Merge pull request 'feature/OVPAY-2485' (#63) from feature/OVPAY-2485 into develop

Reviewed-on: #63
This commit is contained in:
Mirjam Herald 2026-06-22 14:45:48 +00:00
commit 1f8e8f1381
2 changed files with 486 additions and 87 deletions

View File

@ -380,7 +380,7 @@ paths:
type: string
example: Customer
required: false
description: The role of the HTM employee in the case of the SMP
description: The role of the HTM employee in the case of the SMP
requestBody:
content:
application/json:
@ -415,7 +415,7 @@ paths:
type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves
description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header
schema:
@ -429,7 +429,7 @@ paths:
type: string
example: Customer
required: false
description: The role of the HTM employee in the case of the SMP
description: The role of the HTM employee in the case of the SMP
requestBody:
content:
application/json:
@ -464,7 +464,7 @@ paths:
type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves
description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header
schema:
@ -478,7 +478,7 @@ paths:
type: string
example: Customer
required: false
description: The role of the HTM employee in the case of the SMP
description: The role of the HTM employee in the case of the SMP
- name: customerPreferenceId
in: path
required: true
@ -519,7 +519,7 @@ paths:
type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves
description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header
schema:
@ -533,8 +533,8 @@ paths:
type: string
example: Customer
required: false
description: The role of the HTM employee in the case of the SMP
description: The role of the HTM employee in the case of the SMP
requestBody:
content:
application/json:
@ -575,7 +575,7 @@ paths:
type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves
description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header
schema:
@ -589,7 +589,7 @@ paths:
type: string
example: Customer
required: false
description: The role of the HTM employee in the case of the SMP
description: The role of the HTM employee in the case of the SMP
- name: addressId
in: path
required: true
@ -634,7 +634,7 @@ paths:
type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves
description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header
schema:
@ -648,7 +648,7 @@ paths:
type: string
example: Customer
required: false
description: The role of the HTM employee in the case of the SMP
description: The role of the HTM employee in the case of the SMP
- name: addressId
in: path
required: true
@ -669,14 +669,14 @@ paths:
summary: Add a customer phone
description: >-
parameters:
parameters:
- name: X-HTM-JWT-AUTH-HEADER
in: header
schema:
type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves
description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header
schema:
@ -690,7 +690,7 @@ paths:
type: string
example: Customer
required: false
description: The role of the HTM employee in the case of the SMP
description: The role of the HTM employee in the case of the SMP
requestBody:
content:
application/json:
@ -728,7 +728,7 @@ paths:
type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves
description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header
schema:
@ -742,7 +742,7 @@ paths:
type: string
example: Customer
required: false
description: The role of the HTM employee in the case of the SMP
description: The role of the HTM employee in the case of the SMP
- name: phoneId
in: path
required: true
@ -754,7 +754,7 @@ paths:
application/json:
schema:
$ref: "#/components/schemas/phoneEntity"
examples:
examples:
updateFullPhoneEntity:
value:
phone:
@ -789,7 +789,7 @@ paths:
type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves
description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header
schema:
@ -803,7 +803,7 @@ paths:
type: string
example: Customer
required: false
description: The role of the HTM employee in the case of the SMP
description: The role of the HTM employee in the case of the SMP
- name: phoneId
in: path
required: true
@ -816,7 +816,7 @@ paths:
content:
application/json: {}
x-auth-type: Application & Application User
x-throttling-tier: Unlimited
x-throttling-tier: Unlimited
/customers/billinginformations:
get:
tags:
@ -831,7 +831,7 @@ paths:
type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves
description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header
schema:
@ -845,7 +845,7 @@ paths:
type: string
example: Customer
required: false
description: The role of the HTM employee in the case of the SMP
description: The role of the HTM employee in the case of the SMP
responses:
200:
description: OK
@ -866,7 +866,7 @@ paths:
"billingInformationId": 1,
"iban": "NL••••••••••••1234",
"ascription": "J. Doe",
"alias": null,
"alias": null,
"created": "2024-10-20T17:05:52.000",
},
],
@ -875,7 +875,7 @@ paths:
get:
tags:
- Customers
summary: Find direct debit mandates for a customer.
summary: Find direct debit mandates for a customer.
description: Find direct debit mandates for a customer.
parameters:
- name: X-HTM-JWT-AUTH-HEADER
@ -884,7 +884,7 @@ paths:
type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves
description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header
schema:
@ -898,7 +898,7 @@ paths:
type: string
example: Customer
required: false
description: The role of the HTM employee in the case of the SMP
description: The role of the HTM employee in the case of the SMP
responses:
200:
description: OK
@ -914,12 +914,12 @@ paths:
[
{
"directDebitMandateId": 71,
"billingInformationId":
"billingInformationId":
{
"billingInformationId": 15,
"iban": "NL••••••••••••1234",
"ascription": "J. Doe",
"alias": null,
"alias": null,
"created": "2024-10-20T17:05:52.000",
},
"directDebitMandateType":
@ -1081,6 +1081,10 @@ paths:
"photo": null,
},
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links":
{
"self":
@ -1130,9 +1134,9 @@ paths:
},
},
}
OV pas without PAD:
summary: OV pas without PAD
description: OV pas without PAD
OV pas without PAD, without AGO:
summary: OV pas without PAD, without AGO
description: OV pas without PAD, without AGO
value:
{
"ovPayTokens":
@ -1142,7 +1146,7 @@ paths:
"ovPayTokenId": 1,
"xTat": "32089cc8-d187-47ff-a3a9-5c2558def811",
"tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" },
{ "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV34567",
"alias": "MyToken",
"tokenStatus":
@ -1164,6 +1168,10 @@ paths:
"photo": null,
},
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": false,
"isAuthorized": null,
},
"_links":
{
"self":
@ -1213,9 +1221,9 @@ paths:
},
},
}
OV pas with PAD and autoReload:
summary: OV pas with PAD and autoReload
description: OV pas with PAD and autoReload
OV pas with PAD, with autoReload, with AGO:
summary: OV pas with PAD, with autoReload, with AGO
description: OV pas with PAD, with autoReload, with AGO
value:
{
"ovPayTokens":
@ -1225,7 +1233,7 @@ paths:
"ovPayTokenId": 1,
"xTat": "32089cc8-d187-47ff-a3a9-5c2558def811",
"tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" },
{ "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV34567",
"alias": "MyToken",
"tokenStatus":
@ -1287,6 +1295,10 @@ paths:
"ageFromInclusive": 4,
"ageToInclusive": 11,
},
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links":
{
"self":
@ -1348,8 +1360,8 @@ paths:
"ovPayTokenId": 1,
"xTat": "32089cc8-d187-47ff-a3a9-5c2558def811",
"tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV34567",
{ "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV34567",
"alias": "MyToken",
"tokenStatus":
{ "tokenStatusId": 2, "name": "Active" },
@ -1385,6 +1397,10 @@ paths:
"ageFromInclusive": 4,
"ageToInclusive": 11,
},
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links":
{
"self":
@ -1446,7 +1462,7 @@ paths:
"ovPayTokenId": 1,
"xTat": "32089cc8-d187-47ff-a3a9-5c2558def811",
"tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" },
{ "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV34567",
"alias": "MyToken",
"tokenStatus":
@ -1501,6 +1517,10 @@ paths:
"ageFromInclusive": 4,
"ageToInclusive": 11,
},
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links":
{
"self":
@ -1562,7 +1582,7 @@ paths:
"ovPayTokenId": 1,
"xTat": "e7fa3392-646b-40e2-95a6-c417dc0b0969",
"tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" },
{ "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV34567",
"alias": "MyToken",
"tokenStatus":
@ -1583,7 +1603,7 @@ paths:
"ovPayTokenId": 6,
"xTat": "e7fa3392-646b-40e2-95a6-c417dc0b0969",
"tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" },
{ "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV54567",
"alias": "MyToken",
"tokenStatus":
@ -1599,13 +1619,17 @@ paths:
"photo": null,
},
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
},
{
"customerProfileId": 18,
"ovPayTokenId": 13,
"xTat": "e7fa3392-646b-40e2-95a6-c417dc0b0969",
"tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" },
{ "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV34547",
"alias": "MyToken",
"tokenStatus":
@ -1621,13 +1645,17 @@ paths:
"photo": null,
},
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
},
{
"customerProfileId": 132,
"ovPayTokenId": 21,
"xTat": "e7fa3392-646b-40e2-95a6-c417dc0b0969",
"tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" },
{ "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV34831",
"alias": "Mijn OV Pas",
"tokenStatus":
@ -1643,13 +1671,17 @@ paths:
"photo": null,
},
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
},
{
"customerProfileId": 166,
"ovPayTokenId": 28,
"xTat": "e7fa3392-646b-40e2-95a6-c417dc0b0969",
"tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" },
{ "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV34984",
"alias": "Mijn OV Pas",
"tokenStatus":
@ -1668,13 +1700,17 @@ paths:
"photo": null,
},
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
},
{
"customerProfileId": 166,
"ovPayTokenId": 115,
"xTat": "e7fa3392-646b-40e2-95a6-c417dc0b0969",
"tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" },
{ "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV54368",
"alias": "My retired token",
"tokenStatus":
@ -1690,13 +1726,17 @@ paths:
"photo": null,
},
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
},
{
"customerProfileId": 1,
"ovPayTokenId": 118,
"xTat": "e7fa3392-646b-40e2-95a6-c417dc0b0969",
"tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" },
{ "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV98263",
"alias": "My found token",
"tokenStatus":
@ -1712,6 +1752,10 @@ paths:
"photo": null,
},
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
},
],
_links:
@ -1812,6 +1856,10 @@ paths:
"personalAccountData":
{ "name": null, "birthdate": null, "photo": null },
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links":
{
"self":
@ -1890,6 +1938,10 @@ paths:
"personalAccountData":
{ "name": null, "birthdate": null, "photo": null },
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links":
{
"self":
@ -2086,6 +2138,10 @@ paths:
"personalAccountData":
{ "name": null, "birthdate": null, "photo": null },
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links":
{
"self":
@ -2149,6 +2205,10 @@ paths:
"personalAccountData":
{ "name": null, "birthdate": null, "photo": null },
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links":
{
"self":
@ -2905,9 +2965,9 @@ paths:
summary: "**INTEGRATIELAAG** Transfer old OVpay token to new OVpay token."
description: |-
**Note that this directly calls the integratielaag and not the Service Engine!**
First transfers all personal account data (if present), then all products, of an existing OVpay token
First transfers all personal account data (if present), then all products, of an existing OVpay token
to a new OVpay token. The new token will also be persisted in the profile as a replacement
of the old token. This call is asynchronous, and progress can be monitored using the
of the old token. This call is asynchronous, and progress can be monitored using the
`/customers/tokens/transfer/responsestatus/*` endpoint.
tags:
- Token Replace v2
@ -2920,9 +2980,9 @@ paths:
Transfer from a token without PAD to a new token:
summary: Transfer from a token without PAD to a new token
description: |
Transfer of a token without PAD to a new OVpay token. Note the new token in the request is always
identified by xTAT, regardless if the new token already exists in the customer profile. If the new
token does not exist in the customer profile, the user needs to provide an alias for the new token,
Transfer of a token without PAD to a new OVpay token. Note the new token in the request is always
identified by xTAT, regardless if the new token already exists in the customer profile. If the new
token does not exist in the customer profile, the user needs to provide an alias for the new token,
and it will be created in the customer profile.
value:
{
@ -2936,11 +2996,11 @@ paths:
Transfer from a token with PAD to a new token without existing PAD:
summary: Transfer from a token with PAD to a new token without existing PAD
description: |
Transfer of a token with PAD to a new token by xTAT without existing PAD. Note how this request is
different, since it has an e-mail address on which the new PAD should be created. This request may
Transfer of a token with PAD to a new token by xTAT without existing PAD. Note how this request is
different, since it has an e-mail address on which the new PAD should be created. This request may
optionally provide an OTP for verification of th provided email address.
Also note the new token in the request is always identified by xTAT, regardless if the new token
already exists in the customer profile. If the new token does not exist in the customer profile, the
Also note the new token in the request is always identified by xTAT, regardless if the new token
already exists in the customer profile. If the new token does not exist in the customer profile, the
user needs to provide an alias for the new token, and it will be created in the customer profile.
value:
{
@ -2957,8 +3017,8 @@ paths:
summary: Transfer from a token with PAD to a new token with existing PAD
description: |
Transfer of a token with PAD to a new token by xTAT with existing PAD.
Note that the new token in the request is always identified by xTAT, regardless if the new token
already exists in the customer profile. If the new token does not exist in the customer profile, the
Note that the new token in the request is always identified by xTAT, regardless if the new token
already exists in the customer profile. If the new token does not exist in the customer profile, the
user needs to provide an alias for the new token, and it will be created in the customer profile.
value:
{
@ -2996,7 +3056,7 @@ paths:
Transfer of token started:
description: |
The transfer of the token was started successfully. The data of the token will be transferred
asynchronously. In the response body the consumer will find information on how to retrieve the
asynchronously. In the response body the consumer will find information on how to retrieve the
processing status.
value:
{
@ -3038,7 +3098,7 @@ paths:
- Token Replace v2
summary: "**INTEGRATIELAAG** Get the status of the initiated token transfer process."
description: |
**Note that this directly calls the integratielaag and not the Service Engine!** Get the status of the
**Note that this directly calls the integratielaag and not the Service Engine!** Get the status of the
asynchronous token transfer processing.
responses:
"200":
@ -3166,7 +3226,7 @@ paths:
examples:
Token transfer in progress:
description: |
The transfer of the token is still in progress. The response body shows the details of the
The transfer of the token is still in progress. The response body shows the details of the
processing status.
value:
{
@ -3347,7 +3407,7 @@ paths:
in: query
description: External id of the device you want to get the purchased HTM products for.
schema:
type: string
type: string
- name: ovpayTokenId
in: query
description: Id of the OVpay-token you want to get the purchased HTM products for.
@ -3380,9 +3440,9 @@ paths:
}
getTwoBarcodePurchasedProductsForDevice:
summary: Two BarcodeTicket purchased products, one PendingActivation and one Active
description: |-
The first ticket (PendingActivation) shows the 30-day range in which the ticket can be activated
(using the PATCH endpoint) in the validityStart and validityEnd fields. The second ticket (Active)
description: |-
The first ticket (PendingActivation) shows the 30-day range in which the ticket can be activated
(using the PATCH endpoint) in the validityStart and validityEnd fields. The second ticket (Active)
shows the actual validity period of the ticket after activation.
value:
{
@ -3401,14 +3461,14 @@ paths:
"name": "Barcode",
},
"orderId": "501B17EF-36C4-4039-B92C-6517969B464E",
"orderLineId": "38B17EF-36C4-4039-B92C-4817969B464E",
"orderLineId": "38B17EF-36C4-4039-B92C-4817969B464E",
"ticketReference": "KJj43nejhbTxhrfef287",
"serviceId": "HTM-4321-7654-7659",
"issuedAt": "2026-03-21T09:01:35+01:00",
"activatedAt": null,
"blocked": false,
"cancelledAt": null,
"activateBefore": "2026-03-30",
"cancelledAt": null,
"activateBefore": "2026-03-30",
"validityStart": null,
"validityEnd": null,
"barcode": null,
@ -3436,14 +3496,14 @@ paths:
"name": "Barcode",
},
"orderId": "501B17EF-36C4-4039-B92C-6517969B464E",
"orderLineId": "38B17EF-36C4-4039-B92C-4817969B464E",
"orderLineId": "38B17EF-36C4-4039-B92C-4817969B464E",
"ticketReference": "KJj43nejhbTxhr897287",
"serviceId": "HTM-1234-7654-8945",
"issuedAt": "2026-03-21T10:01:12+01:00",
"activatedAt": "2026-03-21T12:45:01+01:00",
"blocked": false,
"cancelledAt": null,
"activateBefore": null,
"cancelledAt": null,
"activateBefore": null,
"validityStart": "2026-03-21T12:45:01+01:00",
"validityEnd": "2026-03-21T14:45:01+01:00",
"barcode": "iVBORw0KGgoAAAANSUhEUgAAAVwAAAFcAQAAAACsbTuBAAAFDElEQVR4Xu2bQa6rOhBEGzHwMEtgKewMyM5YCkvIkAGif50yyc/Tl770piZW9HSNywzqVlW3nXcjc83cusxnvsbMjBieuelf/bzGYz1jWCKmeGS+4g5grSwlz/IaI+JgEfzcvzQZo2yhxQgW7wDutLJrvVLzEInbVHLpM/tK5T7kHmNdbxssgqSipQj/0KLA24yqNvEWWRclpJKpefNgE7YZr/lj1eZ55wMYIWkUbZb7Xj/wH+BezvPkFJhQetmD+7AI2VuSEQMevANYESzqZh49VlEXIKOT7SDtseqnpz0Iyc2DJZezkEB5aaVKSvuF5FMwaIdB7wCGOgb5fFgus2wlKhPDpUiTlogr1tsHG7lfzcqYLlVnDHq6ylYn1OE54qd5cNC6aQxL0UQRy2YJJxCS8N4m273Gm4BJFAhzlytb5T4A0QrCYmUTrxd1bYNVgGqqPndH7vHwYqHLHf9cpO1pHJxU3Nq6vUbAVhXaocnTKO5cpK+4AViLitRwf8IQdYFwBkkKW7FzZxNh/AN/g5NHqXyed5MOz45kjkvKofpLYNwBrNBR/Dz9SKpTDkGd8CApZYonT24B7un56XKnoMeXkOBNHqTDk/NOmrrwyfIWYHe51O4kn4FBnfYbnHjqKuw3AGMreKOvC07DCAebHS5lAXWq5eKVA0HjYA2xM0MYCSMnqTqpx48ZVSmPTd15tT03AF+LVBuOgJoMqc2HL6Gy8nr1/K2DU+YpmKerd45fQ2ypzSFyq8coUM2D1yBksNWqOTWnjqvLpVYPvrt17f6BP+AaQk85zR4MarfHbAlSu/XhgGCJNg6mQNmASXnGhpZY+tKp93lywaY+SjcPhroCWx1BHFAnVemR81mdjEikWlllzYNrCM27bKVt7nInLplEnef6SfPFhb19MDmCbewcjtL/d7FwAzCqmShYzMd/qaPnp0AxV+SOpq5xMCnLZJOhZCNCZuIR4BWwL6un4luF5sE9N7CKXIJ2Zecncnt3vZ0it+hN7wNC6+DU/Ene1gj+lOOr4BDGilyT3D74NZ4OlYm2Xmx9t2rJN+kb7P3A/wUzV6lSQaonIoR3DUdy7vR1WQt782CrzrbbvTOdxwu2ZKy4MZXXflPzYJoVLg6GpbIVtLSb2JxduzEg+6Mm+R3AXECaHYRjG4nH2UIak7jSm9zXNQ9OLha2yhbUCT/vOA1VHUAGXpVuhpsHE7H7O0d6d2+i7rxeI2EVVMTm4wZg5vZUV2/nBUmoG5befZ0XERKkNg9O8zR9Rexls+WgldPRmTYHp90BrAIkqqYYnkmNGfvEY1E2Ijeu/3SQLKar1Q/8AX88eDqCRe3wZKJ89sVCRdaTZfvg/u8uFhoH14J0apHvil2rFwrUNtuDcXLOruNdvRoGB9ezgJXP2OrwN+mz8jl9lPab3Ob0NwDbVteFpEuX+7ylbHGdo5Oeny8y4vJgy2DniHhzQQp3c4yCkLwZvPbXk+INwKeqj6grVB/ha+dC88LVfec3zR/q2gYnlyO5GD+Kvfp03unruKCUygJb1e8HmwdbPp2pg8fgr3XYnE6YQGUWUp20Dz6hSgReznmXY3hLJ5A2ozJT9wN/gfVIEbzBsxvdYSneL571OV279S+/jubBiuCzAL5qt5xHPNHMcHgciSuD15rXbYMtJFbE1piEkEi0fPp6AoLX5Lvjt+paBvOIRQjSEEHaCX5BSP4DBSalHh4bB/8DVeIFt2RfPhQAAAAASUVORK5CYII=",
@ -3499,7 +3559,7 @@ paths:
"barcodeTickets":[],
"vouchers":[]
}
}
}
getSingleVoucherPurchasedProductForCustomer:
summary: One voucher purchased product
value:
@ -3523,7 +3583,7 @@ paths:
"voucherStatus": {
"voucherStatusId": 2,
"name": "issued"
},
},
"mandatoryCustomerDataItems":
[
{
@ -3538,7 +3598,7 @@ paths:
}
]
}
}
}
/purchasedproducts/{purchasedProductId}:
parameters:
- name: X-HTM-JWT-AUTH-HEADER
@ -3586,7 +3646,7 @@ paths:
value:
{
"status": "Active"
}
}
responses:
"200":
description: OK
@ -3636,7 +3696,6 @@ paths:
"vouchers": []
}
}
/customers/devices:
post:
summary: Add a new device to a customer profile.
@ -3813,7 +3872,7 @@ components:
customerProfileId:
type: integer
example: 1
customerPreference:
customerPreference:
$ref: "#/components/schemas/getCustomerPreference"
customerNumber:
type: integer
@ -4014,12 +4073,12 @@ components:
customerPreferenceId:
type: integer
languageId:
type: integer
type: integer
customerStatusEntity:
type: object
properties:
customerStatusId:
type: integer
type: integer
OvPayTokensResponse:
type: object
required:
@ -4298,7 +4357,7 @@ components:
items:
type: object
required:
- purchasedProductId
- purchasedProductId
- productId
- name
- status
@ -4421,13 +4480,13 @@ components:
type: string
example: HTM 2 uurskaart
description: |-
The name of the originating HTM product definition.
The name of the originating HTM product definition.
Will be returned in the language as specified in the Accept-Language header or the customer profile. Otherwise defaults to NL.
description:
type: string
example: "Met deze kaart reis je 2 uur lang onbeperkt met de bussen en trams van HTM. Overstappen is natuurlijk toegestaan!"
description: |-
The description of the originating HTM product definition.
The description of the originating HTM product definition.
Will be returned in the language as specified in the Accept-Language header or the customer profile. Otherwise defaults to NL.
status:
type: string
@ -4486,15 +4545,15 @@ components:
example: "2024-11-30"
description: Only present for barcode tickets that are not yet activated. Tickets can only be activated BEFORE this date.
validityStart:
description: |-
Only present for barcode tickets that have been activated. The date-time at which the ticket will become valid for traveling.
description: |-
Only present for barcode tickets that have been activated. The date-time at which the ticket will become valid for traveling.
The ticket will not be valid before this date/time.
type: string
format: date-time-offset
example: "2024-11-25T13:25:00+01:00"
validityEnd:
description: |-
Only present for barcode tickets that have been activated. The date-time at which the ticket will become invalid for traveling.
description: |-
Only present for barcode tickets that have been activated. The date-time at which the ticket will become invalid for traveling.
The ticket will not be valid after this date/time.
type: string
format: date-time-offset
@ -4603,4 +4662,3 @@ components:
customerDataItem:
type: string
example: emailAddress

View File

@ -0,0 +1,341 @@
openapi: 3.0.1
info:
title: Service Engine APIs for TAT security
description: >-
Service Engine APIs for TAT security. These are NOT the raw GBO APIs to access TAT security at GBO directly.
To be used by touch points to get secure a TAT.
version: "2.0"
servers:
- url: https://services.acc.api.htm.nl/abt/touchpoint/2.0
tags:
- name: TAT Security
paths:
/tokens/securetoken:
parameters:
- name: X-HTM-JWT-AUTH-HEADER
in: header
schema:
type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header
schema:
type: integer
example: 323
required: false
description: The id of the customer Profile
- name: X-HTM-ROLE-HEADER
in: header
schema:
type: string
example: Customer
required: false
description: The role of the HTM employee in the case of the SMP
post:
tags:
- TAT Security
summary: Request additional OV-pas security for a token either in profile or anonymous.
description: Request additional OV-pas security for a token either in profile or anonymous
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/SecureTokenRequest"
examples:
With customer account:
value:
ovPayTokenId: 42
emailAddress: stasjo@htm.nl
Without customer account:
value:
xtat: 62914b49-2c7f-437f-b4b0-2ad61a9f902d
emailAddress: stasjo@htm.nl
responses:
"200":
description: OK
content:
application/json:
schema:
$ref: "#/components/schemas/EmailNotPreApprovedResponse"
example:
uid: 7594f3ee-cd3d-40a3-8e82-73b90d16c481
recipient: xxxxxx.user@gmail.com
key: 123456789123456789123456789abcde
description: OTP Sent
"400":
description: Bad Request
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Missing Parameters:
value:
status: 400
title: Missing Mandatory Parameter
detail: Required parameter {0} is missing.
Invalid Parameters:
value:
status: 400
title: Invalid Parameter
detail: Required parameter {0} is invalid.
"401":
description: Unauthorized
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Unauthorized:
value:
status: 401
title: Unauthorized
detail: Invalid Access Token
"404":
description: Not found
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
TAT not found:
value:
status: 404
title: Not Found
detail: TAT Account Not Found
"409":
description: Conflict
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
TAT Already Secured:
value:
status: 409
title: Conflict
detail: TAT Already Secured
"500":
description: Internal server error
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
example:
error: An unknown error has occurred
/tokens/verifyotp:
parameters:
- name: X-HTM-JWT-AUTH-HEADER
in: header
schema:
type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header
schema:
type: integer
example: 323
required: false
description: The id of the customer Profile
- name: X-HTM-ROLE-HEADER
in: header
schema:
type: string
example: Customer
required: false
description: The role of the HTM employee in the case of the SMP
post:
tags:
- TAT Security
summary: Submit an OTP for a triggered OTP flow.
description: |
Submit an OTP for a triggered OTP flow. This can either be result of an AGO activation, or
result of an AGO authorization flow. Since the backoffice behaves slightly different depending
on which use case is executed, the calling TP needs to provide an `action` in the request body.
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/VerifyOtpRequest"
examples:
OTP verification for TAT security activation for token in customer account:
value:
ovPayTokenId: 42
otp: 123456
action: secure
OTP verification for TAT security authorization for anonymous token:
value:
xtat: 0f0defe8-828c-48e5-97e5-26d1d0179ef0
otp: 123456
action: authorize
responses:
"200":
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/VerifyOtpResponse'
examples:
Tat Secured:
value:
status: Success
description: TAT Secured
Tat Unsecured:
value:
status: Success
description: TAT Unsecured
Tat Authorized:
value:
status: Success
description: TAT Authorized
"400":
description: Bad request
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Missing Parameters:
value:
status: 400
title: Missing Mandatory Parameter
detail: Required parameter {0} is missing.
Invalid Parameters:
value:
status: 400
title: Invalid Parameter
detail: Required parameter {0} is invalid.
"401":
description: Unauthorized
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Unauthorized:
value:
status: 401
title: Unauthorized
detail: Invalid Access Token
"500":
description: Internal server error
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
example:
error: An unknown error has occurred
components:
schemas:
unavailable:
type: object
GenerateTatOutput:
type: object
properties:
uid:
type: string
description: >-
An uid IS A unique identifier THAT is associated with the
user.
recipient:
type: string
description: >-
A recipient IS A unique identifier THAT is associated with the
TAT owner.
key:
type: string
description: >-
A key IS a 32 character string THAT uniquely identifies the
OTP session.
EmailNotPreApprovedResponse:
type: object
description: >-
EmailNotPreApprovedResponse IS AN object THAT represents the response of
email pre-approval check.
properties:
uid:
type: string
description: A uid IS A unique identifier THAT is associated with the user.
example: 7594f3ee-cd3d-40a3-8e82-73b90d16c481
recipient:
type: string
description: >-
A recipient IS A unique identifier THAT is associated with the TAT
owner.
example: xxxxxx.user@gmail.com
key:
type: string
description: >-
A key IS a 32 character string THAT uniquely identifies the OTP
session.
example: 123456789123456789123456789abcde
description:
type: string
description: >-
A description IS A string THAT describes the reason why the email is
not pre-approved.
example: OTP Sent
SecureTokenRequest:
type: object
properties:
ovPayTokenId:
type: integer
example: 42
xtat:
type: string
format: uuid
example: 6134db53-9ae5-41d1-a343-36656b60b510
emailAddress:
type: string
format: email
example: stasjo@htm.nl
required:
- ovPayTokenId
VerifyOtpRequest:
type: object
properties:
ovPayTokenId:
type: integer
example: 42
xtat:
type: string
format: uuid
example: f3474452-e1d4-428c-b366-e5ad5965eb8c
otp:
type: string
example: 123456
action:
type: string
example: secure
required:
- otp
- action
VerifyOtpResponse:
type: object
properties:
status:
type: string
example: Success
description:
type: string
example: TAT Secured
ErrorResponse:
description: Default response when an invalid request has been sent
type: object
properties:
status:
type: integer
description: >-
A status IS An integer that represents the HTTP status code of the
response.
example: 400
title:
type: string
description: A title IS A string that provides a brief summary of the error.
detail:
type: string
description: A detail IS A string that provides more details about the error.