openapi: 3.0.1 info: title: Openpay BankAccounts Cards API description: REST API for the Openpay online payments platform (BBVA group), available in Mexico and Colombia. Resources are scoped to a merchant under the path /v1/{merchant_id}. The API supports charges against cards, convenience stores (cash), and banks (SPEI); customers and stored cards; client-side tokens; recurring plans and subscriptions; payouts and transfers to bank accounts; commission fees; and webhook notifications. Authentication uses HTTP Basic auth with the merchant private API key as the username and an empty password. termsOfService: https://www.openpay.mx/terminos-y-condiciones.html contact: name: Openpay Support url: https://www.openpay.mx email: soporte@openpay.mx version: '1.0' servers: - url: https://api.openpay.mx/v1 description: Production (Mexico) - url: https://sandbox-api.openpay.mx/v1 description: Sandbox (Mexico) - url: https://api.openpay.co/v1 description: Production (Colombia) - url: https://sandbox-api.openpay.co/v1 description: Sandbox (Colombia) security: - basicAuth: [] tags: - name: Cards description: Store and manage cards at merchant or customer level. paths: /{merchant_id}/cards: parameters: - $ref: '#/components/parameters/MerchantId' post: operationId: createMerchantCard tags: - Cards summary: Store a card at the merchant level. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CreateCard' responses: '200': description: Card stored. content: application/json: schema: $ref: '#/components/schemas/Card' get: operationId: listMerchantCards tags: - Cards summary: List merchant-level cards. responses: '200': description: A list of cards. content: application/json: schema: type: array items: $ref: '#/components/schemas/Card' /{merchant_id}/cards/{card_id}: parameters: - $ref: '#/components/parameters/MerchantId' - $ref: '#/components/parameters/CardId' get: operationId: getMerchantCard tags: - Cards summary: Get a merchant-level card. responses: '200': description: The card. content: application/json: schema: $ref: '#/components/schemas/Card' delete: operationId: deleteMerchantCard tags: - Cards summary: Delete a merchant-level card. responses: '204': description: Card deleted. /{merchant_id}/customers/{customer_id}/cards: parameters: - $ref: '#/components/parameters/MerchantId' - $ref: '#/components/parameters/CustomerId' post: operationId: createCustomerCard tags: - Cards summary: Store a card for a customer. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CreateCard' responses: '200': description: Card stored. content: application/json: schema: $ref: '#/components/schemas/Card' get: operationId: listCustomerCards tags: - Cards summary: List a customer's cards. responses: '200': description: A list of cards. content: application/json: schema: type: array items: $ref: '#/components/schemas/Card' /{merchant_id}/customers/{customer_id}/cards/{card_id}: parameters: - $ref: '#/components/parameters/MerchantId' - $ref: '#/components/parameters/CustomerId' - $ref: '#/components/parameters/CardId' get: operationId: getCustomerCard tags: - Cards summary: Get a customer's card. responses: '200': description: The card. content: application/json: schema: $ref: '#/components/schemas/Card' delete: operationId: deleteCustomerCard tags: - Cards summary: Delete a customer's card. responses: '204': description: Card deleted. components: parameters: MerchantId: name: merchant_id in: path required: true description: The merchant identifier that scopes all resources. schema: type: string CustomerId: name: customer_id in: path required: true schema: type: string CardId: name: card_id in: path required: true schema: type: string schemas: CreateCard: type: object properties: card_number: type: string holder_name: type: string expiration_year: type: string expiration_month: type: string cvv2: type: string device_session_id: type: string token_id: type: string description: Provide a token id instead of raw card data. Card: type: object properties: id: type: string type: type: string enum: - debit - credit brand: type: string example: visa card_number: type: string description: Masked card number. holder_name: type: string expiration_year: type: string expiration_month: type: string bank_name: type: string bank_code: type: string creation_date: type: string format: date-time securitySchemes: basicAuth: type: http scheme: basic description: HTTP Basic authentication. Use the merchant private API key as the username and leave the password empty.