Citi Authentication
Citi secures its APIs with apiKey, http, oauth2, and unknown across 10 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode and clientCredentials flow(s).
Security Schemes
Source
Authentication Profile
generated: '2026-09-05'
method: derived
source: openapi/citi-account-balance-inquiry-api-openapi.yaml, openapi/citi-account-notifications-api-openapi.yaml,
openapi/citi-accounts-openapi.yaml, openapi/citi-accountsv5-openapi.yaml, openapi/citi-add-on-service-openapi.yaml,
openapi/citi-addonservice-openapi.yaml, openapi/citi-authentication-api-1-openapi.yaml, openapi/citi-authentication-api-2-openapi.yaml,
openapi/citi-authentication-api-3-openapi.yaml, openapi/citi-authentication-api-4-openapi.yaml,
openapi/citi-balances-api-openapi.yaml, openapi/citi-beneficiary-search-openapi.yaml ...
summary:
types:
- apiKey
- http
- oauth2
- unknown
api_key_in:
- header
- query
oauth2_flows:
- authorizationCode
- clientCredentials
schemes:
- name: clientCredentials
type: oauth2
flows:
- flow: clientCredentials
tokenUrl: https://tts.apib2b.citi.com/tts/cards/api/v1/oauth2/token
scopes: 0
sources:
- openapi/citi-account-balance-inquiry-api-openapi.yaml
- openapi/citi-account-notifications-api-openapi.yaml
- openapi/citi-accounts-openapi.yaml
- openapi/citi-accountsv5-openapi.yaml
- openapi/citi-addonservice-openapi.yaml
- openapi/citi-balances-api-openapi.yaml
- openapi/citi-beneficiary-search-openapi.yaml
- openapi/citi-blocksandfilters-openapi.yaml
- openapi/citi-bulk-payments-openapi.yaml
- openapi/citi-card-disputes-openapi.yaml
- openapi/citi-cash-balances-openapi.yaml
- openapi/citi-cash-transactions-openapi.yaml
- openapi/citi-clearing-exception-report-openapi.yaml
- openapi/citi-custody-billing-openapi.yaml
- openapi/citi-custody-fx-transactions-openapi.yaml
- openapi/citi-custody-penalties-openapi.yaml
- openapi/citi-direct-debit-api-openapi.yaml
- openapi/citi-due-date-openapi.yaml
- openapi/citi-e-mandate-api-v1-openapi.yaml
- openapi/citi-e-mandate-api-v2-openapi.yaml
- openapi/citi-finance-undertaking-api-openapi.yaml
- openapi/citi-fx-benchmark-async-api-openapi.yaml
- openapi/citi-fx-benchmark-sync-api-openapi.yaml
- openapi/citi-fx-cancel-async-api-openapi.yaml
- openapi/citi-fx-cancel-sync-api-openapi.yaml
- openapi/citi-fx-ecommerce-api-openapi.yaml
- openapi/citi-fx-gateway-reporting-async-api-openapi.yaml
- openapi/citi-fx-gateway-reporting-sync-api-openapi.yaml
- openapi/citi-fx-market-async-api-openapi.yaml
- openapi/citi-fx-market-sync-api-openapi.yaml
- openapi/citi-fx-orders-async-api-openapi.yaml
- openapi/citi-fx-orders-sync-api-openapi.yaml
- openapi/citi-fx-quote-async-api-openapi.yaml
- openapi/citi-fx-quote-sync-api-openapi.yaml
- openapi/citi-fx-reporting-async-api-openapi.yaml
- openapi/citi-fx-reporting-sync-api-openapi.yaml
- openapi/citi-grace-iva-openapi.yaml
- openapi/citi-id-provisioning-openapi.yaml
- openapi/citi-immediate-openapi.yaml
- openapi/citi-marketplace-management-openapi.yaml
- openapi/citi-marqueta-openapi.yaml
- openapi/citi-mobile-wallets-openapi.yaml
- openapi/citi-mobilecardonboarding-openapi.yaml
- openapi/citi-mobilevirtuallifecycle-openapi.yaml
- openapi/citi-online-payment-acceptance-api-openapi.yaml
- openapi/citi-order-approval-openapi.yaml
- openapi/citi-payerid-api-openapi.yaml
- openapi/citi-payment-reconfirmation-openapi.yaml
- openapi/citi-payment-refund-openapi.yaml
- openapi/citi-payment-status-openapi.yaml
- openapi/citi-paymentcancellation-json-openapi.yaml
- openapi/citi-paymentcancellation-xml-openapi.yaml
- openapi/citi-paymentenhancedinquiry-json-openapi.yaml
- openapi/citi-paymentenhancedinquiry-xml-openapi.yaml
- openapi/citi-paymentinitiation-pacs008-openapi.yaml
- openapi/citi-paymentinitiation-pacs009-openapi.yaml
- openapi/citi-paymentinitiation-pain102-openapi.yaml
- openapi/citi-paymentinitiation-pain103-openapi.yaml
- openapi/citi-payto-openapi.yaml
- openapi/citi-portfolio-listing-openapi.yaml
- openapi/citi-purchase-openapi.yaml
- openapi/citi-reporting-get-2-openapi.yaml
- openapi/citi-request-to-pay-openapi.yaml
- openapi/citi-safekeeping-accounts-openapi.yaml
- openapi/citi-safekeeping-positions-openapi.yaml
- openapi/citi-securitytransactionsaccounts-openapi.yaml
- openapi/citi-self-service-api-openapi.yaml
- openapi/citi-statement-transactions-openapi.yaml
- openapi/citi-statements-api-openapi.yaml
- openapi/citi-submit-action-openapi.yaml
- openapi/citi-tax-reclaims-openapi.yaml
- openapi/citi-trade-api-openapi.yaml
- openapi/citi-transfer-agency-accounts-openapi.yaml
- openapi/citi-transfer-agency-holding-openapi.yaml
- openapi/citi-transfer-agency-investors-openapi.yaml
- openapi/citi-transfer-agency-transactions-openapi.yaml
- openapi/citi-ukraine-bank-data-sharing-api-openapi.yaml
- openapi/citi-ukraine-payment-service-initiation-api-openapi.yaml
- openapi/citi-vamanagement-openapi.yaml
- openapi/citi-vca-api-openapi.yaml
- openapi/citi-vcaeventssubscriptions-openapi.yaml
- openapi/citi-vcagetnotifications-openapi.yaml
- openapi/citi-virtual-cards-lifecycle-v1-openapi.yaml
- openapi/citi-virtual-cards-lifecycle-v4-openapi.yaml
- openapi/citi-virtual-cards-notifications-openapi.yaml
- openapi/citi-virtual-cards-pi-openapi.yaml
- openapi/citi-virtual-cards-pi-v2-openapi.yaml
- openapi/citi-virtual-cards-reporting-openapi.yaml
- openapi/citi-virtual-cards-reporting-v1-openapi.yaml
- openapi/citi-worldlink-ir-api-openapi.yaml
- openapi/citi-worldlink-v1-api-openapi.yaml
- openapi/citi-worldlink-v2-api-openapi.yaml
- openapi/citi-worldlink-v3-api-openapi.yaml
- openapi/citi-worldlink-v5-api-openapi.yaml
- name: clientCredentials
type: oauth2
flows:
- flow: authorizationCode
authorizationUrl: /authenticationservices/v3/oauth/token
tokenUrl: /authenticationservices/v3/oauth/token
scopes: 2
description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
token to authenticate your API call. The Token URL includes the version of authentication
used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
Citi Authentication API reference</a> for information on requesting a token.
sources:
- openapi/citi-add-on-service-openapi.yaml
- openapi/citi-brazillocalmandate-openapi.yaml
- openapi/citi-contractstatusinquiry-openapi.yaml
- openapi/citi-digitalpaymentscollectionsv12-openapi.yaml
- openapi/citi-entityid-openapi.yaml
- openapi/citi-express-payments-api-openapi.yaml
- openapi/citi-express-payments-webhooks-openapi.yaml
- openapi/citi-idd-openapi.yaml
- openapi/citi-proof-of-payment-openapi.yaml
- openapi/citi-statementsv2-api-openapi.yaml
- openapi/citi-static-openapi.yaml
- openapi/citi-virtual-cards-pi-webhooks-openapi.yaml
- name: Basic Authentication
type: http
scheme: basic
description: Username is the application's client_id and password is the client_secret.
sources:
- openapi/citi-authentication-api-1-openapi.yaml
- openapi/citi-authentication-api-2-openapi.yaml
- openapi/citi-authentication-api-3-openapi.yaml
- openapi/citi-authentication-api-4-openapi.yaml
- openapi/citi-fx-authentication-api-openapi.yaml
- openapi/citi-ukraine-open-banking-authentication-api-openapi.yaml
- openapi/citi-virtual-cards-pi-webhooks-openapi.yaml
- name: clientIdHeader
type: apiKey
in: header
parameter: X-IBM-Client-Id
sources:
- openapi/citi-authentication-api-1-openapi.yaml
- openapi/citi-authentication-api-2-openapi.yaml
- openapi/citi-authentication-api-3-openapi.yaml
- openapi/citi-authentication-api-4-openapi.yaml
- openapi/citi-ukraine-open-banking-authentication-api-openapi.yaml
- name: clientSecretHeader
type: apiKey
in: header
parameter: X-IBM-Client-Secret
sources:
- openapi/citi-authentication-api-1-openapi.yaml
- openapi/citi-authentication-api-2-openapi.yaml
- openapi/citi-authentication-api-3-openapi.yaml
- openapi/citi-authentication-api-4-openapi.yaml
- openapi/citi-ukraine-open-banking-authentication-api-openapi.yaml
- name: clientCredentials
type: unknown
description: All CitiConnect APIs use the oAuth2 authentication scheme, which requires a bearer
token to authenticate your API call. The Token URL includes the version of authentication
used by this API. See <a href="../../authentication/authentication-api-reference/" target="_blank">the
Citi Authentication API reference</a> for information on requesting a token.
sources:
- openapi/citi-digitalpaymentscollectionsv12-openapi.yaml
- name: oauthBearerToken
type: http
scheme: bearer
bearerFormat: opaque OAuth 2.0
description: The access token obtained as a result of OAuth 2.0 flows.
sources:
- openapi/citi-finance-undertaking-api-openapi.yaml
- name: client_id
type: apiKey
in: query
parameter: client_id
sources:
- openapi/citi-fx-benchmark-async-api-openapi.yaml
- openapi/citi-fx-benchmark-sync-api-openapi.yaml
- openapi/citi-fx-cancel-async-api-openapi.yaml
- openapi/citi-fx-cancel-sync-api-openapi.yaml
- openapi/citi-fx-ecommerce-api-openapi.yaml
- openapi/citi-fx-gateway-reporting-async-api-openapi.yaml
- openapi/citi-fx-gateway-reporting-sync-api-openapi.yaml
- openapi/citi-fx-market-async-api-openapi.yaml
- openapi/citi-fx-market-sync-api-openapi.yaml
- openapi/citi-payment-reconfirmation-openapi.yaml
- openapi/citi-payment-refund-openapi.yaml
- openapi/citi-payment-status-openapi.yaml
- name: mutualTLS
type: http
scheme: mutual-tls
description: Mutual TLS (mTLS) authentication. Both root and intermediary certificates must
be exchanged with the API provider as part of the formal onboarding process before any API
calls can be made.
sources:
- openapi/citi-vca-dual-auth-authorization-openapi.yaml
- name: ApiKeyAuth
type: apiKey
in: header
parameter: X-API-Key
sources:
- openapi/citi-virtual-cards-pi-webhooks-openapi.yaml
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
curl "https://apis.io/api/v1/security/citi-authentication"
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.