Citigroup · Authentication Profile

Citigroup Authentication

Authentication

Citigroup secures its APIs with oauth2 and mutualTLS across 3 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode and clientCredentials flow(s).

BankingFinancial ServicesUnited StatesMoney Center BankOpen BankingOpen FinanceTreasury and Trade SolutionsCitiConnectPaymentsFXCorporate BankingFortune 100
Methods: oauth2, mutualTLS Schemes: 3 OAuth flows: authorizationCode, clientCredentials API key in:

Security Schemes

CitiOAuth2AuthorizationCode oauth2
· flows: authorizationCode
CitiConnectOAuth2 oauth2
· flows: clientCredentials
CitiConnectMutualTLS mutualTLS

Source

Authentication Profile

citigroup-authentication.yml Raw ↑
generated: '2026-07-23'
method: searched
source: >-
  Citi Developer Hub / Citi Partner Portal and CitiConnect API documentation
  (partner.citi.com/developers, developer.citi.com, citigroup.com CitiConnect
  API portal). No public OpenAPI is published, so securitySchemes are
  transcribed from Citi's published HTML documentation rather than derived
  from a machine-readable spec.
docs:
  - https://partner.citi.com/developers
  - https://www.citigroup.com/global/insights/citiconnect-api-portal
summary:
  types:
    - oauth2
    - mutualTLS
  api_key_in: []
  oauth2_flows:
    - authorizationCode
    - clientCredentials
  notes: >-
    Two distinct authentication surfaces. The retail Citi Developer Hub uses
    OAuth 2.0 authorization-code with an explicit customer consent (strong
    customer authentication) step to authorize third-party access to a
    consenting customer's account data and payment initiation. The corporate
    CitiConnect (Treasury and Trade Solutions) channel uses OAuth 2.0 together
    with mutual TLS (client-certificate) for enterprise ERP/TMS connectivity.
schemes:
  - name: CitiOAuth2AuthorizationCode
    type: oauth2
    surface: Citi Developer Hub (retail open banking)
    flows:
      - flow: authorizationCode
        note: >-
          Third-party application redirects the customer to Citi to
          authenticate and grant consent; Citi returns an authorization code
          exchanged for access and refresh tokens. Consent is scoped per
          product family (Accounts, Money Movement, Customers, etc.).
    consent: true
    sca: true
    sources:
      - apis.yml (citi-authorize-api, citi-accounts-transactions-api)
  - name: CitiConnectOAuth2
    type: oauth2
    surface: CitiConnect (corporate Treasury and Trade Solutions)
    flows:
      - flow: clientCredentials
        note: >-
          Machine-to-machine access for onboarded corporate clients; documented
          as OAuth 2.0 in the CitiConnect API portal.
    sources:
      - apis.yml (citiconnect-api, citiconnect-worldlink-api, citiconnect-fx-api)
  - name: CitiConnectMutualTLS
    type: mutualTLS
    surface: CitiConnect (corporate Treasury and Trade Solutions)
    note: >-
      Client-certificate (mutual TLS) is required in addition to OAuth 2.0 for
      CitiConnect enterprise connectivity, per Citi's published CitiConnect
      documentation.
    sources:
      - apis.yml (citiconnect-api)

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/citigroup-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.