of token protection.
Available values:
- SOFTWARE
- TRUSTED_EXECUTION_ENVIRONMENT
- SECURE_ELEMENT
- CLOUD
'
enum:
- SOFTWARE
- TRUSTED_EXECUTION_ENVIRONMENT
- SECURE_ELEMENT
- CLOUD
maxLength: 3
example: SOFTWARE
ObjReplaceEnrollment:
type: object
properties:
responseStatus:
type: string
description: 'Response status value.
Available values:
- S
- W
- F
'
enum:
- S
- W
- F
rejectCode:
type: string
maxLength: 2
description: 'Contains the Reject Code for the failure. Present only when the Response Status = F.
'
example: ER
rejectDesc:
type: string
maxLength: 100
description: 'Contains the Reject Reason for the failure. Present only when the Response Status = F.
'
example: ERROR DETAIL
ObjAccountLevelInfoResp:
type: object
properties:
rpinEnrollment:
$ref: '#/components/schemas/ObjRpinEnrollment'
replaceEnrollment:
$ref: '#/components/schemas/ObjReplaceEnrollment'
linkEnrollment:
$ref: '#/components/schemas/ObjLinkEnrollment'
RQApproveProvision:
type: object
required:
- tokenRequestorID
- tokenReferenceID
- panReferenceID
- panSource
- walletAccountEmailAddress
- clientWalletAccountID
- tokenInfo
- encryptedData
properties:
tokenRequestorID:
type: integer
description: 'Unique ID assigned to the client requesting the token.
'
example: 40022358888
tokenReferenceID:
type: string
description: 'Unique ID associating a token with a card. This ID can be used in
future calls to make operations related to the token in the I-TSP.
'
example: DNITHE30194726875288888
panReferenceID:
type: string
description: 'Unique ID representing a card. This ID can be used in future calls
referred to the card in the Tokenization flow.
'
example: V-3019231458906209630635
panSource:
type: string
description: 'Origin of the information of the PAN.
Allowed values:
- KEY_ENTERED
- ON_FILE
- MOBILE_BANKING_APP
- TOKEN
- CHIP_DIP
- CONTACTLESS_TAP
'
enum:
- KEY_ENTERED
- ON_FILE
- MOBILE_BANKING_APP
- TOKEN
- CHIP_DIP
- CONTACTLESS_TAP
example: KEY_ENTERED
cvv2ResultsCode:
type: string
description: "Result code of the validation of CVV2 made by VISA.\nAvailable Values:\n- M: The CVV2 is match.\n- N: The CVV2 enter by the user is incorrect.\n- P: The CVV2 was not validate.\n- S: Indicates that V.I.P. or the issuer was unable to perform CVV2\n verification.\n\n- U: Issuer was not available does not participate in the CVV2\n Service or that STIP has responded to an issuer-unavailable\n response.\n\n- NULL: When the provisioning process occured without CVV\n"
enum:
- M
- N
- P
- S
- U
- null
maxLength: 1
example: M
walletAccountEmailAddress:
type: string
description: 'Hash of the email account from which the account is opened in the
wallet that sends the request.
'
maxLength: 64
example: 5DA...27
clientWalletAccountID:
type: string
description: 'Identifier of the wallet that sends the request.
Client provided consumer ID that identifies the wallet account holder
entity.
'
maxLength: 32
example: 5DA...D8
addressVerificationResultCode:
type: string
description: 'Code that describes the result of an address verification.
'
maxLength: 1
example: 5DA...D8
ConsumerEntryMode:
type: string
description: 'Method of consumer entry.
Available values:
- KEY_ENTERED
- CAMERA_CAPTURED
- UNKNOWN
'
enum:
- KEY_ENTERED
- CAMERA_CAPTURED
- UNKNOWN
example: KEY_ENTERED
locale:
type: string
description: 'The language for the app,if need a country code should be separated
using a “_“.
Example: en_US
Format: String; ISO language ISO 639-1 and alpha-2 country code
ISO 3166-1 alpha-2
'
maxLength: 5
example: en_US
deviceInfo:
$ref: '#/components/schemas/ObjDeviceInformation'
tokenInfo:
$ref: '#/components/schemas/ObjTokenInfo'
encryptedData:
type: object
description: 'Represents the encrypted payload, contains Cardholder Information and Risk Information with the applicable information.
'
properties:
cardholderInfo:
$ref: '#/components/schemas/ObjCardHolderInfo_Provisioning'
riskInfo:
$ref: '#/components/schemas/ObjRiskInfo'
ObjBillingAddress:
type: object
properties:
name:
type: string
description: Physical address or shipping address.
maxLength: 100
example: Novo InApp
line1:
type: string
description: 'First line of the address. Usually for the complete address,
this is Required for the US and Canada.
'
maxLength: 256
example: 10808 Research Boulevard
line2:
type: string
description: 'Second line, usually corresponds to house, apartment,
suite, etc.
'
maxLength: 256
example: Provisioning Boulevard
city:
type: string
description: Name of the city.
maxLength: 100
example: Austin
state:
type: string
description: 'State or province in the country.This field must be valid
for the respective country.The country will be related to the
country of the bank.
'
example: TX
postalCode:
type: string
description: 'Postal Code.
Condition: If address is provided this field has the following
characteristics.
'
maxLength: 40
example: 78759
ObjRiskInfo:
type: object
description: 'Structure with risk information.
This object can be sent when messageReasonCode is equal to TOKEN_CREATED
'
properties:
walletProviderRiskAssessment:
type: string
maxLength: 1
description: 'Risk rating of the wallet, it can be one of the following values:
- 0: Unconditionally approved.
- 1: Conditionally approved with further consumer verification.
- 2: Not approved
'
enum:
- 0
- 1
- 2
walletProviderRiskAssessmentVersion:
type: string
maxLength: 10
description: 'Information for the Issuer related to the security level of the wallet
'
walletProviderAccountScore:
type: string
maxLength: 2
description: 'The wallet provider account score. Score value is between 1 and 5,
indicating the confidence level of the account, where 5 indicates
the most confidence on the account.
'
enum:
- 1
- 2
- 3
- 4
- 5
walletProviderDeviceScore:
type: string
maxLength: 2
description: The wallet provider device score. Score value is between 1 and 5, indicating the confidence level of the device, where 5 indicates the most confidence.
enum:
- 1
- 2
- 3
- 4
- 5
walletProviderReasonCodes:
type: string
maxLength: 100
description: Wallet provider reason codes, in a comma-separated format.
deviceBluetoothMac:
type: string
maxLength: 24
description: MAC address for Bluetooth.
deviceIMEI:
type: string
maxLength: 24
description: Hardware ID of the device.
deviceSerialNumber:
type: string
maxLength: 24
description: Serial number of the mobile device.
deviceTimeZone:
type: string
maxLength: 5
description: Time-zone abbreviation.
deviceTimeZoneSetting:
type: string
description: 'Device time-zone setting.
Available Values:
- NETWORK_SET
- CONSUMER_SET
'
enum:
- NETWORK_SET
- CONSUMER_SET
osID:
type: string
maxLength: 24
description: OS ID to allow building velocity and risk rules.
simSerialNumber:
type: string
maxLength: 24
description: SIM serial number of the mobile device
deviceLostMode:
type: string
maxLength: 4
description: Number of days. Values are up to 9999 number of days.
daysSinceConsumerDataLastAccountChange:
type: string
maxLength: 4
description: 'Number of days since account settings were changed (in case of a
password update). If the number of days exceeds 9999, it will stay
at 9999.
'
accountHolderName:
type: string
maxLength: 64
description: Account-holder’s name.
walletProviderPANAge:
type: string
maxLength: 4
description: 'Length of time (in days) that a PAN has been on file for
a user.
'
walletAccountHolderCardNameMatch:
type: string
maxLength: 4
description: 'Name of the accountholder and name of cardholder matched.
Available Values:
- Y: Indicates the two names match.
- N: Indicates the two names do not match.
'
enum:
- Y
- N
accountToDeviceBindingAge:
type: string
maxLength: 4
description: 'Number of days this device has been used by this account.
If the number of days exceeds 9999, it will stay at 9999.
Example: 9999
'
userAccountAge:
type: string
maxLength: 4
description: 'Number of days since an account for this user has existed.
Values are 0 through 9999.
Example: 9999
'
walletAccountAge:
type: string
description: 'Number of days since the user created a wallet account or started
using a wallet. If the number of days exceeds 256, it will stay at 256.
'
provisioningAttemptsOnDeviceIn24Hours:
type: string
maxLength: 2
description: 'Number of provisioning attempts on this device in the past 24 hours.
If the number of attempts exceeds 99, it will stay at 99.
'
example: 99
distinctCardholderNames:
type: string
maxLength: 2
description: 'Number of distinct cardholder names used in provisioning from this
device.
'
example: 99
deviceCountry:
type: string
maxLength: 2
description: 'Country of device at time of provisioning. ISO 3166-1, alpha-2
'
example: US
walletAccountCountry:
type: string
maxLength: 2
description: Country of accountholder. ISO 3166-1, alpha-2
example: US
suspendedCardsInAccount:
type: string
maxLength: 2
description: 'Number of cards suspended in the account.
If the number of days exceeds 99, it will stay at 99.
'
example: 99
daysSinceLastAccountActivity:
type: string
maxLength: 4
description: 'Number of days since the last activity on account.
If the number of days exceeds 9999, it will stay at 9999.
'
example: 9999
numberOfTransactionsInLast12months:
type: string
maxLength: 4
description: 'Number of transactions on this account in the last 12 months.
If the number of transactions exceeds 9999, it will stay at 9999.
'
example: 9999
numberOfActiveTokens:
type: string
maxLength: 2
description: 'Number of active tokens on this account.
If the number of tokens exceeds 99, it will stay at 99.
'
example: 99
deviceWithActiveTokens:
type: string
maxLength: 2
description: 'Number of devices for this user with the same token.
If the number of tokens exceeds 99, it will stay at 99.
'
example: 99
activeTokensOnAllDeviceForAccount:
type: string
maxLength: 4
description: 'Number of active tokens for this user, across all devices.
If the number of tokens exceeds 9999, it will stay at 9999.
'
example: 9999
visaTokenScore:
type: string
maxLength: 2
description: 'Value indicating the degree of risk associated with the token.
Numeric value is 01 through 99.
'
visaTokenDecisioning:
type: number
maxLength: 2
description: "Results from the token provisioning service.\n\nAvailable values:\n- 00: Provision and activate\n- 05: Do not provision\n- 85: Provision in inactive state (requires further consumer\n authentication prior to activation - Yellow Flow)\n"
enum:
- '00'
- '05'
- '85'
riskAssessmentScore:
type: string
maxLength: 2
description: 'Values are 0 through 99. A higher value indicates a higher risk.
This is calculated by the AA Risk Engine, based on the PAN’s
transaction pattern (long term and short term).
'
issuerSpecialConditionCodes:
type: string
maxLength: 100
description: 'Supported for issuers participating in 0100 TAR. The issuer can send
values for this element in the 0100 TAR response.
If the issuer sends a value in the 0100 TAR, it will be sent in this
element of the Get CVM.
If no value is sent in 0100 TAR or if the issuer does not participate
in TAR, this element will not be present.
'
ObjApproveProvisionIssuerDiscretionaryData:
type: object
properties:
fileControlInformation:
type: string
description: 'File control information.
hexBinary, hex characters must be uppercase; max length of 128 bytes.
'
issuerApplicationDiscretionaryData:
type: string
description: 'Discretionary data
'
RSErrorCode400:
type: object
description: 'Error message code only if the HTTP status is different from 200.
This field shows the I-TSP if an error was generated in the request.
'
properties:
errorCode:
type: string
description: 'Error response Codes:
- ISE40000: ISS_ERROR_REQUIRED_DATA_MISSING
- ISE40005: ISS_ERROR_INVALID_FIELD_LENGTH
- ISE40006: ISS_ERROR_INVALID_FIELD_TYPE
- ISE40010: ISS_ERROR_CRYPTOGRAPHY_ERROR
- ISE40013: ISS_ERROR_INVALID_EXP_DATE
- ISE40001: ISS_ERROR_PAN_INELIGIBLE
'
enum:
- ISE40000
- ISE40005
- ISE40006
- ISE40010
- ISE40013
- ISE40001
ObjCheckEligibilityApplicationInfo:
type: object
properties:
supportsTokenNotifications:
type: boolean
description: 'Indicates whether the card supports token claims for transactions
originated from the device.
'
enum:
- true
- false
supportsFPANNotifications:
type: boolean
description: 'Indicates if the card supports FPAN Notifications for all transactions
that point to the FPAN.
'
enum:
- true
- false
transactionServiceURL:
type: string
description: 'Transaction history URL (TransactionDetails) of the issuer''s web
service.
'
maxLength: 128
messageServiceURL:
type: string
description: 'URL of the message/web service offer. It conforms to the API as
described in the SOPs and Issuers in the Card Notification Services
API Specification.
'
maxLength: 32
transactionPushTopic:
type: string
description: The issuer notifies the device of new available transactions.
maxLength: 128
messagePushTopic:
type: string
description: 'The notification push provider notifies the device of new
available messages.
'
maxLength: 128
appLaunchURL:
type: string
description: 'URL given to the issuer associated with the mobile application upon
launch. If this key is present, the AssociatedStoreIdentifiers key
must also be present.
'
maxLength: 128
appLaunchURLScheme:
type: string
description: 'Registered app URL scheme, in order to deep link from transaction
notifications and display all transaction notifications.
App ID must be included in the associated ApplicationIdentifiers
matrix and the application itself must register for the URL scheme
specified in this key.
'
maxLength: 32
associatedStoreIdentifiers:
type: array
description: 'A list of mobile app store items identifiers for the partner issuer''s
mobile banking app. The format is specific to a mobile store/phone
platform. Only one item from the list is used.
'
items:
type: string
maxLength: 20
associatedApplicationIdentifiers:
type: array
description: 'An array of associated application identifiers. Similar to
AssociatedStoreIdentifiers, but with explicit application IDs
(only applicable to SE DWP).
'
items:
type: integer
ObjLinkEnrollment:
type: object
properties:
groupResp:
$ref: '#/components/schemas/ObjGroupResp'
ObjActivationMethod:
type: object
required:
- type
- destiny
description: "Object with the information of the identification method chosen \nby the cardholder.\n"
properties:
type:
type: string
description: "Specifies the activation method type. Must be one of:\n- TEXT_TO_CARDHOLDER_NUMBER = Text message to Account holder's \nmobile phone number. Value will be the Account holder's masked \nmobile phone number.\n- EMAIL_TO_CARDHOLDER_ADDRESS = Email to Account holder's email \naddress. Value will be the Account holder's masked email address\n- CARDHOLDER_TO_CALL_AUTOMATED_NUMBER = Account holder-initiated \ncall to automated call center phone number. Value will be the phone \nnumber for the Account holder to call\n- CARDHOLDER_TO_CALL_MANNED_NUMBER = Account holder-initiated call \nto manned call center phone number. Value will be the phone number \nfor the Account holder to call\n- CARDHOLDER_TO_VISIT_WEBSITE = Account holder to visit a website. \nValue will be the website URL\n- CARDHOLDER_TO_USE_MOBILE_APP = Account holder to use a specific \nmobile app to activate token. Value will be replaced by a formatted \nstring\n- ISSUER_TO_CALL_CARDHOLDER_NUMBER = Issuer-initiated voice call to \nAccount holder's phone. Value will be the Account holder's masked \nvoice call phone number.\n"
example: TEXT_TO_CARDHOLDER_NUMBER
destiny:
type: string
description: 'Specifies the activation method value.
'
example: someaccount@novopayment.com
maxLength: 64
otpMethodIdentifier:
type: string
description: "Unique ID that allows to associate an OTP action to the cardholder. \nThis value is delivered by the issuer when the I-TSP calls the \nendpoint Cardholder Verification Methods. Only available for VISA.\n"
maxLength: 32
prm_tokenUniqueReference:
type: string
description: "Unique ID associating a token with a card. \nThis ID can be used in future calls to make operations related to the token in the I-TSP, \nfor example events related to the management of the life cycle.\n"
example: DWSPMC000000000132d72d4fcb2f4136a0532d3093ff1a45
maxLength: 64
ObjencryptedPayload_StatusUpdate:
required:
- panUniqueReference
type: object
properties:
panUniqueReference:
type: string
$ref: '#/components/schemas/prm_panUniqueReference'
source:
type: string
$ref: '#/components/schemas/prm_source'
dataValidUntilTimestamp:
type: string
description: "The date/time after which this encrypted object is considered invalid. If present, all systems must reject this encrypted object after this time and treat it as invalid data. Must be expressed in ISO 8601 extended format as one of the following:\n - YYYY-MM-DDThh:mm:ss[.sss]Z\n - YYYY-MM-DDThh:mm:ss[.sss]±hh:mm\n\nWhere [.sss] is optional and can be 1 to 3 digits. Must be a value no more than 30 days in the future. Mastercard recommends using a value of (Current Time + 30 minutes).\n"
minLength: 20
maxLength: 29
example: 2015-07-04 12:09:56.123000-07:00
cardAccountData:
$ref: '#/components/schemas/ObjcardAccountData'
description: Required if reasonCode is "FUNDING_ACCOUNT_UPDATE".
tokenData:
$ref: '#/components/schemas/ObjTokenData'
description: Required if reasonCode is "REDIGITIZATION_COMPLETE" or "FUNDING_ACCOUNT_UPDATE".
paymentAccountReference:
type: string
description: The unique account reference assigned to the PAN.
minLength: 29
maxLength: 29
example: 512381d9f8e0629211e3949a08002
financialAccountData:
$ref: '#/components/schemas/ObjFinancialAccountData'
prm_decision:
type: string
description: 'Status of the token.
'
enum:
- APPROVED
- REQUIRE_ADDITIONAL_AUTHENTICATION
- DECLINED
example: APPROVED
maxLength: 14
RQNotServiceActivated:
type: object
required:
- requestId
- reasonCode
- dateTime
- notificationBody
properties:
requestId:
type: string
$ref: '#/components/schemas/prm_requestId'
reasonCode:
type: string
description: 'SERVICE_ACTIVATED
'
example: SERVICE_ACTIVATED
dateTime:
type: string
description: 'dateTime. Format: yyyy-MM-ddTHH:mm:ss.SSSZ
'
example: 2026-07-04 19:08:56.123000+00:00
notificationBody:
type: object
$ref: '#/components/schemas/ObjBodyServiceActivated'
prm_panUniqueReference:
type: string
description: Reference to the PAN that is unique per Token Requestor.
minLength: 1
maxLength: 64
example: FWSPMC000000000159f71f703d2141efaf04dd26803f922b
ObjAccountHolderData:
type: object
properties:
accountHolderName:
type: string
description: The name of the account holder in the format LASTNAME/FIRSTNAME or FIRSTNAME LASTNAME . Max length - 27. Type - String.
minLength: 1
maxLength: 27
example: John Doe
accountHolderEmailAddress:
type: string
description: The email address of the account holder. Not required - Optionally present in pushAccount request. Not present otherwise.
minLength: 6
maxLength: 320
example: abcdef@xyz.com
accountHolderMobilePhoneNumber:
$ref: '#/components/schemas/ObjPhoneNumber'
accountHolderAddress:
$ref: '#/components/schemas/ObjAccountHolderAddress'
sourceIp:
type: string
description: The IP of the device initiating the request.
minLength: 7
maxLength: 64
example: 127.0.0.1
deviceLocation:
type: string
description: Latitude and longitude where the device the consumer is attempting to authorize is located. In the format "(sign) latitude/(sign) longitude" with a precision of 2 decimal places. Ex:"38.63/-90.2". Latitude is between -90 and 90. Longitude between -180 and 180.
minLength: 1
maxLength: 64
example: 38.63/-90.2
consumerIdentifier:
type: string
description: Consumer Identifier provided by the token requestor. Not required – Optionally present in AuthorizeService when provided by the wallet provider.
minLength: 1
maxLength: 88
example: 1b24f24a24ba98e27d43e345b532a245e4723d7a9c4f624e93452c1b24f24a24b
description: Information related to the account holder, such as name, address, etc.
prm_accountNumber:
type: string
description: The Primary Account Number of the card (PAN).
minLength: 9
maxLength: 19
example: '5808123456789808'
ObjPhoneNumber:
type: object
properties:
countryDialInCode:
type: string
description: The country code for the phone number. E.g. 1 for US or 44 for UK.
minLength: 1
maxLength: 4
example: '1'
phoneNumber:
type: string
description: The phone number, may contain country code along with phone number when countryDialInCode is not present.
minLength: 1
maxLength: 20
example: '4692392391'
description: The mobile phone number of the account holder. Not required.
prm_services:
type: array
description: Array of services that are being requested for the account. Must be one of ; DIGITIZATION = Provision the Funding Account to a device. Max length - Not applicable. Type - Array [String].
items:
type: string
example: DIGITIZATION
prm_tokenAssuranceLevel:
type: integer
description: The assurance level of the token. Between 0 and 99.
minLength: 1
maxLength: 2
ObjcardAccountData:
required:
- accountNumber
type: object
properties:
accountNumber:
type: string
$ref: '#/components/schemas/prm_accountNumber'
expiryMonth:
type: string
$ref: '#/components/schemas/prm_CardExpiryMonth'
expiryYear:
type: string
$ref: '#/components/schemas/prm_CardExpiryYear'
securityCode:
type: string
$ref: '#/components/schemas/prm_CardSecurityCode'
description: The card information for the account that is being tokenized.
prm_requestId:
type: string
description: "Unique ID assigned to the request. Use this identification in \ncase you need to report issues.\n"
example: '123456'
maxLength: 64
ObjBodyTokenUpdated:
type: object
required:
- tokens
properties:
tokens:
type: array
description: Arrary that contains the Tokens which were updated.
items:
$ref: '#/components/schemas/ObjToken_StatusUpdate'
prm_tokenActivatedDateTime:
type: string
description: 'Time Stamp in ISO 8601 format for example, 2017-07-21T17:32:28Z
'
example: '2022-04-25T23:19:12.000Z'
minLength: 24
maxLength: 24
RSIssuer_InvalidSignature:
type: object
required:
- code
- message
- datetime
properties:
code:
type: string
description: "Presented when error codes in business logic.\nAvailable Value\n401.22.992\tInvalid signature\n"
enum:
- 401.22.992
maxLength: 10
example: VSE40007
message:
type: string
description: Response code description
example: Invalid signature
maxLength: 140
datetime:
type: string
example: '2022-04-25T23:19:12.000Z'
description: 'Operation Time Stamp in ISO 8601 format
date-time - the date-time notation as defined by [RFC 3339, section 5.6](https://tools.ietf.org/html/rfc3339#section-5.6), for example, 2017-07-21T17:32:28Z
'
minLength: 24
maxLength: 24
prm_CardExpiryYear:
type: string
description: The year of the expiration date of the card to be digitized. Note that the expiry date may not be in the past. May be omitted if the card does not have an expiry date. (Numeric).
minLength: 2
maxLength: 2
example: '15'
ObjTokenInformation_ActSer:
type: object
required:
- source
- tokenType
- tokenUniqueReference
- tokenRequestorId
- accountPanSuffix
- serviceRequestDateTime
properties:
source:
type: string
$ref: '#/components/schemas/prm_source'
tokenType:
type: string
$ref: '#/components/schemas/prm_tokenType'
tokenUniqueReference:
type: string
$ref: '#/components/schemas/prm_tokenUniqueReference'
tokenRequestorId:
type: string
$ref: '#/components/schemas/prm_tokenRequestorID'
accountPanSuffix:
type: string
description: The last few digits (typically four) of the Account PAN being digitized.
minLength: 4
maxLength: 8
example: '1234'
serviceRequestDateTime:
type: string
description: The date and time the service for the PAN was requested. Expressed in ISO 8601 extended format as one of the following - YYYY-MM-DDThh:mm:ss[ .sss ]Z, YYYY-MM-DDThh:mm:ss[ .sss ]±hh:mm . Where [ .sss ] is optional and can be 1 to 3 digits.
minLength: 20
maxLength: 29
example: 2015-07-04 12:08:56.123000-07:00
panUniqueReference:
type: string
$ref: '#/components/schemas/prm_panUniqueReference'
tokenRequestorName:
type: string
$ref: '#/components/schemas/prm_tokenRequestorName'
cardId:
type: string
$ref: '#/components/schemas/prm_cardId'
walletId:
type: string
description: The identifier of the Wallet Provider who requested the digitization. Only present when the token is provided to a Wallet Provider.
minLength: 1
maxLength: 3
example: '123'
paymentAppInstanceId:
type: string
description: The identifier of the Payment App instance within a device that will be provisioned with a token. Only present when supplied by a Wallet Provider. Max length - 48. Type - String.
minLength: 1
maxLength: 48
example: 1b24f24a24ba98e27d43e345b532a245e4723d7a9c4f624e
secureElementId:
type: string
description: The identifier of the Secure Element to be provisioned with the token. Present only when the token is provisioned to a Secure Element and when provided by the Wallet Provider.
minLength: 1
maxLength: 128
example: 1b24f24a24ba98e27d43e345b532a245e4723d7a9c4f624e93452c
termsAndConditionsAssetId:
type: string
description: The Terms and Conditions as presented to and accepted by the Account holder.
minLength: 1
maxLength: 64
example: a9f027e5-629d-11e3-949a-0800200c9a66
termsAndConditionsAcceptedTimestamp:
type: string
description: The date and time the Terms and Conditions were accepted by the Account holder. Expressed in ISO 8601 extended format as one of the following - YYYY-MM-DDThh:mm:ss[ .sss ]Z, YYYY-MM-DDThh:mm:ss[ .sss ]±hh:mm . Where [ .sss ] is optional and can be 1 to 3 digits.
minLength: 20
maxLength: 29
example: 2015-07-04 12:09:56.123000-07:00
productConfigurationId:
type: string
description: Freeform identifier for the product configuration as assigned by the Issuer.
minLength: 1
maxLength: 64
example: '1234'
consumerLanguage:
type: string
description: Language preference selected by the consumer. Formatted as an ISO-639-1 two-letter language code.
minLength: 2
maxLength: 2
example: en
encryptedPayload:
type: string
$ref: '#/components/schemas/ObjencryptedPayload_ServiceActivated'
description: Payload Encrypted, contains information detailed about Card, Account Cardholder and Token Details
ObjAccountHolderAddress:
type: object
properties:
line1:
type: string
description: First line of the billing address.
minLength: 1
maxLength: 64
example: 100 1st Street
line2:
type: string
description: Second line of the billing address.
minLength: 1
maxLength: 64
example: Apt. 4B
city:
type: string
description: The city of the billing address.
minLength: 1
maxLength: 32
example: St. Louis
countrySubdivision:
type: string
description: The country subdivision (for example, the state in the U.S.) of the billing address.
minLength: 1
maxLength: 12
example: MO
postalCode:
type: string
description: The postal code (for example, zipcode in the U.S.) of the billing address.
minLength: 1
maxLength: 16
example: '61000'
country:
type: string
description: The country of the billing address. Expressed as a 3-letter (alpha-3) country code as defined in ISO 3166-1.
minLength: 3
maxLength: 3
example: USA
description: The address for the account holder. Verified as part of reaching the digitization decision. Max length - Not applicable.
prm_tokenType:
type: string
description: The type of token requested for this digitization. Valid values are - SE Token is a Secure Element, this kind of token is for Wallets. - HCE Token is used for contactless payments with NFC Chip. - COF Card on File Token, normally is used for recurrent payments. - ECOM Token is used for online payments, or payments started by the end-user. - QRC Token is used for QR Payments, only applicable for VISA.
enum:
- SE
- HCE
- COF
- ECOM
- QRC
minLength: 1
maxLength: 16
example: ECOM
prm_numberOfActivationAttempts:
type: integer
description: Number of intents with the OTP.
minLength: 1
maxLength: 1
prm_source:
type: string
description: 'Origin of the card information.
Available values:
- ON_FILE
- ADDED_MANUALLY
- ADDED_VIA_APPLICATION
- ADDED_VIA_BROWSER
- EXISTING_TOKEN_CREDENTIAL
- ADDED_VIA_CHIP_DATA
'
enum:
- ON_FILE
- ADDED_MANUALLY
- ADDED_VIA_APPLICATION
- ADDED_VIA_BROWSER
- EXISTING_TOKEN_CREDENTIAL
- ADDED_VIA_CHIP_DATA
maxLength: 32
example: ON_FILE
ObjFinancialAccountData:
required:
- countryCode
- financialAccountId
- interbankCardAssociationId
type: object
properties:
financialAccountId:
type: string
description: The identifier of the financial account being tokenized. This could be a bank account number or other types of financial accounts.
minLength: 9
maxLength: 64
example: '5123456789012345'
interbankCardAssociationId:
type: string
description: The id assigned by Mastercard to the financial institution.
minLength: 3
maxLength: 11
example: '1234'
countryCode:
type: string
description: The country of the financial account. Expressed as a 3-letter (alpha-3) country code as defined in ISO 3166-1.
minLength: 3
maxLength: 3
example: GBR
description: The financial account information for the account that is being tokenized. – Required if there is a bank account or other type of financial account being tokenized. Only applicable for MasterCard.
prm_cardId:
type: string
description: 'Unique Card Identifier at NovoPayment’s Issuance Service, of Original Card.
'
maxLength: 40
example: 5DA...27
prm_TokenExpiryYear:
type: string
description: The year of the expiration date. (Numeric)
minLength: 2
maxLength: 2
example: '15'
ObjBodyServiceActivated:
type: object
required:
- services
- correlationId
- decision
- tokenInformation
- decisionMadeBy
- tokenActivatedDateTime
properties:
services:
type: array
$ref: '#/components/schemas/prm_services'
correlationId:
type: string
description: "Identification of the Tokenization Process. This value linked \nboth processes.\n"
example: D98765432104
maxLength: 14
decision:
type: string
$ref: '#/components/schemas/prm_decision'
decisionMadeBy:
type: string
$ref: '#/components/schemas/prm_decisionMadeBy'
tokenActivatedDateTime:
$ref: '#/components/schemas/prm_tokenActivatedDateTime'
numberOfActivationAttempts:
$ref: '#/components/schemas/prm_decisionMadeBy'
numberOfActiveTokens:
$ref: '#/components/schemas/prm_numberOfActivationAttempts'
tokenAssuranceLevel:
$ref: '#/components/schemas/prm_tokenAssuranceLevel'
tokenInformation:
type: object
$ref: '#/components/schemas/ObjTokenInformation_ActSer'
ObjBodyNotSuspiciousEv:
required:
- tokenUniqueReference
- events
type: object
properties:
tokenUniqueReference:
type: string
$ref: '#/components/schemas/prm_tokenUniqueReference'
tokenRequestorId:
type: string
$ref: '#/components/schemas/prm_tokenRequestorID'
tokenRequestorName:
type: string
$ref: '#/components/schemas/prm_tokenRequestorName'
cardId:
type: string
$ref: '#/components/schemas/prm_cardId'
status:
type: string
description: "The current status of token. Available Values: INACTIVE - Token has not yet been activated ACTIVE - Token is active and ready to transact SUSPENDED - Token is suspended and unable to transact DEACTIVATED - Token has been permanently deactivated. Present only if reasonCode = \"STATUS_UPDATE\". \n"
minLength: 1
maxLength: 32
example: ACTIVE
paymentAppInstanceId:
type: string
description: The identifier of the Payment App instance within a device that will be provisioned with a token. Only present when supplied by a Wallet Provider.
minLength: 1
maxLength: 48
example: 1b24f24a24ba98e27d43e345b532a245e4723d7a9c4f624e
events:
$ref: '#/components/schemas/SuspiciousEvent'
prm_tokenRequestorID:
type: integer
description: 'Unique ID assigned to the entity that is requesting the token.
'
example: 40022358888
prm_sequenceNumber:
type: string
description: Sequence number of the Token. Conditional – required in AuthorizeServiceResponseData. Optional otherwise.
minLength: 2
maxLength: 2
example: '01'
RS200:
type: object
properties:
code:
type: string
description: Operation response code
example: 200.22.000
maxLength: 10
message:
type: string
description: Response code description
example: Process Ok
maxLength: 140
datetime:
type: string
description: 'Operation Time Stamp in ISO 8601 format date-time - the date-time notation as defined by
[RFC 3339, section 5.6](https://tools.ietf.org/html/rfc3339#section-5.6), for example, 2017-07-21T17:32:28Z
'
example: '2022-04-25T23:19:12.000Z'
minLength: 24
maxLength: 24
RQSendVerifyCode:
type: object
required:
- correlationId
- requestId
- activationCode
- codeExpiration
- activationMethod
properties:
correlationId:
type: string
description: "Identification of the Tokenization Process. This value linked \nboth processes.\n"
example: D98765432104
maxLength: 14
requestId:
type: string
$ref: '#/components/schemas/prm_requestId'
tokenRequestorID:
type: integer
description: 'Unique ID assigned to the entity that is requesting the token.
'
example: 40022358888
tokenRequestorName:
type: string
description: 'Name of the token requestor.
'
example: My Merchant
tokenUniqueReference:
type: string
description: "Unique ID associating a token with a card. This ID can be used in \nfuture calls to make operations related to the token in the I-TSP, \nfor example events related to the management of the life cycle.\n"
example: DWSPMC000000000132d72d4fcb2f4136a0532d3093ff1a45
maxLength: 64
panUniqueID:
type: string
description: "Unique ID representing a card. This ID can be used instead of the \nPAN number for tokenization calls.\n"
example: V-3019231458906209630635
cardId:
type: string
description: "Unique Identification for the card in NovoPayment Issuance Services.\nThis value only exists for Issuers that are clients of NovoPayment \nIssuance Services.\n"
maxLength: 40
clientWalletAccountID:
type: string
description: "Identifier of the wallet that sends the request. Client provided \nconsumer ID that identifies the wallet account holder entity. \nOnly available for VISA.\n"
maxLength: 32
otpMaxReached:
type: boolean
description: "If this field is active, it means the user with the referenced token \nhas exceeded the number of requests for authentication methods or OTP \nrequests, thus, the response must not include the value when requesting \nthem again. Only available for VISA.\n"
activationCode:
type: string
description: 'The value that the cardholder needs to validate his/her identity.
'
example: A1B2C3D4
maxLength: 8
reasonCodes:
type: array
description: "Array of OTP reason codes.\nAllowed values: \n- ADD_CARD: The account holder is being authenticated after adding \nthe card to the token requestor.\n- VERIFY_ACCOUNT: The account holder is being authenticated to verify \naccount ownership.\n- OTHER: The account holder is being authenticated for a reason not \nenumerated in this list. Conditional - Only present for Consent Service\n"
example:
- ADD_CARD
codeExpiration:
type: string
description: 'Token expiration date. Format: yyyy-MM-ddTHH:mm:ss.SSSZ
'
example: 2026-07-04 19:08:56.123000+00:00
activationMethod:
$ref: '#/components/schemas/ObjActivationMethod'
ObjTokenData:
required:
- expiryMonth
- expiryYear
- token
type: object
properties:
token:
type: string
description: The token issued for this service request.
minLength: 12
maxLength: 19
example: '5345678901234521'
expiryMonth:
type: string
$ref: '#/components/schemas/prm_TokenExpiryMonth'
expiryYear:
type: string
$ref: '#/components/schemas/prm_TokenExpiryYear'
sequenceNumber:
type: string
$ref: '#/components/schemas/prm_sequenceNumber'
description: Only present if reason code is Redigitization, not present otherwise.
description: Detailed information of the token.
prm_CardExpiryMonth:
type: string
description: The month of the expiration date of the card to be digitized. Note that the expiry date may not be in the past. May be omitted if the card does not have an expiry date. (Numeric).
minLength: 2
maxLength: 2
example: '12'
RQNotTokenUpdated:
type: object
required:
- requestId
- reasonCode
- dateTime
- notificationBody
properties:
requestId:
type: string
$ref: '#/components/schemas/prm_requestId'
reasonCode:
type: string
description: "The reason that cause the notification.\nAvailable values:\nREDIGITIZATION_COMPLETE : The token has been re-digitized to the device in the token expiry and FPAN update to a new range use cases.\nDELETED_FROM_CONSUMER_APP : The token has been deleted from the consumer application. The token may still be active in MDES\nSTATUS_UPDATE : The status of the tokens has been changed when the token is activated, suspended, deleted, or inactivated.\nAUTHENTICATION_PERFORMED - Account holder authentication was performed on the token. \nPAYMT_CHANNEL_PREFERENCE_UPDATED - Cardholder has updated the payment channels the token is allowed to be used for (India only).\nFUNDING_ACCOUNT_UPDATE - Token and FPAN mapping has been updated due to FPAN or expiry or Financial account has been changed but Token is not changed. The status did not change as a result.\n"
enum:
- REDIGITIZATION_COMPLETE
- DELETED_FROM_CONSUMER_APP
- STATUS_UPDATE
- AUTHENTICATION_PERFORMED
- PAYMT_CHANNEL_PREFERENCE_UPDATED
- FUNDING_ACCOUNT_UPDATE
example: STATUS_UPDATE
dateTime:
type: string
description: 'dateTime. Format: yyyy-MM-ddTHH:mm:ss.SSSZ
'
example: 2026-07-04 19:08:56.123000+00:00
notificationBody:
$ref: '#/components/schemas/ObjBodyTokenUpdated'
prm_CardSecurityCode:
type: string
description: The CVC2 for the card to be digitized, as entered by the Cardholder. Verified as part of reaching the digitization decision.
minLength: 3
maxLength: 3
example: '123'
SuspiciousEvent:
required:
- eventName
type: object
properties:
eventName:
type: string
description: The name of the suspicious event. Must be one of; REPLENISH - There were suspicious ATC values reporting during Replenish
minLength: 1
maxLength: 32
example: REPLENISH
walletAtcStatus:
$ref: '#/components/schemas/WalletAtcStatus'
description: The ATCs statuses are reported by the wallet. Required if EventName is REPLENISH.
systemAtcStatus:
$ref: '#/components/schemas/SystemAtcStatus'
description: The ATCs statuses as reported by authorization network. Required if EventName is REPLENISH
prm_TokenExpiryMonth:
type: string
description: The month of the expiration date.(Numeric)
minLength: 2
maxLength: 2
example: '12'
RSInternalServerError:
type: object
properties:
code:
type: string
example: 500.22.999
description: Operation response code
minLength: 10
maxLength: 10
message:
type: string
example: Internal Server Error
description: Response code description
maxLength: 140
datetime:
type: string
example: '2022-04-25T23:19:12.000Z'
minLength: 24
maxLength: 24
RQNotSuspiciousEvents:
type: object
required:
- requestId
- reasonCode
- dateTime
- notificationBody
properties:
requestId:
type: string
$ref: '#/components/schemas/prm_requestId'
reasonCode:
type: string
description: 'SUSPICIOUS_EVENTS
'
enum:
- SUSPICIOUS_EVENTS
example: SUSPICIOUS_EVENTS
dateTime:
type: string
description: 'dateTime. Format: yyyy-MM-ddTHH:mm:ss.SSSZ
'
example: 2026-07-04 19:08:56.123000+00:00
notificationBody:
$ref: '#/components/schemas/ObjBodyNotSuspiciousEv'
WalletAtcStatus:
type: object
properties:
unusedDiscarded:
type: array
description: The ATCs reported by the wallet that are unused discarded. Max length - Not applicable. Type - Array[String].
items:
type: string
example: '1234'
usedForContactless:
type: array
description: The ATCs reported by the wallet that are used for contactless transaction. Max length - Not applicable. Type - Array[String].
items:
type: string
example: '1234'
usedForDsrp:
type: array
description: The ATCs reported by the wallet that are used for DSRP transaction. Max length - Not applicable. Type - Array[String]
items:
type: string
example: '1234'
unusedActive:
type: array
description: The ATCs reported by the wallet that are unused active. Max length - Not applicable. Type - Array[String]
items:
type: string
example: '1234'
description: The ATCs statuses are reported by the wallet. Conditional – required if EventName is REPLENISH
RSFromIssuer_BadRequest:
type: object
required:
- code
- data
- message
- datetime
properties:
code:
type: string
description: "Presented when error codes in business logic.\nAvailable Values\n400.22.002\tJWE invalid format\n400.22.003\tParams Required\n400.22.009\tInvalid Card ID\n"
enum:
- 400.22.002
- 400.22.003
- 400.22.009
maxLength: 10
example: 400.22.009
data:
type: object
description: Required when Error Code is Params Required, include the list.
maxLength: 2
example:
- fieldName
message:
type: string
description: Response code description
example: Params required
maxLength: 140
datetime:
type: string
example: '2022-04-25T23:19:12.000Z'
description: 'Operation Time Stamp in ISO 8601 format
date-time - the date-time notation as defined by [RFC 3339, section 5.6](https://tools.ietf.org/html/rfc3339#section-5.6), for example, 2017-07-21T17:32:28Z
'
minLength: 24
maxLength: 24
prm_decisionMadeBy:
type: string
description: "Related to how the decision was taken, aply for MasterCard; \nfor VISA the content is goint to be UNDEFINED.\n"
enum:
- ELIGIBILITY_REQUEST
- AUTHORIZATION_REQUEST
- RULES
- UNDEFINED
example: RULES
maxLength: 14
SystemAtcStatus:
type: object
properties:
atcNotFound:
type: array
description: The ATCs reported by the authorization network as not found. Max length - Not applicable. Type - Array[String].
items:
type: string
example: '1234'
atcAlreadyProcessed:
type: array
description: The ATCs reported by the authorization network as processed for a transaction. Max length - Not applicable. Type - Array[String].
items:
type: string
example: '1234'
atcReportedUsedByWallet:
type: array
description: The ATCs prviously reported by the wallet as processed or discarded. Max length - Not applicable. Type - Array[String]
items:
type: string
example: '1234'
unusedActive:
type: array
description: The ATCs reported by the wallet that are unused active. Max length - Not applicable. Type - Array[String]
items:
type: string
example: '1234'
description: The ATCs statuses as reported by authorization network. Conditional – required if EventName is REPLENISH
prm_status:
type: string
description: "The current status of token. Available Values: INACTIVE - Token has not yet been activated ACTIVE - Token is active and ready to transact SUSPENDED - Token is suspended and unable to transact DEACTIVATED - Token has been permanently deactivated. Present only if reasonCode = \"STATUS_UPDATE\". \n"
minLength: 1
maxLength: 32
example: ACTIVE
ObjToken_StatusUpdate:
type: object
required:
- tokenUniqueReference
properties:
tokenUniqueReference:
type: string
$ref: '#/components/schemas/prm_tokenUniqueReference'
tokenRequestorId:
type: string
$ref: '#/components/schemas/prm_tokenRequestorID'
tokenRequestorName:
type: string
$ref: '#/components/schemas/prm_tokenRequestorName'
cardId:
type: string
$ref: '#/components/schemas/prm_cardId'
status:
type: string
$ref: '#/components/schemas/prm_status'
suspendedBy:
type: array
description: "The origin of the token suspension, Present only if status = SUSPENDED except for VISA. Available Values: ISSUER = Suspended by the Issuer. PaymentAppProvider unable to unsuspend this token, TOKEN_REQUESTOR = Suspended by the Token Requestor, MOBILE_PIN_LOCKED = Suspended due to the Mobile PIN being locked, CARDHOLDER = Suspended by the Cardholder. \n"
enum:
- ISSUER
- PaymentAppProvider
- TOKEN_REQUESTOR
- MOBILE_PIN_LOCKED
- CARDHOLDER
items:
type: string
example: ISSUER
tokenExpiry:
type: string
description: 'The expiry of the Token PAN given in MMYY format. Present only if reasonCode is "REDIGITIZATION_COMPLETE".
'
minLength: 4
maxLength: 4
example: '0721'
encryptedPayload:
type: object
$ref: '#/components/schemas/ObjencryptedPayload_StatusUpdate'
ObjencryptedPayload_ServiceActivated:
required:
- cardAccountData
type: object
properties:
source:
type: string
$ref: '#/components/schemas/prm_source'
dataValidUntilTimestamp:
type: string
description: "The date/time after which this encrypted object is considered invalid. If present, all systems must reject this encrypted object after this time and treat it as invalid data. Must be expressed in ISO 8601 extended format as one of the following:\n - YYYY-MM-DDThh:mm:ss[.sss]Z\n - YYYY-MM-DDThh:mm:ss[.sss]±hh:mm\n\nWhere [.sss] is optional and can be 1 to 3 digits. Must be a value no more than 30 days in the future. Mastercard recommends using a value of (Current Time + 30 minutes).\n"
minLength: 20
maxLength: 29
example: 2015-07-04 12:09:56.123000-07:00
cardAccountData:
$ref: '#/components/schemas/ObjcardAccountData'
financialAccountData:
$ref: '#/components/schemas/ObjFinancialAccountData'
tokenData:
$ref: '#/components/schemas/ObjTokenData'
description: The token information.
paymentAccountReference:
type: string
description: The unique account reference assigned to the PAN.
minLength: 29
maxLength: 29
example: 512381d9f8e0629211e3949a08002
accountHolderData:
$ref: '#/components/schemas/ObjAccountHolderData'
prm_tokenRequestorName:
type: string
description: 'Name of the token requestor.
'
example: My Merchant
requestBodies:
RQCardInfo:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/RQCardInfo'
RQCheckEligibility:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/RQCheckEligibility'
RQNotification:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/RQNotification'
examples:
TOKEN_CREATED:
$ref: '#/components/examples/RQNotificationTokenCreated'
TOKEN_ACTIVATION_STIP:
$ref: '#/components/examples/RQNotificationTokenActivationSTIP'
TOKEN_STATUS_UPDATE:
$ref: '#/components/examples/RQNotificationTokenStatusUpdate'
PAN_UPDATE:
$ref: '#/components/examples/RQNotificationPanUpdate'
CARD_METADATA_UPDATED:
$ref: '#/components/examples/RQNotificationCardMetadataUpdate'
RQApproveProvision:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/RQApproveProvision'
RQSendPasscode:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/RQSendPasscode'
RQCardholderVerificationMethods:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/RQCardholderVerificationMethods'
RQDeviceTokenBinding:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/RQDeviceTokenBinding'
RQNotSuspiciousEvents:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/RQNotSuspiciousEvents'
examples:
SUSPICIOUS_EVENTS:
$ref: '#/components/examples/RQNotificationSuspiciousEvents'
RQNotTokenUpdated:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/RQNotTokenUpdated'
examples:
REDIGITIZATION_COMPLETE:
$ref: '#/components/examples/RQNotificationRedigitizationComplete'
DELETED_FROM_CONSUMER_APP:
$ref: '#/components/examples/RQNotificationSU_DeletedFromApp'
SUSPENDED:
$ref: '#/components/examples/RQNotificationSU_Suspend'
ACTIVATED:
$ref: '#/components/examples/RQNotificationSU_Activated'
TOKEN_EXPIRY:
$ref: '#/components/examples/RQNotificationSU_TokenExpiry'
PAN_SAME_RANGE:
$ref: '#/components/examples/RQNotificationSU_PANSameRange'
AUTHENTICATION_PERFORMED:
$ref: '#/components/examples/RQNotificationSU_AuthenticationPerf'
RQSendVerifyCode:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/RQSendVerifyCode'
RQNotServiceActivated:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/RQNotServiceActivated'
examples:
SERVICE_ACTIVATED:
$ref: '#/components/examples/RQNotServiceActivated'
examples:
InvalidParams:
value:
code: 400.22.396
message: Invalid parameters.
datetime: '2024-07-17T00:57:36.360Z'
RQNotificationPanUpdate:
value:
eventType: PAN_UPDATED
panReferenceID: V-3021084701796922123456
messageReason: Account updated OK
messageReasonCode: ACCOUNT_UPDATE
dateTimeOfEvent: '2022-04-25T23:19:12.000Z'
accountLevelInfoResp: null
RSErrorCode400-ISE40006:
description: ISS_ERROR_INVALID_FIELD_TYPE
value:
errorCode: ISE40006
ErrorGeneralService:
value:
code: 400.22.350
message: Error General Service.
datetime: '2022-04-25T23:19:12.000Z'
RSErrorCode400-ISE40000:
description: ISS_ERROR_REQUIRED_DATA_MISSING
value:
errorCode: ISE40000
RQNotificationTokenCreated:
value:
eventType: TOKEN_CREATED
panReferenceID: V-3021084701796922123456
tokenReferenceID: DNITHE30161617843905731102000000
tokenRequestorID: 40000000055
messageReason: Token created successfully
messageReasonCode: TOKEN_CREATED
dateTimeOfEvent: 2022-04-25 23:19:12+00:00
deviceInfo:
deviceID: OTc0MzJhMmEtYWUxOC0zMGUy
deviceLanguageCode: eng
deviceType: MOBILE_PHONE
deviceName: TTIxMDJKMjBTRw..
osType: ANDROID
osVersion: 11
osBuildID: RKQ1.200826.002
deviceIDType: Derived
deviceManufacturer: Xiaomi
deviceBrand: POCO
deviceModel: M2102J20SG
tokenProtectionMethod: SOFTWARE
encryptedData: ZXlKMGVYQWlPaUpLV...qdHgzd2dod1pJbkN2d3Qtdy1jRTJ1cGVDekZnN3o0Zk5wRFRFOV...enUxME1nWkJTQXVEQ3ZfVzlZaVZUdEx1TGli...NOWFphSWxtN1ZfY0pZOUpEdFZFTWROWjNy...WaGdGT3ZRQWx5O
actionCode: 0
lifeCycleTraceID: 302291744095994
clientWalletAccountID: 7f7e9cef-1234
panSource: KEY_ENTERED
cvv2ResultsCode: M
consumerEntryMode: UNKNOWN
locale: en_US
termsAndConditions:
id: 3f7f87ae2ff0439f80f322ec3dfa8777
date: 1970-01-03T10:45:18.000+0000
tokenRequestorTspID: 40000000055
walletAccountEmailAddressHash: A9C49C43A63249115F6DD9CD72C6A8AC58F5D44E35EDC6D36CFF999BAC3B228E
addressVerificationResultCode: A
RQNotificationCardMetadataUpdate:
value:
eventType: CARD_METADATA_UPDATED
tokenReferenceID: DNITHE302213059337966526
tokenRequestorID: 40010021347
messageReasonCode: CARD_METADATA_UPDATED
taskID: ed39279e-2fc7-43f6-b89d-756420564c91
statusCode: FAILURE
errorCode: VSE40001
CardNotFound:
value:
code: 400.22.487
message: Card not found
datetime: '2024-08-13T00:18:05.183Z'
ComponentConfigurationNotFound:
value:
code: 400.22.356
message: Component configuration not found.
datetime: '2024-07-17T00:57:36.360Z'
InternalServerError:
value:
code: 500.22.001
message: Internal Server Error
datetime: '2022-04-25T23:19:12.000Z'
RQNotificationTokenStatusUpdate:
value:
eventType: TOKEN_STATUS_UPDATED
panReferenceID: V-3021084701796922123456
tokenReferenceID: DNITHE30161617843905731102000000
tokenRequestorID: 40000000055
messageReason: Test status update
messageReasonCode: TOKEN_DEVICE_BINDING_RESULT
dateTimeOfEvent: '2022-04-25T23:19:12.000Z'
deviceInfo:
deviceID: OTc0MzJhMmEtYWUxOC0zMGUy
deviceLanguageCode: eng
deviceType: MOBILE_PHONE
deviceName: TTIxMDJKMjBTRw..
osType: ANDROID
osVersion: 11
osBuildID: RKQ1.200826.002
deviceIDType: Derived
deviceManufacturer: Xiaomi
deviceBrand: POCO
deviceModel: M2102J20SG
tokenProtectionMethod: SOFTWARE
encryptedData:
panReferenceID: V-3019231458906209630635
tokenReferenceID: DNITHE30194726875288888
tokenRequestorID: 40022358888
messageReason: TOKEN_CREATED
dateTimeOfEvent: 2019-11-04T20:32:50.000z
deviceInfo:
deviceID: CTF0000000001
deviceType: MOBILE_PHONE
deviceName: MyCTFDeviceTEst
deviceNumber: 6506198963
deviceIndex: 1
termsAndConditions:
id: 13c5e2ba-eb5c-432d-a027-97ddaf109af1
date: 111115
actionCode: 0
lifeCycleTraceID: 302291744095994
tokenRequestorTspID: 40000000055
deviceID: OTc0MzJhMmEtYWUxOC0zMGUy
activationVerificationResult: VERIFICATION_SUCCESS
cardHolderStepupResult: CARDHOLDER_STEPUP_OTP
deviceBindingResult: DEVICE_BINDING_CALL_CENTER
trustedListingResult: TRUSTED_LISTING_ADDED
merchantInfo:
merchantID: 421
merchantName: Mi comercio
tokenUserInfo: null
RSErrorCode400-ISE40005:
description: ISS_ERROR_INVALID_FIELD_LENGTH
value:
errorCode: ISE40005
RQNotificationTokenActivationSTIP:
value:
eventType: TOKEN_ACTIVATION_STIP
panReferenceID: V-3021084701796922123456
tokenReferenceID: DNITHE30161617843905731102000000
tokenRequestorID: 40000000055
messageReasonCode: TOKEN_ACTIVATION_STIP
dateTimeOfEvent: 2021-03-30 19:50:15+00:00
deviceInfo:
deviceID: WIRO202110
deviceLanguageCode: eng
deviceType: MOBILE_PHONE
deviceName: MyXvv73vv73vv70.
deviceNumber: 7868671470
osType: ANDROID
osVersion: 4.4.4
osBuildID: KTU84M
deviceIDType: TEE
deviceManufacturer: Samsung
deviceBrand: Android Brand
deviceModel: ANDROID-999
tokenProtectionMethod: SOFTWARE
encryptedData: ZXlKMGVYQWlPaUpLV...qdHgzd2dod1pJbkN2d3Qtdy1jRTJ1cGVDekZnN3o0Zk5wRFRFOV...enUxME1nWkJTQXVEQ3ZfVzlZaVZUdEx1TGli...NOWFphSWxtN1ZfY0pZOUpEdFZFTWROWjNy...WaGdGT3ZRQWx5O
actionCode: N7
lifeCycleTraceID: 302291744095994
clientWalletAccountID: 7f7e9cef-1234
panSource: KEY_ENTERED
cvv2ResultsCode: N
consumerEntryMode: UNKNOWN
locale: en_US
stipReasonCode: 9020
tokenRequestorTspID: 40000000055
walletAccountEmailAddressHash: A9C49C43A63249115F6DD9CD72C6A8AC58F5D44E35EDC6D36CFF999BAC3B228E
addressVerificationResultCode: X
RSErrorCode400-ISE40010:
description: ISS_ERROR_CRYPTOGRAPHY_ERROR
value:
errorCode: ISE40010
RSErrorCode400-ISE40001:
description: ISS_ERROR_PAN_INELIGIBLE
value:
errorCode: ISE40001
RSErrorCode400-ISE40013:
description: ISS_ERROR_INVALID_EXP_DATE
value:
errorCode: ISE40013
HeaderParamsRequired:
value:
code: 400.22.001
message: Header Params Required
datetime: '2022-04-25T23:19:12.000Z'
InvalidadCardId:
value:
code: 400.22.009
message: Invalid Card Id
datetime: '2022-04-25T23:19:12.000Z'
RQNotificationSuspiciousEvents:
value:
requestId: 808808080808
reasonCode: SUSPICIOUS_EVENTS
dateTime: 2026-07-04 19:08:56.123000+00:00
notificationBody:
tokenUniqueReference: DWSPMC000000000132d72d4fcb2f4136a0532d3093ff1a45
tokenRequestorId: 40022358888
tokenRequestorName: My Merchant
cardId: 5DA...27
status: ACTIVE
paymentAppInstanceId: 1b24f24a24ba98e27d43e345b532a245e4723d7a9c4f624e
events:
- eventName: REPLENISH
walletAtcStatus:
- unusedDiscarded: 1234
usedForContactless: 1234
usedForDsrp: 1234
unusedActive: 1234
SystemAtcStatus:
- atcNotFound: 1234
atcAlreadyProcessed: 1234
atcReportedUsedByWallet: 1234
unusedActive: 1234
InvalidSignature:
value:
code: 401.22.992
message: Invalid signature
datetime: '2022-04-25T23:19:12.000Z'
RQNotificationSU_DeletedFromApp:
value:
requestId: 808808080808
reasonCode: DELETED_FROM_CONSUMER_APP
dateTime: 2026-07-04 19:08:56.123000+00:00
notificationBody:
tokens:
tokenUniqueReference: DWSPMC000000000132d72d4fcb2f4136a0532d3093ff1a45
tokenRequestorId: 40022358888
tokenRequestorName: My Merchant
cardId: 5DA...27
RQNotServiceActivated:
value:
requestId: 808808080808
reasonCode: SERVICE_ACTIVATED
dateTime: 2026-07-04 19:08:56.123000+00:00
notificationBody:
services:
- DIGITIZATION
correlationId: D98765432104
decision: APPROVED
decisionMadeBy: RULES
tokenActivatedDateTime: 2022-04-25 23:19:12+00:00
numberOfActivationAttempts: RULES
numberOfActiveTokens: 0
tokenAssuranceLevel: 0
tokenInformation:
source: ON_FILE
tokenType: ECOM
tokenUniqueReference: DWSPMC000000000132d72d4fcb2f4136a0532d3093ff1a45
tokenRequestorId: 40022358888
accountPanSuffix: 1234
serviceRequestDateTime: 2015-07-04 12:08:56.123000-07:00
panUniqueReference: FWSPMC000000000159f71f703d2141efaf04dd26803f922b
tokenRequestorName: My Merchant
cardId: 5DA...27
walletId: 123
paymentAppInstanceId: 1b24f24a24ba98e27d43e345b532a245e4723d7a9c4f624e
secureElementId: 1b24f24a24ba98e27d43e345b532a245e4723d7a9c4f624e93452c
termsAndConditionsAssetId: a9f027e5-629d-11e3-949a-0800200c9a66
termsAndConditionsAcceptedTimestamp: 2015-07-04 12:09:56.123000-07:00
productConfigurationId: 1234
consumerLanguage: en
encryptedPayload:
source: ON_FILE
dataValidUntilTimestamp: 2015-07-04 12:09:56.123000-07:00
cardAccountData:
accountNumber: 5808123456789808
expiryMonth: 12
expiryYear: 15
securityCode: 808
financialAccountData:
financialAccountId: 5123456789012345
interbankCardAssociationId: 1234
countryCode: GBR
tokenData:
token: 5345678901234521
expiryMonth: 12
expiryYear: 15
sequenceNumber: 1
paymentAccountReference: 512381d9f8e0629211e3949a08002
accountHolderData:
accountHolderName: John Doe
accountHolderEmailAddress: abcdef@xyz.com
accountHolderMobilePhoneNumber:
countryDialInCode: 1
phoneNumber: 4692392391
accountHolderAddress:
line1: 100 1st Street
line2: Apt. 4B
city: St. Louis
countrySubdivision: MO
postalCode: 61000
country: USA
sourceIp: 127.0.0.1
deviceLocation: 38.63/-90.2
consumerIdentifier: 1b24f24a24ba98e27d43e345b532a245e4723d7a9c4f624e93452c1b24f24a24b
ParamsRequired:
value:
code: 400.22.324
message: We were unable to process your request
datetime: '2022-04-25T23:19:12.000Z'
data: "\"fieldName\":\n [\n \"reasonCodes\",\n \"tokenUniqueReference\"\n ]\n"
RQNotificationSU_PANSameRange:
value:
requestId: 808808080808
reasonCode: REDIGITIZATION_COMPLETE
dateTime: 2026-07-04 19:08:56.123000+00:00
notificationBody:
tokens:
tokenUniqueReference: DWSPMC000000000132d72d4fcb2f4136a0532d3093ff1a45
tokenRequestorId: 40022358888
tokenRequestorName: My Merchant
cardId: 5DA...27
tokenExpiry: 465
encryptedPayload:
dataValidUntilTimestamp: 2015-07-04 12:09:56.123000-07:00
cardAccountData:
accountNumber: 5808123456789808
expiryMonth: 12
expiryYear: 15
securityCode: 123
tokenData:
token: 5345678901234521
expiryMonth: 12
expiryYear: 15
sequenceNumber: 1
RQNotificationSU_TokenExpiry:
value:
requestId: 808808080808
reasonCode: REDIGITIZATION_COMPLETE
dateTime: 2026-07-04 19:08:56.123000+00:00
notificationBody:
tokens:
tokenUniqueReference: DWSPMC000000000132d72d4fcb2f4136a0532d3093ff1a45
tokenRequestorId: 40022358888
tokenRequestorName: My Merchant
cardId: 5DA...27
tokenExpiry: 465
encryptedPayload:
dataValidUntilTimestamp: 2015-07-04 12:09:56.123000-07:00
tokenData:
token: 5345678901234521
expiryMonth: 12
expiryYear: 15
sequenceNumber: 1
InternalServerError_2:
value:
code: 500.22.999
message: Internal Server Error
datetime: '2022-04-25T23:19:12.000Z'
JWEInvalidFormat:
value:
code: 400.22.002
message: JWE Invalid format
datetime: '2022-04-25T23:19:12.000Z'
RQNotificationRedigitizationComplete:
value:
requestId: 808808080808
reasonCode: REDIGITIZATION_COMPLETE
dateTime: 2026-07-04 19:08:56.123000+00:00
notificationBody:
tokens:
- tokenUniqueReference: DWSPMC000000000132d72d4fcb2f4136a0532d3093ff1a45
tokenRequestorId: 40022358888
tokenRequestorName: My Merchant
cardId: 5DA...27
tokenExpiry: 465
encryptedPayload:
panUniqueReference: FWSPMC000000000159f71f703d2141efaf04dd26803f922b
dataValidUntilTimestamp: 2015-07-04 12:09:56.123000-07:00
source: ON_FILE
cardAccountData:
accountNumber: 5808123456789808
expiryMonth: 12
expiryYear: 15
securityCode: 123
financialAccountData:
financialAccountId: 5123456789012345
interbankCardAssociationId: 1234
countryCode: GBR
tokenData:
token: 5345678901234521
expiryMonth: 12
expiryYear: 15
sequenceNumber: 1
paymentAccountReference: 512381d9f8e0629211e3949a08002
RQNotificationSU_Activated:
value:
requestId: 808808080808
reasonCode: STATUS_UPDATE
dateTime: 2026-07-04 19:08:56.123000+00:00
notificationBody:
tokens:
tokenUniqueReference: DWSPMC000000000132d72d4fcb2f4136a0532d3093ff1a45
tokenRequestorId: 40022358888
tokenRequestorName: My Merchant
cardId: 5DA...27
status: ACTIVE
tokenExpiry: 465
RQNotificationSU_AuthenticationPerf:
value:
requestId: 808808080808
reasonCode: AUTHENTICATION_PERFORMED
dateTime: 2026-07-04 19:08:56.123000+00:00
notificationBody:
tokens:
tokenUniqueReference: DWSPMC000000000132d72d4fcb2f4136a0532d3093ff1a45
tokenRequestorId: 40022358888
tokenRequestorName: My Merchant
cardId: 5DA...27
tokenExpiry: 465
RQNotificationSU_Suspend:
value:
requestId: 808808080808
reasonCode: STATUS_UPDATE
dateTime: 2026-07-04 19:08:56.123000+00:00
notificationBody:
tokens:
tokenUniqueReference: DWSPMC000000000132d72d4fcb2f4136a0532d3093ff1a45
tokenRequestorId: 40022358888
tokenRequestorName: My Merchant
cardId: 5DA...27
status: SUSPENDED
suspendedBy: '[ISSUER]
'
tokenExpiry: 465
responses:
RS500:
description: 'Internal Server Error. Visa must send request again or contact the
issuer support.---
'
RSDeviceTokenBinding200:
description: Successful Operation response code
content:
application/json:
schema:
$ref: '#/components/schemas/RSDeviceTokenBinding200'
examples:
Default:
value:
actionCode: '00'
RSCardInfo200:
description: Successful Operation response code
content:
application/json:
schema:
$ref: '#/components/schemas/RSCardInfo200'
examples:
Default:
value:
code: 200.22.000
message: Process Ok
datetime: '2022-04-25T23:19:12.000Z'
data:
cardInfoList:
- cardId: 866f4af6-69a8-4c51-9940-95bdd05124c6
cardProduct: Lynk Visa Debit
cardProductId: '2'
cardStatus: Active
cardStatusId: '1'
cardType: Debit
cardTypeId: '1'
customerName: Gen Lynk
expirationDate: '2810'
maskedNumber: '************8603'
pan: '4537850008998603'
- cardId: f18eaabb-bdce-43eb-b17a-e5560f36687c
cardProduct: Lynk Visa Debit
cardProductId: '2'
cardStatus: Active
cardStatusId: '1'
cardType: Debit
cardTypeId: '1'
customerName: Gen Lynk
expirationDate: '2902'
maskedNumber: '************9932'
pan: '4537850004369932'
RSApproveProvision200:
description: Successful Operation response code
content:
application/json:
schema:
$ref: '#/components/schemas/RSApproveProvision200'
examples:
Default:
value:
actionCode: '00'
addressVerificationResultCode: ''
cvv2ResultsCode: M
issuerSpecialConditionCodes:
issuerDiscretionaryData: ''
fileControlInformation: ''
issuerApplicationDiscretionaryData: ''
RSCardholderVerificationMethods200:
description: Successful Operation response code
content:
application/json:
schema:
$ref: '#/components/schemas/RSCardholderVerificationMethods200'
examples:
Default:
value:
responseCode: STEPUP
stepUpMethods:
- value: '****-4422'
type: OTPSMS
identifier: 66a031837fe947569f4f6c9953f57293
sourceAddress: email
otpMethodPlatform: IOS
- value: an*************@gmail.com
type: OTPEMAIL
identifier: mar43cb1f23b4cdbbd9b5b7a6ec41vcg
sourceAddress: 382-2
otpMethodPlatform: IOS
- value: 1-800-227-8431
type: OUTBOUNDCALL
identifier: ba6031837fe947569f4f6c9953f57abd
RSCheckEligibility200:
description: Successful Operation response code
content:
application/json:
schema:
$ref: '#/components/schemas/RSCheckEligibility200'
examples:
Default:
value:
cardMetadataInfo:
cardIssuer: string
foregroundColor: '255122235'
backgroundColor: '255122235'
labelColor: '255122235'
shortDescription: The Bank Card
longDescription: The Bank Card
profileID: The Bank Card
cardArtData:
cardArtRefID: string
termsAndConditionsID: The Bank Card
contactInfo:
contactWebsite: https://issuer.com
contactEmail: user@issuer.com
contactNumber: 800-000-0000
contactName: Issuer
applicationInfo:
supportsTokenNotifications: true
supportsFPANNotifications: true
transactionServiceURL: string
messageServiceURL: string
transactionPushTopic: string
messagePushTopic: string
appLaunchURL: string
appLaunchURLScheme: string
associatedStoreIdentifiers:
- string
associatedApplicationIdentifiers:
- 0
privacyPolicyURL: https://issuer.com/privacyPolicyURL
termsAndConditionsURL: https://issuer.com/termsAndConditionsURL
RS401:
description: 'Unauthorized: Invalid or missing authentication credentials.
'
RS400:
description: 'Bad Request: The request could not be understood by the server due to
malformed syntax.
The client should not complete the request until it is corrected.
'
RSCardInfo400:
description: Bad Request
content:
application/json:
schema:
$ref: '#/components/schemas/RS400Tk'
examples:
Header Params Required:
$ref: '#/components/examples/HeaderParamsRequired'
Error General Service:
$ref: '#/components/examples/ErrorGeneralService'
Invalid parameters:
$ref: '#/components/examples/InvalidParams'
Component configuration not found:
$ref: '#/components/examples/ComponentConfigurationNotFound'
Card not found:
$ref: '#/components/examples/CardNotFound'
RSCardInfo500:
description: Internal Server Error
content:
application/json:
schema:
$ref: '#/components/schemas/RS500Tk'
examples:
Internal Server Error:
$ref: '#/components/examples/InternalServerError'
RS200:
description: 'Success
'
RSErrorCode400:
description: Error Codes
content:
application/json:
schema:
$ref: '#/components/schemas/RSErrorCode400'
examples:
ISE40000:
$ref: '#/components/examples/RSErrorCode400-ISE40000'
ISE40005:
$ref: '#/components/examples/RSErrorCode400-ISE40005'
ISE40006:
$ref: '#/components/examples/RSErrorCode400-ISE40006'
ISE40010:
$ref: '#/components/examples/RSErrorCode400-ISE40010'
ISE40013:
$ref: '#/components/examples/RSErrorCode400-ISE40013'
ISE40001:
$ref: '#/components/examples/RSErrorCode400-ISE40001'
RSInvalidSignature:
description: Invalid Signature
content:
application/json:
schema:
$ref: '#/components/schemas/RSIssuer_InvalidSignature'
examples:
JWE Invalid format:
$ref: '#/components/examples/InvalidSignature'
RSFromIssuer_200:
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/RS200'
examples:
Default:
value:
code: 200.22.000
message: Process Ok
datetime: '2022-04-25T23:19:12.000Z'
RSInternalServerError:
description: Internal Server Error
content:
application/json:
schema:
$ref: '#/components/schemas/RSInternalServerError'
examples:
Internal Server Error:
$ref: '#/components/examples/InternalServerError_2'
RSFromIssuer_400:
description: Bad Request
content:
application/json:
schema:
$ref: '#/components/schemas/RSFromIssuer_BadRequest'
examples:
JWE Invalid format:
$ref: '#/components/examples/JWEInvalidFormat'
Invalid Card Id:
$ref: '#/components/examples/InvalidadCardId'
Params Required:
$ref: '#/components/examples/ParamsRequired'
parameters:
ContentType:
name: Content-Type
in: header
required: true
description: 'Response body type. Operation related information.
It is not required if the body of the request is empty, like a “GET” request.
Sample: application / json; charset = UTF-8
'
schema:
type: string
securitySchemes:
oAuth2ClientCredentials:
type: oauth2
description: 'See [Oauth2 API](https://developer.novopayment.com/api/authentication-method-and-encryption/oauth2-api)
'
flows:
clientCredentials:
tokenUrl: https://sandbox-api.novopayment.com/oauth2/token
scopes: {}
x-refined-from:
- novopayment-issuer-tokenization-openapi.yml
- novopayment-mastercard-issuer-tokenization-openapi.yml