Citi · AsyncAPI Specification

Citi Webhooks

Version

View Spec View on GitHub BankingFinancial-ServicesOpen BankingPaymentsTreasuryISO 20022Commercial CardsForeign ExchangeCustodyTrade FinanceCorporate BankingAPI GatewayAsyncAPIEvents

AsyncAPI Specification

Raw ↑
generated: '2026-09-05'
method: derived
source: openapi/ — the OpenAPI 3.1 webhooks blocks and the notification/subscription contracts among the 118 first-party
  Citi specifications harvested from https://developer.citi.com/apidocs on 2026-09-05
asyncapi_published: false
asyncapi_note: 'Citi publishes NO AsyncAPI document. The event surface is described inside OpenAPI instead: two
  contracts use the OpenAPI 3.1 webhooks: keyword, and eight more model notifications as callback-style POST endpoints
  the client implements plus subscription-management operations. Probed for /asyncapi.yaml and searched the Citi
  GitHub org — nothing. This is recorded as an absence, not fabricated.'
transport: HTTPS POST from Citi to a client-hosted endpoint
webhooks:
- event: prenotification
  spec: openapi/citi-express-payments-webhooks-openapi.yaml
  method: POST
  style: openapi-3.1-webhooks
  description: Pre-notifications are alerts sent by Citibank to inform you of incoming funds before the money is
    officially credited to your bank account.
- event: pushnotification
  spec: openapi/citi-express-payments-webhooks-openapi.yaml
  method: POST
  style: openapi-3.1-webhooks
  description: Webhook notifications sent for events not triggered directly by the client — for example an incoming
    credit.
- event: beneficiaryvalidationnotification
  spec: openapi/citi-express-payments-webhooks-openapi.yaml
  method: POST
  style: openapi-3.1-webhooks
  description: Notification of the outcome of a beneficiary validation.
- event: prenotification
  spec: openapi/citi-digitalpaymentscollections-webhooks-openapi.yaml
  method: POST
  style: openapi-3.1-webhooks
  description: Incoming-funds pre-notification on the payment acceptance / collections surface.
- event: pushnotification
  spec: openapi/citi-digitalpaymentscollections-webhooks-openapi.yaml
  method: POST
  style: openapi-3.1-webhooks
  description: Event notification on the payment acceptance / collections surface.
- event: dispute status notification
  spec: openapi/citi-dispute-webhook-openapi.yaml
  method: POST
  path: /v1/webhook
  style: callback-endpoint
  description: Commercial card dispute case status notifications (DisputeCaseStatusNotification v1.0).
- event: VCA authorisation push notification
  spec: openapi/citi-virtual-cards-pi-webhooks-openapi.yaml
  style: callback-endpoint
  description: Virtual Card Account client webhooks for payment intermediaries (Vca-PI-Client-webhooks 2.0.0).
- event: VCA push notification
  spec: openapi/citi-vcanotificationswebhooks-openapi.yaml
  style: callback-endpoint
  description: Virtual Card Account push notification webhook.
- event: VCA dual-authorisation notification
  spec: openapi/citi-vca-dual-auth-notification-openapi.yaml
  style: callback-endpoint
  description: Real-time dual-authorisation notification over mutual TLS (orchestrationNotf_mTLS).
- event: account notification
  spec: openapi/citi-account-notifications-api-openapi.yaml
  style: subscription+callback
  description: Account-level credit/debit notifications on the account reporting surface.
subscription_management:
- spec: openapi/citi-vcaeventssubscriptions-openapi.yaml
  operations:
  - createSubscription
  - getSubscription
  - updateSubscription
  - deleteSubscription
  path: /vca/v2/events/subscriptions
- spec: openapi/citi-virtual-cards-notifications-openapi.yaml
  operations:
  - deleteSubscription
  path: /vca/v1/authorizations/subscriptions/{subscriptionId}
- spec: openapi/citi-vcagetnotifications-openapi.yaml
  note: Pull-based retrieval of notifications, for clients that cannot host a webhook receiver.
delivery_semantics:
  retries: not published
  signing: not published as a shared HMAC convention; the dual-authorisation notification uses mutual TLS instead
  note: Citi does not publish webhook retry policy, replay window or a signature-verification scheme. Not asserted
    here.
note: 'The event surface is real and product-specific: it exists on payments, collections, virtual cards and account
  reporting, and is absent everywhere else. Ten of 118 contracts carry it.'

Work with this as data

Every AsyncAPI spec here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for asyncapi

4 MCP tools reach this
  • find_asyncapisBrowse and filter every AsyncAPI spec in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This AsyncAPI spec
curl "https://apis.io/api/v1/asyncapis/citi-webhooks"
All asyncapi
curl "https://apis.io/api/v1/asyncapis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.