Wise Sca Pin API

PIN (Personal Identification Number) is a knowledge-based SCA challenge factor. Users create a 4-digit PIN that can be used to verify their identity when accessing SCA-protected endpoints. All PIN creation and verification requests use JOSE (JWE) encryption to ensure the PIN is never transmitted in plain text. See the [SCA over API guide](/guides/developer/auth-and-security/sca-and-2fa) for encryption details.

Operations 4

POST /v1/one-time-token/pin/verify Verify PIN #
POST /v2/profiles/{profileId}/pin Create a PIN #
DELETE /v2/profiles/{profileId}/pin Delete a PIN #
POST /v2/profiles/{profileId}/pin/verify Verify a PIN #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/wise-sca-pin-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

wise-sca-pin-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Wise Platform Sca Pin API
  version: ''
  description: The Wise Platform API is a REST-based interface that enables programmatic access to Wise's payment infrastructure.
servers:
- url: https://api.wise.com
  description: Production Environment
- url: https://api.wise-sandbox.com
  description: Sandbox Environment
tags:
- name: sca-pin
  x-displayName: PIN
  description: 'PIN (Personal Identification Number) is a knowledge-based SCA challenge factor. Users create a 4-digit PIN that can be used to verify their identity when accessing SCA-protected endpoints.


    All PIN creation and verification requests use JOSE (JWE) encryption to ensure the PIN is never transmitted in plain text. See the SCA over API guide for encryption details.'
paths:
  /v1/one-time-token/pin/verify:
    post:
      deprecated: true
      operationId: ottPinVerify
      summary: Verify PIN
      description: '{% img src="https://img.shields.io/badge/jose-direct_encryption-blue" /%}{% .d-inline-block %}


        To clear a **PIN** challenge listed in a OTT.


        Notes:

        1. User is required to create pin before the verification can be successful.

        2. Rate limit may be applied if there are 5 continuous unsuccessful attempts and OTT creation will be blocked for 15 minutes.'
      tags:
      - sca-pin
      security:
      - UserToken: []
      parameters:
      - name: One-Time-Token
        in: header
        required: true
        description: Text value of a OTT.
        schema:
          type: string
      - name: Accept
        in: header
        required: true
        schema:
          type: string
          enum:
          - application/jose+json
        example: application/jose+json
      - name: X-TW-JOSE-Method
        in: header
        required: true
        description: JOSE method identifier.
        schema:
          type: string
          enum:
          - jwe
        example: jwe
      - $ref: '#/components/parameters/X-External-Correlation-Id'
      x-codeSamples:
      - lang: bash
        label: cURL
        source: "curl -i -X POST \\\n  https://api.wise-sandbox.com/v1/one-time-token/pin/verify \\\n  -H 'Authorization: Bearer <YOUR_TOKEN_HERE>' \\\n  -H 'Accept: application/jose+json' \\\n  -H 'Accept-Encoding: identity' \\\n  -H 'Content-Type: application/jose+json' \\\n  -H 'Content-Encoding: identity' \\\n  -H 'X-TW-JOSE-Method: jwe' \\\n  -H 'One-Time-Token: <one time token>' \\\n  -d 'eyJlbmMiOiJBMjU2R0NNIiwi...'\n"
      requestBody:
        required: true
        content:
          application/jose+json:
            schema:
              type: string
              description: 'JWE-encrypted string. The payload before encryption should contain a `pin` field.


                Original payload:

                ```json

                {"pin": "1234"}

                ```


                Encoded (JWE):

                ```

                eyJlbmMiOiJBMjU2R0NNIiwi...

                ```

                '
            example: eyJlbmMiOiJBMjU2R0NNIiwi...
      responses:
        '200':
          description: Encrypted one time token status.
          content:
            application/jose+json:
              schema:
                type: string
                description: 'JWE-encrypted string. Please refer to our [JOSE guide](/guides/developer/auth-and-security/jose-jws) on how to decrypt this.


                  When decrypted, the response contains `oneTimeTokenProperties` with the one time token details.

                  '
              example: eyJlbmMiOiJBMjU2R0NNIiwi...
          headers:
            X-External-Correlation-Id:
              $ref: '#/components/headers/X-External-Correlation-Id'
            x-trace-id:
              $ref: '#/components/headers/x-trace-id'
        '429':
          $ref: '#/components/responses/429'
  /v2/profiles/{profileId}/pin:
    post:
      operationId: scaPinCreate
      summary: Create a PIN
      description: 'Creates a new PIN factor used to resolve a SCA knowledge challenge type.


        The request and response are encrypted using the JOSE framework. Please refer to the SCA over API guide to understand how encryption and decryption work.'
      tags:
      - sca-pin
      security:
      - UserToken: []
      parameters:
      - name: profileId
        in: path
        required: true
        description: The profile ID.
        schema:
          type: integer
          format: int64
      - name: Accept
        in: header
        required: true
        schema:
          type: string
          default: application/jose+json
      - name: Accept-Encoding
        in: header
        required: true
        schema:
          type: string
          default: identity
      - name: Content-Encoding
        in: header
        required: true
        schema:
          type: string
          default: identity
      - name: X-tw-jose-method
        in: header
        required: true
        schema:
          type: string
          default: jwe
      - $ref: '#/components/parameters/X-External-Correlation-Id'
      x-codeSamples:
      - lang: bash
        label: cURL
        source: "curl -X POST \\\n  'https://api.wise-sandbox.com/v2/profiles/{profileId}/pin' \\\n  -H 'Authorization: Bearer <YOUR_JWT_HERE>' \\\n  -H 'Accept: application/jose+json' \\\n  -H 'Accept-Encoding: identity' \\\n  -H 'Content-Type: application/jose+json' \\\n  -H 'Content-Encoding: identity' \\\n  -H 'X-tw-jose-method: jwe' \\\n  -d 'eyJlbmMiOiJBMjU2R0NNIiwiYWxnIjoiUlNBLU9BRVAtMjU2In0.W0fuxaZOoyaBcx...'\n"
      requestBody:
        required: true
        content:
          application/jose+json:
            schema:
              type: string
              description: 'A JWE encrypted string. The decrypted payload contains:

                - `pin` — A four-digit string.


                Payload before encryption:

                ```json

                {"pin": "1234"}

                ```

                '
            example: <JWE encrypted string>
      responses:
        '200':
          description: The PIN has been successfully created.
          headers:
            X-External-Correlation-Id:
              $ref: '#/components/headers/X-External-Correlation-Id'
            x-trace-id:
              $ref: '#/components/headers/x-trace-id'
        '409':
          description: A PIN has already been created for this profile.
          headers:
            X-External-Correlation-Id:
              $ref: '#/components/headers/X-External-Correlation-Id'
            x-trace-id:
              $ref: '#/components/headers/x-trace-id'
        '429':
          $ref: '#/components/responses/429'
    delete:
      operationId: scaPinDelete
      summary: Delete a PIN
      description: 'Deletes a PIN associated to a profile.


        To update a PIN for a profile, use this endpoint followed by Create a PIN.


        {% admonition type="warning" %}

        This operation is irreversible.

        {% /admonition %}'
      tags:
      - sca-pin
      security:
      - UserToken: []
      parameters:
      - name: profileId
        in: path
        required: true
        description: The profile ID.
        schema:
          type: integer
          format: int64
      - $ref: '#/components/parameters/X-External-Correlation-Id'
      responses:
        '204':
          description: The PIN has been deleted.
          headers:
            X-External-Correlation-Id:
              $ref: '#/components/headers/X-External-Correlation-Id'
            x-trace-id:
              $ref: '#/components/headers/x-trace-id'
        '404':
          description: No PIN has been set up for this profile.
          headers:
            X-External-Correlation-Id:
              $ref: '#/components/headers/X-External-Correlation-Id'
            x-trace-id:
              $ref: '#/components/headers/x-trace-id'
        '429':
          $ref: '#/components/responses/429'
  /v2/profiles/{profileId}/pin/verify:
    post:
      operationId: scaPinVerify
      summary: Verify a PIN
      description: 'Verifies a PIN challenge when calling a SCA-secured endpoint. Make sure to create a PIN before using this endpoint.


        The request and response are encrypted using the JOSE framework. Please refer to the SCA over API guide to understand how encryption and decryption work.'
      tags:
      - sca-pin
      security:
      - UserToken: []
      parameters:
      - name: profileId
        in: path
        required: true
        description: The profile ID.
        schema:
          type: integer
          format: int64
      - name: One-Time-Token
        in: header
        required: true
        description: A one-time token unique identifier.
        schema:
          type: string
          format: uuid
      - name: Accept
        in: header
        required: true
        schema:
          type: string
          default: application/jose+json
      - name: Accept-Encoding
        in: header
        required: true
        schema:
          type: string
          default: identity
      - name: Content-Encoding
        in: header
        required: true
        schema:
          type: string
          default: identity
      - name: X-tw-jose-method
        in: header
        required: true
        schema:
          type: string
          default: jwe
      - $ref: '#/components/parameters/X-External-Correlation-Id'
      x-codeSamples:
      - lang: bash
        label: cURL
        source: "curl -X POST \\\n  'https://api.wise-sandbox.com/v2/profiles/{profileId}/pin/verify' \\\n  -H 'Authorization: Bearer <YOUR_JWT_HERE>' \\\n  -H 'Accept: application/jose+json' \\\n  -H 'Accept-Encoding: identity' \\\n  -H 'Content-Type: application/jose+json' \\\n  -H 'Content-Encoding: identity' \\\n  -H 'X-tw-jose-method: jwe' \\\n  -H 'One-Time-Token: <one-time token>' \\\n  -d 'eyJlbmMiOiJBMjU2R0NNIiwiYWxnIjoiUlNBLU9BRVAtMjU2In0.W0fuxaZOoyaBcx...'\n"
      requestBody:
        required: true
        content:
          application/jose+json:
            schema:
              type: string
              description: 'A JWE encrypted string. The decrypted payload contains:

                - `pin` — A four-digit string.


                Payload before encryption:

                ```json

                {"pin": "1234"}

                ```

                '
            example: <JWE encrypted string>
      responses:
        '200':
          description: The PIN has been successfully verified.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/one-time-token'
          headers:
            X-External-Correlation-Id:
              $ref: '#/components/headers/X-External-Correlation-Id'
            x-trace-id:
              $ref: '#/components/headers/x-trace-id'
        '400':
          description: The PIN verification failed or PIN was blocked.
          headers:
            X-External-Correlation-Id:
              $ref: '#/components/headers/X-External-Correlation-Id'
            x-trace-id:
              $ref: '#/components/headers/x-trace-id'
        '404':
          description: The PIN was not found or has not been set up.
          headers:
            X-External-Correlation-Id:
              $ref: '#/components/headers/X-External-Correlation-Id'
            x-trace-id:
              $ref: '#/components/headers/x-trace-id'
        '429':
          $ref: '#/components/responses/429'
components:
  responses:
    '429':
      x-global: true
      description: Rate limit exceeded. Retry after the number of seconds specified in the `Retry-After` header.
      headers:
        Retry-After:
          description: Number of seconds to wait before retrying the request.
          schema:
            type: integer
          example: 5
        X-Rate-Limited-By:
          description: Identifies the rate limiter that triggered the 429 response.
          schema:
            type: string
          example: wise-public-api
        X-External-Correlation-Id:
          $ref: '#/components/headers/X-External-Correlation-Id'
        x-trace-id:
          $ref: '#/components/headers/x-trace-id'
      content:
        application/json:
          schema:
            type: object
  headers:
    x-trace-id:
      x-global: true
      description: Unique trace identifier assigned by Wise. Useful when contacting support about a specific request.
      schema:
        type: string
      example: fba501b6d453b96789f52338f019341f
    X-External-Correlation-Id:
      x-global: true
      description: Echoed back when `X-External-Correlation-Id` was included in the request. [Learn more](/guides/developer/headers/correlation-id).
      schema:
        type: string
        format: uuid
        maxLength: 36
      example: f47ac10b-58cc-4372-a567-0e02b2c3d479
  schemas:
    one-time-token:
      title: One-Time Token
      x-tags:
      - sca-ott
      type: object
      description: 'A one-time token is generated when accessing an endpoint secured by SCA. This token includes a list of all available challenges to complete.


        You can use the [OTT status endpoint](/api-reference/sca-ott/ottstatusget) to view challenges and their statuses, or use [create SCA session](/api-reference/sca-sessions/scasessioncreate) to manually trigger SCA and return a one-time token.

        '
      properties:
        oneTimeToken:
          type: string
          format: uuid
          description: A one-time token unique identifier.
          example: 5932d5b5-ec13-452f-8688-308feade7834
        challenges:
          type: array
          description: An array of challenges.
          items:
            type: object
            properties:
              primaryChallenge:
                type: object
                properties:
                  type:
                    type: string
                    description: A type of challenge.
                    example: PIN
              passed:
                type: boolean
                description: The status of a challenge.
                example: false
        validity:
          type: integer
          description: The One-Time Token expiration in seconds.
          example: 3600
  parameters:
    X-External-Correlation-Id:
      x-global: true
      name: X-External-Correlation-Id
      in: header
      required: false
      description: 'Optional UUID for correlating requests across systems. If provided, Wise echoes it back in the response. Maximum 36 characters. [Learn more](/guides/developer/headers/correlation-id).

        '
      schema:
        type: string
        format: uuid
        maxLength: 36
      example: f47ac10b-58cc-4372-a567-0e02b2c3d479
  securitySchemes:
    UserToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: 'User Access Token for making API calls on behalf of a Wise user.


        Can be obtained via two OAuth 2.0 flows:

        - **registration_code grant**: For partners creating users via API

        - **authorization_code grant**: For partners using Wise''s authorization page


        Access tokens are valid for 12 hours and can be refreshed using a refresh token.

        '
    PersonalToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: 'Personal API Token for individual personal or small business users.

        Generated from Wise.com > Settings > Connect and manage apps > API tokens.

        Has limited API access compared to OAuth tokens (PSD2 restrictions apply for EU/UK users).

        '
    ClientCredentialsToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: 'Application-level token for partner operations that don''t require a specific user context, such as bulk settlement and card spend controls.


        Obtained via `POST /oauth/token` with Basic Authentication (client-id:client-secret) and `grant_type=client_credentials`.


        Valid for 12 hours. No refresh token — fetch a new token when expired.


        See [create an OAuth token](/api-reference/oauth-token/oauthtokencreate) for details.

        '
    BasicAuth:
      type: http
      scheme: basic
      description: 'Basic Authentication using your Client ID and Client Secret as the username and password.


        Client credentials are provided by Wise when your partnership begins. See [Getting Started](/guides/developer) for details.

        '
x-tagGroups:
- name: Authentication
  tags:
  - oauth-token
- name: Enhanced Security
  tags:
  - jose
- name: Users
  tags:
  - user
  - claim-account
- name: Profiles
  tags:
  - profile
  - activity
  - address
- name: Verification
  tags:
  - kyc-review
  - verification
  - facetec
- name: Strong Customer Authentication
  tags:
  - sca-ott
  - sca-sessions
  - sca-pin
  - sca-facemaps
  - sca-device-fingerprints
  - sca-otp
  - user-security
- name: Balances
  tags:
  - balance
  - balance-statement
  - bank-account-details
  - multi-currency-account
- name: Cards
  tags:
  - card
  - card-sensitive-details
  - 3ds
  - card-kiosk-collection
  - card-order
  - card-transaction
  - spend-limits
  - spend-controls
  - digital-wallet
  - disputes
- name: Quotes
  tags:
  - quote
  - rate
  - comparison
- name: Recipients
  tags:
  - recipient
  - contact
- name: Transfers
  tags:
  - transfer
  - delivery-estimate
  - currencies
  - batch-group
- name: Funding
  tags:
  - payin-deposit-detail
  - direct-debit-account
  - bulk-settlement
  - payins
- name: Webhooks
  tags:
  - webhook
  - webhook-event
- name: Simulations
  tags:
  - simulation
- name: Partner Support
  tags:
  - case