Citi · AsyncAPI Specification
Citi Webhooks
Version
View Spec
View on GitHub
BankingFinancial-ServicesOpen BankingPaymentsTreasuryISO 20022Commercial CardsForeign ExchangeCustodyTrade FinanceCorporate BankingAPI GatewayAsyncAPIEvents
AsyncAPI Specification
generated: '2026-09-05'
method: derived
source: openapi/ — the OpenAPI 3.1 webhooks blocks and the notification/subscription contracts among the 118 first-party
Citi specifications harvested from https://developer.citi.com/apidocs on 2026-09-05
asyncapi_published: false
asyncapi_note: 'Citi publishes NO AsyncAPI document. The event surface is described inside OpenAPI instead: two
contracts use the OpenAPI 3.1 webhooks: keyword, and eight more model notifications as callback-style POST endpoints
the client implements plus subscription-management operations. Probed for /asyncapi.yaml and searched the Citi
GitHub org — nothing. This is recorded as an absence, not fabricated.'
transport: HTTPS POST from Citi to a client-hosted endpoint
webhooks:
- event: prenotification
spec: openapi/citi-express-payments-webhooks-openapi.yaml
method: POST
style: openapi-3.1-webhooks
description: Pre-notifications are alerts sent by Citibank to inform you of incoming funds before the money is
officially credited to your bank account.
- event: pushnotification
spec: openapi/citi-express-payments-webhooks-openapi.yaml
method: POST
style: openapi-3.1-webhooks
description: Webhook notifications sent for events not triggered directly by the client — for example an incoming
credit.
- event: beneficiaryvalidationnotification
spec: openapi/citi-express-payments-webhooks-openapi.yaml
method: POST
style: openapi-3.1-webhooks
description: Notification of the outcome of a beneficiary validation.
- event: prenotification
spec: openapi/citi-digitalpaymentscollections-webhooks-openapi.yaml
method: POST
style: openapi-3.1-webhooks
description: Incoming-funds pre-notification on the payment acceptance / collections surface.
- event: pushnotification
spec: openapi/citi-digitalpaymentscollections-webhooks-openapi.yaml
method: POST
style: openapi-3.1-webhooks
description: Event notification on the payment acceptance / collections surface.
- event: dispute status notification
spec: openapi/citi-dispute-webhook-openapi.yaml
method: POST
path: /v1/webhook
style: callback-endpoint
description: Commercial card dispute case status notifications (DisputeCaseStatusNotification v1.0).
- event: VCA authorisation push notification
spec: openapi/citi-virtual-cards-pi-webhooks-openapi.yaml
style: callback-endpoint
description: Virtual Card Account client webhooks for payment intermediaries (Vca-PI-Client-webhooks 2.0.0).
- event: VCA push notification
spec: openapi/citi-vcanotificationswebhooks-openapi.yaml
style: callback-endpoint
description: Virtual Card Account push notification webhook.
- event: VCA dual-authorisation notification
spec: openapi/citi-vca-dual-auth-notification-openapi.yaml
style: callback-endpoint
description: Real-time dual-authorisation notification over mutual TLS (orchestrationNotf_mTLS).
- event: account notification
spec: openapi/citi-account-notifications-api-openapi.yaml
style: subscription+callback
description: Account-level credit/debit notifications on the account reporting surface.
subscription_management:
- spec: openapi/citi-vcaeventssubscriptions-openapi.yaml
operations:
- createSubscription
- getSubscription
- updateSubscription
- deleteSubscription
path: /vca/v2/events/subscriptions
- spec: openapi/citi-virtual-cards-notifications-openapi.yaml
operations:
- deleteSubscription
path: /vca/v1/authorizations/subscriptions/{subscriptionId}
- spec: openapi/citi-vcagetnotifications-openapi.yaml
note: Pull-based retrieval of notifications, for clients that cannot host a webhook receiver.
delivery_semantics:
retries: not published
signing: not published as a shared HMAC convention; the dual-authorisation notification uses mutual TLS instead
note: Citi does not publish webhook retry policy, replay window or a signature-verification scheme. Not asserted
here.
note: 'The event surface is real and product-specific: it exists on payments, collections, virtual cards and account
reporting, and is absent everywhere else. Ten of 118 contracts carry it.'
Work with this as data
Every AsyncAPI spec here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for asyncapi
4 MCP tools reach this
find_asyncapisBrowse and filter every AsyncAPI spec in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This AsyncAPI spec
curl "https://apis.io/api/v1/asyncapis/citi-webhooks"
All asyncapi
curl "https://apis.io/api/v1/asyncapis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.