OpenAPI Specification
openapi: 3.1.0
info:
title: Mercado Pago REST Authentication Cards API
description: 'Mercado Pago REST API covering payments, Checkout Pro preferences,
subscriptions (preapprovals), customers, cards, merchant orders, Orders
API, refunds, chargebacks, claims, reports, Point (POS), QR, and OAuth.
All requests authenticate with a Bearer access token in the
`Authorization` header. Webhook deliveries are signed via the
`x-signature` and `x-request-id` headers.
'
version: v1
contact:
name: Mercado Pago Developers
url: https://www.mercadopago.com.br/developers/en/reference
license:
name: Mercado Pago Terms of Service
url: https://www.mercadopago.com.br/ayuda/terminos-y-politicas_299
servers:
- url: https://api.mercadopago.com
description: Mercado Pago Production API
security:
- bearerAuth: []
tags:
- name: Cards
description: Tokenised customer cards
paths:
/v1/customers/{customer_id}/cards:
parameters:
- name: customer_id
in: path
required: true
schema:
type: string
post:
tags:
- Cards
summary: Save A Card For A Customer
operationId: saveCustomerCard
requestBody:
required: true
content:
application/json:
schema:
type: object
properties:
token:
type: string
required:
- token
responses:
'201':
description: Card saved
content:
application/json:
schema:
$ref: '#/components/schemas/Card'
get:
tags:
- Cards
summary: List Customer Cards
operationId: listCustomerCards
responses:
'200':
description: Cards
content:
application/json:
schema:
type: array
items:
$ref: '#/components/schemas/Card'
/v1/customers/{customer_id}/cards/{card_id}:
parameters:
- name: customer_id
in: path
required: true
schema:
type: string
- name: card_id
in: path
required: true
schema:
type: string
get:
tags:
- Cards
summary: Get A Customer Card
operationId: getCustomerCard
responses:
'200':
description: Card
content:
application/json:
schema:
$ref: '#/components/schemas/Card'
delete:
tags:
- Cards
summary: Delete A Customer Card
operationId: deleteCustomerCard
responses:
'200':
description: Deleted
components:
schemas:
Card:
type: object
properties:
id:
type: string
customer_id:
type: string
expiration_month:
type: integer
expiration_year:
type: integer
first_six_digits:
type: string
last_four_digits:
type: string
payment_method:
type: object
properties:
id:
type: string
name:
type: string
security_code:
type: object
properties:
length:
type: integer
card_location:
type: string
issuer:
type: object
properties:
id:
type: integer
name:
type: string
cardholder:
type: object
properties:
name:
type: string
identification:
type: object
properties:
type:
type: string
number:
type: string
date_created:
type: string
format: date-time
date_last_updated:
type: string
format: date-time
securitySchemes:
bearerAuth:
type: http
scheme: bearer
bearerFormat: access_token
description: 'Mercado Pago access token. Send as `Authorization: Bearer {ACCESS_TOKEN}`.
HTTPS is required. Idempotency is supported via the `X-Idempotency-Key`
header on POST/PUT operations.
'
oauth2:
type: oauth2
flows:
authorizationCode:
authorizationUrl: https://auth.mercadopago.com/authorization
tokenUrl: https://api.mercadopago.com/oauth/token
scopes:
offline_access: Persistent refresh token
read: Read merchant data
write: Write merchant data