Citi · OAuth Scopes

Citi OAuth Scopes

OAuth 2.0 derived

Citi publishes 24 OAuth 2.0 scopes via the clientCredentials and authorizationCode flows. Scopes are the fine-grained permissions an application requests at authorization time to act against the Citi API on a user’s behalf.

Tokens are issued from https://tts.apib2b.citi.com/tts/cards/api/v1/oauth2/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

BankingFinancial-ServicesOpen BankingPaymentsTreasuryISO 20022Commercial CardsForeign ExchangeCustodyTrade FinanceCorporate BankingAPI Gateway
Scopes: 24 Flows: clientCredentials, authorizationCode Method: derived

OAuth endpoints

Authorization URL
/authenticationservices/v3/oauth/token /authenticationservices/v2/oauth/token https://tts.apib2b.citi.com/tts/api/v1/oauth2/authorize
Token URL
https://tts.apib2b.citi.com/tts/cards/api/v1/oauth2/token /authenticationservices/v3/oauth/token https://tts.apib2b.citi.com/api/oauth2/token /markets/api/oauth2/token https://tts.sandbox.apib2b.citi.com/citiconnect/sb/authenticationservices/v1/oauth/token https://tts.sit.apib2b.citi.com/citiconnect/sit5/authenticationservices/v1/oauth/token /v1/oauth2/token https://api.citivelocity.com/markets/cv/api/fx/oauth2/token https://sandbox.api.citivelocity.com/markets/cv/api/fx/oauth2/token https://icg.api.citigroup.net/markets/internal/cv/api/fx/oauth2/token https://tts.apib2b.citi.com/tts/cards/api/oauth2/token https://b2b.api.icg.citi.com/authenticationservices/v3/oauth/token https://tts.apib2b.citi.com/tts/cards/mvca/v1/token-lifecycle-events/cv/api/oauth2/token https://tts.apib2b.citi.com/tts/api/v1/oauth2/token /tts/api/v1/oauth2/token authenticationservices/v3/oauth/token /authenticationservices/v1/oauth/token $(catalog.url)/authenticationservices/v1/oauth/token https://tts.sit.apib2b.citi.com/citiconnect/sit5/authenticationservices/v3/oauth/token https://authenticationservices/v3/oauth/token https://tts.apib2b.citi.com/citiconnect/prod/requesttopayservice/v1/validate/address/authenticationservices/v1/oauth/token https://tts.apib2b.citi.com/api/v1/oauth2/token authenticationservices/v2/oauth/token /tts/internal/api/oauth2 https://secure.api-preprod.bkm.com.tr/oauth-provider/oauth2/token https://tts.sandbox.apib2b.citi.com/tts/cards/api/oauth2/token
Flows
clientCredentialsauthorizationCode

Scopes (24)

ScopeDescriptionFlows
/api Access to ETF Order API clientCredentials
/authenticationservices/v1 Access to Accounts, Balances, Transactions Information clientCredentials
/dod Access to Cash Balances Information clientCredentials
/fxapi clientCredentials
account_information Account Information clientCredentials
addonservices Grant read-only access to add-on services authorizationCode
admin Grants read and write access to administrative information authorizationCode
authenticationservices/v1 Grant read-only access to payment initation service authorizationCode, clientCredentials
authenticationservices/v2 API Access for authorizationCode
authenticationservices/v3 Grant read-only access to WorldLink FX service authorizationCode
cob.read Permission to consult Immediate collection clientCredentials
cob.write Permission to change Immediate collection clientCredentials
cobv.read Authenticates to retrieve collection item with due date clientCredentials
cobv.write Authenticates to update collection with due date clientCredentials
directDebitService Grant read-only access to emandate initation service authorizationCode
emandateservices Grant read-only access to emandate initation service clientCredentials
fxapi clientCredentials
payment_order Payment Order clientCredentials
paymentservices Grant read-only access to payment initiation service authorizationCode
read Grants read access authorizationCode, clientCredentials
selfservices Grant read-only access to beneficiary validation authorizationCode
webhook.write
webhookcobr.write
write Grants write access authorizationCode, clientCredentials

Source

OAuth Scopes

Raw ↑
generated: '2026-09-05'
method: derived
source: openapi/citi-account-balance-inquiry-api-openapi.yaml, openapi/citi-account-notifications-api-openapi.yaml,
  openapi/citi-accounts-openapi.yaml, openapi/citi-accountsv5-openapi.yaml, openapi/citi-add-on-service-openapi.yaml,
  openapi/citi-addonservice-openapi.yaml, openapi/citi-balances-api-openapi.yaml, openapi/citi-beneficiary-search-openapi.yaml,
  openapi/citi-blocksandfilters-openapi.yaml, openapi/citi-brazillocalmandate-openapi.yaml,
  openapi/citi-bulk-payments-openapi.yaml, openapi/citi-card-disputes-openapi.yaml, openapi/citi-cash-balances-openapi.yaml,
  openapi/citi-cash-transactions-openapi.yaml, openapi/citi-clearing-exception-report-openapi.yaml,
  openapi/citi-contractstatusinquiry-openapi.yaml, openapi/citi-custody-billing-openapi.yaml,
  openapi/citi-custody-fx-transactions-openapi.yaml, openapi/citi-custody-penalties-openapi.yaml,
  openapi/citi-digitalpaymentscollectionsv12-openapi.yaml, openapi/citi-direct-debit-api-openapi.yaml,
  openapi/citi-due-date-openapi.yaml, openapi/citi-e-mandate-api-v1-openapi.yaml, openapi/citi-e-mandate-api-v2-openapi.yaml,
  openapi/citi-entityid-openapi.yaml, openapi/citi-express-payments-api-openapi.yaml, openapi/citi-express-payments-webhooks-openapi.yaml,
  openapi/citi-finance-undertaking-api-openapi.yaml, openapi/citi-fx-benchmark-async-api-openapi.yaml,
  openapi/citi-fx-benchmark-sync-api-openapi.yaml, openapi/citi-fx-cancel-async-api-openapi.yaml,
  openapi/citi-fx-cancel-sync-api-openapi.yaml, openapi/citi-fx-ecommerce-api-openapi.yaml,
  openapi/citi-fx-gateway-reporting-async-api-openapi.yaml, openapi/citi-fx-gateway-reporting-sync-api-openapi.yaml,
  openapi/citi-fx-market-async-api-openapi.yaml, openapi/citi-fx-market-sync-api-openapi.yaml,
  openapi/citi-fx-orders-async-api-openapi.yaml, openapi/citi-fx-orders-sync-api-openapi.yaml,
  openapi/citi-fx-quote-async-api-openapi.yaml, openapi/citi-fx-quote-sync-api-openapi.yaml,
  openapi/citi-fx-reporting-async-api-openapi.yaml, openapi/citi-fx-reporting-sync-api-openapi.yaml,
  openapi/citi-grace-iva-openapi.yaml, openapi/citi-id-provisioning-openapi.yaml, openapi/citi-idd-openapi.yaml,
  openapi/citi-immediate-openapi.yaml, openapi/citi-marketplace-management-openapi.yaml, openapi/citi-marqueta-openapi.yaml,
  openapi/citi-mobile-wallets-openapi.yaml, openapi/citi-mobilecardonboarding-openapi.yaml,
  openapi/citi-mobilevirtuallifecycle-openapi.yaml, openapi/citi-online-payment-acceptance-api-openapi.yaml,
  openapi/citi-order-approval-openapi.yaml, openapi/citi-payerid-api-openapi.yaml, openapi/citi-payment-reconfirmation-openapi.yaml,
  openapi/citi-payment-refund-openapi.yaml, openapi/citi-payment-status-openapi.yaml, openapi/citi-paymentcancellation-json-openapi.yaml,
  openapi/citi-paymentcancellation-xml-openapi.yaml, openapi/citi-paymentenhancedinquiry-json-openapi.yaml,
  openapi/citi-paymentenhancedinquiry-xml-openapi.yaml, openapi/citi-paymentinitiation-pacs008-openapi.yaml,
  openapi/citi-paymentinitiation-pacs009-openapi.yaml, openapi/citi-paymentinitiation-pain102-openapi.yaml,
  openapi/citi-paymentinitiation-pain103-openapi.yaml, openapi/citi-payto-openapi.yaml, openapi/citi-portfolio-listing-openapi.yaml,
  openapi/citi-proof-of-payment-openapi.yaml, openapi/citi-purchase-openapi.yaml, openapi/citi-reporting-get-2-openapi.yaml,
  openapi/citi-request-to-pay-openapi.yaml, openapi/citi-safekeeping-accounts-openapi.yaml,
  openapi/citi-safekeeping-positions-openapi.yaml, openapi/citi-securitytransactionsaccounts-openapi.yaml,
  openapi/citi-self-service-api-openapi.yaml, openapi/citi-statement-transactions-openapi.yaml,
  openapi/citi-statements-api-openapi.yaml, openapi/citi-statementsv2-api-openapi.yaml, openapi/citi-static-openapi.yaml,
  openapi/citi-submit-action-openapi.yaml, openapi/citi-tax-reclaims-openapi.yaml, openapi/citi-trade-api-openapi.yaml,
  openapi/citi-transfer-agency-accounts-openapi.yaml, openapi/citi-transfer-agency-holding-openapi.yaml,
  openapi/citi-transfer-agency-investors-openapi.yaml, openapi/citi-transfer-agency-transactions-openapi.yaml,
  openapi/citi-ukraine-bank-data-sharing-api-openapi.yaml, openapi/citi-ukraine-payment-service-initiation-api-openapi.yaml,
  openapi/citi-vamanagement-openapi.yaml, openapi/citi-vca-api-openapi.yaml, openapi/citi-vcaeventssubscriptions-openapi.yaml,
  openapi/citi-vcagetnotifications-openapi.yaml, openapi/citi-virtual-cards-lifecycle-v1-openapi.yaml,
  openapi/citi-virtual-cards-lifecycle-v4-openapi.yaml, openapi/citi-virtual-cards-notifications-openapi.yaml,
  openapi/citi-virtual-cards-pi-openapi.yaml, openapi/citi-virtual-cards-pi-v2-openapi.yaml,
  openapi/citi-virtual-cards-pi-webhooks-openapi.yaml, openapi/citi-virtual-cards-reporting-openapi.yaml,
  openapi/citi-virtual-cards-reporting-v1-openapi.yaml, openapi/citi-worldlink-ir-api-openapi.yaml,
  openapi/citi-worldlink-v1-api-openapi.yaml, openapi/citi-worldlink-v2-api-openapi.yaml, openapi/citi-worldlink-v3-api-openapi.yaml,
  openapi/citi-worldlink-v5-api-openapi.yaml
schemes:
- name: clientCredentials
  source: openapi/citi-account-balance-inquiry-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://tts.apib2b.citi.com/tts/cards/api/v1/oauth2/token
- name: clientCredentials
  source: openapi/citi-account-notifications-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /authenticationservices/v3/oauth/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.
- name: clientCredentials
  source: openapi/citi-accounts-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /authenticationservices/v3/oauth/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.
- name: oAuth
  source: openapi/citi-accountsv5-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /authenticationservices/v3/oauth/token
- name: clientCredentials
  source: openapi/citi-add-on-service-openapi.yaml
  flows:
  - flow: authorizationCode
    authorizationUrl: /authenticationservices/v3/oauth/token
    tokenUrl: /authenticationservices/v3/oauth/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.
- name: Client Credentials
  source: openapi/citi-addonservice-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /authenticationservices/v3/oauth/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.
- name: clientCredentials
  source: openapi/citi-balances-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /authenticationservices/v3/oauth/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.
- name: clientCredentials
  source: openapi/citi-beneficiary-search-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://tts.apib2b.citi.com/tts/cards/api/v1/oauth2/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.
- name: clientCredentials
  source: openapi/citi-blocksandfilters-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /authenticationservices/v3/oauth/token
- name: OAuth2
  source: openapi/citi-brazillocalmandate-openapi.yaml
  flows:
  - flow: authorizationCode
    authorizationUrl: /authenticationservices/v3/oauth/token
    tokenUrl: /authenticationservices/v3/oauth/token
- name: clientCredentials
  source: openapi/citi-bulk-payments-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /authenticationservices/v3/oauth/token
- name: ClientCredentials
  source: openapi/citi-card-disputes-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://tts.apib2b.citi.com/api/oauth2/token
- name: client-Credential-Oauth-Security-Schema
  source: openapi/citi-cash-balances-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /markets/api/oauth2/token
  description: This API uses OAuth 2 with the client credentials flow
- name: client-Credential-Oauth-Security-Schema
  source: openapi/citi-cash-transactions-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /markets/api/oauth2/token
  description: This API uses OAuth 2 with the client credentials flow
- name: clientCredentials
  source: openapi/citi-clearing-exception-report-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://tts.apib2b.citi.com/tts/cards/api/v1/oauth2/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.
- name: clientCredentials
  source: openapi/citi-contractstatusinquiry-openapi.yaml
  flows:
  - flow: authorizationCode
    authorizationUrl: /authenticationservices/v3/oauth/token
    tokenUrl: /authenticationservices/v3/oauth/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.
- name: client-Credential-Oauth-Security-Schema
  source: openapi/citi-custody-billing-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /markets/api/oauth2/token
  description: This API uses OAuth 2 with the client credentials flow
- name: client-Credential-Oauth-Security-Schema
  source: openapi/citi-custody-fx-transactions-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /markets/api/oauth2/token
  description: This API uses OAuth 2 with the client credentials flow
- name: client-Credential-Oauth-Security-Schema
  source: openapi/citi-custody-penalties-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /markets/api/oauth2/token
  description: This API uses OAuth 2 with the client credentials flow
- name: oAuth2
  source: openapi/citi-digitalpaymentscollectionsv12-openapi.yaml
  flows:
  - flow: authorizationCode
    authorizationUrl: /authenticationservices/v3/oauth/token
    tokenUrl: /authenticationservices/v3/oauth/token
- name: clientCredentials
  source: openapi/citi-direct-debit-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://tts.sandbox.apib2b.citi.com/citiconnect/sb/authenticationservices/v1/oauth/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.
- name: cobVWriteSample
  source: openapi/citi-due-date-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /authenticationservices/v3/oauth/token
- name: cobVReadSample
  source: openapi/citi-due-date-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /authenticationservices/v3/oauth/token
- name: clientCredentials
  source: openapi/citi-e-mandate-api-v1-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://tts.sit.apib2b.citi.com/citiconnect/sit5/authenticationservices/v1/oauth/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.
- name: clientCredentials
  source: openapi/citi-e-mandate-api-v2-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://tts.sandbox.apib2b.citi.com/citiconnect/sb/authenticationservices/v1/oauth/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.
- name: Client Credentials
  source: openapi/citi-entityid-openapi.yaml
  flows:
  - flow: authorizationCode
    authorizationUrl: /authenticationservices/v3/oauth/token
    tokenUrl: /authenticationservices/v3/oauth/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.
- name: oAuth2
  source: openapi/citi-express-payments-api-openapi.yaml
  flows:
  - flow: authorizationCode
    authorizationUrl: /authenticationservices/v3/oauth/token
    tokenUrl: /authenticationservices/v3/oauth/token
- name: oAuth2
  source: openapi/citi-express-payments-webhooks-openapi.yaml
  flows:
  - flow: authorizationCode
    authorizationUrl: /authenticationservices/v3/oauth/token
    tokenUrl: /authenticationservices/v3/oauth/token
- name: oAuth2
  source: openapi/citi-finance-undertaking-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /v1/oauth2/token
  description: This API uses OAuth2 with the client credentials grant type for service provider
    API gateway integration.
- name: OAuth2
  source: openapi/citi-fx-benchmark-async-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://api.citivelocity.com/markets/cv/api/fx/oauth2/token
  description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. See <a href="../../fx/authentication/authentication-api-reference/"
    target="_blank">the Citi Authentication API reference</a> for information on requesting
    a token.
- name: OAuth2
  source: openapi/citi-fx-benchmark-sync-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://api.citivelocity.com/markets/cv/api/fx/oauth2/token
  description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. See <a href="../../fx/authentication/authentication-api-reference/"
    target="_blank">the Citi Authentication API reference</a> for information on requesting
    a token.
- name: OAuth2
  source: openapi/citi-fx-cancel-async-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://sandbox.api.citivelocity.com/markets/cv/api/fx/oauth2/token
  description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. See <a href="../../fx/authentication/authentication-api-reference/"
    target="_blank">the Citi Authentication API reference</a> for information on requesting
    a token.
- name: OAuth2
  source: openapi/citi-fx-cancel-sync-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://sandbox.api.citivelocity.com/markets/cv/api/fx/oauth2/token
  description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. See <a href="../../fx/authentication/authentication-api-reference/"
    target="_blank">the Citi Authentication API reference</a> for information on requesting
    a token.
- name: client_credential
  source: openapi/citi-fx-ecommerce-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://icg.api.citigroup.net/markets/internal/cv/api/fx/oauth2/token
  description: client_credential
- name: OAuth2
  source: openapi/citi-fx-gateway-reporting-async-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://sandbox.api.citivelocity.com/markets/cv/api/fx/oauth2/token
  description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. See <a href="../../fx/authentication/authentication-api-reference/"
    target="_blank">the Citi Authentication API reference</a> for information on requesting
    a token.
- name: OAuth2
  source: openapi/citi-fx-gateway-reporting-sync-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://sandbox.api.citivelocity.com/markets/cv/api/fx/oauth2/token
  description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. See <a href="../../fx/authentication/authentication-api-reference/"
    target="_blank">the Citi Authentication API reference</a> for information on requesting
    a token.
- name: OAuth2
  source: openapi/citi-fx-market-async-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://sandbox.api.citivelocity.com/markets/cv/api/fx/oauth2/token
  description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. See <a href="../../fx/authentication/authentication-api-reference/"
    target="_blank">the Citi Authentication API reference</a> for information on requesting
    a token.
- name: OAuth2
  source: openapi/citi-fx-market-sync-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://sandbox.api.citivelocity.com/markets/cv/api/fx/oauth2/token
  description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. See <a href="../../fx/authentication/authentication-api-reference/"
    target="_blank">the Citi Authentication API reference</a> for information on requesting
    a token.
- name: OAuth2
  source: openapi/citi-fx-orders-async-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://api.citivelocity.com/markets/cv/api/fx/oauth2/token
  description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. See <a href="../../fx/authentication/authentication-api-reference/"
    target="_blank">the Citi Authentication API reference</a> for information on requesting
    a token.
- name: OAuth2
  source: openapi/citi-fx-orders-sync-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://sandbox.api.citivelocity.com/markets/cv/api/fx/oauth2/token
  description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. See <a href="../../fx/authentication/authentication-api-reference/"
    target="_blank">the Citi Authentication API reference</a> for information on requesting
    a token.
- name: OAuth2
  source: openapi/citi-fx-quote-async-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://api.citivelocity.com/markets/cv/api/fx/oauth2/token
  description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. See <a href="../../fx/authentication/authentication-api-reference/"
    target="_blank">the Citi Authentication API reference</a> for information on requesting
    a token.
- name: OAuth2
  source: openapi/citi-fx-quote-sync-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://api.citivelocity.com/markets/cv/api/fx/oauth2/token
  description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. See <a href="../../fx/authentication/authentication-api-reference/"
    target="_blank">the Citi Authentication API reference</a> for information on requesting
    a token.
- name: OAuth2
  source: openapi/citi-fx-reporting-async-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://api.citivelocity.com/markets/cv/api/fx/oauth2/token
  description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. See <a href="../../fx/authentication/authentication-api-reference/"
    target="_blank">the Citi Authentication API reference</a> for information on requesting
    a token.
- name: OAuth2
  source: openapi/citi-fx-reporting-sync-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://api.citivelocity.com/markets/cv/api/fx/oauth2/token
  description: Citi Velocity APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. See <a href="../../fx/authentication/authentication-api-reference/"
    target="_blank">the Citi Authentication API reference</a> for information on requesting
    a token.
- name: clientCredentials
  source: openapi/citi-grace-iva-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://tts.apib2b.citi.com/tts/cards/api/v1/oauth2/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.
- name: clientCredentials
  source: openapi/citi-id-provisioning-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://tts.apib2b.citi.com/tts/cards/api/oauth2/token
  description: 'All CitiConnect APIs use the oAuth2 authentication scheme, which requires a
    bearer token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.<br><br>Sandbox
    Token URL: https://tts.sandbox.apib2b.citi.com/tts/api/oauth2/token<br>'
- name: clientCredentials
  source: openapi/citi-idd-openapi.yaml
  flows:
  - flow: authorizationCode
    authorizationUrl: /authenticationservices/v3/oauth/token
    tokenUrl: /authenticationservices/v3/oauth/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.
- name: cobWriteSample
  source: openapi/citi-immediate-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /authenticationservices/v3/oauth/token
- name: cobReadSample
  source: openapi/citi-immediate-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /authenticationservices/v3/oauth/token
- name: oAuth2
  source: openapi/citi-marketplace-management-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://b2b.api.icg.citi.com/authenticationservices/v3/oauth/token
- name: clientCredentials
  source: openapi/citi-marqueta-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://tts.apib2b.citi.com/tts/cards/api/v1/oauth2/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.
- name: clientCredentials
  source: openapi/citi-mobile-wallets-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://tts.apib2b.citi.com/tts/cards/mvca/v1/token-lifecycle-events/cv/api/oauth2/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.
- name: clientCredentials
  source: openapi/citi-mobilecardonboarding-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://tts.apib2b.citi.com/tts/api/v1/oauth2/token
- name: clientCredentials
  source: openapi/citi-mobilevirtuallifecycle-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://tts.apib2b.citi.com/tts/api/v1/oauth2/token
- name: Client Credentials
  source: openapi/citi-online-payment-acceptance-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /authenticationservices/v3/oauth/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.
- name: Authorization
  source: openapi/citi-order-approval-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /tts/api/v1/oauth2/token
  description: "Client applications must supply an\n authentication token with every request,\
    \ and therefore must first\n authenticate before it can proceed. A client can use the OAuth\
    \ 2 client\n credential grant flow to obtain a time limited access token. To get an\n access\
    \ token send a HTTP Post request to the token endpoint using basic\n authentication with\
    \ the client key and secret.<br><br>**Request**<br><br>```POST {baseURL}/tts/api/v1/oauth2/token\
    \ HTTPS/1.1\n Authorization: Basic base64(key:secret) \n Content-Type:application/x-www-form-urlencoded\n\
    \ {\n  scope=/api&grant_type=client_credentials\n }```<br><br>\n **Response**<br><br>```\n\
    \   {\n     \"token_type\": \"bearer\", \n     \"access_token\": <access token>, \n    \
    \ \"expires_in\": <seconds until expiry>, \n     \"consented_on\":<timestamp>, \n     \"\
    scope\": \"api\"\n   }```    <br><br>The bearer token is valid for 1800 seconds (30 minutes)\
    \ after which it will expire. At this point, you would need to re-authenticate.<br><br>"
- name: oAuth2
  source: openapi/citi-payerid-api-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: authenticationservices/v3/oauth/token
- name: clientCredentials
  source: openapi/citi-payment-reconfirmation-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /authenticationservices/v1/oauth/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See the Citi Authentication API Reference for information on requesting
    a token.
- name: clientCredentials
  source: openapi/citi-payment-refund-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /authenticationservices/v1/oauth/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See the Citi Authentication API Reference for information on requesting
    a token.
- name: clientCredentials
  source: openapi/citi-payment-status-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: $(catalog.url)/authenticationservices/v1/oauth/token
  description: All CitiConnect APIs use the OAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See the Citi Authentication API Reference for information on requesting
    a token.
- name: clientCredentials
  source: openapi/citi-paymentcancellation-json-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://tts.sit.apib2b.citi.com/citiconnect/sit5/authenticationservices/v3/oauth/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.
- name: clientCredentials
  source: openapi/citi-paymentcancellation-xml-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://tts.sit.apib2b.citi.com/citiconnect/sit5/authenticationservices/v3/oauth/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.
- name: clientCredentials
  source: openapi/citi-paymentenhancedinquiry-json-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://authenticationservices/v3/oauth/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.
- name: clientCredentials
  source: openapi/citi-paymentenhancedinquiry-xml-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: https://authenticationservices/v3/oauth/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
    Citi Authentication API reference</a> for information on requesting a token.
- name: clientCredentials
  source: openapi/citi-paymentinitiation-pacs008-openapi.yaml
  flows:
  - flow: clientCredentials
    tokenUrl: /authenticationservices/v3/oauth/token
  description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
    token to authenticate your API call. The Token URL includes the version of authentication
    used by this API

# --- truncated at 32 KB (57 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/citi/refs/heads/main/scopes/citi-scopes.yml

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/citi-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.