Weavr Step-up Challenges API
Issue and verify step-up challenges that elevate an existing user token.
Issue and verify step-up challenges that elevate an existing user token.
openapi: 3.1.0
info:
version: v3
title: Weavr Multi Product BackOffice Access Token Step-up Challenges API
x-logo:
url: https://storage.googleapis.com/weavr-cdn/weavr_logo-new.png
backgroundColor: '#FFFFFF'
altText: Weavr
description: 'Weavr Multi Back Office API allows you, as an innovator, to perform various back office operations concerning
identities and their instruments, without requiring the users to be logged in.
A token is to be obtained through the `access_token` method, and this will allow relevant operations
to be performed on behalf of this same identity.
'
contact:
name: Weavr
url: https://weavr.io
servers:
- description: Weavr Sandbox Environment
url: https://sandbox.weavr.io/multi/backoffice
tags:
- name: Step-up Challenges
description: Issue and verify step-up challenges that elevate an existing user token.
paths:
/stepup/challenges/otp/{channel}:
post:
tags:
- Step-up Challenges
description: 'Initiates the step-up token process by sending an SMS with an one-time-password to a device belonging to the logged-in user that was previously enrolled through `/authentication_factors/otp/{channel}` endpoint.
This process is required for endpoints that require a step-up token to complete the call.
_Note that on the Sandbox Environment, text messages are not sent and the one-time-password is always \"123456\"._
'
summary: Issue a one-time password that can be used to step-up a token
operationId: stepupSCAChallenge
parameters:
- $ref: '#/components/parameters/idempotency-ref'
- $ref: '#/components/parameters/channel'
responses:
'204':
$ref: '#/components/responses/NoContent'
'400':
$ref: '#/components/responses/BadRequestError'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'405':
$ref: '#/components/responses/MethodNotAllowed'
'409':
$ref: '#/components/responses/StepUpSCAChallengeConflict'
'429':
$ref: '#/components/responses/TooManyRequests'
'500':
$ref: '#/components/responses/InternalServerError'
'503':
$ref: '#/components/responses/ServiceUnavailable'
default:
$ref: '#/components/responses/Error'
security:
- auth_token: []
api-key: []
/stepup/challenges/otp/{channel}/verify:
post:
tags:
- Step-up Challenges
description: 'Completes the verification process for a step up token.
The challenge expires after 5 minutes and the number of incorrect OTP attempts is limited to reduce the risk of fraud, in that case challenge has to be issued again.
_Note that on the Sandbox Environment, text messages are not sent and the `verificationCode` is always \"123456\"._
'
summary: Verify a step-up token using a one-time password
operationId: stepupSCAVerify
parameters:
- $ref: '#/components/parameters/idempotency-ref'
- $ref: '#/components/parameters/channel'
requestBody:
$ref: '#/components/requestBodies/SCAVerifyRequest'
responses:
'204':
$ref: '#/components/responses/NoContent'
'400':
$ref: '#/components/responses/BadRequestError'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'409':
$ref: '#/components/responses/StepUpSCAVerifyConflict'
'429':
$ref: '#/components/responses/TooManyRequests'
'500':
$ref: '#/components/responses/InternalServerError'
'503':
$ref: '#/components/responses/ServiceUnavailable'
default:
$ref: '#/components/responses/Error'
security:
- auth_token: []
api-key: []
/stepup/challenges/push/{channel}:
post:
tags:
- Step-up Challenges
description: 'Initiates the step-up token process by submitting a push notification to a device belonging to the logged-in user that was previously enrolled through the `/authentication_factors/push/{channel}` endpoint.
You should only start this process if the token step-up isn''t already in flight.
'
summary: Issue a push notification that can be used to step-up a token
operationId: stepupSCAChallengePush
parameters:
- $ref: '#/components/parameters/idempotency-ref'
- $ref: '#/components/parameters/scaPushChannel'
responses:
'200':
$ref: '#/components/responses/StepUpSCAChallengePushResponse'
'400':
$ref: '#/components/responses/BadRequestError'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'405':
$ref: '#/components/responses/MethodNotAllowed'
'409':
$ref: '#/components/responses/StepUpSCAChallengePushConflict'
'429':
$ref: '#/components/responses/TooManyRequests'
'500':
$ref: '#/components/responses/InternalServerError'
'503':
$ref: '#/components/responses/ServiceUnavailable'
default:
$ref: '#/components/responses/Error'
security:
- auth_token: []
api-key: []
components:
parameters:
scaPushChannel:
name: channel
in: path
required: true
schema:
$ref: '#/components/schemas/SCAPushChannel'
channel:
name: channel
in: path
required: true
description: The unique identifier for the channel.
schema:
$ref: '#/components/schemas/SCAOtpChannel'
idempotency-ref:
name: idempotency-ref
in: header
description: A unique call reference generated by the caller that, taking into consideration the payload as well as the operation itself, helps avoid duplicate operations. Idempotency reference uniqueness is maintained for at least 24 hours.
required: false
schema:
type: string
responses:
InternalServerError:
description: Internal Server Error - There is a problem with the server. Please try again later.
headers:
request-ref:
$ref: '#/components/headers/request-ref'
BadRequestError:
description: Bad Request Error - Your request is invalid.
headers:
request-ref:
$ref: '#/components/headers/request-ref'
content:
application/json:
schema:
type: object
properties:
message:
maxLength: 255
type: string
description: When present helps to identify and fix the problem.
syntaxErrors:
$ref: '#/components/schemas/SyntaxError'
Error:
description: Error
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
StepUpSCAChallengePushConflict:
description: Conflict
content:
application/json:
schema:
type: object
properties:
errorCode:
type: string
enum:
- STATE_INVALID
- CHANNEL_NOT_SUPPORTED
- CHANNEL_NOT_REGISTERED
- CHALLENGE_LIMIT_EXCEEDED
TooManyRequests:
description: Too many requests.
headers:
request-ref:
$ref: '#/components/headers/request-ref'
x-ratelimit-limit:
$ref: '#/components/headers/x-ratelimit-limit'
x-ratelimit-reset:
$ref: '#/components/headers/x-ratelimit-reset'
StepUpSCAChallengeConflict:
description: Conflict
content:
application/json:
schema:
type: object
properties:
errorCode:
type: string
enum:
- CHANNEL_NOT_SUPPORTED
- CHANNEL_NOT_REGISTERED
- MOBILE_NUMBER_INVALID
- MOBILE_COUNTRY_NOT_SUPPORTED
- RETRY_IN_15SEC
- CHALLENGE_LIMIT_EXCEEDED
ServiceUnavailable:
description: Service Unavailable - The requested service is temporarily unavailable. Please try again later.
headers:
request-ref:
$ref: '#/components/headers/request-ref'
StepUpSCAChallengePushResponse:
description: Success
headers:
request-ref:
$ref: '#/components/headers/request-ref'
content:
application/json:
schema:
type: object
properties:
id:
type: string
pattern: ^[0-9]+$
description: The challenge id.
Forbidden:
description: Forbidden - Access to the requested resource or action is forbidden.
headers:
request-ref:
$ref: '#/components/headers/request-ref'
content:
application/json:
schema:
type: object
properties:
errorCode:
type: string
enum:
- INSUFFICIENT_PERMISSIONS
StepUpSCAVerifyConflict:
description: Conflict
content:
application/json:
schema:
type: object
properties:
errorCode:
type: string
enum:
- STATE_INVALID
- VERIFICATION_CODE_EXPIRED
- VERIFICATION_CODE_INVALID
- CHANNEL_NOT_SUPPORTED
- CHANNEL_NOT_REGISTERED
- ONE_CHALLENGE_LIMIT_REMAINING
- CHALLENGE_LIMIT_EXCEEDED
- ALREADY_VERIFIED
Unauthorized:
description: Unauthorized - Your credentials or access token are invalid.
headers:
request-ref:
$ref: '#/components/headers/request-ref'
NoContent:
description: Success - No Content.
headers:
request-ref:
$ref: '#/components/headers/request-ref'
MethodNotAllowed:
description: Method Not Allowed - The request was received but has been rejected for the requested resource.
headers:
request-ref:
$ref: '#/components/headers/request-ref'
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
headers:
request-ref:
description: A request identifier. Providing this reference when contacting our support team will help us investigate your query.
required: true
schema:
type: string
x-ratelimit-reset:
description: The number of seconds until the window is reset.
required: true
schema:
minimum: 0
type: integer
format: int32
x-ratelimit-limit:
description: 'Example: `20, 10;w=60, 20;w=3600, 200;w=86400`
The first number (20) is the limit that has been exceeded.
The remaining numbers are the limits that are in force, with ''w'' meaning ''window in seconds''. In this example `20;w=3600` was exceeded. 20 calls in 3600secs (1hr)
'
required: true
schema:
type: string
schemas:
SyntaxError:
type: object
description: Is returned as part of an HTTP error response whenever a syntax error is detected. A list of the fields together with their syntax error will be provided.
properties:
invalidFields:
type: array
items:
type: object
properties:
params:
type: array
items:
type: string
fieldName:
type: string
error:
type: string
enum:
- REQUIRED
- HAS_TEXT
- REQUIRES
- SIZE
- RANGE
- IN
- NOT_IN
- REGEX
- EXACTLY
- AT_LEAST
- AT_MOST
- ALL_OR_NONE
SCAPushChannel:
type: string
enum:
- AUTHY
- BIOMETRIC
description: '- "AUTHY": The push notification is sent on the user''s device using [Twilio Authy](https://www.twilio.com/authy)
- "BIOMETRIC": The push notification is sent to the user''s device
'
Nonce:
type: string
description: A randomly generated one-time use code.
pattern: ^[0-9]{6}$
SCAOtpChannel:
type: string
enum:
- SMS
description: '- "SMS": The one-time-password is sent as a text message
'
Error:
type: object
properties:
code:
type: string
message:
type: string
requestBodies:
SCAVerifyRequest:
required: true
content:
application/json:
schema:
required:
- verificationCode
type: object
properties:
verificationCode:
description: The code received by the user on the device.
$ref: '#/components/schemas/Nonce'
securitySchemes:
api_key:
type: apiKey
description: The API Key representing your Multi account.
name: api-key
in: header
auth_token:
type: http
description: The authentication token representing the user. This will be included in the login response object.
scheme: bearer
bearerFormat: JWT
x-tagGroups:
- name: Access
tags:
- Access Token
- User Impersonation
- Consent Request
- name: Identities
tags:
- Corporates
- Consumers
- name: User Management
tags:
- Authorised Users
- name: Instruments
tags:
- Managed Accounts
- Managed Cards
- name: Transactions
tags:
- Transfers
- name: Fees
tags:
- Fees
- name: Bulk Operations [Beta]
tags:
- Operations
- Manage