Every API here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for apis
7 MCP tools reach this
find_apisBrowse and filter every API in the catalog.
get_api_artifactsOne API's artifacts, grouped by type.
get_openapiThe primary OpenAPI for this API.
find_similar_apisAPIs that look like this one.
apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
resolveTurn a domain, URL or GitHub org into the provider it belongs to.
find_cohortsEvery scored population of providers in the catalog.
All 92 tools →
Call it yourself
curl for this page
This API
curl "https://apis.io/api/v1/apis/paypal-payment-tokens-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: Paypal Subscriptions Authorizations Payment Tokens API
description: You can use billing plans and subscriptions to create subscriptions that process recurring PayPal payments for physical or digital goods, or services. A plan includes pricing and billing cycle information that defines the amount and frequency of charge for a subscription. You can also define a fixed plan, such as a $5 basic plan or a volume- or graduated-based plan with pricing tiers based on the quantity purchased. For more information, see <a href="/docs/subscriptions/">Subscriptions Overview</a>.
version: '1.6'
contact: {}
servers:
- url: https://api-m.sandbox.paypal.com
description: PayPal Sandbox Environment
- url: https://api-m.paypal.com
description: PayPal Live Environment
tags:
- name: Payment-Tokens
description: Use the `/vault/payment-tokens` resource to create, retrieve, and delete a payment token that may optionally be associated with a customer.
paths:
/v3/vault/payment-tokens:
post:
description: Creates a Payment Token from the given payment source and adds it to the Vault of the associated customer.
summary: Paypal Create payment token for a given payment source
operationId: payment-tokens.create
responses:
'200':
description: Idempotent response for a successful creation of payment token.
content:
application/json:
schema:
$ref: '#/components/schemas/payment_token_response'
examples:
payment_token_response:
value:
id: 8kk8451t
customer:
id: customer_4029352050
payment_source:
card:
last_digits: '1111'
expiry: 2027-02
brand: VISA
name: John Doe
billing_address:
address_line_1: 2211 N First Street
address_line_2: 17.3.160
admin_area_2: San Jose
admin_area_1: CA
postal_code: '95131'
country_code: US
links:
- rel: self
href: https://api-m.paypal.com/v3/vault/payment-tokens/8kk8451t
method: GET
encType: application/json
- rel: delete
href: https://api-m.paypal.com/v3/vault/payment-tokens/8kk8451t
method: DELETE
encType: application/json
'201':
description: A successful creation of payment token.
content:
application/json:
schema:
$ref: '#/components/schemas/payment_token_response'
examples:
payment_token_response:
value:
id: 8kk8451t
customer:
id: customer_4029352050
payment_source:
card:
last_digits: '1111'
expiry: 2027-02
brand: VISA
name: John Doe
billing_address:
address_line_1: 2211 N First Street
address_line_2: 17.3.160
admin_area_2: San Jose
admin_area_1: CA
postal_code: '95131'
country_code: US
links:
- rel: self
href: https://api-m.paypal.com/v3/vault/payment-tokens/8kk8451t
method: GET
encType: application/json
- rel: delete
href: https://api-m.paypal.com/v3/vault/payment-tokens/8kk8451t
method: DELETE
encType: application/json
'400':
description: Request is not well-formed, syntactically incorrect, or violates schema.
content:
application/json:
schema:
$ref: '#/components/schemas/error'
'403':
description: Authorization failed due to insufficient permissions.
content:
application/json:
schema:
$ref: '#/components/schemas/error'
'404':
description: Request contains reference to resources that do not exist.
content:
application/json:
schema:
$ref: '#/components/schemas/error'
'422':
description: The requested action could not be performed, semantically incorrect, or failed business validation.
content:
application/json:
schema:
$ref: '#/components/schemas/error'
'500':
description: An internal server error has occurred.
content:
application/json:
schema:
$ref: '#/components/schemas/error'
parameters:
- $ref: '#/components/parameters/paypal_request_id'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/payment_token_request'
examples:
payment_token_request:
value:
payment_source:
token:
id: 5C991763VB2781612
type: BILLING_AGREEMENT
description: Payment Token creation with a financial instrument and an optional customer_id.
required: true
security:
- Oauth2:
- https://uri.paypal.com/services/vault/payment-tokens/readwrite
tags:
- Payment-Tokens
get:
description: Returns all payment tokens for a customer.
summary: Paypal List all payment tokens
operationId: customer.payment-tokens.get
responses:
'200':
description: Successful execution.
content:
application/json:
schema:
$ref: '#/components/schemas/customer_vault_payment_tokens_response'
examples:
customer_vault_payment_tokens_response:
value:
customer:
id: customer_4029352050
payment_tokens:
- id: 8kk8451t
customer:
id: customer_4029352050
payment_source:
card:
brand: VISA
last_digits: '1111'
expiry: 2027-02
name: John Doe
billing_address:
address_line_1: 2211 N First Street
address_line_2: 17.3.160
admin_area_2: San Jose
admin_area_1: CA
postal_code: '95131'
country_code: US
links:
- rel: self
href: https://api-m.paypal.com/v3/vault/payment-tokens/8kk8451t
method: GET
encType: application/json
- rel: delete
href: https://api-m.paypal.com/v3/vault/payment-tokens/8kk8451t
method: DELETE
encType: application/json
- id: fgh6561t
customer:
id: customer_4029352050
payment_source:
paypal:
description: Description for PayPal to be shown to PayPal payer
email_address: john.doe@example.com
account_id: VYYFH3WJ4JPJQ
shipping:
name:
full_name: John Doe
address:
address_line_1: 2211 N First Street
address_line_2: 17.3.160
admin_area_2: San Jose
admin_area_1: CA
postal_code: '95131'
country_code: US
usage_pattern: IMMEDIATE
usage_type: MERCHANT
customer_type: CONSUMER
name:
given_name: John
surname: Doe
address:
address_line_1: 2211 N First Street
address_line_2: 17.3.160
admin_area_2: San Jose
admin_area_1: CA
postal_code: '95131'
country_code: US
links:
- rel: self
href: https://api-m.paypal.com/v3/vault/payment-tokens/fgh6561t
method: GET
encType: application/json
- rel: delete
href: https://api-m.paypal.com/v3/vault/payment-tokens/fgh6561t
method: DELETE
encType: application/json
- id: hg654s1t
customer:
id: customer_4029352050
payment_source:
venmo:
description: Description for Venmo to be shown to Venmo payer
shipping:
name:
full_name: John Doe
address:
address_line_1: 2211 N First Street
address_line_2: 17.3.160
admin_area_2: San Jose
admin_area_1: CA
postal_code: '95131'
country_code: US
usage_pattern: IMMEDIATE
usage_type: MERCHANT
customer_type: CONSUMER
email_address: john.doe@example.com
user_name: johndoe
name:
given_name: John
surname: Doe
account_id: VYYFH3WJ4JPJQ
address:
address_line_1: PayPal
address_line_2: 2211 North 1st Street
admin_area_1: CA
admin_area_2: San Jose
postal_code: '96112'
country_code: US
links:
- rel: self
href: https://api-m.paypal.com/v3/vault/payment-tokens/hg654s1t
method: GET
encType: application/json
- rel: delete
href: https://api-m.paypal.com/v3/vault/payment-tokens/hg654s1t
method: DELETE
encType: application/json
links:
- rel: self
href: https://api-m.paypal.com/v3/vault/payment-tokens?customer_id=customer_4029352050&page=1&page_size=5&total_required=false
method: GET
encType: application/json
- rel: first
href: https://api-m.paypal.com/v3/vault/payment-tokens?customer_id=customer_4029352050&page=1&page_size=5&total_required=false
method: GET
encType: application/json
- rel: last
href: https://api-m.paypal.com/v3/vault/payment-tokens?customer_id=customer_4029352050&page=1&page_size=5&total_required=false
method: GET
encType: application/json
'400':
description: Request is not well-formed, syntactically incorrect, or violates schema.
content:
application/json:
schema:
$ref: '#/components/schemas/error'
'403':
description: Authorization failed due to insufficient permissions.
content:
application/json:
schema:
$ref: '#/components/schemas/error'
'500':
description: An internal server error has occurred.
content:
application/json:
schema:
$ref: '#/components/schemas/error'
parameters:
- $ref: '#/components/parameters/customer_id'
- $ref: '#/components/parameters/page_size'
- $ref: '#/components/parameters/page'
- $ref: '#/components/parameters/total_required'
security:
- Oauth2:
- https://uri.paypal.com/services/vault/payment-tokens/readwrite
tags:
- Payment-Tokens
/v3/vault/payment-tokens/{id}:
get:
description: Returns a readable representation of vaulted payment source associated with the payment token id.
summary: Paypal Retrieve a payment token
operationId: payment-tokens.get
responses:
'200':
description: Successful execution.
content:
application/json:
schema:
$ref: '#/components/schemas/payment_token_response'
'403':
description: Authorization failed due to insufficient permissions.
content:
application/json:
schema:
$ref: '#/components/schemas/error'
'404':
description: The specified resource does not exist.
content:
application/json:
schema:
$ref: '#/components/schemas/error'
'422':
description: The requested action could not be performed, semantically incorrect, or failed business validation.
content:
application/json:
schema:
$ref: '#/components/schemas/error'
'500':
description: An internal server error has occurred.
content:
application/json:
schema:
$ref: '#/components/schemas/error'
parameters:
- $ref: '#/components/parameters/id'
security:
- Oauth2:
- https://uri.paypal.com/services/vault/payment-tokens/readwrite
tags:
- Payment-Tokens
delete:
description: Delete the payment token associated with the payment token id.
summary: Paypal Delete payment token
operationId: payment-tokens.delete
responses:
'204':
description: The server has successfully executed the method, but there is no entity body to return.
'400':
description: Request is not well-formed, syntactically incorrect, or violates schema.
content:
application/json:
schema:
$ref: '#/components/schemas/error'
'403':
description: Authorization failed due to insufficient permissions.
content:
application/json:
schema:
$ref: '#/components/schemas/error'
'500':
description: An internal server error has occurred.
content:
application/json:
schema:
$ref: '#/components/schemas/error'
parameters:
- $ref: '#/components/parameters/id'
security:
- Oauth2:
- https://uri.paypal.com/services/vault/payment-tokens/readwrite
tags:
- Payment-Tokens
components:
schemas:
error:
type: object
title: Error
description: The error details.
properties:
name:
type: string
description: The human-readable, unique name of the error.
message:
type: string
description: The message that describes the error.
debug_id:
type: string
description: The PayPal internal ID. Used for correlation purposes.
information_link:
type: string
description: The information link, or URI, that shows detailed information about this error for the developer.
readOnly: true
details:
type: array
description: An array of additional details about the error.
items:
$ref: '#/components/schemas/error_details-2'
links:
type: array
description: An array of request-related [HATEOAS links](/api/rest/responses/#hateoas-links).
readOnly: true
items:
$ref: '#/components/schemas/link_description'
readOnly: true
required:
- name
- message
- debug_id
link_description:
type: object
title: Link Description
description: The request-related [HATEOAS link](/api/rest/responses/#hateoas-links) information.
required:
- href
- rel
properties:
href:
type: string
description: The complete target URL. To make the related call, combine the method with this [URI Template-formatted](https://tools.ietf.org/html/rfc6570) link. For pre-processing, include the `$`, `(`, and `)` characters. The `href` is the key HATEOAS component that links a completed call with a subsequent call.
rel:
type: string
description: The [link relation type](https://tools.ietf.org/html/rfc5988#section-4), which serves as an ID for a link that unambiguously describes the semantics of the link. See [Link Relations](https://www.iana.org/assignments/link-relations/link-relations.xhtml).
method:
type: string
description: The HTTP method required to make the related call.
enum:
- GET
- POST
- PUT
- DELETE
- HEAD
- CONNECT
- OPTIONS
- PATCH
apple_pay_payment_token_response:
type: object
title: Apple Pay Response
description: A resource representing a response for Apple Pay.
properties:
card:
description: Card data for the card linked to the apple pay token.
$ref: '#/components/schemas/apple_pay_card'
money:
type: object
title: Money
description: The currency and amount for a financial transaction, such as a balance or payment due.
properties:
currency_code:
$ref: '#/components/schemas/currency_code'
value:
type: string
description: The value, which might be:<ul><li>An integer for currencies like `JPY` that are not typically fractional.</li><li>A decimal fraction for currencies like `TND` that are subdivided into thousandths.</li></ul>For the required number of decimal places for a currency code, see [Currency Codes](/api/rest/reference/currency-codes/).
maxLength: 32
pattern: ^((-?[0-9]+)|(-?([0-9]+)?[.][0-9]+))$
required:
- currency_code
- value
merchant_partner_customer_id:
type: string
description: The unique ID for a customer generated by PayPal.
minLength: 1
maxLength: 22
pattern: ^[0-9a-zA-Z_-]+$
date_time:
type: string
description: The date and time, in [Internet date and time format](https://tools.ietf.org/html/rfc3339#section-5.6). Seconds are required while fractional seconds are optional.<blockquote><strong>Note:</strong> The regular expression provides guidance but does not reject all invalid dates.</blockquote>
format: ppaas_date_time_v3
minLength: 20
maxLength: 64
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[1-2][0-9]|3[0-1])[T,t]([0-1][0-9]|2[0-3]):[0-5][0-9]:([0-5][0-9]|60)([.][0-9]+)?([Zz]|[+-][0-9]{2}:[0-9]{2})$
venmo_response:
title: Venmo Response
description: Full representation of a Venmo Payment Token.
type: object
allOf:
- $ref: '#/components/schemas/wallet_base'
- readOnly: true
$ref: '#/components/schemas/payer'
- properties:
user_name:
description: The Venmo username, as chosen by the user.
type: string
pattern: ^[-a-zA-Z0-9_]*$
minLength: 1
maxLength: 50
account_id:
type: string
title: PayPal Account Identifier
description: The account identifier for a PayPal account.
format: ppaas_payer_id_v3
minLength: 13
maxLength: 13
pattern: ^[2-9A-HJ-NP-Z]{13}$
3ds_result: {}
currency_code:
description: The [three-character ISO-4217 currency code](/api/rest/reference/currency-codes/) that identifies the currency.
type: string
format: ppaas_common_currency_code_v2
minLength: 3
maxLength: 3
vault_id:
type: string
description: The PayPal-generated ID for the vault token.
minLength: 1
maxLength: 36
pattern: ^[0-9a-zA-Z_-]+$
phone_type:
type: string
title: Phone Type
description: The phone type.
enum:
- FAX
- HOME
- MOBILE
- OTHER
- PAGER
payer_base:
type: object
title: Payer Base
description: The customer who approves and pays for the order. The customer is also known as the payer.
properties:
email_address:
description: The email address of the payer.
$ref: '#/components/schemas/email'
payer_id:
description: The PayPal-assigned ID for the payer.
readOnly: true
$ref: '#/components/schemas/account_id'
email:
type: string
description: The internationalized email address.<blockquote><strong>Note:</strong> Up to 64 characters are allowed before and 255 characters are allowed after the <code>@</code> sign. However, the generally accepted maximum length for an email address is 254 characters. The pattern verifies that an unquoted <code>@</code> sign exists.</blockquote>
format: merchant_common_email_address_v2
maxLength: 254
minLength: 3
pattern: (?:[a-zA-Z0-9!#$%&'*+/=?^_`{|}~-]+(?:\.[a-zA-Z0-9!#$%&'*+/=?^_`{|}~-]+)*|(?:[\x01-\x08\x0b\x0c\x0e-\x1f\x21\x23-\x5b\x5d-\x7f]|\[\x01-\x09\x0b\x0c\x0e-\x7f])*")@(?:(?:[a-zA-Z0-9](?:[a-zA-Z0-9-]*[a-zA-Z0-9])?\.)+[a-zA-Z0-9](?:[a-zA-Z0-9-]*[a-zA-Z0-9])?|\[(?:(?:(2(5[0-5]|[0-4][0-9])|1[0-9][0-9]|[1-9]?[0-9]))\.){3}(?:(2(5[0-5]|[0-4][0-9])|1[0-9][0-9]|[1-9]?[0-9])|[a-zA-Z0-9-]*[a-zA-Z0-9]:(?:[\x01-\x08\x0b\x0c\x0e-\x1f\x21-\x5a\x53-\x7f]|\[\x01-\x09\x0b\x0c\x0e-\x7f])+)\])
card_verification_status:
title: Card Verification Status
type: string
minLength: 1
maxLength: 255
pattern: ^[0-9A-Z_]+$
description: Verification status of Card.
payment_token_request:
title: Payment Token Request
description: Payment Token Request where the `source` defines the type of instrument to be stored.
type: object
properties:
customer:
description: Customer in merchant's or partner's system of records.
$ref: '#/components/schemas/customer'
payment_source:
title: Payment source request
description: The payment method to vault with the instrument details.
type: object
properties:
card:
$ref: '#/components/schemas/card_request'
token:
$ref: '#/components/schemas/token_id_request'
metadata:
$ref: '#/components/schemas/metadata'
required:
- payment_source
metadata: {}
card_response:
type: object
title: Card Response
description: Full representation of a Card Payment Token.
properties:
name:
type: string
description: The card holder's name as it appears on the card.
minLength: 2
maxLength: 300
pattern: ^[A-Za-z ]+$
last_digits:
type: string
description: The last digits of the payment card.
pattern: '[0-9]{2,}'
minLength: 2
maxLength: 4
readOnly: true
brand:
description: The card brand or network. Typically used in the response.
readOnly: true
$ref: '#/components/schemas/card_brand'
expiry:
description: The card expiration year and month, in [Internet date format](https://tools.ietf.org/html/rfc3339#section-5.6).
$ref: '#/components/schemas/date_year_month'
billing_address:
description: The billing address for this card. Supports only the `address_line_1`, `address_line_2`, `admin_area_1`, `admin_area_2`, `postal_code`, and `country_code` properties.
$ref: '#/components/schemas/address_entity'
verification_status:
description: Card Verification status.
$ref: '#/components/schemas/card_verification_status'
verification:
$ref: '#/components/schemas/card_verification_details'
bank_response:
title: Bank Response
description: Full representation of a Bank Payment Token.
type: object
properties:
ach_debit:
description: ACH Debit Response.
$ref: '#/components/schemas/ach_debit_response-2'
shipping_detail:
type: object
description: The shipping details.
title: Shipping Details
properties:
name:
description: The name of the person to whom to ship the items. Supports only the `full_name` property.
$ref: '#/components/schemas/name'
type:
description: The method by which the payer wants to get their items from the payee e.g shipping, in-person pickup. Either type or options but not both may be present.
type: string
minLength: 1
maxLength: 255
pattern: ^[0-9A-Z_]+$
enum:
- SHIPPING
- PICKUP_IN_PERSON
address:
description: The address of the person to whom to ship the items. Supports only the `address_line_1`, `address_line_2`, `admin_area_1`, `admin_area_2`, `postal_code`, and `country_code` properties.
$ref: '#/components/schemas/address_portable'
phone:
type: object
title: Phone
description: The phone number, in its canonical international [E.164 numbering plan format](https://www.itu.int/rec/T-REC-E.164/en).
properties:
country_code:
type: string
description: The country calling code (CC), in its canonical international [E.164 numbering plan format](https://www.itu.int/rec/T-REC-E.164/en). The combined length of the CC and the national number must not be greater than 15 digits. The national number consists of a national destination code (NDC) and subscriber number (SN).
minLength: 1
maxLength: 3
pattern: ^[0-9]{1,3}?$
national_number:
type: string
description: The national number, in its canonical international [E.164 numbering plan format](https://www.itu.int/rec/T-REC-E.164/en). The combined length of the country calling code (CC) and the national number must not be greater than 15 digits. The national number consists of a national destination code (NDC) and subscriber number (SN).
minLength: 1
maxLength: 14
pattern: ^[0-9]{1,14}?$
extension_number:
type: string
description: The extension number.
minLength: 1
maxLength: 15
pattern: ^[0-9]{1,15}?$
required:
- country_code
- national_number
name:
type: object
title: Name
description: The name of the party.
properties:
prefix:
type: string
description: The prefix, or title, to the party's name.
maxLength: 140
given_name:
type: string
description: When the party is a person, the party's given, or first, name.
maxLength: 140
surname:
type: string
description: When the party is a person, the party's surname or family name. Also known as the last name. Required when the party is a person. Use also to store multiple surnames including the matronymic, or mother's, surname.
maxLength: 140
middle_name:
type: string
description: When the party is a person, the party's middle name. Use also to store multiple middle names including the patronymic, or father's, middle name.
maxLength: 140
suffix:
type: string
description: The suffix for the party's name.
maxLength: 140
alternate_full_name:
type: string
description: DEPRECATED. The party's alternate name. Can be a business name, nickname, or any other name that cannot be split into first, last name. Required when the party is a business.
maxLength: 300
full_name:
type: string
description: When the party is a person, the party's full name.
maxLength: 300
customer:
type: object
title: Customer Request
description: Customer in merchant's or partner's system of records.
properties:
id:
description: The unique ID for a customer in merchant's or partner's system of records.
$ref: '#/components/schemas/merchant_partner_customer_id'
ach_debit_response-2:
title: ACH Debit Response
description: A Resource representing a response of vaulted a ACH Debit Account.
allOf:
- $ref: '#/components/schemas/ach_debit_response'
- properties:
verification_status:
description: ACH Debit Verification Status
$ref: '#/components/schemas/ach_debit_verification_status'
token_id_request:
type: object
title: Token Request
description: The Tokenized Payment Source representing a Request to Vault a Token.
properties:
id:
type: string
description: The PayPal-generated ID for the token.
minLength: 1
maxLength: 255
pattern: ^[0-9A-Z_-]+$
type:
type: string
description: The tokenization method that generated the ID.
minLength: 1
maxLength: 255
pattern: ^[0-9A-Z_-]+$
enum:
- BILLING_AGREEMENT
attributes:
description: The auxiliary details of the token.
$ref: '#/components/schemas/token_attributes'
required:
- id
- type
token_attributes: {}
paypal_wallet_response:
title: PayPal Wallet Response
description: Full representation of a PayPal Payment Token.
type: object
allOf:
- $ref: '#/components/schemas/wallet_base'
- readOnly: true
$ref: '#/components/schemas/payer'
- properties:
account_id:
readOnly: true
description: The account identifier for a PayPal account.
$ref: '#/components/schemas/account_id'
phone_number:
readOnly: true
description: The phone number, in its canonical international [E.164 numbering plan format](https://www.itu.int/rec/T-REC-E.164/en).
$ref: '#/components/schemas/phone'
card_type:
type: string
title: Card Type
description: Type of card. i.e Credit, Debit and so on.
minLength: 1
maxLength: 255
pattern: ^[A-Z_]+$
enum:
- CREDIT
- DEBIT
- PREPAID
- STORE
- UNKNOWN
vault_instruction:
title: Vault Instruction
type: string
description: Vault Instruction on action to be performed after a successful payer approval.
minLength: 1
maxLength: 255
pattern: ^[A-Z_]+$
default: ON_CREATE_PAYMENT_TOKENS
date_no_time:
type: string
description: The stand-alone date, in [Internet date and time format](https://tools.ietf.org/html/rfc3339#section-5.6). To represent special legal values, such as a date of birth, you should use dates with no associated time or time-zone data. Whenever possible, use the standard `date_time` type. This regular expression does not validate all dat
# --- truncated at 32 KB (58 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/paypal/refs/heads/main/openapi/paypal-payment-tokens-api-openapi.yml