Compare commits

...

15 Commits

Author SHA1 Message Date
Max Martens
3d387e451b Added contractVersions in SE contracts list response, fixed some example formatting 2026-07-15 14:37:20 +02:00
Max Martens
851f60d665 Updated SE-vouchers-supplier spec after review 2026-07-14 17:31:52 +02:00
Max Martens
0987cedb4f Fix JSON schema errors 2026-07-14 15:50:57 +02:00
23dd83fac9 added schema for the post Order endpoint 2026-07-10 13:28:02 +02:00
a637cfb4f2 Removed voucher query param on the CRUD's en updated SE-order POST/ PATCH orderline in regards to vouchers 2026-07-09 17:50:14 +02:00
1f8e8f1381 Merge pull request 'feature/OVPAY-2485' (#63) from feature/OVPAY-2485 into develop
Reviewed-on: #63
2026-06-22 14:45:48 +00:00
1f0481119c OVPAY-2485 - Typo in url. 2026-06-18 16:04:41 +02:00
3d2885f2b8 OVPAY-2485 - Added support for anonymous TAT security. 2026-06-18 14:43:08 +02:00
280d3b1fcd OVPAY-2485 - Extended token details response bodies with security. 2026-06-18 11:58:34 +02:00
f28a797b6b OVPAY-2485 - Improved TP requests. 2026-06-18 11:17:04 +02:00
87d8f7df58 OVPAY-2485 - Updated OTP response body for TP. 2026-06-18 10:25:06 +02:00
30e8860a39 OVPAY-2485 - Added schemas. 2026-06-17 16:26:39 +02:00
d18afcae8c OVPAY-2485 - Minor additions. 2026-06-17 16:23:11 +02:00
eb03aa04e6 OVPAY-2485 - Added SE endpoint for AGO OTP verification. 2026-06-17 16:22:38 +02:00
aca160f65c OVPAY-2485 - Added SE endpoint for AGO activation. 2026-06-17 16:08:06 +02:00
6 changed files with 805 additions and 171 deletions

View File

@ -45,12 +45,36 @@ paths:
"contractStatus":
{ "contractStatusId": 2, "name": "active" },
"productId": 1,
"productName": "HTM Maand 20% korting",
"termDuration": "P0Y1M0D",
"productName": "HTM Maand 20% korting doorlopend",
"termDuration": "P1M",
"billingDay": 15,
"highestInvoiceTerm": 1,
"created": "2024-08-01 15:01:00.000",
"created": "2024-08-01T15:01:00.000Z",
"ovPayTokenId": 1337,
"contractVersions": [
{
"contractVersionId": 1,
"termsAndConditions": "https://www.htm.nl/reisproducten/productvoorwaarden/htm-maandkorting/",
"productId": 1,
"productName": "HTM Maand 20% korting doorlopend",
"taxCode": "V9",
"taxPercentage": 9,
"termAmountInclTax": 400,
"start": "2024-08-01T15:01:00.000Z",
"end": "2025-01-01T03:00:00.000Z"
},
{
"contractVersionId": 2,
"termsAndConditions": "https://www.htm.nl/reisproducten/productvoorwaarden/htm-maandkorting/",
"productId": 1,
"productName": "HTM Maand 20% korting doorlopend",
"taxCode": "V9",
"taxPercentage": 9,
"termAmountInclTax": 500,
"start": "2025-01-01T03:00:00.000Z",
"end": null
}
],
"_links":
{
"get_token":
@ -68,14 +92,38 @@ paths:
"orderLineId": "42f68042-908f-41f4-9d9b-4cab843ff0e8",
"touchpointId": 2,
"contractStatus":
{ "contractStatusId": 1, "name": "new" },
{ "contractStatusId": 6, "name": "pending cancellation" },
"productId": 1,
"productName": "HTM Maand 20% korting",
"termDuration": "P0Y1M0D",
"productName": "HTM 20% Korting doorlopend",
"termDuration": "P1M",
"billingDay": 15,
"highestInvoiceTerm": 1,
"created": "2024-08-01 15:01:00.000",
"created": "2024-08-01T15:01:00.000Z",
"ovPayTokenId": 1338,
"contractVersions": [
{
"contractVersionId": 1,
"termsAndConditions": "https://www.htm.nl/reisproducten/productvoorwaarden/htm-maandkorting/",
"productId": 1,
"productName": "HTM 20% Korting doorlopend",
"taxCode": "V9",
"taxPercentage": 9,
"termAmountInclTax": 400,
"start": "2024-08-01T15:01:00.000Z",
"end": "2025-01-01T03:00:00.000Z"
},
{
"contractVersionId": 2,
"termsAndConditions": "https://www.htm.nl/reisproducten/productvoorwaarden/htm-maandkorting/",
"productId": 1,
"productName": "HTM 20% Korting doorlopend",
"taxCode": "V9",
"taxPercentage": 9,
"termAmountInclTax": 500,
"start": "2025-01-01T03:00:00.000Z",
"end": "2025-02-01T03:00:00.000Z"
}
],
"_links":
{
"get_token":
@ -154,8 +202,8 @@ paths:
"contractStatus":
{ "contractStatusId": 2, "name": "active" },
"productId": 1,
"productName": "HTM Maand 20% korting",
"termDuration": "P0Y1M0D",
"productName": "HTM 20% Korting doorlopend",
"termDuration": "P1M",
"billingDay": 15,
"highestInvoiceTerm": 1,
"ovPayTokenId": 1337,
@ -165,22 +213,22 @@ paths:
"contractVersionId": 1,
"termsAndConditions": "https://www.htm.nl/reisproducten/productvoorwaarden/htm-maandkorting/",
"productId": 1,
"productName": "HTM Maand 20% korting",
"productName": "HTM 20% Korting doorlopend",
"taxCode": "V9",
"taxPercentage": 9.0,
"termAmountInclTax": 400,
"start": "2024-07-04 15:01:00.000",
"end": "2024-12-31 15:01:00.000",
"start": "2024-08-01T15:01:00.000Z",
"end": "2025-01-01T03:00:00.000Z",
},
{
"contractVersionId": 2,
"termsAndConditions": "https://www.htm.nl/reisproducten/productvoorwaarden/htm-maandkorting/",
"productId": 1,
"productName": "HTM Maand 20% korting",
"productName": "HTM 20% Korting doorlopend",
"taxCode": "V9",
"taxPercentage": 9.0,
"termAmountInclTax": 400,
"start": "2025-01-01 15:01:00.000",
"start": "2025-01-01T03:00:00.000Z",
},
],
"contractActions":
@ -190,7 +238,7 @@ paths:
"actionType":
{ "actionTypeId": 1, "name": "create" },
"user": "subid123456",
"timestamp": "2024-07-02 15:01:00.000",
"timestamp": "2024-07-02T15:01:00.000Z",
"details": "Contract created",
"correlationId": "976e7a4c-bf24-43d2-b444-55817556e7ee",
},
@ -199,7 +247,7 @@ paths:
"actionType":
{ "actionTypeId": 2, "name": "change" },
"user": "subid123456",
"timestamp": "2024-07-03 15:01:00.000",
"timestamp": "2024-07-03T15:01:00.000Z",
"details": "Contract changed",
"correlationId": "e2462347-6749-4841-b42a-cf8de19ec727",
},
@ -211,8 +259,8 @@ paths:
"externalReference": "F2024-0001",
"term": 1,
"invoiceDate": "2024-07-02",
"created": "2024-07-02 15:01:00.000",
"updated": "2024-07-02 15:01:00.000",
"created": "2024-07-02T15:01:00.000Z",
"updated": "2024-07-02T15:01:00.000Z",
"state": "invoice_created",
"data": "{json}",
"isCredit": false,
@ -270,8 +318,8 @@ paths:
"externalReference": "F2024-0001",
"term": 1,
"invoiceDate": "2024-07-02",
"created": "2024-07-02 15:01:34.000",
"updated": "2024-07-04 00:04:56.000",
"created": "2024-07-02T15:01:34.000Z",
"updated": "2024-07-04T00:04:56.000Z",
"state": "invoice_created",
"public_link": "http://mijnfactuurinzien.nl/F2024-0001",
"isCredit": false,
@ -282,8 +330,8 @@ paths:
"externalReference": "F2024-0002",
"term": 2,
"invoiceDate": "2024-08-02",
"created": "2024-08-02 15:01:34.000",
"updated": "2024-08-04 00:04:56.000",
"created": "2024-08-02T15:01:34.000Z",
"updated": "2024-08-04T00:04:56.000Z",
"state": "invoice_created",
"public_link": "http://mijnfactuurinzien.nl/F2024-0002",
"isCredit": false,
@ -328,8 +376,8 @@ paths:
"cancellationMoment": "termBound",
"termDuration": "P1M",
"billingDay": 18,
"cancellationFrom": "2024-08-10T00:00:00",
"cancellationUntil": "2026-08-10T00:00:00",
"cancellationFrom": "2024-08-10T00:00:00Z",
"cancellationUntil": "2026-08-10T00:00:00Z",
}
/contracts/{contractId}/cancellationvalidation:
parameters:
@ -382,7 +430,7 @@ paths:
{
"validationResult": true,
"validationMessage": "",
"end": "2024-08-10T03:59:59",
"end": "2024-08-10T03:59:59Z",
"refundAmount": 2489,
"refundMethods": ["creditInvoice", "iDeal"],
}
@ -451,7 +499,7 @@ paths:
the refund amount and refund method.
value:
{
"end": "2024-08-10T03:59:59",
"end": "2024-08-10T03:59:59Z",
"refundAmount": 2489,
"refundMethod": "creditInvoice",
}
@ -516,8 +564,8 @@ paths:
"taxCode": "V9",
"taxPercentage": 9.0,
"termAmountInclTax": 400,
"start": "2024-07-04 15:01:00.000",
"end": "2024-12-31 15:01:00.000",
"start": "2024-07-04T15:01:00.000Z",
"end": "2024-12-31T15:01:00.000Z",
},
{
"contractVersionId": 2,
@ -527,7 +575,8 @@ paths:
"taxCode": "V9",
"taxPercentage": 9.0,
"termAmountInclTax": 400,
"start": "2025-01-01 15:01:00.000",
"start": "2025-01-01T15:01:00.000Z",
"end": null
},
],
"contractActions":
@ -537,7 +586,7 @@ paths:
"actionType":
{ "actionTypeId": 1, "name": "create" },
"user": "subid123456",
"timestamp": "2024-07-02 15:01:00.000",
"timestamp": "2024-07-02T15:01:00.000Z",
"details": "Contract created",
"correlationId": "976e7a4c-bf24-43d2-b444-55817556e7ee",
},
@ -546,7 +595,7 @@ paths:
"actionType":
{ "actionTypeId": 2, "name": "change" },
"user": "subid123456",
"timestamp": "2024-07-03 15:01:00.000",
"timestamp": "2024-07-03T15:01:00.000Z",
"details": "Contract changed",
"correlationId": "e2462347-6749-4841-b42a-cf8de19ec727",
},
@ -558,8 +607,8 @@ paths:
"externalReference": "F2024-0001",
"term": 1,
"invoiceDate": "2024-07-02",
"created": "2024-07-02 15:01:00.000",
"updated": "2024-07-02 15:01:00.000",
"created": "2024-07-02T15:01:00.000Z",
"updated": "2024-07-02T15:01:00.000Z",
"state": "invoice_created",
"data": "{json}",
"isCredit": false,
@ -682,7 +731,7 @@ paths:
"termDuration": "P0Y1M0D",
"billingDay": 15,
"highestInvoiceTerm": 1,
"created": "2024-08-01 15:01:00.000",
"created": "2024-08-01T15:01:00.000Z",
"ovPayTokenId": 1337,
"contractVersions":
[
@ -781,7 +830,7 @@ paths:
"termDuration": "P0Y1M0D",
"billingDay": 15,
"highestInvoiceTerm": 1,
"created": "2024-08-01 15:01:00.000",
"created": "2024-08-01T15:01:00.000Z",
"ovPayTokenId": 1337,
"contractVersions":
[

View File

@ -1081,6 +1081,10 @@ paths:
"photo": null,
},
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links":
{
"self":
@ -1130,9 +1134,9 @@ paths:
},
},
}
OV pas without PAD:
summary: OV pas without PAD
description: OV pas without PAD
OV pas without PAD, without AGO:
summary: OV pas without PAD, without AGO
description: OV pas without PAD, without AGO
value:
{
"ovPayTokens":
@ -1164,6 +1168,10 @@ paths:
"photo": null,
},
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": false,
"isAuthorized": null,
},
"_links":
{
"self":
@ -1213,9 +1221,9 @@ paths:
},
},
}
OV pas with PAD and autoReload:
summary: OV pas with PAD and autoReload
description: OV pas with PAD and autoReload
OV pas with PAD, with autoReload, with AGO:
summary: OV pas with PAD, with autoReload, with AGO
description: OV pas with PAD, with autoReload, with AGO
value:
{
"ovPayTokens":
@ -1287,6 +1295,10 @@ paths:
"ageFromInclusive": 4,
"ageToInclusive": 11,
},
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links":
{
"self":
@ -1385,6 +1397,10 @@ paths:
"ageFromInclusive": 4,
"ageToInclusive": 11,
},
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links":
{
"self":
@ -1501,6 +1517,10 @@ paths:
"ageFromInclusive": 4,
"ageToInclusive": 11,
},
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links":
{
"self":
@ -1599,6 +1619,10 @@ paths:
"photo": null,
},
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
},
{
"customerProfileId": 18,
@ -1621,6 +1645,10 @@ paths:
"photo": null,
},
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
},
{
"customerProfileId": 132,
@ -1643,6 +1671,10 @@ paths:
"photo": null,
},
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
},
{
"customerProfileId": 166,
@ -1668,6 +1700,10 @@ paths:
"photo": null,
},
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
},
{
"customerProfileId": 166,
@ -1690,6 +1726,10 @@ paths:
"photo": null,
},
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
},
{
"customerProfileId": 1,
@ -1712,6 +1752,10 @@ paths:
"photo": null,
},
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
},
],
_links:
@ -1812,6 +1856,10 @@ paths:
"personalAccountData":
{ "name": null, "birthdate": null, "photo": null },
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links":
{
"self":
@ -1890,6 +1938,10 @@ paths:
"personalAccountData":
{ "name": null, "birthdate": null, "photo": null },
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links":
{
"self":
@ -2086,6 +2138,10 @@ paths:
"personalAccountData":
{ "name": null, "birthdate": null, "photo": null },
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links":
{
"self":
@ -2149,6 +2205,10 @@ paths:
"personalAccountData":
{ "name": null, "birthdate": null, "photo": null },
"gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links":
{
"self":
@ -3636,7 +3696,6 @@ paths:
"vouchers": []
}
}
/customers/devices:
post:
summary: Add a new device to a customer profile.
@ -4603,4 +4662,3 @@ components:
customerDataItem:
type: string
example: emailAddress

View File

@ -0,0 +1,341 @@
openapi: 3.0.1
info:
title: Service Engine APIs for TAT security
description: >-
Service Engine APIs for TAT security. These are NOT the raw GBO APIs to access TAT security at GBO directly.
To be used by touch points to get secure a TAT.
version: "2.0"
servers:
- url: https://services.acc.api.htm.nl/abt/touchpoint/2.0
tags:
- name: TAT Security
paths:
/tokens/securetoken:
parameters:
- name: X-HTM-JWT-AUTH-HEADER
in: header
schema:
type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header
schema:
type: integer
example: 323
required: false
description: The id of the customer Profile
- name: X-HTM-ROLE-HEADER
in: header
schema:
type: string
example: Customer
required: false
description: The role of the HTM employee in the case of the SMP
post:
tags:
- TAT Security
summary: Request additional OV-pas security for a token either in profile or anonymous.
description: Request additional OV-pas security for a token either in profile or anonymous
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/SecureTokenRequest"
examples:
With customer account:
value:
ovPayTokenId: 42
emailAddress: stasjo@htm.nl
Without customer account:
value:
xtat: 62914b49-2c7f-437f-b4b0-2ad61a9f902d
emailAddress: stasjo@htm.nl
responses:
"200":
description: OK
content:
application/json:
schema:
$ref: "#/components/schemas/EmailNotPreApprovedResponse"
example:
uid: 7594f3ee-cd3d-40a3-8e82-73b90d16c481
recipient: xxxxxx.user@gmail.com
key: 123456789123456789123456789abcde
description: OTP Sent
"400":
description: Bad Request
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Missing Parameters:
value:
status: 400
title: Missing Mandatory Parameter
detail: Required parameter {0} is missing.
Invalid Parameters:
value:
status: 400
title: Invalid Parameter
detail: Required parameter {0} is invalid.
"401":
description: Unauthorized
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Unauthorized:
value:
status: 401
title: Unauthorized
detail: Invalid Access Token
"404":
description: Not found
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
TAT not found:
value:
status: 404
title: Not Found
detail: TAT Account Not Found
"409":
description: Conflict
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
TAT Already Secured:
value:
status: 409
title: Conflict
detail: TAT Already Secured
"500":
description: Internal server error
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
example:
error: An unknown error has occurred
/tokens/verifyotp:
parameters:
- name: X-HTM-JWT-AUTH-HEADER
in: header
schema:
type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header
schema:
type: integer
example: 323
required: false
description: The id of the customer Profile
- name: X-HTM-ROLE-HEADER
in: header
schema:
type: string
example: Customer
required: false
description: The role of the HTM employee in the case of the SMP
post:
tags:
- TAT Security
summary: Submit an OTP for a triggered OTP flow.
description: |
Submit an OTP for a triggered OTP flow. This can either be result of an AGO activation, or
result of an AGO authorization flow. Since the backoffice behaves slightly different depending
on which use case is executed, the calling TP needs to provide an `action` in the request body.
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/VerifyOtpRequest"
examples:
OTP verification for TAT security activation for token in customer account:
value:
ovPayTokenId: 42
otp: 123456
action: secure
OTP verification for TAT security authorization for anonymous token:
value:
xtat: 0f0defe8-828c-48e5-97e5-26d1d0179ef0
otp: 123456
action: authorize
responses:
"200":
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/VerifyOtpResponse'
examples:
Tat Secured:
value:
status: Success
description: TAT Secured
Tat Unsecured:
value:
status: Success
description: TAT Unsecured
Tat Authorized:
value:
status: Success
description: TAT Authorized
"400":
description: Bad request
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Missing Parameters:
value:
status: 400
title: Missing Mandatory Parameter
detail: Required parameter {0} is missing.
Invalid Parameters:
value:
status: 400
title: Invalid Parameter
detail: Required parameter {0} is invalid.
"401":
description: Unauthorized
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Unauthorized:
value:
status: 401
title: Unauthorized
detail: Invalid Access Token
"500":
description: Internal server error
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
example:
error: An unknown error has occurred
components:
schemas:
unavailable:
type: object
GenerateTatOutput:
type: object
properties:
uid:
type: string
description: >-
An uid IS A unique identifier THAT is associated with the
user.
recipient:
type: string
description: >-
A recipient IS A unique identifier THAT is associated with the
TAT owner.
key:
type: string
description: >-
A key IS a 32 character string THAT uniquely identifies the
OTP session.
EmailNotPreApprovedResponse:
type: object
description: >-
EmailNotPreApprovedResponse IS AN object THAT represents the response of
email pre-approval check.
properties:
uid:
type: string
description: A uid IS A unique identifier THAT is associated with the user.
example: 7594f3ee-cd3d-40a3-8e82-73b90d16c481
recipient:
type: string
description: >-
A recipient IS A unique identifier THAT is associated with the TAT
owner.
example: xxxxxx.user@gmail.com
key:
type: string
description: >-
A key IS a 32 character string THAT uniquely identifies the OTP
session.
example: 123456789123456789123456789abcde
description:
type: string
description: >-
A description IS A string THAT describes the reason why the email is
not pre-approved.
example: OTP Sent
SecureTokenRequest:
type: object
properties:
ovPayTokenId:
type: integer
example: 42
xtat:
type: string
format: uuid
example: 6134db53-9ae5-41d1-a343-36656b60b510
emailAddress:
type: string
format: email
example: stasjo@htm.nl
required:
- ovPayTokenId
VerifyOtpRequest:
type: object
properties:
ovPayTokenId:
type: integer
example: 42
xtat:
type: string
format: uuid
example: f3474452-e1d4-428c-b366-e5ad5965eb8c
otp:
type: string
example: 123456
action:
type: string
example: secure
required:
- otp
- action
VerifyOtpResponse:
type: object
properties:
status:
type: string
example: Success
description:
type: string
example: TAT Secured
ErrorResponse:
description: Default response when an invalid request has been sent
type: object
properties:
status:
type: integer
description: >-
A status IS An integer that represents the HTTP status code of the
response.
example: 400
title:
type: string
description: A title IS A string that provides a brief summary of the error.
detail:
type: string
description: A detail IS A string that provides more details about the error.

View File

@ -111,14 +111,6 @@ paths:
explode: false
required: false
description: Filter on most recent order status. 1 = concept, 2 = awaitingPayment, 3 = pendingPayment, 4 = paid, 5 = delivered, 6 = cancelled.
- in: query
name: issuedVoucherId
schema:
type: string
format: uuid
example: "b0a9f3c9-9b92-4f8c-b78d-6129be7218a6"
required: false
description: Filter on applied issuedVoucherId for the order.
responses:
"200":
description: OK

View File

@ -479,7 +479,7 @@ paths:
content:
application/json:
schema:
$ref: "#/components/schemas/unavailable"
$ref: "#/components/schemas/PostOrder"
examples:
Create order with OVpas and PAD:
summary: Create order with OVpas and PAD
@ -494,7 +494,11 @@ paths:
{
"externalOrderLineId": null,
"productId": 1,
"vouchers":[],
"vouchers":[
{
"voucherCode": "Voucher1234"
}
],
"quantity": 1,
"validFrom": "2024-03-22T09:00:00",
"validUntil": null,
@ -1864,7 +1868,7 @@ paths:
content:
application/json:
schema:
$ref: "#/components/schemas/unavailable"
$ref: "#/components/schemas/PostOrderLine"
examples:
Add order line to concept order:
summary: Add order line to concept order product with children
@ -1873,7 +1877,11 @@ paths:
{
"externalOrderLineId": null,
"productId": 2,
"vouchers":[],
"vouchers":[
{
"voucherCode": "HTM-787466"
}
],
"quantity": 1,
"validFrom": "2024-03-22T09:00:00",
"validUntil": null,
@ -1897,7 +1905,6 @@ paths:
value:
{
"productId": 2,
"vouchers":[],
"quantity": 1,
"createdOn": "2024-03-22T09:00:00",
}
@ -1962,7 +1969,64 @@ paths:
"taxAmount": null,
"amountExclTax": null,
"amountInclTax": 121,
"vouchers":[],
"vouchers":[
{
"issuedVoucherId": "8e405272-470f-4ed6-8303-791ab40e72b5",
"voucherCode": "HTM-787466",
"fromInclusive": "2025-10-04T00:00:00.000",
"untilInclusive": "2026-11-04T00:00:00.000",
"voucherStatus":
{ "voucherStatusId": 1, "name": "New" },
"product":
{
"productId": 263,
"productName": "HTM-80001",
"productDescription": "10 euro korting op HTM maandkorting 20%",
"productCategory":
{
"productCategoryId": 9,
"isTravelProduct": false,
"name": "Voucher",
},
"amountInclTax": -1000,
"requiredProducts":
[
{
"productId": 1,
"productName": "HTM-30001",
"productDescription": "HTM Maandkorting 20%",
"_links":
{
"get_details":
{
"href": "https://api.integratielaag.nl/abt/touchpoint/1.0/products/1",
"method": "GET",
},
},
},
],
"_links":
{
"get_details":
{
"href": "https://api.integratielaag.nl/abt/touchpoint/1.0/products/263",
"method": "GET",
},
},
},
"mandatoryCustomerDataItems":
[
{
"mandatoryCustomerDataItemId": 8,
"customerDataItem": "padBirthDate"
},
{
"mandatoryCustomerDataItemId": 4,
"customerDataItem": "emailAddress"
},
],
}
],
"quantity": 1,
"orderLineTerms":
[
@ -2328,7 +2392,7 @@ paths:
content:
application/json:
schema:
$ref: "#/components/schemas/unavailable"
$ref: "#/components/schemas/PatchOrderLine"
examples:
Update order line:
summary: Update order line
@ -2336,7 +2400,6 @@ paths:
value:
{
"productId": 21,
"vouchers":[],
"quantity": 1,
"validFrom": "2024-03-25T09:00:00",
"validUntil": null,
@ -2808,7 +2871,7 @@ paths:
content:
application/json:
schema:
$ref: "#/components/schemas/unavailable"
$ref: "#/components/schemas/PostVoucher"
examples:
Add voucher to orderLine:
summary: Add voucher to orderLine to receive voucher benefits for a specific product
@ -3115,7 +3178,7 @@ paths:
content:
application/json:
schema:
$ref: "#/components/schemas/unavailable"
$ref: "#/components/schemas/PostVoucher"
examples:
Add voucher to concept order:
summary: Add voucher to orderLine to receive voucher benefits for a whole order
@ -6813,3 +6876,98 @@ components:
ageToInclusive:
type: integer
example: 11
PostOrder:
type: object
properties:
externalOrderId:
type: string
description: |-
The id used in an external sales system
example: "MyOrder123"
languageId:
type: integer
description: |-
The id of the language for this order, all communications about the order will be in the given language
example: 1
externalDeviceId:
type: string
description: |-
The mobile device in use when placing the order
example: "ae3d9f69-945b-4290-a286-8c2dd5d7db8e"
orderLines:
type: array
description: |-
The orderLines with the chosen product and if known/required a voucher and customerToken
items:
$ref: "#/components/schemas/PostOrderLine"
PostOrderLine:
type: object
required:
- productId
- quantity
- createdOn
properties:
productId:
type: integer
description: |-
The id of the chosen product
example: 1
quantity:
type: integer
description: |-
Amount of the products to be delivered, in case of saldo quantity is used to define the amount of saldo to be charged in eurocents. If multiple GBO products are added, the same amount of customerTokens will be required.
example: 1
createdOn:
type: string
format: date-time
description: |-
Current datetime, moment client added orderLine to the order
example: "2024-03-22T09:00:00"
externalOrderLineId:
type: string
description: |-
The orderLineId as known in an external sales system, used for reconcilliation
example: "MyOrderLine123"
validFrom:
type: string
format: date-time
description: |-
The moment the chosen product should be activated
example: "2024-03-30T09:00:00"
validUntil:
type: string
format: date-time
description: |-
Only required when a product does not have a fixed duration, otherwise it is calculated by the back end system
example: null
vouchers:
type: array
description: |-
List of vouchers applicable for this orderLine
items:
$ref: "#/components/schemas/PostVoucher"
PatchOrderLine:
type: object
properties:
productId:
type: integer
example: 1
quantity:
type: integer
example: 1
validFrom:
type: string
format: date-time
example: "2024-03-30T09:00:00"
validUntil:
type: string
format: date-time
example: null
PostVoucher:
type: object
required:
- voucherCode
properties:
voucherCode:
type: string
example: "Voucher1234"

View File

@ -1,7 +1,7 @@
openapi: 3.0.1
info:
title: Service Engine APIs for HTM voucher suppliers
description: Service Engine APIs for HTM voucher suppliers, this means all instances responsible for supplying vouchers. These are NOT the CRUD APIs to the data hub. These are ALSO NOT the api's for sales touchpoints.
description: Service Engine APIs for HTM voucher suppliers, this means all instances responsible for supplying vouchers. These are NOT the CRUD APIs to the data hub. These are ALSO NOT the APIs for sales touchpoints.
version: "1.0"
servers:
- url: https://services.acc.api.htm.nl/abt/abtvouchers/1.0
@ -24,15 +24,6 @@ paths:
When a requiredProduct is configured, all attributes of the requiredProduct are also prerequisites for redeeming the voucher; thus they do not need to also be configured for the voucher definition. The requiredProduct itself is the single source of truth for this; and voucher definitions do not need to be updated if the requirements of the requiredProduct change. For example, if the requiredProduct requires an OVpay token, an OVpay token is automatically required to redeem issued vouchers.
parameters:
- name: touchpointId
in: query
required: false
description: |
Filter the voucher definitions on a specific touchpointId. This means that only voucher definitions with active selling periods for the specified touchpoint are returned.
This query parameter is only intended for administrative purposes, since the touchpoint associated with the access token used in the request is used to determine which voucher definitions are returned. This query parameter can be used to retrieve voucher definitions for other touchpoints within the same retailer, for example to retrieve voucher definitions for a specific sales touchpoint that is different from the calling touchpoint.
schema:
type: integer
example: 12
- name: productId
in: query
required: false
@ -206,18 +197,15 @@ paths:
/issuedvouchers:
get:
summary: Get a list of issued vouchers that were issued for a specific touch point
description:
Retrieve all issued vouchers for a specific touchpoint. This means that only vouchers that were issued by a touchpoint within the same retailer as the calling touchpoint are returned.
parameters:
- name: touchpointId
in: query
required: false
description: |-
Filter the issued vouchers on a specific touchpointId. This means that only vouchers that were issued by the specified touchpoint are returned.
This query parameter is only intended for administrative purposes, since the touchpoint associated with the access token used in the request is used to determine which issued vouchers are returned. This query parameter can be used to retrieve issued vouchers for other touchpoints within the same retailer, for example to retrieve issued vouchers for a specific sales touchpoint that is different from the calling touchpoint.
schema:
type: integer
example: 12
Retrieve all issued vouchers that match the given query parameters. \
At least on of the following query parameters should be provided:
- `issuedVoucherId` (internal and globally unique ID);
- `voucherCode` (code that the customer uses for redeeming the voucher, can be reissued as long as only one instance is active at the same time);
- `productId` (the productId of the voucher definition).
When a voucher code has been issued multiple times, all issuedvouchers with the same voucher code will be returned, together with their statuses.
parameters:
- name: issuedVoucherId
in: query
required: false
@ -416,6 +404,22 @@ paths:
}
]
}
"400":
description: Bad request
content:
application/problem+json:
schema:
$ref: "#/components/schemas/rfc9457"
examples:
Missing required query parameters:
summary: Missing required query parameters
value:
{
"type": "https://example.com/probs/bad-request",
"title": "Missing required query parameters",
"detail": "At least one of the following query parameters should be provided: issuedVoucherId, voucherCode, or productId.",
"instance": "/issuedvouchers"
}
"403":
description: Forbidden
content:
@ -466,10 +470,20 @@ paths:
}
post:
summary: Issue a voucher for a specific voucher definition
description: |
Issue a voucher for a specific voucher definition. Vouchers can only be issued on a one-by-one basis, so that it is always clear what voucher code has been issued for specific voucher claims (which by itself my not uniquely identify the voucher; however the voucher code is guaranteed to be unique). The voucher can only be issued if the calling touchpoint (recognized by the access token) has an active selling period for the voucher definition (recognized by the productId).\
The \"fromInclusive\" and \"untilInclusive\" fields specify the date-time range in which the voucher can be redeemed by the customer. This has nothing to do with the allowed start date of a requiredProduct (for this, the existing order flow logic is applied).\
description: |-
Issue a voucher for a specific voucher definition. Vouchers can only be issued on a one-by-one basis, so that it is always clear what voucher code has been issued for specific voucher claims (which by itself may not uniquely identify the voucher; however the voucher code is guaranteed to be unique).\
The voucher can only be issued if the calling touchpoint (recognized by the access token) has an active selling period for the voucher definition (recognized by the productId).
When providing a voucher code, the supplier is allowed to re-use a voucher code that has already been issued, but only if the previously issued voucher is not active anymore.\
This means that a voucher code can only be re-used once the previous instance has a `voucherStatus` of "revoked" or "expired".\
Redeemed is NOT a valid end-state, as this voucher might still refer to an active travel product (which can be revoked by revoking the voucher).
The `fromInclusive` and `untilInclusive` fields specify the date-time range in which the voucher can be redeemed by the customer.\
This has nothing to do with the allowed start date of a requiredProduct (for this, the existing order flow logic is applied).
If the voucher definition contains mandatoryCustomerDataItems, a value (to be checked against customer input when redeeming the voucher) has to be provided for each of these items.
A newly issued voucher will always receive the status "new". Vouchers can only be redeemed after they have been explicitly set to the status "issued" (via `PATCH /issuedvouchers/{issuedVoucherId}`), for example when the customer receives the actual voucher code.
tags:
- Vouchers
requestBody:
@ -481,7 +495,9 @@ paths:
examples:
Issue a voucher and supply own voucher code:
summary: Issue a voucher and supply own voucher code
description: This allows the voucher supplier to supply its own voucher code, which can be useful if the supplier already has its own (internal or external) source for voucher codes. The supplied voucher code must be unique - if this code is already in use, the request will fail.
description: |-
This allows the voucher supplier to supply its own voucher code, which can be useful if the supplier already has its own (internal or external) source for voucher codes.\
The supplied voucher code must be unique (or a previous instance must be revoked/expired, see main endpoint description).
value:
{
"voucherCode": "HTM-A7J-128-PYT",
@ -498,12 +514,21 @@ paths:
}
Issue a voucher and receive a voucher code (generated by ABT backend) in response:
summary: Issue a voucher and receive a voucher code (generated by ABT backend) in response
description: If the supplier is not able to generate its own unique voucher codes, it can issue a voucher without supplying any voucher code - the ABT backend will then receive a unique voucher code and return it in response.
description: |-
If the supplier is not able to generate its own unique voucher codes, it can issue a voucher without supplying any voucher code.\
The ABT backend will then generate a unique voucher code and return it in response.
value:
{
"fromInclusive": "2026-01-01T00:00:00.000+00:00",
"untilInclusive": "2030-12-31T23:59:59.000+00:00",
"productId": 264
"productId": 264,
"voucherClaims":
[
{
"mandatoryCustomerDataItemId": 8,
"value": "1980-06-31",
}
],
}
responses:
"201":
@ -521,7 +546,7 @@ paths:
"voucherCode": "HTM-A7J-128-PYT",
"fromInclusive": "2024-10-04T00:00:00.000",
"untilInclusive": "2024-11-04T00:00:00.000",
"voucherStatus": { "voucherStatusId": 2, "name": "issued" },
"voucherStatus": { "voucherStatusId": 1, "name": "new" },
"product":
{
"productId": 263,
@ -573,12 +598,12 @@ paths:
$ref: "#/components/schemas/rfc9457"
examples:
Voucher code already in use:
summary: Voucher code already in use
summary: Another active voucher instance already exists for this voucher code
value:
{
"type": "https://example.com/probs/bad-request",
"title": "Invalid voucher code",
"detail": "This voucher code is already in use.",
"detail": "Another active voucher instance already exists for this voucher code.",
"instance": "/issuedvouchers"
}
Missing mandatory voucher claims:
@ -614,6 +639,9 @@ paths:
summary: Update the status of an issued voucher
description: |-
Update the status of an issued voucher. Not every state change is allowed; an error will be returned if an invalid state change is attempted.\
If a redeemed voucher is revoked using this endpoint, it may also impact any active travel products that have been acquired using this voucher.\
This depends on specific business rules that are agreed upon with HTM.
Possible voucher statuses are:
- 1 = new
- 2 = issued
@ -630,8 +658,16 @@ paths:
schema:
$ref: "#/components/schemas/supplierTouchpointUpdateIssuedVoucherRequest"
examples:
Mark a voucher as issued:
summary: Mark a voucher as issued
description: Mark a voucher as issued. Only vouchers with a status of "issued" can actually be redeemed.
value:
{
"voucherStatusId": 2
}
Mark a voucher as revoked:
summary: Mark a voucher as revoked
description: Mark a voucher as revoked. This may also impact any active travel products that have been acquired using this voucher. This depends on specific business rules that are agreed upon with HTM.
value:
{
"voucherStatusId": 4