Citi API Authentication Services
OAuth 2.0 token issuance for every Citi institutional API. Four concurrent versions (V1-V4) of the authentication endpoint are published; each product API's own specification names the version it requires. V1-V3 additionally require the request payload to be signed and encrypted with asymmetric PKI keys over mutual TLS; V4 removes the signing and encryption requirement. Citi publishes 4 machine-readable specifications for this family covering 4 operations, served from developer.citi.com.