Method Financial Account Sensitive API
Sensitive data for accounts
Sensitive data for accounts
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/method-financial-account-sensitive-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
openapi: 3.2.0
info:
title: Method Account Sensitive API
version: '2026-03-30'
license:
name: Proprietary
url: https://methodfi.com
description: "The Method API enables you to retrieve financial data, create payments, and manage\nentities and accounts programmatically. This specification covers the public API\nsurface for version `2026-03-30`.\n\n## Authentication\n\nMost API requests require a Bearer token in the `Authorization` header.\nUse your secret key (`sk_...`) for server-side requests and public key (`pk_...`)\nfor client-side Element requests. Public Message-Level Encryption key discovery\nendpoints are documented separately and do not require authentication.\n\n## Versioning\n\nThe API version is selected via the `Method-Version` header. This spec targets\nversion `2026-03-30`. The SDK sets this header automatically.\n\n## Response Envelope\n\nMost JSON responses are wrapped in a standard envelope:\n\n```json\n{\n \"success\": true,\n \"data\": { ... },\n \"message\": null\n}\n```\n\nThe `/.well-known/jwks.json` endpoint is an exception and returns a bare JWK set.\n\n## Pagination\n\nList endpoints return pagination metadata in response headers:\n`Pagination-Page`, `Pagination-Page-Count`, `Pagination-Page-Limit`,\n`Pagination-Total-Count`, `Pagination-Page-Cursor-Prev`, `Pagination-Page-Cursor-Next`.\n\n## Expandable Fields\n\nCertain resource fields can be expanded from IDs to full objects using the\n`expand` query parameter. Maximum nesting depth is 4 levels.\n"
contact:
name: Method Financial
url: https://methodfi.com
email: team@methodfi.com
servers:
- url: https://production.methodfi.com
description: Production
x-fern-server-name: Production
- url: https://sandbox.methodfi.com
description: Sandbox
x-fern-server-name: Sandbox
- url: https://dev.methodfi.com
description: Development
x-fern-server-name: Development
security:
- SecretKey: []
tags:
- name: Account Sensitive
description: Sensitive data for accounts
paths:
/accounts/{accountId}/sensitive:
get:
operationId: listAccountSensitives
summary: List all account sensitive records
description: Returns a list of sensitive data records for the specified account.
tags:
- Account Sensitive
security:
- SecretKey: []
parameters:
- $ref: '#/components/parameters/method_version'
- $ref: '#/components/parameters/AccountIdParam'
- $ref: '#/components/parameters/PageParam'
- $ref: '#/components/parameters/PageLimitParam'
- $ref: '#/components/parameters/PageCursorParam'
responses:
'200':
description: A paginated list of account sensitive records.
headers:
Pagination-Page:
$ref: '#/components/headers/Pagination-Page'
Pagination-Page-Count:
$ref: '#/components/headers/Pagination-Page-Count'
Pagination-Page-Limit:
$ref: '#/components/headers/Pagination-Page-Limit'
Pagination-Total-Count:
$ref: '#/components/headers/Pagination-Total-Count'
Pagination-Page-Cursor-Prev:
$ref: '#/components/headers/Pagination-Page-Cursor-Prev'
Pagination-Page-Cursor-Next:
$ref: '#/components/headers/Pagination-Page-Cursor-Next'
content:
application/json:
schema:
$ref: '#/components/schemas/AccountSensitiveListResponse'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
'429':
$ref: '#/components/responses/RateLimited'
'500':
$ref: '#/components/responses/InternalError'
post:
operationId: createAccountSensitive
summary: Create an account sensitive record
description: Creates a new sensitive data request for the specified account.
tags:
- Account Sensitive
security:
- SecretKey: []
parameters:
- $ref: '#/components/parameters/method_version'
- $ref: '#/components/parameters/idempotency_key'
- $ref: '#/components/parameters/AccountIdParam'
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/AccountSensitiveCreateRequest'
responses:
'200':
description: The newly created account sensitive record.
content:
application/json:
schema:
$ref: '#/components/schemas/AccountSensitiveResponse'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
'422':
$ref: '#/components/responses/UnprocessableEntity'
'429':
$ref: '#/components/responses/RateLimited'
'500':
$ref: '#/components/responses/InternalError'
/accounts/{accountId}/sensitive/{astvId}:
get:
operationId: retrieveAccountSensitive
summary: Retrieve an account sensitive record
description: Retrieves an account sensitive record by its unique identifier.
tags:
- Account Sensitive
security:
- SecretKey: []
parameters:
- $ref: '#/components/parameters/method_version'
- $ref: '#/components/parameters/AccountIdParam'
- $ref: '#/components/parameters/AccountSensitiveIdParam'
responses:
'200':
description: The requested account sensitive record.
content:
application/json:
schema:
$ref: '#/components/schemas/AccountSensitiveResponse'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
'429':
$ref: '#/components/responses/RateLimited'
'500':
$ref: '#/components/responses/InternalError'
components:
schemas:
AccountSensitiveCreateRequest:
type: object
description: Request body for creating an account sensitive data request.
required:
- expand
properties:
expand:
type: array
description: List of sensitive field names to retrieve.
items:
type: string
AccountSensitiveListResponse:
allOf:
- $ref: '#/components/schemas/ListEnvelope'
- type: object
properties:
data:
type: array
items:
$ref: '#/components/schemas/AccountSensitive'
ListEnvelope:
type: object
description: Standard envelope for successful responses that return a list payload.
required:
- success
- data
- message
properties:
success:
type: boolean
description: Always `true` for successful responses.
data:
description: Operation-specific list payload.
message:
type:
- string
- 'null'
example:
success: true
data: []
message: null
ErrorEnvelope:
type: object
required:
- success
- data
- message
properties:
success:
type: boolean
description: Always `false` for error responses.
data:
type: object
required:
- error
properties:
error:
$ref: '#/components/schemas/ErrorObject'
message:
type: string
ErrorObject:
type: object
required:
- type
- code
- message
properties:
type:
type: string
description: Error type category.
enum:
- invalid_request
- api_error
- resource_error
code:
type: integer
description: Numeric error code. Common codes include 400 (bad request), 401 (unauthorized), 403 (forbidden), 404 (not found), 422 (unprocessable entity), 429 (rate limited), and 500 (internal error).
sub_type:
type:
- string
- 'null'
description: More specific error classification.
message:
type: string
description: Human-readable error description.
AccountSensitive:
type: object
description: Sensitive data for an account.
required:
- id
- account_id
- status
- type
- created_at
- updated_at
properties:
id:
type: string
description: Unique identifier for the sensitive record.
pattern: ^astv_\w+$
example: astv_aTJMbnCjw34yQ
account_id:
type: string
description: The account this sensitive data belongs to.
pattern: ^acc_\w+$
status:
type: string
description: Current status of the sensitive data request.
enum:
- completed
- pending
- failed
type:
type: string
description: The type of sensitive data.
credit_card:
type:
- object
- 'null'
description: Card details. Present when type is credit_card.
properties:
number:
type:
- string
- 'null'
description: The card number.
exp_month:
type:
- string
- 'null'
description: Card expiration month.
exp_year:
type:
- string
- 'null'
description: Card expiration year.
cvv:
type:
- string
- 'null'
description: Card CVV.
billing_zip_code:
type:
- string
- 'null'
description: Billing zip code.
error:
$ref: '#/components/schemas/AccountSensitiveResourceError'
created_at:
type: string
format: date-time
description: Timestamp when the sensitive record was created.
updated_at:
type: string
format: date-time
description: Timestamp when the sensitive record was last updated.
AccountSensitiveResourceError:
type:
- object
- 'null'
description: Error details when retrieving account sensitive data fails.
required:
- type
- code
- sub_type
- message
properties:
type:
type: string
description: The category of sensitive data error.
enum:
- ACCOUNT_SENSITIVE_FAILED
code:
type: integer
description: Numeric error code (17XXX range).
enum:
- 17001
sub_type:
type: string
description: Specific sensitive data error classification.
enum:
- ACCOUNT_SENSITIVE_FAILED_VERIFICATION_REQUIRED
message:
type: string
description: Human-readable error description.
example:
type: ACCOUNT_SENSITIVE_FAILED
code: 17001
sub_type: ACCOUNT_SENSITIVE_FAILED_VERIFICATION_REQUIRED
message: Account sensitive failed due to missing required verification.
SuccessEnvelope:
type: object
description: Standard envelope for successful responses that return a single payload.
required:
- success
- data
- message
properties:
success:
type: boolean
description: Always `true` for successful responses.
data:
description: Operation-specific response payload.
message:
type:
- string
- 'null'
example:
success: true
data: {}
message: null
AccountSensitiveResponse:
allOf:
- $ref: '#/components/schemas/SuccessEnvelope'
- type: object
properties:
data:
$ref: '#/components/schemas/AccountSensitive'
parameters:
idempotency_key:
name: Idempotency-Key
in: header
required: false
description: 'Idempotency key for safely retrying a write request. Reuse the same value when
retrying the same logical operation to avoid creating duplicate side effects.
'
schema:
type: string
format: uuid
AccountSensitiveIdParam:
name: astvId
in: path
required: true
description: Unique identifier for the account sensitive record.
schema:
type: string
pattern: ^astv_\w+$
PageCursorParam:
name: page_cursor
in: query
required: false
description: Cursor for cursor-based pagination. Use the value from `Pagination-Page-Cursor-Next` or `Pagination-Page-Cursor-Prev` response headers.
schema:
type: string
PageLimitParam:
name: page_limit
in: query
required: false
description: Number of items per page.
schema:
type: integer
minimum: 1
maximum: 100
default: 10
AccountIdParam:
name: accountId
in: path
required: true
description: Unique identifier for the account.
schema:
type: string
pattern: ^acc_\w+$
method_version:
name: Method-Version
in: header
required: true
description: 'API version to use for this request. This spec targets `2026-03-30`.
The SDK sets this header automatically.
'
schema:
type: string
enum:
- '2026-03-30'
default: '2026-03-30'
PageParam:
name: page
in: query
required: false
description: Page number for pagination (1-indexed).
schema:
type: integer
minimum: 1
default: 1
headers:
Pagination-Page-Count:
description: Total number of pages.
schema:
type: integer
Pagination-Page-Cursor-Next:
description: Cursor for the next page, if available.
schema:
type:
- string
- 'null'
Pagination-Page:
description: Current page number.
schema:
type: integer
Pagination-Page-Cursor-Prev:
description: Cursor for the previous page, if available.
schema:
type:
- string
- 'null'
Pagination-Total-Count:
description: Total number of items across all pages.
schema:
type: integer
Pagination-Page-Limit:
description: Number of items per page.
schema:
type: integer
responses:
Unauthorized:
description: Unauthorized - missing or invalid authentication token.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorEnvelope'
InternalError:
description: Internal server error.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorEnvelope'
RateLimited:
description: Too many requests - rate limit exceeded.
headers:
Retry-After:
description: Number of seconds to wait before retrying.
schema:
type: integer
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorEnvelope'
BadRequest:
description: Bad request - invalid parameters or request body.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorEnvelope'
NotFound:
description: Not found - the requested resource does not exist.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorEnvelope'
UnprocessableEntity:
description: Unprocessable entity - the request was valid JSON but failed business or validation rules.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorEnvelope'
securitySchemes:
OpalToken:
type: http
scheme: bearer
description: 'Opal token authentication for Opal session endpoints. Use an Opal token (`otkn_...`)
as the Bearer token. Created via POST /opal/token using a secret key.
'
SecretKey:
type: http
scheme: bearer
description: 'Secret key authentication. Use your team''s secret key (`sk_...`) as the Bearer token.
All authenticated API endpoints require this scheme unless otherwise noted.
'