swagger: '2.0' info: description: 'The current set of APIs will be available in Q2 2026 on Worldline Global Issuing Platforms. Additional APIs are under construction and planned to be available in 2026.' version: 2.41.1 title: Worldline Card Issuing Account - AccountState Card - LinkedAccountState API contact: {} host: sbx-wlip.api1-eu2.psapigateway.preprod.giservices.io/card-issuing basePath: /api/v2 schemes: - https tags: - name: Card - LinkedAccountState description: Card Linked Account State Controller paths: /issuers/{issuerId}/cards/linked-accounts-states: post: tags: - Card - LinkedAccountState summary: Retrieves the current effective state of accounts matching the provided pan operationId: enquireLinkedAccountStatesForPan consumes: - application/json produces: - application/json parameters: - in: body name: body description: body required: true schema: $ref: '#/definitions/GetLinkedAccountStatesRequest' - name: issuerId in: path description: issuerId required: true type: string - name: rank in: query description: rank required: false type: integer format: int32 - name: WL-Correlation-ID in: header description: WL-Correlation-ID required: false type: string - name: WL-Peer-ID in: header description: WL-Peer-ID required: false type: string - name: WL-Username in: header description: WL-Username required: false type: string responses: '200': description: OK schema: $ref: '#/definitions/ApiResponseEntityGetAccountStates' '400': description: Bad request schema: $ref: '#/definitions/BadRequestErrorApiResponse' '401': description: Unauthorized schema: $ref: '#/definitions/UnauthorizedResponseMetadata' '403': description: Forbidden schema: $ref: '#/definitions/ForbiddenErrorApiResponse' '404': description: Not found schema: $ref: '#/definitions/NotFoundErrorApiResponse' '500': description: Internal server error schema: $ref: '#/definitions/InternalServerErrorErrorApiResponse' '502': description: Bad gateway schema: $ref: '#/definitions/BadGatewayErrorApiResponse' security: - basic: [] /issuers/{issuerId}/cards/{cardReference}/linked-accounts-states: get: tags: - Card - LinkedAccountState summary: Retrieves the current effective state details of all accounts linked to the provided card reference operationId: getLinkedAccountStatesByCardReference produces: - application/json parameters: - name: cardReference in: path description: cardReference required: true type: string - name: issuerId in: path description: issuerId required: true type: string - name: rank in: query description: rank required: false type: integer format: int32 - name: WL-Correlation-ID in: header description: WL-Correlation-ID required: false type: string - name: WL-Peer-ID in: header description: WL-Peer-ID required: false type: string - name: WL-Username in: header description: WL-Username required: false type: string responses: '200': description: OK schema: $ref: '#/definitions/ApiResponseEntityGetAccountStates' '400': description: Bad request schema: $ref: '#/definitions/BadRequestErrorApiResponse' '401': description: Unauthorized schema: $ref: '#/definitions/UnauthorizedResponseMetadata' '403': description: Forbidden schema: $ref: '#/definitions/ForbiddenErrorApiResponse' '404': description: Not found schema: $ref: '#/definitions/NotFoundErrorApiResponse' '500': description: Internal server error schema: $ref: '#/definitions/InternalServerErrorErrorApiResponse' '502': description: Bad gateway schema: $ref: '#/definitions/BadGatewayErrorApiResponse' security: - basic: [] definitions: GetLinkedAccountStatesRequest: type: object properties: pan: type: string description: The Pan Number title: GetLinkedAccountStatesRequest Links: type: object required: - self properties: self: type: string example: /x/{x}?x=x description: Service method URL next: type: string example: /x/{x}?page[offset]=2 description: URL pagination query parameter next page title: Links NotFoundResponseMetadata: type: object required: - correlationId - responseDateTime - statusCode - statusMessage properties: correlationId: type: string description: Correlation Identifier responseDateTime: type: string example: format:yyyy-MM-dd'T'HH:mm:ss.SSSZ description: Timestamp when response date was generated statusCode: type: integer format: int32 example: 404 description: HTTP status code statusMessage: type: string example: Not found description: Executed REST API status message title: NotFoundResponseMetadata BadRequestResponseMetadata: type: object required: - correlationId - responseDateTime - statusCode - statusMessage properties: correlationId: type: string description: Correlation Identifier responseDateTime: type: string example: format:yyyy-MM-dd'T'HH:mm:ss.SSSZ description: Timestamp when response date was generated statusCode: type: integer format: int32 example: 400 description: HTTP status code statusMessage: type: string example: Bad request description: Executed REST API status message title: BadRequestResponseMetadata ResponseMetadata: type: object required: - correlationId - responseDateTime - statusCode - statusMessage properties: correlationId: type: string description: Correlation Identifier links: description: Metadata Links allOf: - $ref: '#/definitions/Links' statusMessage: type: string example: Executed successfully description: Executed REST API status message statusCode: type: integer format: int32 example: 200 description: HTTP status code responseDateTime: type: string example: format:yyyy-MM-dd'T'HH:mm:ss.SSSZ description: Timestamp when response date was generated timeTakenMs: type: integer format: int64 example: 12 description: Wall clock time required from service to generate the response title: ResponseMetadata AccountState: type: object properties: accountNumber: type: string description: The account number. accountProfileName: type: string description: Descriptive text for the account profile. accountProfileReference: type: string description: Identifies the profile to which the account belongs. accountReference: type: string description: Account reference is to identify the Account calculated by the system. maximumPinTryCounter: type: integer format: int32 description: The maximum amount of failed PIN tries which the cardholder can do. pinTryCounter: type: integer format: int32 description: Number of failed PIN entries. rank: type: integer format: int32 description: Level assigned to the account profile of the account. whiteListEnd: type: string format: date-time description: End of period in which the result of the fraud dectection system (FDS) call will not impact the authorization decision for transactions in context of the account. whiteListStart: type: string format: date-time description: Start of period in which the result of the fraud dectection system (FDS) call will not impact the authorization decision for transactions in context of the account. title: AccountState BadGatewayResponseMetadata: type: object required: - correlationId - responseDateTime - statusCode - statusMessage properties: correlationId: type: string description: Correlation Identifier responseDateTime: type: string example: format:yyyy-MM-dd'T'HH:mm:ss.SSSZ description: Timestamp when response date was generated statusCode: type: integer format: int32 example: 502 description: HTTP status code statusMessage: type: string example: Bad Gateway description: Executed REST API status message title: BadGatewayResponseMetadata NotFoundErrorApiResponse: type: object required: - responseMetadata properties: responseMetadata: allOf: - $ref: '#/definitions/NotFoundResponseMetadata' title: NotFoundErrorApiResponse BadGatewayErrorApiResponse: type: object required: - responseMetadata properties: responseMetadata: allOf: - $ref: '#/definitions/BadGatewayResponseMetadata' title: BadGatewayErrorApiResponse InternalServerErrorErrorApiResponse: type: object required: - responseMetadata properties: responseMetadata: allOf: - $ref: '#/definitions/InternalServerErrorResponseMetadata' title: InternalServerErrorErrorApiResponse InternalServerErrorResponseMetadata: type: object required: - correlationId - responseDateTime - statusCode - statusMessage properties: correlationId: type: string description: Correlation Identifier responseDateTime: type: string example: format:yyyy-MM-dd'T'HH:mm:ss.SSSZ description: Timestamp when response date was generated statusCode: type: integer format: int32 example: 500 description: HTTP status code statusMessage: type: string example: Internal server error description: Executed REST API status message title: InternalServerErrorResponseMetadata ForbiddenErrorApiResponse: type: object required: - responseMetadata properties: responseMetadata: allOf: - $ref: '#/definitions/ForbiddenResponseMetadata' title: ForbiddenErrorApiResponse ApiResponseEntityGetAccountStates: type: object required: - responseMetadata properties: data: type: array items: $ref: '#/definitions/AccountState' responseMetadata: description: Response metadata $ref: '#/definitions/ResponseMetadata' title: ApiResponseEntityGetAccountStates description: Issuer response entity BadRequestErrorApiResponse: type: object required: - responseMetadata properties: responseMetadata: allOf: - $ref: '#/definitions/BadRequestResponseMetadata' title: BadRequestErrorApiResponse UnauthorizedResponseMetadata: type: object required: - correlationId - responseDateTime - statusCode - statusMessage properties: correlationId: type: string description: Correlation Identifier responseDateTime: type: string example: format:yyyy-MM-dd'T'HH:mm:ss.SSSZ description: Timestamp when response date was generated statusCode: type: integer format: int32 example: 401 description: HTTP status code statusMessage: type: string example: Unauthorized description: Executed REST API status message title: UnauthorizedResponseMetadata ForbiddenResponseMetadata: type: object required: - correlationId - responseDateTime - statusCode - statusMessage properties: correlationId: type: string description: Correlation Identifier responseDateTime: type: string example: format:yyyy-MM-dd'T'HH:mm:ss.SSSZ description: Timestamp when response date was generated statusCode: type: integer format: int32 example: 403 description: HTTP status code statusMessage: type: string example: Forbidden description: Executed REST API status message title: ForbiddenResponseMetadata securityDefinitions: basic: type: oauth2 flow: application tokenUrl: https://sbx-wlip.api1-eu2.psapigateway.preprod.giservices.io/token