Tap Payments Tokens API

Single-use tokenization of cards and wallets.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/tap-payments-tokens-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

tap-payments-tokens-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Tap Payments Authorize Tokens API
  description: REST API for Tap Payments, a payment gateway and financial infrastructure provider for the Middle East and North Africa. Merchants accept online payments across the GCC and Egypt using cards (Visa, Mastercard, Amex), local schemes (mada, KNET, Benefit), and wallets (Apple Pay, Google Pay). The core flows are Charges (charge a source now), Authorize/Capture (hold then capture), Tokens (single-use tokenization of a card or wallet), Customers and Cards (vaulting for recurring / card-on-file), Refunds, Invoices, Payouts, and Business/merchant onboarding. All requests are authenticated with a secret API key passed as a Bearer token; separate test (sk_test_...) and live (sk_live_...) keys are issued from the Tap dashboard. Endpoint paths and methods are grounded in the public Tap developer reference and its published OpenAPI index (developers.tap.company/llms.txt); request and response schemas below are modeled for common fields and are not an exhaustive reproduction of Tap's object schemas - verify field-level detail against the live reference.
  version: '1.0'
  contact:
    name: Tap Payments Developers
    url: https://developers.tap.company
  x-modeled-note: Endpoint list and HTTP methods are grounded in Tap's public developer reference and OpenAPI index. Property-level schemas are modeled (representative), not copied verbatim from Tap.
servers:
- url: https://api.tap.company/v2
  description: Tap Payments production API (test vs live selected by API key)
security:
- bearerAuth: []
tags:
- name: Tokens
  description: Single-use tokenization of cards and wallets.
paths:
  /tokens:
    post:
      operationId: createToken
      tags:
      - Tokens
      summary: Create a token (card)
      description: Tokenizes raw card data into a single-use token id consumed by the Charges or Authorize APIs. Tokens cannot be stored or reused. Variants exist for encrypted cards, saved cards, Apple Pay, Samsung Pay, and network tokens.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/TokenInput'
      responses:
        '200':
          description: The created token.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Token'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /tokens/{token_id}:
    parameters:
    - name: token_id
      in: path
      required: true
      description: The id of the token.
      schema:
        type: string
    get:
      operationId: retrieveToken
      tags:
      - Tokens
      summary: Retrieve a token
      description: Retrieves a token by its id.
      responses:
        '200':
          description: The requested token.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Token'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
components:
  responses:
    Unauthorized:
      description: Missing or invalid API key.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    NotFound:
      description: The requested resource was not found.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  schemas:
    TokenInput:
      type: object
      properties:
        card:
          type: object
          properties:
            number:
              type: string
            exp_month:
              type: integer
            exp_year:
              type: integer
            cvc:
              type: string
            name:
              type: string
        client_ip:
          type: string
    Token:
      type: object
      properties:
        id:
          type: string
        object:
          type: string
          example: token
        used:
          type: boolean
        type:
          type: string
        card:
          $ref: '#/components/schemas/Card'
    Card:
      type: object
      properties:
        id:
          type: string
        object:
          type: string
          example: card
        last_four:
          type: string
        brand:
          type: string
        exp_month:
          type: integer
        exp_year:
          type: integer
        funding:
          type: string
    Error:
      type: object
      properties:
        errors:
          type: array
          items:
            type: object
            properties:
              code:
                type: string
              description:
                type: string
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: 'Secret API key passed as a Bearer token in the Authorization header: `Authorization: Bearer sk_test_...` (test) or `sk_live_...` (live). Keys are issued from the Tap dashboard. Never expose the secret key in client-side code.'