openapi: 3.1.0
info:
title: Wise Platform 3ds sca-device-fingerprints API
version: ''
description: "The Wise Platform API is a REST-based interface that enables programmatic access to Wise's payment infrastructure. All endpoints return JSON-formatted responses and use standard HTTP methods and status codes.\n{% admonition type=\"success\" name=\"New to wise?\" %}\n We strongly recommend first reading our **[Getting Started Guide](/guides/developer/index.md)** to help you set up credentials and make your first call.\n{% /admonition %}\n\nBefore you begin {% .title-2 .m-t-5 %}\n\nTo use this API reference effectively, you should have:\n\n- Received Valid [API credentials from Wise](/guides/developer/auth-and-security/index.md) (Client ID and Client Secret)\n- Understand OAuth 2.0 authentication\n- Be familiar with RESTful API concepts\n\nCore API resources {% .title-2 .m-t-5 .m-b-0 %}\n\n| Resource | Purpose |\n|----------|---------|\n| **[Quote](/api-reference/quote)** | Exchange rate and fee calculations |\n| **[Recipient](/api-reference/recipient)** | Beneficiary account management |\n| **[Transfer](/api-reference/transfer)** | Payment creation and execution |\n| **[Balance](/api-reference/balance)** | Multi-currency account operations |\n| **[Profile](/api-reference/profile)** | Account ownership details |\n| **[Rate](/api-reference/rate)** | Current and historical exchange rates |\n\n**Not sure which workflow to build?**
\nStart with our [Integration Guides](/guides/product/send-money/use-cases/index.md) for step-by-step implementation examples.{% .m-t-3 .m-b-5 %}\n"
servers:
- url: https://api.wise.com
description: Production Environment
- url: https://api.wise-sandbox.com
description: Sandbox Environment
tags:
- name: sca-device-fingerprints
x-displayName: Device Fingerprints
description: 'Device fingerprints are possession-based SCA challenge factors. They allow you to verify that a user is accessing the API from a recognized device.
A profile can have up to 3 device fingerprints registered simultaneously. All device fingerprint operations use JOSE (JWE) encryption. See the [SCA over API guide](/guides/developer/auth-and-security/sca-and-2fa) for encryption details.'
paths:
/v1/one-time-token/partner-device-fingerprint/verify:
post:
deprecated: true
operationId: ottDeviceFingerprintVerify
summary: Verify Device Fingerprint
description: '[{% img src="https://img.shields.io/badge/jose-direct_encryption-blue" /%}](/guides/developer/auth-and-security/jose-jwe){% .d-inline-block %}
To clear a **Device Fingerprint** challenge listed in an OTT.
Notes:
1. User is required to [create a device fingerprint](/api-reference/user-security/usersecuritydevicefingerprintcreate) before the verification can be successful.
2. Rate limit may be applied if there are 5 continuous unsuccessful attempts and OTT creation will be blocked for 15 minutes.
'
tags:
- sca-device-fingerprints
security:
- UserToken: []
parameters:
- name: One-Time-Token
in: header
required: true
description: Text value of a OTT.
schema:
type: string
- name: Accept
in: header
required: true
schema:
type: string
enum:
- application/jose+json
example: application/jose+json
- name: X-TW-JOSE-Method
in: header
required: true
description: JOSE method identifier.
schema:
type: string
enum:
- jwe
example: jwe
- $ref: '#/components/parameters/X-External-Correlation-Id'
x-codeSamples:
- lang: bash
label: cURL
source: "curl -i -X POST \\\n https://api.wise-sandbox.com/v1/one-time-token/partner-device-fingerprint/verify \\\n -H 'Authorization: Bearer ' \\\n -H 'Accept: application/jose+json' \\\n -H 'Accept-Encoding: identity' \\\n -H 'Content-Type: application/jose+json' \\\n -H 'Content-Encoding: identity' \\\n -H 'X-TW-JOSE-Method: jwe' \\\n -H 'One-Time-Token: ' \\\n -d 'eyJlbmMiOiJBMjU2R0NNIiwi...'\n"
requestBody:
required: true
content:
application/jose+json:
schema:
type: string
description: 'JWE-encrypted string. The payload before encryption should contain a `deviceFingerprint` field.
Original payload:
```json
{"deviceFingerprint": ""}
```
Encoded (JWE):
```
eyJlbmMiOiJBMjU2R0NNIiwi...
```
'
example: eyJlbmMiOiJBMjU2R0NNIiwi...
responses:
'200':
description: Encrypted one time token status.
content:
application/jose+json:
schema:
type: string
description: 'JWE-encrypted string. Please refer to our [JOSE guide](/guides/developer/auth-and-security/jose-jws) on how to decrypt this.
When decrypted, the response contains `oneTimeTokenProperties` with the one time token details. When successful, response may return the next challenge in `challenges` array. If `challenges` array is empty, you may now use the OTT to access an SCA protected endpoint.
'
example: eyJlbmMiOiJBMjU2R0NNIiwi...
headers:
X-External-Correlation-Id:
$ref: '#/components/headers/X-External-Correlation-Id'
x-trace-id:
$ref: '#/components/headers/x-trace-id'
'429':
$ref: '#/components/responses/429'
/v2/profiles/{profileId}/device-fingerprints:
post:
operationId: scaDeviceFingerprintCreate
summary: Create a device fingerprint
description: 'Creates a new device fingerprint factor used to resolve a SCA possession challenge type.
The request and response are encrypted using the JOSE framework. Please refer to the [SCA over API guide](/guides/developer/auth-and-security/sca-over-api) to understand how encryption and decryption work.
'
tags:
- sca-device-fingerprints
security:
- UserToken: []
parameters:
- name: profileId
in: path
required: true
description: The profile ID.
schema:
type: integer
format: int64
- name: Accept
in: header
required: true
schema:
type: string
default: application/jose+json
- name: Accept-Encoding
in: header
required: true
schema:
type: string
default: identity
- name: Content-Encoding
in: header
required: true
schema:
type: string
default: identity
- name: X-tw-jose-method
in: header
required: true
schema:
type: string
default: jwe
- $ref: '#/components/parameters/X-External-Correlation-Id'
x-codeSamples:
- lang: bash
label: cURL
source: "curl -X POST \\\n 'https://api.wise-sandbox.com/v2/profiles/{profileId}/device-fingerprints' \\\n -H 'Authorization: Bearer ' \\\n -H 'Accept: application/jose+json' \\\n -H 'Accept-Encoding: identity' \\\n -H 'Content-Type: application/jose+json' \\\n -H 'Content-Encoding: identity' \\\n -H 'X-tw-jose-method: jwe' \\\n -d 'eyJlbmMiOiJBMjU2R0NNIiwiYWxnIjoiUlNBLU9BRVAtMjU2In0.W0fuxaZOoyaBcx...'\n"
requestBody:
required: true
content:
application/jose+json:
schema:
type: string
description: 'A JWE encrypted string. The decrypted payload contains:
- `deviceFingerprint` — A string value used as a device fingerprint.
Payload before encryption:
```json
{"deviceFingerprint": "3207da22-a0d3-4b6b-a591-6297e646fe32"}
```
'
example:
responses:
'200':
description: The device fingerprint has been successfully created.
content:
application/json:
schema:
type: object
properties:
deviceFingerprintId:
type: string
format: uuid
description: The identifier of the device fingerprint.
createdAt:
type: string
format: date-time
description: The device fingerprint creation timestamp.
example:
deviceFingerprintId: 636a5514-aa86-4719-8700-e9a9a0ae7ea7
createdAt: '2025-05-24T07:27:58.273205554Z'
headers:
X-External-Correlation-Id:
$ref: '#/components/headers/X-External-Correlation-Id'
x-trace-id:
$ref: '#/components/headers/x-trace-id'
'400':
description: Maximum number of device fingerprints reached (default is 3).
headers:
X-External-Correlation-Id:
$ref: '#/components/headers/X-External-Correlation-Id'
x-trace-id:
$ref: '#/components/headers/x-trace-id'
'409':
description: The device fingerprint has already been created.
headers:
X-External-Correlation-Id:
$ref: '#/components/headers/X-External-Correlation-Id'
x-trace-id:
$ref: '#/components/headers/x-trace-id'
'429':
$ref: '#/components/responses/429'
/v2/profiles/{profileId}/device-fingerprints/verify:
post:
operationId: scaDeviceFingerprintVerify
summary: Verify a device fingerprint
description: 'Verifies a device fingerprint challenge when calling a SCA-secured endpoint. Make sure to [create a device fingerprint](/api-reference/sca-device-fingerprints/scadevicefingerprintcreate) before using this endpoint.
The request and response are encrypted using the JOSE framework. Please refer to the [SCA over API guide](/guides/developer/auth-and-security/sca-over-api) to understand how encryption and decryption work.
'
tags:
- sca-device-fingerprints
security:
- UserToken: []
parameters:
- name: profileId
in: path
required: true
description: The profile ID.
schema:
type: integer
format: int64
- name: One-Time-Token
in: header
required: true
description: A one-time token unique identifier.
schema:
type: string
format: uuid
- name: Accept
in: header
required: true
schema:
type: string
default: application/jose+json
- name: Accept-Encoding
in: header
required: true
schema:
type: string
default: identity
- name: Content-Encoding
in: header
required: true
schema:
type: string
default: identity
- name: X-tw-jose-method
in: header
required: true
schema:
type: string
default: jwe
- $ref: '#/components/parameters/X-External-Correlation-Id'
x-codeSamples:
- lang: bash
label: cURL
source: "curl -X POST \\\n 'https://api.wise-sandbox.com/v2/profiles/{profileId}/device-fingerprints/verify' \\\n -H 'Authorization: Bearer ' \\\n -H 'Accept: application/jose+json' \\\n -H 'Accept-Encoding: identity' \\\n -H 'Content-Type: application/jose+json' \\\n -H 'Content-Encoding: identity' \\\n -H 'X-tw-jose-method: jwe' \\\n -H 'One-Time-Token: ' \\\n -d 'eyJlbmMiOiJBMjU2R0NNIiwiYWxnIjoiUlNBLU9BRVAtMjU2In0.W0fuxaZOoyaBcx...'\n"
requestBody:
required: true
content:
application/jose+json:
schema:
type: string
description: 'A JWE encrypted string. The decrypted payload contains:
- `deviceFingerprint` — A device fingerprint value.
Payload before encryption:
```json
{"deviceFingerprint": "3207da22-a0d3-4b6b-a591-6297e646fe32"}
```
'
example:
responses:
'200':
description: The device fingerprint has been successfully verified.
content:
application/json:
schema:
$ref: '#/components/schemas/one-time-token'
headers:
X-External-Correlation-Id:
$ref: '#/components/headers/X-External-Correlation-Id'
x-trace-id:
$ref: '#/components/headers/x-trace-id'
'400':
description: The device fingerprint verification failed.
headers:
X-External-Correlation-Id:
$ref: '#/components/headers/X-External-Correlation-Id'
x-trace-id:
$ref: '#/components/headers/x-trace-id'
'404':
description: The device fingerprint was not found.
headers:
X-External-Correlation-Id:
$ref: '#/components/headers/X-External-Correlation-Id'
x-trace-id:
$ref: '#/components/headers/x-trace-id'
'429':
$ref: '#/components/responses/429'
/v2/profiles/{profileId}/device-fingerprints/{deviceFingerprintId}:
delete:
operationId: scaDeviceFingerprintDelete
summary: Delete a device fingerprint
description: 'Deletes a device fingerprint associated to a profile. Include the `deviceFingerprintId` in the URL to delete a device fingerprint. This ID is provided in the response when the device fingerprint is created.
{% admonition type="warning" %}
This operation is irreversible.
{% /admonition %}
'
tags:
- sca-device-fingerprints
security:
- UserToken: []
parameters:
- name: profileId
in: path
required: true
description: The profile ID.
schema:
type: integer
format: int64
- name: deviceFingerprintId
in: path
required: true
description: The device fingerprint ID.
schema:
type: string
format: uuid
- $ref: '#/components/parameters/X-External-Correlation-Id'
responses:
'204':
description: The device fingerprint has been deleted.
headers:
X-External-Correlation-Id:
$ref: '#/components/headers/X-External-Correlation-Id'
x-trace-id:
$ref: '#/components/headers/x-trace-id'
'404':
description: The device fingerprint ID does not exist.
headers:
X-External-Correlation-Id:
$ref: '#/components/headers/X-External-Correlation-Id'
x-trace-id:
$ref: '#/components/headers/x-trace-id'
'429':
$ref: '#/components/responses/429'
components:
parameters:
X-External-Correlation-Id:
x-global: true
name: X-External-Correlation-Id
in: header
required: false
description: 'Optional UUID for correlating requests across systems. If provided, Wise echoes it back in the response. Maximum 36 characters. [Learn more](/guides/developer/headers/correlation-id).
'
schema:
type: string
format: uuid
maxLength: 36
example: f47ac10b-58cc-4372-a567-0e02b2c3d479
schemas:
one-time-token:
title: One-Time Token
x-tags:
- sca-ott
type: object
description: 'A one-time token is generated when accessing an endpoint secured by SCA. This token includes a list of all available challenges to complete.
You can use the [OTT status endpoint](/api-reference/sca-ott/ottstatusget) to view challenges and their statuses, or use [create SCA session](/api-reference/sca-sessions/scasessioncreate) to manually trigger SCA and return a one-time token.
'
properties:
oneTimeToken:
type: string
format: uuid
description: A one-time token unique identifier.
example: 5932d5b5-ec13-452f-8688-308feade7834
challenges:
type: array
description: An array of challenges.
items:
type: object
properties:
primaryChallenge:
type: object
properties:
type:
type: string
description: A type of challenge.
example: PIN
passed:
type: boolean
description: The status of a challenge.
example: false
validity:
type: integer
description: The One-Time Token expiration in seconds.
example: 3600
headers:
X-External-Correlation-Id:
x-global: true
description: Echoed back when `X-External-Correlation-Id` was included in the request. [Learn more](/guides/developer/headers/correlation-id).
schema:
type: string
format: uuid
maxLength: 36
example: f47ac10b-58cc-4372-a567-0e02b2c3d479
x-trace-id:
x-global: true
description: Unique trace identifier assigned by Wise. Useful when contacting support about a specific request.
schema:
type: string
example: fba501b6d453b96789f52338f019341f
responses:
'429':
x-global: true
description: Rate limit exceeded. Retry after the number of seconds specified in the `Retry-After` header.
headers:
Retry-After:
description: Number of seconds to wait before retrying the request.
schema:
type: integer
example: 5
X-Rate-Limited-By:
description: Identifies the rate limiter that triggered the 429 response.
schema:
type: string
example: wise-public-api
X-External-Correlation-Id:
$ref: '#/components/headers/X-External-Correlation-Id'
x-trace-id:
$ref: '#/components/headers/x-trace-id'
content:
application/json:
schema:
type: object
securitySchemes:
UserToken:
type: http
scheme: bearer
bearerFormat: JWT
description: 'User Access Token for making API calls on behalf of a Wise user.
Can be obtained via two OAuth 2.0 flows:
- **registration_code grant**: For partners creating users via API
- **authorization_code grant**: For partners using Wise''s authorization page
Access tokens are valid for 12 hours and can be refreshed using a refresh token.
'
PersonalToken:
type: http
scheme: bearer
bearerFormat: JWT
description: 'Personal API Token for individual personal or small business users.
Generated from Wise.com > Settings > Connect and manage apps > API tokens.
Has limited API access compared to OAuth tokens (PSD2 restrictions apply for EU/UK users).
'
ClientCredentialsToken:
type: http
scheme: bearer
bearerFormat: JWT
description: 'Application-level token for partner operations that don''t require a specific user context, such as bulk settlement and card spend controls.
Obtained via `POST /oauth/token` with Basic Authentication (client-id:client-secret) and `grant_type=client_credentials`.
Valid for 12 hours. No refresh token — fetch a new token when expired.
See [create an OAuth token](/api-reference/oauth-token/oauthtokencreate) for details.
'
BasicAuth:
type: http
scheme: basic
description: 'Basic Authentication using your Client ID and Client Secret as the username and password.
Client credentials are provided by Wise when your partnership begins. See [Getting Started](/guides/developer) for details.
'
x-tagGroups:
- name: Authentication
tags:
- oauth-token
- name: Enhanced Security
tags:
- jose
- name: Users
tags:
- user
- claim-account
- name: Profiles
tags:
- profile
- activity
- address
- name: Verification
tags:
- kyc-review
- verification
- facetec
- name: Strong Customer Authentication
tags:
- sca-ott
- sca-sessions
- sca-pin
- sca-facemaps
- sca-device-fingerprints
- sca-otp
- user-security
- name: Balances
tags:
- balance
- balance-statement
- bank-account-details
- multi-currency-account
- name: Cards
tags:
- card
- card-sensitive-details
- 3ds
- card-kiosk-collection
- card-order
- card-transaction
- spend-limits
- spend-controls
- digital-wallet
- disputes
- name: Quotes
tags:
- quote
- rate
- comparison
- name: Recipients
tags:
- recipient
- contact
- name: Transfers
tags:
- transfer
- delivery-estimate
- currencies
- batch-group
- name: Funding
tags:
- payin-deposit-detail
- direct-debit-account
- bulk-settlement
- payins
- name: Webhooks
tags:
- webhook
- webhook-event
- name: Simulations
tags:
- simulation
- name: Partner Support
tags:
- case