Citi User Profile API

The User Profile API from Citi — 1 operation(s) for user profile.

Operations 1

POST /v1/user/profile User Profile #

Documentation

📖
Documentation
https://developer.citi.com/apidocs/authentication/authentication-only-guide
📖
APIReference
https://developer.citi.com/apidocs/authentication/authentication-api-reference
📖
Authentication
https://raw.githubusercontent.com/api-evangelist/citi/refs/heads/main/authentication/citi-authentication.yml
📖
Documentation
https://developer.citi.com/apidocs/account-reporting/balances/balances-overview
📖
APIReference
https://developer.citi.com/apidocs/account-reporting/balances/balances-api-reference
📖
Documentation
https://developer.citi.com/apidocs/outgoing-payments/payments/payments-overview
📖
APIReference
https://developer.citi.com/apidocs/outgoing-payments/payments/payments-api-reference
📖
Documentation
https://developer.citi.com/apidocs/accept-payments/online-payment-acceptance/online-payment-acceptance-overview
📖
APIReference
https://developer.citi.com/apidocs/accept-payments/online-payment-acceptance/online-payment-acceptance-api-reference
📖
Documentation
https://developer.citi.com/apidocs/commercial-cards/virtual-cards/commercial-cards-overview
📖
APIReference
https://developer.citi.com/apidocs/commercial-cards/virtual-cards/virtual-cards-api-reference
📖
Documentation
https://developer.citi.com/apidocs/fx/gateway/citifx-gateway-overview
📖
APIReference
https://developer.citi.com/apidocs/fx/instant-fx/instant-fx-overview
📖
Documentation
https://developer.citi.com/apidocs/custody/accounts/accounts-overview
📖
APIReference
https://developer.citi.com/apidocs/custody/safekeeping-positions/safekeeping-positions-api-reference
📖
Documentation
https://developer.citi.com/apidocs/transfer-agency/accounts/accounts-overview
📖
APIReference
https://developer.citi.com/apidocs/transfer-agency/accounts/accounts-api-reference
📖
Documentation
https://developer.citi.com/apidocs/open-banking/ukraine-open-banking/ukraine-open-banking-overview
📖
APIReference
https://developer.citi.com/apidocs/open-banking/ukraine-open-banking/ukraine-bank-data-sharing-api-reference
📖
Documentation
https://developer.citi.com/apidocs/trade/standby-letters-of-credit/trade-overview
📖
APIReference
https://developer.citi.com/apidocs/trade/standby-letters-of-credit/trade-api-reference
📖
Documentation
https://developer.citi.com/apidocs/gateway-services/gateway-services-user-guide
📖
APIReference
https://developer.citi.com/apidocs/gateway-services/gateway-services-api-reference
📖
Documentation
https://developer.citi.com/apidocs/additional-payment-services/additional-payment-services/additional-payment-services-overview
📖
APIReference
https://developer.citi.com/apidocs/additional-payment-services/additional-payment-services/additional-payment-services-api-reference

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/citi-user-profile-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

citi-user-profile-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  description: IVA capabilities allow users to self-service when facing issues or inquiries such as username/password reset, unlock accounts, authorizations and declines, registration, card status, contact details update, merchant.
  version: ''
  title: IVA-GRACE User Profile API
servers:
- url: https://tts.apib2b.citi.com/tts/cards/iva
security:
- clientCredentials: []
tags:
- name: User Profile
paths:
  /v1/user/profile:
    post:
      tags:
      - User Profile
      summary: User Profile
      description: ''
      operationId: userProfile
      parameters:
      - name: Content-Type
        in: header
        description: Supports application/json
        required: true
        schema:
          type: string
      - name: Authorization
        in: header
        description: 'Request should contain Authorization header OAuth <br> **OAuth:** <br> Request contains a header field in the form of Authorization: Bearer (access_token), where access_token is generated using the OAuth url <br>

          `Example` : Bearer AAIkMjU2OTI4OGQtODY5Ny00ZjgzLTg0NzEtY2QyZWYwZjM5ZjJk_m3yqnGAbxR_ovVx5bs9OUfF0dd52qHadLtw2ARkwCw2BJcwg1zHsTOuvjPtsW5ioxxd2xXXjlDDCKLuvg15Ce1gzGxTu17xEvLOzSECLIdU_02JbpS3h9ee9GzB-u_MPfKseOiACXYAh_7AVWQhtRMLDKd8RgCUsNzTGXXBeE4'
        required: true
        schema:
          type: string
          maxLength: 255
      - name: client_id
        in: query
        required: true
        description: This is your unique identifier shared during your CitiConnect API onboarding. This is the same `client_id` used for oauth token generation
        schema:
          type: string
      - name: region
        in: header
        description: 'region of the client. <br>`Example`: APAC, EMEA, NAM'
        required: true
        schema:
          type: string
          maxLength: 3
          minLength: 3
      - name: country
        in: header
        description: 'Country code in ISO 3166 alpha-2 format.. <br>`Example`: USA(United States of America),SGP(Singapore), PHL(Philippines), THA(Thailand)'
        required: true
        schema:
          type: string
          maxLength: 3
          minLength: 3
      - name: req-sys-id
        in: header
        description: 'Client Unique id to identify the particular request.<br> `Format`: UUID <br> `Example`: 123d837e-958a-4e9f-bc97-4843ec948123'
        required: true
        schema:
          type: string
          maxLength: 36
          minLength: 12
      responses:
        '200':
          description: Success response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IVAUserProfileResponse'
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IVAUserProfileResponse'
        '401':
          description: Authentication Failure
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/unAuthorizedResponse'
        '405':
          description: Method not allowed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/methodNotAllowedResponse'
        '500':
          description: Technical Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/internalServerErrorResponse'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/IVAUserProfileRequest'
        description: This is a input request for User profile operations
components:
  schemas:
    methodNotAllowedResponse:
      properties:
        httpCode:
          type: string
          example: '405'
          description: Error code to be sent to the Client
          minLength: 1
          maxLength: 10
        httpMessage:
          type: string
          example: Method Not ALLowed
          description: Error message to be sent to the Client
          minLength: 1
          maxLength: 255
        moreInformation:
          type: string
          example: Requested HTTP operation is not supported
          description: Details related to the error to be sent to the Client
          minLength: 1
          maxLength: 255
    unAuthorizedResponse:
      properties:
        httpCode:
          type: string
          example: '401'
          description: Error code to be sent to the Client
          minLength: 1
          maxLength: 10
        httpMessage:
          type: string
          example: Unauthorized
          description: Error message to be sent to the Client
          minLength: 1
          maxLength: 255
        moreInformation:
          type: string
          example: Access Denied
          description: Details related to the error to be sent to the Client
          minLength: 1
          maxLength: 255
    ErrorMessage:
      required:
      - errorCode
      - errorDescription
      properties:
        errorCode:
          type: string
          description: Error code to be sent to the Client
          minLength: 1
          maxLength: 10
          enum:
          - EVB0300
          - EVB0301
          - EVB0302
          - EVB0303
          - EVB0304
          - EVB0305
          - EVB0306
          - EVB0307
          - EVB0308
          - EVB0309
          - EVB0310
          - EVB0311
          - GRC0001
          - GRC0002
          - GRC0003
          - GRC0004
          - GRC0005
          - GRC0006
          - GRC0007
          - GRC0008
          - GRC0009
          - GRC0010
          - GRC0011
          - GRC0012
          - GRC0014
          - GRC0015
          - GRC0016
          - CMERR02
          - CMERR16
          - CMERR17
          - CMERR18
          - CMERR22
          - CMERR23
          - CMERR24
          - CMERR25
        errorDescription:
          type: string
          description: EVB0300 - operationId is mandatory\\ \'EVB0301' - Invalid value passed. operationId accepts ["getUserProfile"\ \resetLockedCard","unlockUser","resetPassword","resetChallengeQuestion","forgotUserName"\ \"phoneNumber","emailId" ] `EVB0302` - encodedCardNumber is mandatory\ \`EVB0303` - source is mandatory `EVB0304` - userType is mandatory\ \`EVB0305` - Invalid value passed. userType accepts [CH,NCH]\ \`EVB0306` - mobileNumber is mandatory when operation id is phoneNumber\ \`EVB0307` - mobileCountryCode is mandatory when operation id is phoneNumber\ \`EVB0308` - emailId is mandatory when operation id is emailId.\ \`EVB0309` - Email Type can be Primary or Alternate\ \`EVB0310` - Mail address is required when mailType is Temporary for resetPassword.\ \`EVB0311` - Mail address is should be null or empty when mailType is not Temporary for resetPassword.\ \`GRC0001` - We have encountered an error and couldn't receive your request. Please try again, or contact Citi support if you \have any further questions or comments.\ \`GRC0002` - Client ID is missing in the request header\ \`GRC0003` - Invalid JSON Input\ \`GRC0004` - Region ID is not available in the request \`GRC0005` - Client Tracking ID is missing in the request header \`GRC0006` - We have encountered an error and couldn't receive your request. Please try again, or contact Citi support if you \have any further questions or comments.\ \`GRC0007` - Client requested MediaType is not supported.\ \`GRC0008` - Invalid request. Unable to bind incoming request\ \`GRC0009` - We have encountered an error and couldn't receive your request. Please try again, or contact Citi support if you \have any further questions or comments\ \`GRC0010` - Client Tracking ID length should contain a min of 12 character and a max of 36 characters\ \`GRC0011` - Client ID and/or Country and/or region id is missing in Client Onboard Configuration setup. Contact Citi support.\ \`GRC0012` - Necessary header value is missing\ \`GRC0014` - We have encountered an error and couldn't receive your request. Please try again, or contact Citi support if you \have any further questions or comments\ \`GRC0015` - We have encountered an error and couldn't receive your request. Please try again, or contact Citi support if you \have any further questions or comments\ \`GRC0016` - Country code is not available in the request\ \`CMERR02` - Invalid Input Parameter(s)\ \`CMERR17` - Only Individual Accounts (cards) and Centrally Billed cards can be updated\ \`CMERR18` - Not authorized to perform this action\ \`CMERR22` - Data not Found for the given Card Number\ \`CMERR24` - Email primary/alternate mail id not found\ \`CMERR25` - Error in password creation
          minLength: 1
          maxLength: 255
    IVAUserProfileResponse:
      properties:
        operationId:
          type: string
          format: alpha[a-zA-Z]
          description: Unique ID for defining the action to be taken.
          example: getuserprofile
        requestStatus:
          type: string
          example: 'true'
          description: This field represents request status
          minLength: 0
          maxLength: 100
        additionalMessage:
          type: string
          description: This field represents additional message per request
          minLength: 0
          maxLength: 255
          example: User profile retrieved successfully
        profileResponse:
          $ref: '#/components/schemas/ProfileResponseFields'
        errors:
          type: array
          items:
            $ref: '#/components/schemas/ErrorMessage'
    ProfileResponseFields:
      properties:
        userName:
          type: string
          description: This data will be populated when operation ID is getUserProfile
          minLength: 0
          maxLength: 255
          example: encrypted value
        userStatus:
          type: string
          description: This data will be populated when operation ID is getUserProfile
          minLength: 0
          maxLength: 255
          example: Activated
        userMobileNumber:
          type: string
          description: This data will be populated when operation ID is getUserProfile
          minLength: 0
          maxLength: 255
          example: encrypted value
        userPrimaryEmailAddress:
          type: string
          description: This data will be populated when operation ID is getUserProfile
          minLength: 0
          maxLength: 255
          example: avc@citi.com
        userLastLoginDate:
          type: string
          description: This data will be populated when operation ID is getUserProfile
          minLength: 0
          maxLength: 255
          example: 30-Oct-2023 12:09:31
        userLastEmailUpdatedOn:
          type: string
          description: This data will be populated when operation ID is getUserProfile
          minLength: 0
          maxLength: 255
          example: 19-Dec-2023 06:12:12
        userLastMobileUpdatedOn:
          type: string
          description: This data will be populated when operation ID is getUserProfile
          minLength: 0
          maxLength: 255
          example: 19-Dec-2023 06:12:12
        noOfInvalidLoginAttempts:
          type: number
          format: numeric [0-9]
          description: This data will be populated when operation ID is getUserProfile
          example: '0'
        ccasettingenabledOTP:
          type: string
          description: This data will be populated when operation ID is getUserProfile
          minLength: 0
          maxLength: 255
          example: N
        ccasettingautoRegistrationEnabled:
          type: string
          description: This data will be populated when operation ID is getUserProfile
          minLength: 0
          maxLength: 255
          example: N
        ccasettinglockedAccountsEnabled:
          type: string
          description: This data will be populated when operation ID is getUserProfile
          minLength: 0
          maxLength: 255
          example: N
        ccasettinguseTextMessage:
          type: string
          description: This data will be populated when operation ID is getUserProfile
          minLength: 0
          maxLength: 255
          example: N
        ccasettingUseBioMetrics:
          type: string
          description: This data will be populated when operation ID is getUserProfile
          minLength: 0
          maxLength: 255
          example: N
        ccasettingEmailDomains:
          type: object
          description: This data will be populated when operation ID is getUserProfile
          example: 'null'
          properties: {}
        hdVerificationQuestion:
          type: object
          description: This data will be populated when operation ID is getUserProfile
          example: What is your favorite color?
          properties: {}
        hdVerificationAnswer:
          type: object
          description: This data will be populated when operation ID is getUserProfile
          example: encrypted value
          properties: {}
        ssoEnabled:
          type: string
          description: This data will be populated when operation ID is getUserProfile
          minLength: 0
          maxLength: 255
    IVAUserProfileRequest:
      required:
      - encodedEncryptedCardNumber
      - operationId
      - source
      - userType
      properties:
        operationId:
          type: string
          format: alpha[a-zA-Z]
          description: Unique Id for defining the action to be taken
        encodedEncryptedCardNumber:
          type: string
          description: A reference number that uniquely identifies the virtual cardccount.
        userType:
          type: string
          format: alpha[a-zA-Z]
          description: A field to identify the user type based on the card
        source:
          type: string
          format: alphanumeric [a-zA-Z0-9 ]
          example: IVA
          description: Represents the Source system
          maxLength: 255
        emailType:
          type: string
          description: Represents the mail type. Is required when operation ID emailId, resetPassword and forgotUserName
        mobileNumber:
          type: string
          description: 'Represent the phone number to be updated for a profile. Is required when operation ID phoneNumber '
          maxLength: 255
        mobileCountryCode:
          type: string
          description: Represents the country code of the phone number
          maxLength: 255
        emailId:
          type: string
          description: Represent the email id to be updated for a profile. IS required when operation ID emailId. Emailid is mandatory when emailType is Temporary and Operation is resetPassword. EmailId should be null or empty if Operation is resetPassword and emailType is Primary/Alternate
    internalServerErrorResponse:
      required:
      - errors
      properties:
        errors:
          type: array
          items:
            $ref: '#/components/schemas/ErrorMessage'
  securitySchemes:
    clientCredentials:
      type: oauth2
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: https://tts.apib2b.citi.com/tts/cards/api/v1/oauth2/token
      description: 'All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer token to authenticate your API call. The Token URL includes the version of authentication used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the Citi Authentication API reference</a> for information on requesting a token.


        '