openapi: 3.0.3 info: title: Wompi Merchants PSE API description: Wompi is the payment gateway of Grupo Bancolombia, serving Colombia (COP). The REST API creates and tracks transactions across local payment methods - CARD, NEQUI (mobile wallet), PSE (Pagos Seguros en Linea / online bank debit), BANCOLOMBIA_TRANSFER (Boton Bancolombia), and BANCOLOMBIA_COLLECT - plus card and Nequi tokenization, reusable payment sources, and hosted payment links. Public-key endpoints are safe for the browser; private-key endpoints are server-side only. termsOfService: https://wompi.co/es/co/terminos-y-condiciones contact: name: Wompi Soporte url: https://docs.wompi.co email: soporte@wompi.co version: '1.0' servers: - url: https://production.wompi.co/v1 description: Production - url: https://sandbox.wompi.co/v1 description: Sandbox (test keys pub_test_ / prv_test_) tags: - name: PSE description: PSE financial institution catalog. paths: /pse/financial_institutions: get: operationId: listPseFinancialInstitutions tags: - PSE summary: List PSE financial institutions description: Returns the catalog of PSE (Pagos Seguros en Linea) banks - the financial_institution_code + name pairs a customer picks from when paying by online bank debit. security: - PublicKey: [] responses: '200': description: PSE financial institution catalog. content: application/json: schema: $ref: '#/components/schemas/PseInstitutionsResponse' components: schemas: PseInstitutionsResponse: type: object properties: data: type: array items: type: object properties: financial_institution_code: type: string example: '1' financial_institution_name: type: string example: Banco que aprueba securitySchemes: PublicKey: type: http scheme: bearer description: Bearer authorization with the merchant PUBLIC key (pub_prod_... / pub_test_...). Safe for client-side use; grants tokenization, merchant read, transaction create/read, and PSE catalog access. PrivateKey: type: http scheme: bearer description: Bearer authorization with the merchant PRIVATE key (prv_prod_... / prv_test_...). Server-side only; required for payment sources, voids, and payment links.