Moneris Disputes API

Perform and Manage Disputes

Operations 4

GET /disputes/{case-id}/{case-record-number} Dispute Details #
POST /disputes/{case-id}/{case-record-number}/accept Accept Dispute #
POST /disputes/{case-id}/{case-record-number}/uploads Upload Images #
GET /disputes/{case-id}/{case-record-number}/uploads/{upload-reference-id} Check image upload status #

Documentation

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/moneris-disputes-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

moneris-disputes-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  version: 2.6.1
  title: Moneris Disputes API
  description: 'Moneris API Platform



    [<img src="https://run.pstmn.io/button.svg" alt="Run In Postman" style="width: 128px; height:32px;">](https://god.gw.postman.com/run-collection/25575461-f04750a0-88e9-4c83-8b58-a3aff15eeea8?action=collection%2Ffork&collection-url=entityId%3D25575461-f04750a0-88e9-4c83-8b58-a3aff15eeea8%26entityType%3Dcollection%26workspaceId%3D5d2a9a0f-57a7-441c-b2af-fe6315e80a08)'
  termsOfService: https://www.moneris.com/en/legal/terms-of-use
  contact:
    url: https://api-developer.moneris.com
    email: UnifiedAPI@moneris.com
  license:
    name: Moneris
    url: https://developer.moneris.com/Agreements/Terms%20of%20Use
  x-audience: external-public
servers:
- url: https://api.sb.moneris.io
  description: Sandbox server (uses test data)
  x-internal: false
- url: https://api.moneris.io
  description: Production server (uses live data)
  x-internal: false
tags:
- name: Disputes
  description: Perform and Manage Disputes
paths:
  /disputes/{case-id}/{case-record-number}:
    get:
      tags:
      - Disputes
      summary: Dispute Details
      description: To determine whether you can upload documents for a specific case.
      parameters:
      - $ref: '#/components/parameters/apiVersion'
      - $ref: '#/components/parameters/merchantId'
      - $ref: '#/components/parameters/correlationId'
      - $ref: '#/components/parameters/caseId'
      - $ref: '#/components/parameters/caseRecNo'
      operationId: getDisputeByCaseIdAndRecordNumber
      security:
      - OAuth2:
        - dispute.read
      - OAuth2:
        - dispute.write
      - ApiKeyAuth: []
      responses:
        '200':
          $ref: '#/components/responses/getDisputeSuccess'
        '400':
          $ref: '#/components/responses/badRequest'
        '401':
          $ref: '#/components/responses/unauthorized'
        '403':
          $ref: '#/components/responses/forbidden'
        '429':
          $ref: '#/components/responses/tooManyRequests'
        '500':
          $ref: '#/components/responses/internalServer'
        '503':
          $ref: '#/components/responses/serviceUnavailable'
  /disputes/{case-id}/{case-record-number}/accept:
    post:
      tags:
      - Disputes
      summary: Accept Dispute
      description: If no longer want to dispute a chargeback or copy request.
      parameters:
      - $ref: '#/components/parameters/apiVersion'
      - $ref: '#/components/parameters/merchantId'
      - $ref: '#/components/parameters/correlationId'
      - $ref: '#/components/parameters/caseId'
      - $ref: '#/components/parameters/caseRecNo'
      operationId: acceptDispute
      security:
      - OAuth2:
        - dispute.write
      - ApiKeyAuth: []
      responses:
        '204':
          $ref: '#/components/responses/disputeAcceptSuccess'
        '400':
          $ref: '#/components/responses/badRequest'
        '401':
          $ref: '#/components/responses/unauthorized'
        '403':
          $ref: '#/components/responses/forbidden'
        '409':
          $ref: '#/components/responses/conflict'
        '429':
          $ref: '#/components/responses/tooManyRequests'
        '500':
          $ref: '#/components/responses/internalServer'
        '503':
          $ref: '#/components/responses/serviceUnavailable'
  /disputes/{case-id}/{case-record-number}/uploads:
    post:
      tags:
      - Disputes
      summary: Upload Images
      description: To upload response documents associated with a disputed transaction.
      parameters:
      - $ref: '#/components/parameters/apiVersion'
      - $ref: '#/components/parameters/merchantId'
      - $ref: '#/components/parameters/correlationId'
      - $ref: '#/components/parameters/caseId'
      - $ref: '#/components/parameters/caseRecNo'
      operationId: uploadDisputeImage
      security:
      - OAuth2:
        - dispute.write
      - ApiKeyAuth: []
      requestBody:
        content:
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/uploadImagesRequest'
        required: true
      responses:
        '202':
          $ref: '#/components/responses/uploadDisputeImagesSuccess'
        '400':
          $ref: '#/components/responses/badRequest'
        '401':
          $ref: '#/components/responses/unauthorized'
        '403':
          $ref: '#/components/responses/forbidden'
        '429':
          $ref: '#/components/responses/tooManyRequests'
        '500':
          $ref: '#/components/responses/internalServer'
        '503':
          $ref: '#/components/responses/serviceUnavailable'
  /disputes/{case-id}/{case-record-number}/uploads/{upload-reference-id}:
    get:
      tags:
      - Disputes
      summary: Check image upload status
      description: This endpoint can be used to check image upload status
      parameters:
      - $ref: '#/components/parameters/apiVersion'
      - $ref: '#/components/parameters/merchantId'
      - $ref: '#/components/parameters/correlationId'
      - $ref: '#/components/parameters/caseId'
      - $ref: '#/components/parameters/caseRecNo'
      - $ref: '#/components/parameters/uploadReferenceId'
      operationId: getDisputeUploadStatus
      security:
      - OAuth2:
        - dispute.read
      - OAuth2:
        - dispute.write
      - ApiKeyAuth: []
      responses:
        '200':
          $ref: '#/components/responses/getUploadStatusSuccess'
        '400':
          $ref: '#/components/responses/badRequest'
        '401':
          $ref: '#/components/responses/unauthorized'
        '403':
          $ref: '#/components/responses/forbidden'
        '404':
          $ref: '#/components/responses/notFound'
        '429':
          $ref: '#/components/responses/tooManyRequests'
        '500':
          $ref: '#/components/responses/internalServer'
        '503':
          $ref: '#/components/responses/serviceUnavailable'
components:
  schemas:
    disputeDocument:
      description: Return the image details for the specific case.
      type: object
      required:
      - receivedAt
      - fileName
      - images
      properties:
        receivedAt:
          description: Date when the original image received.
          type: string
          format: date-time
        fileName:
          description: Name of the image file.
          type: string
        totalPages:
          description: Number of pages in the file.
          type: integer
          format: int32
        images:
          description: Images.
          type: array
          items:
            type: object
            required:
            - image
            properties:
              image:
                description: Image file.
                type: string
                format: base64url
              pageNo:
                description: Page number.
                type: integer
                format: int32
    dispute:
      description: Dispute information for specific case.
      type: object
      required:
      - caseRecordNumber
      - caseId
      - documents
      properties:
        imageUploadAllowed:
          description: Indicates whether documents may or may not be uploaded for the case.
          type: boolean
        acceptAllowed:
          description: Indicates whether acceptance is permitted for the case.
          type: boolean
        caseRecordNumber:
          description: The record number of the case associated with the uploaded files.
          type: string
        caseId:
          description: The case ID of the uploaded files.
          type: string
        documents:
          description: List of evidence documents for the dispute.
          type: array
          items:
            $ref: '#/components/schemas/disputeDocument'
    parameterError:
      title: Parameter error
      description: Request property or header related error.
      type: object
      properties:
        parameterName:
          type: string
          description: Property or header name. Can contain nested path separated by '.'
          example: address.postalCode
        parameterValue:
          type:
          - string
          - 'null'
          description: Property or header value string representation.
          example: MAP3J8
        reasonCode:
          type: string
          description: Reason that triggered the error.
          enum:
          - INVALID_FORMAT
          - REQUIRED_FIELD
          - INVALID_VALUE
          example: INVALID_FORMAT
        errorMessage:
          type:
          - string
          - 'null'
          description: Human readable description of the error.
          example: String 'MAP3J8' does not match the postal code pattern.
      required:
      - parameterName
      - reasonCode
    error:
      description: Error response details.
      properties:
        type:
          description: 'A URI reference that identifies the problem type.  Ideally it should be a stable URL to the documentation of the details about this type of error but it also can be a URN.  If nothing can be provided, a "about:blank" value is returned.

            '
          type: string
          format: uri
          example: https://api-developer.moneris.com/responsehandling
        title:
          description: 'A short, human-readable summary of the problem type.   It SHOULD NOT change from occurrence to occurrence of the problem, except for purposes of localization

            '
          type:
          - string
          - 'null'
          example: INSUFFICIENT_FUNDS
        status:
          description: 'it conveys the HTTP status code used for the convenience of the consumer.

            '
          type:
          - integer
          - 'null'
          format: int32
          minimum: 100
          maximum: 505
        detail:
          description: 'A human-readable message providing more details about the error. For card errors, these messages can be shown to your users.

            '
          type:
          - string
          - 'null'
          example: Funds are insufficient to execute the operation.
        instance:
          description: 'A URI reference that identifies the specific occurrence of the problem. Typically, this resolves to a resource that might include more details about the problem.

            '
          type:
          - string
          - 'null'
          example: /payments/12f3e0a8-1d68-2b86-dd30-4ca51bb66e10
          format: uri-reference
        category:
          description: "The type of error returned. \n - `API_ERROR`: This occurs due to an intermittent issue.  \n - `IDEMPOTENCY_ERROR`: The idempotency key has already been used.\n - `INVALID_REQUEST_ERROR`: The data provided in the request is invalid.\n - `DECLINED_ERROR`: Transaction was declined by the issuer.\n - `UNAUTHORIZED_ERROR`: Caller not authenticated, or not allowed to execute the current operation.\n - `INTERNAL_SERVER_ERROR`: An internal issue with our servers has occured.\n"
          enum:
          - API_ERROR
          - IDEMPOTENCY_ERROR
          - INVALID_REQUEST_ERROR
          - DECLINED_ERROR
          - UNAUTHORIZED_ERROR
          - INTERNAL_SERVER_ERROR
          - null
          type:
          - string
          - 'null'
          example: DECLINED_ERROR
        errors:
          type: array
          description: List of validation errors when error category is INVALID_REQUEST_ERROR.
          items:
            type: object
            $ref: '#/components/schemas/parameterError'
          example:
          - parameterName: address.postalCode
            parameterValue: MAP3J8
            errorMessage: address.Postal code does not match regular expression
            reasonCode: INVALID_FORMAT
      title: API Error
      type: object
      required:
      - type
    uploadImagesRequest:
      description: Information of files.
      type: object
      properties:
        files:
          description: Array of file objects.
          type: array
          maxItems: 5
          items:
            type: string
            format: binary
    uploadStatus:
      description: Response for status check endpoint call.
      type: object
      required:
      - uploadReferenceId
      - uploadStatus
      properties:
        uploadReferenceId:
          description: Upload reference id.
          example: IU1001ARZ3NDEKTSV4RRFFQ69G5FAV
          type: string
        uploadStatus:
          type: string
          description: "Status type. \n  - `PENDING`: The Images have been pending upload.  \n  - `FAILED`: Image upload failed. Failure could be caused by different reasons.\n  - `SUCCESSFUL`: Images uploaded successfully.\n"
          enum:
          - PENDING
          - FAILED
          - SUCCESSFUL
    apiVersion:
      description: 'The endpoint''s API Version.  Must be provided through headers.

        '
      type: string
      example: '2025-08-14'
      default: '2025-08-14'
    merchantId:
      type: string
      description: "Thirteen character long identification provided to merchants by Moneris. \n"
      minLength: 13
      maxLength: 13
      example: 0123456789101
  responses:
    getDisputeSuccess:
      description: OK
      headers:
        Api-Version:
          $ref: '#/components/headers/apiVersion'
        X-Correlation-Id:
          $ref: '#/components/headers/correlationId'
        Sunset:
          $ref: '#/components/headers/sunset'
        X-RateLimit-Limit:
          $ref: '#/components/headers/rateLimitCount'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/rateLimitRemaining'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/dispute'
          example:
            imageUploadAllowed: false
            acceptAllowed: false
            caseRecordNumber: '1'
            caseId: '121719004438'
            documents:
            - receivedAt: '2023-01-01T00:00:00Z'
              fileName: evidence1.jpg
              totalPages: 1
              images:
              - image: base64encodedstring
                pageNo: 1
            - receivedAt: '2023-01-02T00:00:00Z'
              fileName: evidence2.jpg
              totalPages: 1
              images:
              - image: base64encodedstring
                pageNo: 1
              - image: base64encodedstring
                pageNo: 2
    getUploadStatusSuccess:
      description: Upload Status retrieved successfully.
      headers:
        Api-Version:
          $ref: '#/components/headers/apiVersion'
        X-Correlation-Id:
          $ref: '#/components/headers/correlationId'
        Sunset:
          $ref: '#/components/headers/sunset'
        X-RateLimit-Limit:
          $ref: '#/components/headers/rateLimitCount'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/rateLimitRemaining'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/uploadStatus'
    conflict:
      description: Request could not be completed due to a conflict with resource state or existing idempotency key.
      headers:
        Api-Version:
          $ref: '#/components/headers/apiVersion'
        X-Correlation-Id:
          $ref: '#/components/headers/correlationId'
        Sunset:
          $ref: '#/components/headers/sunset'
        X-RateLimit-Limit:
          $ref: '#/components/headers/rateLimitCount'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/rateLimitRemaining'
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/error'
          examples:
            idempotency_error:
              $ref: '#/components/examples/IdempotencyRequestErrorResponse'
    unauthorized:
      description: Not authorized. The user does not have a valid API Key or Access Token.
      headers:
        Api-Version:
          $ref: '#/components/headers/apiVersion'
        X-Correlation-Id:
          $ref: '#/components/headers/correlationId'
        Sunset:
          $ref: '#/components/headers/sunset'
        X-RateLimit-Limit:
          $ref: '#/components/headers/rateLimitCount'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/rateLimitRemaining'
        WWW-Authenticate:
          schema:
            type: string
            example: Bearer, error="invalid_token"
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/error'
          example:
            type: https://developer.moneris.com/en/More/Testing/Response%20Codes
            title: UNAUTHORIZED_REQUEST
            status: 401
            detail: null
            instance: null
            category: UNAUTHORIZED_ERROR
            errors: []
    serviceUnavailable:
      description: Service Temporarily Unavailable
      headers:
        Api-Version:
          $ref: '#/components/headers/apiVersion'
        X-Correlation-Id:
          $ref: '#/components/headers/correlationId'
        Sunset:
          $ref: '#/components/headers/sunset'
        Retry-After:
          $ref: '#/components/headers/retryAfter'
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/error'
          example:
            type: https://api-developer.moneris.com/responsehandling/
            title: SERVICE_UNAVAILABLE
            status: 503
            detail: null
            instance: null
            category: INTERNAL_SERVER_ERROR
            errors: []
    disputeAcceptSuccess:
      description: The dispute has been accepted successfully.
      headers:
        Api-Version:
          $ref: '#/components/headers/apiVersion'
        X-Correlation-Id:
          $ref: '#/components/headers/correlationId'
        Sunset:
          $ref: '#/components/headers/sunset'
        X-RateLimit-Limit:
          $ref: '#/components/headers/rateLimitCount'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/rateLimitRemaining'
    forbidden:
      description: Forbidden. The user does not have permission to access the requested resource.
      headers:
        Api-Version:
          $ref: '#/components/headers/apiVersion'
        X-Correlation-Id:
          $ref: '#/components/headers/correlationId'
        Sunset:
          $ref: '#/components/headers/sunset'
        X-RateLimit-Limit:
          $ref: '#/components/headers/rateLimitCount'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/rateLimitRemaining'
        WWW-Authenticate:
          schema:
            type: string
            example: Bearer, error="insufficient_scope"
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/error'
          example:
            type: https://developer.moneris.com/en/More/Testing/Response%20Codes
            title: FORBIDDEN_REQUEST
            status: 403
            detail: null
            instance: null
            category: UNAUTHORIZED_ERROR
            errors: []
    notFound:
      description: Not Found.
      headers:
        Api-Version:
          $ref: '#/components/headers/apiVersion'
        X-Correlation-Id:
          $ref: '#/components/headers/correlationId'
        Sunset:
          $ref: '#/components/headers/sunset'
        X-RateLimit-Limit:
          $ref: '#/components/headers/rateLimitCount'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/rateLimitRemaining'
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/error'
          example:
            type: https://developer.moneris.com/en/More/Testing/Response%20Codes
            title: NOT_FOUND
            status: 404
            detail: null
            instance: /payments/pi0105ARZ3NDEKTSV4RRFFQ69G5FAV
            category: INVALID_REQUEST_ERROR
            errors: []
    internalServer:
      description: Unexpected error.
      headers:
        Api-Version:
          $ref: '#/components/headers/apiVersion'
        X-Correlation-Id:
          $ref: '#/components/headers/correlationId'
        Sunset:
          $ref: '#/components/headers/sunset'
        X-RateLimit-Limit:
          $ref: '#/components/headers/rateLimitCount'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/rateLimitRemaining'
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/error'
          example:
            type: https://api-developer.moneris.com/responsehandling/
            title: INTERNAL_SERVER_ERROR
            status: 500
            detail: null
            instance: null
            category: INTERNAL_SERVER_ERROR
            errors: []
    tooManyRequests:
      description: Too Many Requests
      headers:
        Api-Version:
          $ref: '#/components/headers/apiVersion'
        X-Correlation-Id:
          $ref: '#/components/headers/correlationId'
        Sunset:
          $ref: '#/components/headers/sunset'
        X-RateLimit-Limit:
          $ref: '#/components/headers/rateLimitCount'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/rateLimitRemaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/rateLimitReset'
        Retry-After:
          $ref: '#/components/headers/rateLimitReset'
    badRequest:
      description: Bad Request.
      headers:
        Api-Version:
          $ref: '#/components/headers/apiVersion'
        X-Correlation-Id:
          $ref: '#/components/headers/correlationId'
        Sunset:
          $ref: '#/components/headers/sunset'
        X-RateLimit-Limit:
          $ref: '#/components/headers/rateLimitCount'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/rateLimitRemaining'
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/error'
    uploadDisputeImagesSuccess:
      description: Dispute image upload has been accepted.
      headers:
        Api-Version:
          $ref: '#/components/headers/apiVersion'
        X-Correlation-Id:
          $ref: '#/components/headers/correlationId'
        Sunset:
          $ref: '#/components/headers/sunset'
        X-RateLimit-Limit:
          $ref: '#/components/headers/rateLimitCount'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/rateLimitRemaining'
        Location:
          $ref: '#/components/headers/location'
  parameters:
    uploadReferenceId:
      description: Upload reference Id.
      example: IU1001ARZ3NDEKTSV4RRFFQ69G5FAV
      in: path
      name: upload-reference-id
      required: true
      schema:
        type: string
    correlationId:
      in: header
      name: X-Correlation-Id
      example: 06f1e47b-a1b5-4902-be9c-bccc506127c4
      description: "Correlates a series of requests within the same flow.\n\nNote: This ID is generated by Moneris with every request or response, if it doesn't exist. \nMerchants are to echo back the value with every request that is part of the call flow.\"\n"
      required: false
      schema:
        type: string
        example: 06f1e47b-a1b5-4902-be9c-bccc506127c4
    apiVersion:
      in: header
      name: Api-Version
      required: true
      example: '2024-09-17'
      description: "The endpoint's API Version. \n\nMust be provided through the headers section. \n"
      schema:
        $ref: '#/components/schemas/apiVersion'
    merchantId:
      in: header
      name: X-Merchant-Id
      example: 0123456789101
      description: "Thirteen character identification code. \n\nNote: This code is provided by Moneris and is required to identify the Merchant executing the transaction.\"\n"
      required: true
      schema:
        $ref: '#/components/schemas/merchantId'
    caseId:
      name: case-id
      in: path
      description: The case ID associated with the uploaded files.
      required: true
      example: '121719004438'
      schema:
        type: string
        pattern: ^[a-zA-Z0-9]{12}$
    caseRecNo:
      name: case-record-number
      in: path
      description: The case record number of the files. This must be a value between "0" and "99".
      required: true
      example: '1'
      schema:
        type: integer
        minimum: 0
        maximum: 99
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-Api-Key
      description: 'An API key is a token that a client provides when making API calls.


        API keys are supposed to be a secret that only the client and server know about.

        '
    OAuth2:
      type: oauth2
      description: 'OAuth 2.0 is an authorization protocol that gives an API client limited access to user data on a web server.


        OAuth relies on authentication scenarios, that allows the resource owner (user) to share the protected content from the server, hosting the resource, without sharing their credentials. For that purpose, an OAuth 2.0 server issues access tokens that the client applications can use to access protected resources on behalf of the resource owner.


        Moneris recommends the use of OAuth 2.0 as it provides fine grained authorization levels.

        '
      flows:
        clientCredentials:
          tokenUrl: /oauth2/token
          scopes:
            payment.read: Grants read access to payment related APIs
            payment.write: Grants read & write access to payment related APIs
            refund.read: Grants read access to refunds
            refund.write: Grants read & write access to refunds
            customer.read: Grants read access to customer data
            customer.write: Grants read & write access to customer data
            kount.read: Grants read access to Kount inquiries
            kount.write: Grants read & write access to Kount inquiries
            onboarding.merchant.read: Grants read access to merchant onboarding related APIs
            onboarding.merchant.write: Grants read & write access to merchant onboarding related APIs
            onboarding.order.read: Grants read access to onboarding orders related APIs
            onboarding.order.write: Grants read & write access to onboarding orders related APIs
            dispute.read: Grants read access to disputes
            dispute.write: Grants read & write access to disputes