Citi Authenticationservices API

The Authenticationservices API from Citi — 4 operation(s) for authenticationservices.

Operations 4

POST /authenticationservices/v1/oauth/token Request v1 Access Token #
POST /authenticationservices/v2/oauth/token Request v2 Access Token #
POST /authenticationservices/v3/oauth/token Request v3 Access Token #
POST /authenticationservices/v4/oauth/token Request v4 Access Token #

Documentation

📖
Documentation
https://developer.citi.com/apidocs/authentication/authentication-only-guide
📖
APIReference
https://developer.citi.com/apidocs/authentication/authentication-api-reference
📖
Authentication
https://raw.githubusercontent.com/api-evangelist/citi/refs/heads/main/authentication/citi-authentication.yml
📖
Documentation
https://developer.citi.com/apidocs/account-reporting/balances/balances-overview
📖
APIReference
https://developer.citi.com/apidocs/account-reporting/balances/balances-api-reference
📖
Documentation
https://developer.citi.com/apidocs/outgoing-payments/payments/payments-overview
📖
APIReference
https://developer.citi.com/apidocs/outgoing-payments/payments/payments-api-reference
📖
Documentation
https://developer.citi.com/apidocs/accept-payments/online-payment-acceptance/online-payment-acceptance-overview
📖
APIReference
https://developer.citi.com/apidocs/accept-payments/online-payment-acceptance/online-payment-acceptance-api-reference
📖
Documentation
https://developer.citi.com/apidocs/commercial-cards/virtual-cards/commercial-cards-overview
📖
APIReference
https://developer.citi.com/apidocs/commercial-cards/virtual-cards/virtual-cards-api-reference
📖
Documentation
https://developer.citi.com/apidocs/fx/gateway/citifx-gateway-overview
📖
APIReference
https://developer.citi.com/apidocs/fx/instant-fx/instant-fx-overview
📖
Documentation
https://developer.citi.com/apidocs/custody/accounts/accounts-overview
📖
APIReference
https://developer.citi.com/apidocs/custody/safekeeping-positions/safekeeping-positions-api-reference
📖
Documentation
https://developer.citi.com/apidocs/transfer-agency/accounts/accounts-overview
📖
APIReference
https://developer.citi.com/apidocs/transfer-agency/accounts/accounts-api-reference
📖
Documentation
https://developer.citi.com/apidocs/open-banking/ukraine-open-banking/ukraine-open-banking-overview
📖
APIReference
https://developer.citi.com/apidocs/open-banking/ukraine-open-banking/ukraine-bank-data-sharing-api-reference
📖
Documentation
https://developer.citi.com/apidocs/trade/standby-letters-of-credit/trade-overview
📖
APIReference
https://developer.citi.com/apidocs/trade/standby-letters-of-credit/trade-api-reference
📖
Documentation
https://developer.citi.com/apidocs/gateway-services/gateway-services-user-guide
📖
APIReference
https://developer.citi.com/apidocs/gateway-services/gateway-services-api-reference
📖
Documentation
https://developer.citi.com/apidocs/additional-payment-services/additional-payment-services/additional-payment-services-overview
📖
APIReference
https://developer.citi.com/apidocs/additional-payment-services/additional-payment-services/additional-payment-services-api-reference

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/citi-authenticationservices-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

citi-authenticationservices-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Citi Authenticationservices API
  x-refined-note:
  - x-ibm-name differs across the merged source definitions and was not carried
  version: '1.0'
  description: 'Operations tagged Authenticationservices across 4 of this provider''s published API definitions: authentication_api_1.yaml, authentication_api_2.yaml, authentication_api_3.yaml, authentication_api_4.yaml. Each path carries the servers of the definition it was published in.'
servers:
- url: https://tts.sandbox.apib2b.citi.com/citiconnect/sb
  description: 'CTE/Sandbox url '
- url: https://tts.apib2b.citi.com/citiconnect/prod
  description: Production gateway url
tags:
- name: Authenticationservices
paths:
  /authenticationservices/v1/oauth/token:
    post:
      summary: Request v1 Access Token
      description: The OAuth v1 token request authenticates your API message sent in the XML format and responds with an access token.
      operationId: oAuthV1UsingPOST
      parameters:
      - name: Content-Type
        in: header
        description: Supports only \"application/xml\".
        required: true
        schema:
          type: string
      - name: Authorization
        in: header
        description: "The authorization will include \"Basic\" followed by a single space, followed by the Base64 encoded value of the APIm `client_id` & `secret key`. \n\nIn the above example, the `client_id` is *1234a5b6-cde7-8f90-12gh-345ij6789012* & secret key is *abcdefghijklmnop*.  \n\nThe Base64 value after appending by adding “:” in between will be “MTIzNGE1YjYtY2RlNy04ZjkwLTEyZ2gtMzQ1aWo2Nzg5MDEyOmFiY2RlZmdoaWprbG1ub3A=”. \n"
        required: true
        example: Basic MTIzNGE1YjYtY2RlNy04ZjkwLTEyZ2gtMzQ1aWo2Nzg5MDEyOmFiY2RlZmdoaWprbG1ub3A=
        schema:
          type: string
      requestBody:
        description: The following is the request body to retrieve an OAuth token using the V1 endpoint.
        content:
          application/xml:
            schema:
              $ref: '#/components/schemas/oAuthToken'
            example: <?xml version="1.0" encoding="UTF-8"?><oAuthToken xmlns="http://com.citi.citiconnect/services/types/oauthtoken/v1"><grantType>client_credentials</grantType><scope>/authenticationservices/v1</scope></oAuthToken>
        required: true
      responses:
        '200':
          description: OK
          content:
            application/xml:
              schema:
                $ref: '#/components/schemas/token'
              example: <?xml version="1.0" encoding="UTF-8"?><token><token_type>Bearer</token_type><access_token>O0n8J+fXQr32nrmBI5let6iDqg5F1iMlocBhqwokdtU3d0C/gNKVPYnmxJYheps4YdnuIijt9E3LKYMEab+lP5M34yGNumBLQUUE8myVo40y3Tyo4d2j1cYYF9RGfpOVzAtb9VrhoMdJORJaIcIvTlRpcqCI/c0kV5t5mk0wmL7blWiTF0NW+w6Y57p4iikn0H+zMQ4zMmZiYI06t0VIH4yQrFw6N4tsoN1GD2A3/XKVVi5CO+I71aq0CaDlR/qEUfyZ6psyqqg94W54Eaq5m5Wp1uq5aQXK+A1II8zHNcARV/Iot3ZUGVYcPfvNEYZaANRbJcXhGepOwkDrRu/jYBguWm+/Vmvr3cIFaQ1bvhpCHxTAW7uJerWJzBE11RE0wv8HGsznQRUsbSq0woOa69Pe0Oym5qzeo9Ar139DIpp0hmeU5Ee8qWZBTalW5QdDIEhWdizlxK/1gvrOU8TK+AR/fI/2h3ApPUf+pT67gqh+EhWlEr0U2jM3EcJmL7aMVjZu9dswX79aGK7ss+JB3iEoC9tD/2cBRbHuitrqiRqp1Bd2L6w9bKx6tUQk+l9/KOX6h/5kOxlFc2z6CXpc1MVXlBQOSdJdj/2ILJ7UPCdmlzBG3q9WtJi1MaeNefUaQlNQUGpP017zLKxNIW5OtSJCneGeOjAxsdtZunO0LUS+2Z6OiiRxsYIZJMzmQ5dh4vGLzMFTH9bG74se1EuPHw==</access_token><expires_in>1800</expires_in><scope>/authenticationservices/v1</scope></token>
        '201':
          description: Created
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '500':
          description: Internal Server Error
      security:
      - Basic Authentication: []
      x-codegen-request-body-name: body
      tags:
      - Authenticationservices
    servers:
    - url: https://tts.sandbox.apib2b.citi.com/citiconnect/sb
      description: 'CTE/Sandbox url '
    - url: https://tts.apib2b.citi.com/citiconnect/prod
      description: Production gateway url
  /authenticationservices/v2/oauth/token:
    post:
      summary: Request v2 Access Token
      description: The OAuth v2 token request authenticates your API message sent in the XML format and responds with an access token.
      operationId: oAuthV2UsingPOST
      parameters:
      - name: Content-Type
        in: header
        description: Supports only \"application/xml\".
        required: true
        schema:
          type: string
      - name: Authorization
        in: header
        description: "The authorization will include \"Basic\" followed by a single space, followed by the Base64 encoded value of the APIm `client_id` & `secret key`. \n\nIn the above example, the `client_id` is *1234a5b6-cde7-8f90-12gh-345ij6789012* & secret key is *abcdefghijklmnop*.  \n\nThe Base64 value after appending by adding “:” in between will be “MTIzNGE1YjYtY2RlNy04ZjkwLTEyZ2gtMzQ1aWo2Nzg5MDEyOmFiY2RlZmdoaWprbG1ub3A=”. \n"
        required: true
        example: Basic MTIzNGE1YjYtY2RlNy04ZjkwLTEyZ2gtMzQ1aWo2Nzg5MDEyOmFiY2RlZmdoaWprbG1ub3A=
        schema:
          type: string
      requestBody:
        description: The following is the request body to retrieve an OAuth token using the V2 endpoint.
        content:
          application/xml:
            schema:
              $ref: '#/components/schemas/oAuthToken_2'
            example: <?xml version="1.0" encoding="UTF-8"?><oAuthToken xmlns="http://com.citi.citiconnect/services/types/oauthtoken/v1"><grantType>client_credentials</grantType><scope>/authenticationservices/v1</scope></oAuthToken>
        required: true
      responses:
        '200':
          description: OK
          content:
            application/xml:
              schema:
                $ref: '#/components/schemas/token_2'
              example: <?xml version="1.0" encoding="UTF-8"?><token><token_type>Bearer</token_type><access_token>O0n8J+fXQr32nrmBI5let6iDqg5F1iMlocBhqwokdtU3d0C/gNKVPYnmxJYheps4YdnuIijt9E3LKYMEab+lP5M34yGNumBLQUUE8myVo40y3Tyo4d2j1cYYF9RGfpOVzAtb9VrhoMdJORJaIcIvTlRpcqCI/c0kV5t5mk0wmL7blWiTF0NW+w6Y57p4iikn0H+zMQ4zMmZiYI06t0VIH4yQrFw6N4tsoN1GD2A3/XKVVi5CO+I71aq0CaDlR/qEUfyZ6psyqqg94W54Eaq5m5Wp1uq5aQXK+A1II8zHNcARV/Iot3ZUGVYcPfvNEYZaANRbJcXhGepOwkDrRu/jYBguWm+/Vmvr3cIFaQ1bvhpCHxTAW7uJerWJzBE11RE0wv8HGsznQRUsbSq0woOa69Pe0Oym5qzeo9Ar139DIpp0hmeU5Ee8qWZBTalW5QdDIEhWdizlxK/1gvrOU8TK+AR/fI/2h3ApPUf+pT67gqh+EhWlEr0U2jM3EcJmL7aMVjZu9dswX79aGK7ss+JB3iEoC9tD/2cBRbHuitrqiRqp1Bd2L6w9bKx6tUQk+l9/KOX6h/5kOxlFc2z6CXpc1MVXlBQOSdJdj/2ILJ7UPCdmlzBG3q9WtJi1MaeNefUaQlNQUGpP017zLKxNIW5OtSJCneGeOjAxsdtZunO0LUS+2Z6OiiRxsYIZJMzmQ5dh4vGLzMFTH9bG74se1EuPHw==</access_token><expires_in>1800</expires_in><scope>/authenticationservices/v1</scope></token>
        '201':
          description: Created
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '500':
          description: Internal Server Error
      security:
      - Basic Authentication: []
      x-codegen-request-body-name: body
      tags:
      - Authenticationservices
    servers:
    - url: https://tts.sandbox.apib2b.citi.com/citiconnect/sb
      description: 'CTE/Sandbox url '
    - url: https://tts.apib2b.citi.com/citiconnect/prod
      description: Production gateway url
  /authenticationservices/v3/oauth/token:
    post:
      summary: Request v3 Access Token
      description: The OAuth v3 token request authenticates your API message sent in either JSON or XML formats and responds with an access token.
      operationId: oAuthV3UsingPOST
      parameters:
      - name: Content-Type
        in: header
        description: Supports \"application/xml\" and \"application/json\".
        required: true
        schema:
          type: string
      - name: Authorization
        in: header
        description: "The authorization will include \"Basic\" followed by a single space, followed by the Base64 encoded value of the APIm `client_id` & `secret key`. \n\nIn the above example, the `client_id` is *1234a5b6-cde7-8f90-12gh-345ij6789012* & secret key is *abcdefghijklmnop*.  \n\nThe Base64 value after appending by adding “:” in between will be “MTIzNGE1YjYtY2RlNy04ZjkwLTEyZ2gtMzQ1aWo2Nzg5MDEyOmFiY2RlZmdoaWprbG1ub3A=”. \n"
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Request'
          application/xml:
            schema:
              $ref: '#/components/schemas/Request'
            example: <?xml version="1.0" encoding="UTF-8"?><oAuthToken xmlns="http://com.citi.citiconnect/services/types/oauthtoken/v2"><grantType>client_credentials</grantType><scope>/authenticationservices/v1</scope><sourceApplication>CCF</sourceApplication></oAuthToken>
        required: true
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Response'
            application/xml:
              schema:
                $ref: '#/components/schemas/Response'
              example: <?xml version="1.0" encoding="UTF-8"?><token><token_type>Bearer</token_type><access_token>O0n8J+fXQr32nrmBI5let6iDqg5F1iMlocBhqwokdtU3d0C/gNKVPYnmxJYheps4YdnuIijt9E3LKYMEab+lP5M34yGNumBLQUUE8myVo40y3Tyo4d2j1cYYF9RGfpOVzAtb9VrhoMdJORJaIcIvTlRpcqCI/c0kV5t5mk0wmL7blWiTF0NW+w6Y57p4iikn0H+zMQ4zMmZiYI06t0VIH4yQrFw6N4tsoN1GD2A3/XKVVi5CO+I71aq0CaDlR/qEUfyZ6psyqqg94W54Eaq5m5Wp1uq5aQXK+A1II8zHNcARV/Iot3ZUGVYcPfvNEYZaANRbJcXhGepOwkDrRu/jYBguWm+/Vmvr3cIFaQ1bvhpCHxTAW7uJerWJzBE11RE0wv8HGsznQRUsbSq0woOa69Pe0Oym5qzeo9Ar139DIpp0hmeU5Ee8qWZBTalW5QdDIEhWdizlxK/1gvrOU8TK+AR/fI/2h3ApPUf+pT67gqh+EhWlEr0U2jM3EcJmL7aMVjZu9dswX79aGK7ss+JB3iEoC9tD/2cBRbHuitrqiRqp1Bd2L6w9bKx6tUQk+l9/KOX6h/5kOxlFc2z6CXpc1MVXlBQOSdJdj/2ILJ7UPCdmlzBG3q9WtJi1MaeNefUaQlNQUGpP017zLKxNIW5OtSJCneGeOjAxsdtZunO0LUS+2Z6OiiRxsYIZJMzmQ5dh4vGLzMFTH9bG74se1EuPHw==</access_token><expires_in>1800</expires_in><scope>/authenticationservices/v3</scope></token>
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorMessage'
              example:
                httpMessage: Bad Request
                httpCode: 400
            application/xml:
              schema:
                $ref: '#/components/schemas/ErrorMessage'
              example: <?xml version="1.0" encoding="UTF-8"?><errormessage><httpMessage>Bad Request</httpMessage><httpCode>400</httpCode></errormessage>
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorMessage'
              example:
                httpMessage: UNAUTHORIZED
                httpCode: 401
            application/xml:
              schema:
                $ref: '#/components/schemas/ErrorMessage'
              example: <?xml version="1.0" encoding="UTF-8"?><errormessage><httpMessage>UNAUTHORIZED</httpMessage><httpCode>401</httpCode></errormessage>
        '404':
          description: Not Found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorMessage'
              example:
                httpMessage: NOT FOUND
                httpCode: 404
            application/xml:
              schema:
                $ref: '#/components/schemas/ErrorMessage'
              example: <?xml version="1.0" encoding="UTF-8"?><errormessage><httpMessage>NOT FOUND</httpMessage><httpCode>404</httpCode></errormessage>
        '405':
          description: Method Not Allowed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorMessage'
              example:
                httpMessage: METHOD NOT ALLOWED
                httpCode: 405
            application/xml:
              schema:
                $ref: '#/components/schemas/ErrorMessage'
              example: <?xml version="1.0" encoding="UTF-8"?><errormessage><httpMessage>METHOD NOT ALLOWED</httpMessage><httpCode>405</httpCode></errormessage>
        '415':
          description: Unsupported Media Type
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorMessage'
              example:
                httpMessage: UNSUPPORTED MEDIA TYPE
                httpCode: 415
            application/xml:
              schema:
                $ref: '#/components/schemas/ErrorMessage'
              example: <?xml version="1.0" encoding="UTF-8"?><errormessage><httpMessage>UNSUPPORTED MEDIA TYPE</httpMessage><httpCode>415</httpCode></errormessage>
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorMessage'
              example:
                httpMessage: Internal Server Error
                httpCode: 500
            application/xml:
              schema:
                $ref: '#/components/schemas/ErrorMessage'
              example: <?xml version="1.0" encoding="UTF-8"?><errormessage><httpMessage>Internal Server Error</httpMessage><httpCode>500</httpCode></errormessage>
      deprecated: false
      security:
      - Basic Authentication: []
      x-codegen-request-body-name: body
      tags:
      - Authenticationservices
    servers:
    - url: https://tts.sandbox.apib2b.citi.com/citiconnect/sb
      description: 'CTE/Sandbox url '
    - url: https://tts.apib2b.citi.com/citiconnect/prod
      description: Production gateway url
  /authenticationservices/v4/oauth/token:
    post:
      summary: Request v4 Access Token
      description: The OAuth v4 token request authenticates your API message sent in either JSON or XML formats and responds with an access token.
      operationId: oAuthV4UsingPOST
      parameters:
      - name: Content-Type
        in: header
        description: Supports \"application/xml\" and \"application/json\".
        required: true
        schema:
          type: string
      - name: Authorization
        in: header
        description: "The authorization will include \"Basic\" followed by a single space, followed by the Base64 encoded value of the APIm `client_id` & `secret key`. \n\nIn the above example, the `client_id` is *1234a5b6-cde7-8f90-12gh-345ij6789012* & secret key is *abcdefghijklmnop*.  \n\nThe Base64 value after appending by adding “:” in between will be “MTIzNGE1YjYtY2RlNy04ZjkwLTEyZ2gtMzQ1aWo2Nzg5MDEyOmFiY2RlZmdoaWprbG1ub3A=”. \n"
        required: true
        schema:
          type: string
      requestBody:
        description: Request body for the V4 OAuth Token.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Request_2'
          application/xml:
            schema:
              $ref: '#/components/schemas/Request_2'
            example: <?xml version="1.0" encoding="UTF-8"?><oAuthToken xmlns="http://com.citi.citiconnect/services/types/oauthtoken/v2"><grantType>client_credentials</grantType><scope>/authenticationservices/v1</scope><sourceApplication>CCF</sourceApplication></oAuthToken>
        required: true
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Response_2'
            application/xml:
              schema:
                $ref: '#/components/schemas/Response_2'
              example: <?xml version="1.0" encoding="UTF-8"?><token><token_type>Bearer</token_type><access_token>O0n8J+fXQr32nrmBI5let6iDqg5F1iMlocBhqwokdtU3d0C/gNKVPYnmxJYheps4YdnuIijt9E3LKYMEab+lP5M34yGNumBLQUUE8myVo40y3Tyo4d2j1cYYF9RGfpOVzAtb9VrhoMdJORJaIcIvTlRpcqCI/c0kV5t5mk0wmL7blWiTF0NW+w6Y57p4iikn0H+zMQ4zMmZiYI06t0VIH4yQrFw6N4tsoN1GD2A3/XKVVi5CO+I71aq0CaDlR/qEUfyZ6psyqqg94W54Eaq5m5Wp1uq5aQXK+A1II8zHNcARV/Iot3ZUGVYcPfvNEYZaANRbJcXhGepOwkDrRu/jYBguWm+/Vmvr3cIFaQ1bvhpCHxTAW7uJerWJzBE11RE0wv8HGsznQRUsbSq0woOa69Pe0Oym5qzeo9Ar139DIpp0hmeU5Ee8qWZBTalW5QdDIEhWdizlxK/1gvrOU8TK+AR/fI/2h3ApPUf+pT67gqh+EhWlEr0U2jM3EcJmL7aMVjZu9dswX79aGK7ss+JB3iEoC9tD/2cBRbHuitrqiRqp1Bd2L6w9bKx6tUQk+l9/KOX6h/5kOxlFc2z6CXpc1MVXlBQOSdJdj/2ILJ7UPCdmlzBG3q9WtJi1MaeNefUaQlNQUGpP017zLKxNIW5OtSJCneGeOjAxsdtZunO0LUS+2Z6OiiRxsYIZJMzmQ5dh4vGLzMFTH9bG74se1EuPHw==</access_token><expires_in>1800</expires_in><scope>/authenticationservices/v1</scope></token>
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorMessage_2'
              example:
                httpMessage: Bad Request
                httpCode: 400
            application/xml:
              schema:
                $ref: '#/components/schemas/ErrorMessage_2'
              example: <?xml version="1.0" encoding="UTF-8"?><errormessage><httpMessage>Bad Request</httpMessage><httpCode>400</httpCode></errormessage>
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorMessage_2'
              example:
                httpMessage: UNAUTHORIZED
                httpCode: 401
            application/xml:
              schema:
                $ref: '#/components/schemas/ErrorMessage_2'
              example: <?xml version="1.0" encoding="UTF-8"?><errormessage><httpMessage>UNAUTHORIZED</httpMessage><httpCode>401</httpCode></errormessage>
        '404':
          description: Not Found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorMessage_2'
              example:
                httpMessage: NOT FOUND
                httpCode: 404
            application/xml:
              schema:
                $ref: '#/components/schemas/ErrorMessage_2'
              example: <?xml version="1.0" encoding="UTF-8"?><errormessage><httpMessage>NOT FOUND</httpMessage><httpCode>404</httpCode></errormessage>
        '405':
          description: Method Not Allowed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorMessage_2'
              example:
                httpMessage: METHOD NOT ALLOWED
                httpCode: 405
            application/xml:
              schema:
                $ref: '#/components/schemas/ErrorMessage_2'
              example: <?xml version="1.0" encoding="UTF-8"?><errormessage><httpMessage>METHOD NOT ALLOWED</httpMessage><httpCode>405</httpCode></errormessage>
        '415':
          description: Unsupported Media Type
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorMessage_2'
              example:
                httpMessage: UNSUPPORTED MEDIA TYPE
                httpCode: 415
            application/xml:
              schema:
                $ref: '#/components/schemas/ErrorMessage_2'
              example: <?xml version="1.0" encoding="UTF-8"?><errormessage><httpMessage>UNSUPPORTED MEDIA TYPE</httpMessage><httpCode>415</httpCode></errormessage>
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorMessage_2'
              example:
                httpMessage: Internal Server Error
                httpCode: 500
            application/xml:
              schema:
                $ref: '#/components/schemas/ErrorMessage_2'
              example: <?xml version="1.0" encoding="UTF-8"?><errormessage><httpMessage>Internal Server Error</httpMessage><httpCode>500</httpCode></errormessage>
      deprecated: false
      security:
      - Basic Authentication: []
      x-codegen-request-body-name: body
      tags:
      - Authenticationservices
    servers:
    - url: https://tts.sandbox.apib2b.citi.com/citiconnect/sb
      description: 'CTE/Sandbox url '
    - url: https://tts.apib2b.citi.com/citiconnect/prod
      description: Production gateway url
components:
  schemas:
    oAuthToken:
      title: oAuthTokenRequest
      description: The request body for the V1 authentication service to retrieve an OAuth token.
      properties:
        grantType:
          type: string
          description: You must always pass 'client_credentials' in this field because Citi only provides credentials-based authentication for API users.
        merchantId:
          type: string
        scope:
          type: string
          description: This is the version scope of the authentication call. Note that this value will be the same for ALL versions of the Authentication API and should be `/authenticationservices/v1`.
        sourceApplication:
          type: string
          description: This represents the route of the authentication call within CitiConnect API.
          enum:
          - CCF
        userDetails:
          $ref: '#/components/schemas/UserDetailsType'
      required:
      - grantType
      - scope
      example:
        grantType: client_credentials
        scope: /authenticationservices/v1
      xml:
        namespace: http://com.citi.citiconnect/services/types/oauthtoken/v1
    token:
      title: oAuthTokenResponse
      description: The response body for the V1 authentication service to retrieve an OAuth token.
      properties:
        token_type:
          type: string
          description: The default value will be “Bearer”.
        access_token:
          type: string
          description: Contains the OAuth Token that will be used for authenticating successive API calls.
        expires_in:
          type: string
          description: The expiry time limit of the OAuth Token in seconds.
        scope:
          type: string
          description: The version scope of the authentication call. The value will be the same for all the API versions.
    UserDetailsType:
      title: UserDetailsType
      type: object
      properties:
        userId:
          type: string
          xml:
            name: userId
            attribute: false
            wrapped: false
        userIdType:
          type: string
          xml:
            name: userIdType
            attribute: false
            wrapped: false
          enum:
          - SAFEWORD
      xml:
        name: userDetailsType
        attribute: false
        wrapped: false
    oAuthToken_2:
      title: oAuthTokenRequest
      description: The request body for the V2 authentication service to retrieve an OAuth token.
      properties:
        grantType:
          type: string
          description: You must always pass 'client_credentials' in this field because Citi only provides credentials-based authentication for API users.
        merchantId:
          type: string
        scope:
          type: string
          description: This is the version scope of the authentication call. Note that this value will be the same for ALL versions of the Authentication API and should be `/authenticationservices/v1` (even for versions 2, 3, and 4).
        sourceApplication:
          type: string
          description: This represents the route of the authentication call within CitiConnect API.
          enum:
          - CCF
        userDetails:
          $ref: '#/components/schemas/UserDetailsType'
      required:
      - grantType
      - scope
      example:
        grantType: client_credentials
        scope: /authenticationservices/v1
      xml:
        namespace: http://com.citi.citiconnect/services/types/oauthtoken/v1
    token_2:
      title: oAuthTokenResponse
      description: The response body for the V2 authentication service to retrieve an OAuth token.
      properties:
        token_type:
          type: string
          description: The default value will be “Bearer”.
        access_token:
          type: string
          description: Contains the OAuth Token that will be used for authenticating successive API calls.
        expires_in:
          type: string
          description: The expiry time limit of the OAuth Token in seconds.
        scope:
          type: string
          description: The version scope of the authentication call. The value will be the same for all the API versions.
    Request:
      properties:
        oAuthToken:
          $ref: '#/components/schemas/OAuthTokenType'
    OAuthTokenType:
      required:
      - grantType
      - scope
      properties:
        grantType:
          type: string
          description: You must always pass 'client_credentials' in this field because Citi only provides credentials-based authentication for API users.
          xml:
            name: grantType
            attribute: false
            wrapped: false
        scope:
          type: string
          description: This is the version scope of the authentication call. Note that this value will be the same for ALL versions of the Authentication API and should be `/authenticationservices/v1` (even for versions 2, 3, and 4).
          xml:
            name: scope
            attribute: false
            wrapped: false
      example:
        grantType: client_credentials
        scope: /authenticationservices/v1
      xml:
        namespace: http://com.citi.citiconnect/services/types/oauthtoken/v1
    Response:
      title: oAuthTokenResponse
      description: The response body for the v3 authentication service to retrieve an OAuth token.
      type: object
      properties:
        token:
          required:
          - access_token
          - expires_in
          - scope
          type: object
          properties:
            access_token:
              type: string
              description: Contains the OAuth Token that will be used for authenticating successive API calls.
            token_type:
              type: string
              description: Default value will be “Bearer".
            scope:
              type: string
              description: The version scope of the authentication call. The value will be the same for all the API versions.
            expires_in:
              type: string
              description: The expiry time of the OAuth Token in seconds.
          xml:
            name: Token
      example:
        token:
          token_type: Bearer
          access_token: BVG0wllkALQd773fXp6TwHj8GkQO+ck2oPXK0wRYaYH0Ellj7TQRcsZG2jtSnM7yw7V70+l11NZWw62v2XkobNa5o9qtC8wq/jKp7++ZFlFikvUlDFiaJgvj2AAqPVZpMar23fnMB4Hvy3ykXzuYqr1rlN2gqDZ02bw7GBqYOlekqs9xOjb69tHWRfqeFv+N7GN0DwUbN6YoicixWaR1TGZp1p3MaDbDwLmKA0fgwgO//14NPq2utvFLNSpPa4EgV5olzcopq3fpSvm3pxUO0pqjw8nY+ApTHcW2+Y4r2eLTBhboJFMONYw3cbI71X/LWG2Hh8HmVZ9ZEeo7oZ0poD5SBbk4a4Kf0laK0WcJ9xaGheG5WoHtc6H07d1Zgu91J0pC2cNIUSvej+6RzV/y7Ei75rxvS0zIu5vzTMu4j9UHe9cRAZv/i8o09r0VgxPYdOKrJJv3zf8hysKSEd9bFK4N5P/c3ztqRHOVQyEfYG3rR7fl80J71s0MNd7yIUy1mk5cMQJur2ggSAhrJrQKCUaBLPDCmfCEx5qpg9KdI/QELyoUlcu7MhL/AjhStEcZ/9yJJKoDieg+cDDIenGMl5LbAy3PqeuGI0lfDCKmOIh/LlHQVELJvHTkfmKlPEJV85/+edQTtvKYA4XvcOjGo1mtpAVRufHW76yraWHSHT40qeMS0RkSk+JlitSq/vQNX3BLnMAZEmb07a6KDbdrHfWQ/MYb9L7HJs5Qk7UiuuERyZMlhvsI/Y3vbzQxxLqE7GKRnNP77BHPxoviMN5mY7HEFq67ZAeo/7iQuagU779jbsPdzTH7+2cMcYru1w/XWm+hB1Sz2Mhj+N3wXsIzy1BYy3t99+FKBurRAK7KhF1iyqsOz1dqchQbkJLOsRsF
          expires_in: '1800'
          scope: /authenticationservices/v1
    ErrorMessage:
      required:
      - httpCode
      properties:
        httpCode:
          type: integer
          format: int32
        httpMessage:
          type: string
      xml:
        name: errormessage
    Request_2:
      properties:
        oAuthToken:
          $ref: '#/components/schemas/OAuthTokenType_2'
      title: Request
    OAuthTokenType_2:
      required:
      - grantType
      - scope
      title: OAuthTokenType
      properties:
        grantType:
          type: string
          title: grantType
          description: You must always pass 'client_credentials' in this field because Citi only provides credentials-based authentication for API users.
          xml:
            name: grantType
            attribute: false
            wrapped: false
        scope:
          type: string
          title: scope
          description: This is the version scope of the authentication call. Note that this value will be the same for ALL versions of the Authentication API and should be `/authenticationservices/v1` (even for versions 2 and 3).
          xml:
            name: scope
            attribute: false
            wrapped: false
      example:
        grantType: client_credentials
        scope: /authenticationservices/v1
      xml:
        namespace: http://com.citi.citiconnect/services/types/oauthtoken/v1
    Response_2:
      title: oAuthTokenResponse
      description: The response body for the v4 authentication service to retrieve an OAuth token.
      type: object
      properties:
        token:
          required:
          - access_token
          - expires_in
          - scope
          type: object
          title: token
          properties:
            access_token:
              type: string
              description: Contains the OAuth Token that will be used for authenticating successive API calls.
              title: access_token
            token_type:
              type: string
              description: Default value will be “Bearer".
              title: token_type
            scope:
              type: string
              description: The version scope of the authentication call. The value will be the same for all the API versions.
              title: scope
            expires_in:
              type: string
              description: The expiry time of the OAuth Token in seconds.
              title: expires_in
          xml:
            name: Token
      example:
        token:
          token_type: Bearer
          access_token: BVG0wllkALQd773fXp6TwHj8GkQO+ck2oPXK0wRYaYH0Ellj7TQRcsZG2jtSnM7yw7V70+l11NZWw62v2XkobNa5o9qtC8wq/jKp7++ZFlFikvUlDFiaJgvj2AAqPVZpMar23fnMB4Hvy3ykXzuYqr1rlN2gqDZ02bw7GBqYOlekqs9xOjb69tHWRfqeFv+N7GN0DwUbN6YoicixWaR1TGZp1p3MaDbDwLmKA0fgwgO//14NPq2utvFLNSpPa4EgV5olzcopq3fpSvm3pxUO0pqjw8nY+ApTHcW2+Y4r2eLTBhboJFMONYw3cbI71X/LWG2Hh8HmVZ9ZEeo7oZ0poD5SBbk4a4Kf0laK0WcJ9xaGheG5WoHtc6H07d1Zgu91J0pC2cNIUSvej+6RzV/y7Ei75rxvS0zIu5vzTMu4j9UHe9cRAZv/i8o09r0VgxPYdOKrJJv3zf8hysKSEd9bFK4N5P/c3ztqRHOVQyEfYG3rR7fl80J71s0MNd7yIUy1mk5cMQJur2ggSAhrJrQKCUaBLPDCmfCEx5qpg9KdI/QELyoUlcu7MhL/AjhStEcZ/9yJJKoDieg+cDDIenGMl5LbAy3PqeuGI0lfDCKmOIh/LlHQVELJvHTkfmKlPEJV85/+edQTtvKYA4XvcOjGo1mtpAVRufHW76yraWHSHT40qeMS0RkSk+JlitSq/vQNX3BLnMAZEmb07a6KDbdrHfWQ/MYb9L7HJs5Qk7UiuuERyZMlhvsI/Y3vbzQxxLqE7GKRnNP77BHPxoviMN5mY7HEFq67ZAeo/7iQuagU779jbsPdzTH7+2cMcYru1w/XWm+hB1Sz2Mhj+N3wXsIzy1BYy3t99+FKBurRAK7KhF1iyqsOz1dqchQbkJLOsRsF
          expires_in: '1800'
          scope: /authenticationservices/v1
    ErrorMessage_2:
      required:
      - httpCode
      title: ErrorMessage
      properties:
        httpCode:
          type: integer
          format: int32
          title: httpCode
        httpMessage:
          type: string
          title: httpMessage
      xml:
        name: errormessage
  securitySchemes:
    Basic_Authentication:
      type: http
      description: Username is the application's client_id and password is the client_secret.
      scheme: basic
    clientIdHeader:
      type: apiKey
      name: X-IBM-Client-Id
      in: header
    clientSecretHeader:
      type: apiKey
      name: X-IBM-Client-Secret
      in: header
x-refined-from:
- authentication_api_1.yaml
- authentication_api_2.yaml
- authentication_api_3.yaml
- authentication_api_4.yaml