Skip to main content
POST
Perform a business operation related to an identity token

Authorizations

Authorization
string
header
required

Basic authentication header of the form Basic <encoded-value>, where <encoded-value> is the base64-encoded string username:password.

Path Parameters

nsid
string<uuid>
required

Globally unique namespace ID. These IDs are opaque, not guessable, and not sequential.

Bango provides each Bango partner with a unique set of resource URIs. All resource URI paths start with /ns/{nsid}, where {nsid} is the namespace ID. No other Bango partner shares this namespace. Partner credentials permit access only to URIs with this namespace.

Example:

"673c74de-ce5b-4f79-9851-2544d1d836cb"

rid
string<uuid>
required

Globally unique resource ID. These IDs are opaque, not guessable, and not sequential.

Each individual resource in a partner's namespace has a unique identifier: this is the identifier immediately after the resource type in the URI path.

For example, in the URI /ns/673c74de-ce5b-4f79-9851-2544d1d836cb/elephants/581b2e40-741c-4683-ae66-46c9fe6f4d5e:

  • The namespace id is 673c74de-ce5b-4f79-9851-2544d1d836cbde
  • elephants indicates the resource type is elephant
  • The resource id is 581b2e40-741c-4683-ae66-46c9fe6f4d5e

Every resource has a read-only property rid that contains the resource ID, for convenience.

Example:

"581b2e40-741c-4683-ae66-46c9fe6f4d5e"

Body

application/json

A request to perform a business operation related to an identity token. A request specifies an action type and any action-specific data (the payload). The response is always the latest version of the identity token held in the Bango Platform.

The following action types are available. See each action type schema for detailed information.

  • CANCEL: A request to permanently disable a payment instrument token, with no possibility of undo
  • FETCH_ELIGIBILITY: A request to fetch eligibility information for the token from the downstream payment provider
  • VALIDATE_PASSPHRASE: A request to validate passphrase for the token from the downstream payment provider
  • GET_ACCOUNT: A request to retrieve the account information associated with a PIT

A request to permanently disable a payment instrument token, with no possibility of undo.

If the payment instrument token is already canceled, returns HTTP 409 with error code pit-already-canceled.

type
any
required
payload
object
required

Empty object

Response

The updated resource.

An identity token resource when CANCEL has been selected.

rid
string<uuid>
required

Globally unique resource ID. These IDs are opaque, not guessable, and not sequential.

Each individual resource in a partner's namespace has a unique identifier: this is the identifier immediately after the resource type in the URI path.

For example, in the URI /ns/673c74de-ce5b-4f79-9851-2544d1d836cb/elephants/581b2e40-741c-4683-ae66-46c9fe6f4d5e:

  • The namespace id is 673c74de-ce5b-4f79-9851-2544d1d836cbde
  • elephants indicates the resource type is elephant
  • The resource id is 581b2e40-741c-4683-ae66-46c9fe6f4d5e

Every resource has a read-only property rid that contains the resource ID, for convenience.

Example:

"581b2e40-741c-4683-ae66-46c9fe6f4d5e"

lastUpdate
string<date-time>
required

RFC 3339 datetime of the last update to this resource

Example:

"2022-12-21T08:59:32Z"

type
any
required

The type of token. Code can use type to infer the schema for the rest of the resource.

For now, only payment-instrument-token is supported. Other values may be supported in future.

state
enum<string>
required

The token state. Tokens of type payment-instrument-token are always one of:

  • active: may be used for payments, if eligible
  • canceled: may not be used for payments

The only permitted state transition is from active to canceled. To make this transition, send a CANCEL action. It is not possible to transition from canceled back to active.

Available options:
active,
canceled
merchantId
string
required

Friendly unique identifier for the merchant partner.

Internally, corresponds to the accountKey property in the route-config-server's partner_namespaces table.

Required string length: 2 - 50
Example:

"AUSSIE_APPS"

paymentProviderId
string
required

Friendly unique identifier for the payment provider.

Internally, corresponds to the accountKey property in the route-config-server's partner_namespaces table.

Required string length: 2 - 50
Example:

"OGNABTEL"

paymentEligibilityStatus
enum<string>
default:unknown

Information about the token related to payment processing.

  • discovering: The Bango Platform is currently waiting for a response from the payment provider about the token
  • enabled: Authorized partners can use the token to process payments
  • not-enabled: The payment provider has not enabled the token to process payments
  • closed: The payment provider has decided the token can no longer process payments (this is permanent)
  • barred: The payment provider has suspended or barred the user associated with the token (this may be temporary)
  • unknown: The payment provider has not provided information about this token
  • unsupported: The payment provider does not support requests for information about this token
Available options:
discovering,
enabled,
not-enabled,
closed,
barred,
unknown,
unsupported
accountType
enum<string>

The account type allocated by the payment provider for an end user's account.

Available options:
prepaid,
postpaid,
unknown
locale
string

A BCP 47 language tag representing the locale of the merchant end user, if known.

Required string length: 1 - 50
Examples:

"en-US"

"ar-SA"

customerProfile
string

Customer’s latest spending limit profile

userProperties
User specific properties · object

Properties that are specific to a user

Example: