feature/OVPAY-2485 #63

Merged
MirjamHTM merged 9 commits from feature/OVPAY-2485 into develop 2026-06-22 14:45:48 +00:00
2 changed files with 486 additions and 87 deletions

View File

@ -380,7 +380,7 @@ paths:
type: string type: string
example: Customer example: Customer
required: false required: false
description: The role of the HTM employee in the case of the SMP description: The role of the HTM employee in the case of the SMP
requestBody: requestBody:
content: content:
application/json: application/json:
@ -415,7 +415,7 @@ paths:
type: string type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER - name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header in: header
schema: schema:
@ -429,7 +429,7 @@ paths:
type: string type: string
example: Customer example: Customer
required: false required: false
description: The role of the HTM employee in the case of the SMP description: The role of the HTM employee in the case of the SMP
requestBody: requestBody:
content: content:
application/json: application/json:
@ -464,7 +464,7 @@ paths:
type: string type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER - name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header in: header
schema: schema:
@ -478,7 +478,7 @@ paths:
type: string type: string
example: Customer example: Customer
required: false required: false
description: The role of the HTM employee in the case of the SMP description: The role of the HTM employee in the case of the SMP
- name: customerPreferenceId - name: customerPreferenceId
in: path in: path
required: true required: true
@ -519,7 +519,7 @@ paths:
type: string type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER - name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header in: header
schema: schema:
@ -533,8 +533,8 @@ paths:
type: string type: string
example: Customer example: Customer
required: false required: false
description: The role of the HTM employee in the case of the SMP description: The role of the HTM employee in the case of the SMP
requestBody: requestBody:
content: content:
application/json: application/json:
@ -575,7 +575,7 @@ paths:
type: string type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER - name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header in: header
schema: schema:
@ -589,7 +589,7 @@ paths:
type: string type: string
example: Customer example: Customer
required: false required: false
description: The role of the HTM employee in the case of the SMP description: The role of the HTM employee in the case of the SMP
- name: addressId - name: addressId
in: path in: path
required: true required: true
@ -634,7 +634,7 @@ paths:
type: string type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER - name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header in: header
schema: schema:
@ -648,7 +648,7 @@ paths:
type: string type: string
example: Customer example: Customer
required: false required: false
description: The role of the HTM employee in the case of the SMP description: The role of the HTM employee in the case of the SMP
- name: addressId - name: addressId
in: path in: path
required: true required: true
@ -669,14 +669,14 @@ paths:
summary: Add a customer phone summary: Add a customer phone
description: >- description: >-
parameters: parameters:
- name: X-HTM-JWT-AUTH-HEADER - name: X-HTM-JWT-AUTH-HEADER
in: header in: header
schema: schema:
type: string type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER - name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header in: header
schema: schema:
@ -690,7 +690,7 @@ paths:
type: string type: string
example: Customer example: Customer
required: false required: false
description: The role of the HTM employee in the case of the SMP description: The role of the HTM employee in the case of the SMP
requestBody: requestBody:
content: content:
application/json: application/json:
@ -728,7 +728,7 @@ paths:
type: string type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER - name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header in: header
schema: schema:
@ -742,7 +742,7 @@ paths:
type: string type: string
example: Customer example: Customer
required: false required: false
description: The role of the HTM employee in the case of the SMP description: The role of the HTM employee in the case of the SMP
- name: phoneId - name: phoneId
in: path in: path
required: true required: true
@ -754,7 +754,7 @@ paths:
application/json: application/json:
schema: schema:
$ref: "#/components/schemas/phoneEntity" $ref: "#/components/schemas/phoneEntity"
examples: examples:
updateFullPhoneEntity: updateFullPhoneEntity:
value: value:
phone: phone:
@ -789,7 +789,7 @@ paths:
type: string type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER - name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header in: header
schema: schema:
@ -803,7 +803,7 @@ paths:
type: string type: string
example: Customer example: Customer
required: false required: false
description: The role of the HTM employee in the case of the SMP description: The role of the HTM employee in the case of the SMP
- name: phoneId - name: phoneId
in: path in: path
required: true required: true
@ -816,7 +816,7 @@ paths:
content: content:
application/json: {} application/json: {}
x-auth-type: Application & Application User x-auth-type: Application & Application User
x-throttling-tier: Unlimited x-throttling-tier: Unlimited
/customers/billinginformations: /customers/billinginformations:
get: get:
tags: tags:
@ -831,7 +831,7 @@ paths:
type: string type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER - name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header in: header
schema: schema:
@ -845,7 +845,7 @@ paths:
type: string type: string
example: Customer example: Customer
required: false required: false
description: The role of the HTM employee in the case of the SMP description: The role of the HTM employee in the case of the SMP
responses: responses:
200: 200:
description: OK description: OK
@ -866,7 +866,7 @@ paths:
"billingInformationId": 1, "billingInformationId": 1,
"iban": "NL••••••••••••1234", "iban": "NL••••••••••••1234",
"ascription": "J. Doe", "ascription": "J. Doe",
"alias": null, "alias": null,
"created": "2024-10-20T17:05:52.000", "created": "2024-10-20T17:05:52.000",
}, },
], ],
@ -875,7 +875,7 @@ paths:
get: get:
tags: tags:
- Customers - Customers
summary: Find direct debit mandates for a customer. summary: Find direct debit mandates for a customer.
description: Find direct debit mandates for a customer. description: Find direct debit mandates for a customer.
parameters: parameters:
- name: X-HTM-JWT-AUTH-HEADER - name: X-HTM-JWT-AUTH-HEADER
@ -884,7 +884,7 @@ paths:
type: string type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER - name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header in: header
schema: schema:
@ -898,7 +898,7 @@ paths:
type: string type: string
example: Customer example: Customer
required: false required: false
description: The role of the HTM employee in the case of the SMP description: The role of the HTM employee in the case of the SMP
responses: responses:
200: 200:
description: OK description: OK
@ -914,12 +914,12 @@ paths:
[ [
{ {
"directDebitMandateId": 71, "directDebitMandateId": 71,
"billingInformationId": "billingInformationId":
{ {
"billingInformationId": 15, "billingInformationId": 15,
"iban": "NL••••••••••••1234", "iban": "NL••••••••••••1234",
"ascription": "J. Doe", "ascription": "J. Doe",
"alias": null, "alias": null,
"created": "2024-10-20T17:05:52.000", "created": "2024-10-20T17:05:52.000",
}, },
"directDebitMandateType": "directDebitMandateType":
@ -1081,6 +1081,10 @@ paths:
"photo": null, "photo": null,
}, },
"gboAgeProfile": null, "gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links": "_links":
{ {
"self": "self":
@ -1130,9 +1134,9 @@ paths:
}, },
}, },
} }
OV pas without PAD: OV pas without PAD, without AGO:
summary: OV pas without PAD summary: OV pas without PAD, without AGO
description: OV pas without PAD description: OV pas without PAD, without AGO
value: value:
{ {
"ovPayTokens": "ovPayTokens":
@ -1142,7 +1146,7 @@ paths:
"ovPayTokenId": 1, "ovPayTokenId": 1,
"xTat": "32089cc8-d187-47ff-a3a9-5c2558def811", "xTat": "32089cc8-d187-47ff-a3a9-5c2558def811",
"tokenType": "tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" }, { "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV34567", "ovpasNumber": "OV34567",
"alias": "MyToken", "alias": "MyToken",
"tokenStatus": "tokenStatus":
@ -1164,6 +1168,10 @@ paths:
"photo": null, "photo": null,
}, },
"gboAgeProfile": null, "gboAgeProfile": null,
"tatSecurity": {
"isSecured": false,
"isAuthorized": null,
},
"_links": "_links":
{ {
"self": "self":
@ -1213,9 +1221,9 @@ paths:
}, },
}, },
} }
OV pas with PAD and autoReload: OV pas with PAD, with autoReload, with AGO:
summary: OV pas with PAD and autoReload summary: OV pas with PAD, with autoReload, with AGO
description: OV pas with PAD and autoReload description: OV pas with PAD, with autoReload, with AGO
value: value:
{ {
"ovPayTokens": "ovPayTokens":
@ -1225,7 +1233,7 @@ paths:
"ovPayTokenId": 1, "ovPayTokenId": 1,
"xTat": "32089cc8-d187-47ff-a3a9-5c2558def811", "xTat": "32089cc8-d187-47ff-a3a9-5c2558def811",
"tokenType": "tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" }, { "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV34567", "ovpasNumber": "OV34567",
"alias": "MyToken", "alias": "MyToken",
"tokenStatus": "tokenStatus":
@ -1287,6 +1295,10 @@ paths:
"ageFromInclusive": 4, "ageFromInclusive": 4,
"ageToInclusive": 11, "ageToInclusive": 11,
}, },
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links": "_links":
{ {
"self": "self":
@ -1348,8 +1360,8 @@ paths:
"ovPayTokenId": 1, "ovPayTokenId": 1,
"xTat": "32089cc8-d187-47ff-a3a9-5c2558def811", "xTat": "32089cc8-d187-47ff-a3a9-5c2558def811",
"tokenType": "tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" }, { "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV34567", "ovpasNumber": "OV34567",
"alias": "MyToken", "alias": "MyToken",
"tokenStatus": "tokenStatus":
{ "tokenStatusId": 2, "name": "Active" }, { "tokenStatusId": 2, "name": "Active" },
@ -1385,6 +1397,10 @@ paths:
"ageFromInclusive": 4, "ageFromInclusive": 4,
"ageToInclusive": 11, "ageToInclusive": 11,
}, },
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links": "_links":
{ {
"self": "self":
@ -1446,7 +1462,7 @@ paths:
"ovPayTokenId": 1, "ovPayTokenId": 1,
"xTat": "32089cc8-d187-47ff-a3a9-5c2558def811", "xTat": "32089cc8-d187-47ff-a3a9-5c2558def811",
"tokenType": "tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" }, { "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV34567", "ovpasNumber": "OV34567",
"alias": "MyToken", "alias": "MyToken",
"tokenStatus": "tokenStatus":
@ -1501,6 +1517,10 @@ paths:
"ageFromInclusive": 4, "ageFromInclusive": 4,
"ageToInclusive": 11, "ageToInclusive": 11,
}, },
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links": "_links":
{ {
"self": "self":
@ -1562,7 +1582,7 @@ paths:
"ovPayTokenId": 1, "ovPayTokenId": 1,
"xTat": "e7fa3392-646b-40e2-95a6-c417dc0b0969", "xTat": "e7fa3392-646b-40e2-95a6-c417dc0b0969",
"tokenType": "tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" }, { "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV34567", "ovpasNumber": "OV34567",
"alias": "MyToken", "alias": "MyToken",
"tokenStatus": "tokenStatus":
@ -1583,7 +1603,7 @@ paths:
"ovPayTokenId": 6, "ovPayTokenId": 6,
"xTat": "e7fa3392-646b-40e2-95a6-c417dc0b0969", "xTat": "e7fa3392-646b-40e2-95a6-c417dc0b0969",
"tokenType": "tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" }, { "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV54567", "ovpasNumber": "OV54567",
"alias": "MyToken", "alias": "MyToken",
"tokenStatus": "tokenStatus":
@ -1599,13 +1619,17 @@ paths:
"photo": null, "photo": null,
}, },
"gboAgeProfile": null, "gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
}, },
{ {
"customerProfileId": 18, "customerProfileId": 18,
"ovPayTokenId": 13, "ovPayTokenId": 13,
"xTat": "e7fa3392-646b-40e2-95a6-c417dc0b0969", "xTat": "e7fa3392-646b-40e2-95a6-c417dc0b0969",
"tokenType": "tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" }, { "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV34547", "ovpasNumber": "OV34547",
"alias": "MyToken", "alias": "MyToken",
"tokenStatus": "tokenStatus":
@ -1621,13 +1645,17 @@ paths:
"photo": null, "photo": null,
}, },
"gboAgeProfile": null, "gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
}, },
{ {
"customerProfileId": 132, "customerProfileId": 132,
"ovPayTokenId": 21, "ovPayTokenId": 21,
"xTat": "e7fa3392-646b-40e2-95a6-c417dc0b0969", "xTat": "e7fa3392-646b-40e2-95a6-c417dc0b0969",
"tokenType": "tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" }, { "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV34831", "ovpasNumber": "OV34831",
"alias": "Mijn OV Pas", "alias": "Mijn OV Pas",
"tokenStatus": "tokenStatus":
@ -1643,13 +1671,17 @@ paths:
"photo": null, "photo": null,
}, },
"gboAgeProfile": null, "gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
}, },
{ {
"customerProfileId": 166, "customerProfileId": 166,
"ovPayTokenId": 28, "ovPayTokenId": 28,
"xTat": "e7fa3392-646b-40e2-95a6-c417dc0b0969", "xTat": "e7fa3392-646b-40e2-95a6-c417dc0b0969",
"tokenType": "tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" }, { "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV34984", "ovpasNumber": "OV34984",
"alias": "Mijn OV Pas", "alias": "Mijn OV Pas",
"tokenStatus": "tokenStatus":
@ -1668,13 +1700,17 @@ paths:
"photo": null, "photo": null,
}, },
"gboAgeProfile": null, "gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
}, },
{ {
"customerProfileId": 166, "customerProfileId": 166,
"ovPayTokenId": 115, "ovPayTokenId": 115,
"xTat": "e7fa3392-646b-40e2-95a6-c417dc0b0969", "xTat": "e7fa3392-646b-40e2-95a6-c417dc0b0969",
"tokenType": "tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" }, { "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV54368", "ovpasNumber": "OV54368",
"alias": "My retired token", "alias": "My retired token",
"tokenStatus": "tokenStatus":
@ -1690,13 +1726,17 @@ paths:
"photo": null, "photo": null,
}, },
"gboAgeProfile": null, "gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
}, },
{ {
"customerProfileId": 1, "customerProfileId": 1,
"ovPayTokenId": 118, "ovPayTokenId": 118,
"xTat": "e7fa3392-646b-40e2-95a6-c417dc0b0969", "xTat": "e7fa3392-646b-40e2-95a6-c417dc0b0969",
"tokenType": "tokenType":
{ "tokenTypeId": 2, "name": "OV-pas physical" }, { "tokenTypeId": 2, "name": "OV-pas physical" },
"ovpasNumber": "OV98263", "ovpasNumber": "OV98263",
"alias": "My found token", "alias": "My found token",
"tokenStatus": "tokenStatus":
@ -1712,6 +1752,10 @@ paths:
"photo": null, "photo": null,
}, },
"gboAgeProfile": null, "gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
}, },
], ],
_links: _links:
@ -1812,6 +1856,10 @@ paths:
"personalAccountData": "personalAccountData":
{ "name": null, "birthdate": null, "photo": null }, { "name": null, "birthdate": null, "photo": null },
"gboAgeProfile": null, "gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links": "_links":
{ {
"self": "self":
@ -1890,6 +1938,10 @@ paths:
"personalAccountData": "personalAccountData":
{ "name": null, "birthdate": null, "photo": null }, { "name": null, "birthdate": null, "photo": null },
"gboAgeProfile": null, "gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links": "_links":
{ {
"self": "self":
@ -2086,6 +2138,10 @@ paths:
"personalAccountData": "personalAccountData":
{ "name": null, "birthdate": null, "photo": null }, { "name": null, "birthdate": null, "photo": null },
"gboAgeProfile": null, "gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links": "_links":
{ {
"self": "self":
@ -2149,6 +2205,10 @@ paths:
"personalAccountData": "personalAccountData":
{ "name": null, "birthdate": null, "photo": null }, { "name": null, "birthdate": null, "photo": null },
"gboAgeProfile": null, "gboAgeProfile": null,
"tatSecurity": {
"isSecured": true,
"isAuthorized": true,
},
"_links": "_links":
{ {
"self": "self":
@ -2905,9 +2965,9 @@ paths:
summary: "**INTEGRATIELAAG** Transfer old OVpay token to new OVpay token." summary: "**INTEGRATIELAAG** Transfer old OVpay token to new OVpay token."
description: |- description: |-
**Note that this directly calls the integratielaag and not the Service Engine!** **Note that this directly calls the integratielaag and not the Service Engine!**
First transfers all personal account data (if present), then all products, of an existing OVpay token First transfers all personal account data (if present), then all products, of an existing OVpay token
to a new OVpay token. The new token will also be persisted in the profile as a replacement to a new OVpay token. The new token will also be persisted in the profile as a replacement
of the old token. This call is asynchronous, and progress can be monitored using the of the old token. This call is asynchronous, and progress can be monitored using the
`/customers/tokens/transfer/responsestatus/*` endpoint. `/customers/tokens/transfer/responsestatus/*` endpoint.
tags: tags:
- Token Replace v2 - Token Replace v2
@ -2920,9 +2980,9 @@ paths:
Transfer from a token without PAD to a new token: Transfer from a token without PAD to a new token:
summary: Transfer from a token without PAD to a new token summary: Transfer from a token without PAD to a new token
description: | description: |
Transfer of a token without PAD to a new OVpay token. Note the new token in the request is always Transfer of a token without PAD to a new OVpay token. Note the new token in the request is always
identified by xTAT, regardless if the new token already exists in the customer profile. If the new identified by xTAT, regardless if the new token already exists in the customer profile. If the new
token does not exist in the customer profile, the user needs to provide an alias for the new token, token does not exist in the customer profile, the user needs to provide an alias for the new token,
and it will be created in the customer profile. and it will be created in the customer profile.
value: value:
{ {
@ -2936,11 +2996,11 @@ paths:
Transfer from a token with PAD to a new token without existing PAD: Transfer from a token with PAD to a new token without existing PAD:
summary: Transfer from a token with PAD to a new token without existing PAD summary: Transfer from a token with PAD to a new token without existing PAD
description: | description: |
Transfer of a token with PAD to a new token by xTAT without existing PAD. Note how this request is Transfer of a token with PAD to a new token by xTAT without existing PAD. Note how this request is
different, since it has an e-mail address on which the new PAD should be created. This request may different, since it has an e-mail address on which the new PAD should be created. This request may
optionally provide an OTP for verification of th provided email address. optionally provide an OTP for verification of th provided email address.
Also note the new token in the request is always identified by xTAT, regardless if the new token Also note the new token in the request is always identified by xTAT, regardless if the new token
already exists in the customer profile. If the new token does not exist in the customer profile, the already exists in the customer profile. If the new token does not exist in the customer profile, the
user needs to provide an alias for the new token, and it will be created in the customer profile. user needs to provide an alias for the new token, and it will be created in the customer profile.
value: value:
{ {
@ -2957,8 +3017,8 @@ paths:
summary: Transfer from a token with PAD to a new token with existing PAD summary: Transfer from a token with PAD to a new token with existing PAD
description: | description: |
Transfer of a token with PAD to a new token by xTAT with existing PAD. Transfer of a token with PAD to a new token by xTAT with existing PAD.
Note that the new token in the request is always identified by xTAT, regardless if the new token Note that the new token in the request is always identified by xTAT, regardless if the new token
already exists in the customer profile. If the new token does not exist in the customer profile, the already exists in the customer profile. If the new token does not exist in the customer profile, the
user needs to provide an alias for the new token, and it will be created in the customer profile. user needs to provide an alias for the new token, and it will be created in the customer profile.
value: value:
{ {
@ -2996,7 +3056,7 @@ paths:
Transfer of token started: Transfer of token started:
description: | description: |
The transfer of the token was started successfully. The data of the token will be transferred The transfer of the token was started successfully. The data of the token will be transferred
asynchronously. In the response body the consumer will find information on how to retrieve the asynchronously. In the response body the consumer will find information on how to retrieve the
processing status. processing status.
value: value:
{ {
@ -3038,7 +3098,7 @@ paths:
- Token Replace v2 - Token Replace v2
summary: "**INTEGRATIELAAG** Get the status of the initiated token transfer process." summary: "**INTEGRATIELAAG** Get the status of the initiated token transfer process."
description: | description: |
**Note that this directly calls the integratielaag and not the Service Engine!** Get the status of the **Note that this directly calls the integratielaag and not the Service Engine!** Get the status of the
asynchronous token transfer processing. asynchronous token transfer processing.
responses: responses:
"200": "200":
@ -3166,7 +3226,7 @@ paths:
examples: examples:
Token transfer in progress: Token transfer in progress:
description: | description: |
The transfer of the token is still in progress. The response body shows the details of the The transfer of the token is still in progress. The response body shows the details of the
processing status. processing status.
value: value:
{ {
@ -3347,7 +3407,7 @@ paths:
in: query in: query
description: External id of the device you want to get the purchased HTM products for. description: External id of the device you want to get the purchased HTM products for.
schema: schema:
type: string type: string
- name: ovpayTokenId - name: ovpayTokenId
in: query in: query
description: Id of the OVpay-token you want to get the purchased HTM products for. description: Id of the OVpay-token you want to get the purchased HTM products for.
@ -3380,9 +3440,9 @@ paths:
} }
getTwoBarcodePurchasedProductsForDevice: getTwoBarcodePurchasedProductsForDevice:
summary: Two BarcodeTicket purchased products, one PendingActivation and one Active summary: Two BarcodeTicket purchased products, one PendingActivation and one Active
description: |- description: |-
The first ticket (PendingActivation) shows the 30-day range in which the ticket can be activated The first ticket (PendingActivation) shows the 30-day range in which the ticket can be activated
(using the PATCH endpoint) in the validityStart and validityEnd fields. The second ticket (Active) (using the PATCH endpoint) in the validityStart and validityEnd fields. The second ticket (Active)
shows the actual validity period of the ticket after activation. shows the actual validity period of the ticket after activation.
value: value:
{ {
@ -3401,14 +3461,14 @@ paths:
"name": "Barcode", "name": "Barcode",
}, },
"orderId": "501B17EF-36C4-4039-B92C-6517969B464E", "orderId": "501B17EF-36C4-4039-B92C-6517969B464E",
"orderLineId": "38B17EF-36C4-4039-B92C-4817969B464E", "orderLineId": "38B17EF-36C4-4039-B92C-4817969B464E",
"ticketReference": "KJj43nejhbTxhrfef287", "ticketReference": "KJj43nejhbTxhrfef287",
"serviceId": "HTM-4321-7654-7659", "serviceId": "HTM-4321-7654-7659",
"issuedAt": "2026-03-21T09:01:35+01:00", "issuedAt": "2026-03-21T09:01:35+01:00",
"activatedAt": null, "activatedAt": null,
"blocked": false, "blocked": false,
"cancelledAt": null, "cancelledAt": null,
"activateBefore": "2026-03-30", "activateBefore": "2026-03-30",
"validityStart": null, "validityStart": null,
"validityEnd": null, "validityEnd": null,
"barcode": null, "barcode": null,
@ -3436,14 +3496,14 @@ paths:
"name": "Barcode", "name": "Barcode",
}, },
"orderId": "501B17EF-36C4-4039-B92C-6517969B464E", "orderId": "501B17EF-36C4-4039-B92C-6517969B464E",
"orderLineId": "38B17EF-36C4-4039-B92C-4817969B464E", "orderLineId": "38B17EF-36C4-4039-B92C-4817969B464E",
"ticketReference": "KJj43nejhbTxhr897287", "ticketReference": "KJj43nejhbTxhr897287",
"serviceId": "HTM-1234-7654-8945", "serviceId": "HTM-1234-7654-8945",
"issuedAt": "2026-03-21T10:01:12+01:00", "issuedAt": "2026-03-21T10:01:12+01:00",
"activatedAt": "2026-03-21T12:45:01+01:00", "activatedAt": "2026-03-21T12:45:01+01:00",
"blocked": false, "blocked": false,
"cancelledAt": null, "cancelledAt": null,
"activateBefore": null, "activateBefore": null,
"validityStart": "2026-03-21T12:45:01+01:00", "validityStart": "2026-03-21T12:45:01+01:00",
"validityEnd": "2026-03-21T14:45:01+01:00", "validityEnd": "2026-03-21T14:45:01+01:00",
"barcode": "iVBORw0KGgoAAAANSUhEUgAAAVwAAAFcAQAAAACsbTuBAAAFDElEQVR4Xu2bQa6rOhBEGzHwMEtgKewMyM5YCkvIkAGif50yyc/Tl770piZW9HSNywzqVlW3nXcjc83cusxnvsbMjBieuelf/bzGYz1jWCKmeGS+4g5grSwlz/IaI+JgEfzcvzQZo2yhxQgW7wDutLJrvVLzEInbVHLpM/tK5T7kHmNdbxssgqSipQj/0KLA24yqNvEWWRclpJKpefNgE7YZr/lj1eZ55wMYIWkUbZb7Xj/wH+BezvPkFJhQetmD+7AI2VuSEQMevANYESzqZh49VlEXIKOT7SDtseqnpz0Iyc2DJZezkEB5aaVKSvuF5FMwaIdB7wCGOgb5fFgus2wlKhPDpUiTlogr1tsHG7lfzcqYLlVnDHq6ylYn1OE54qd5cNC6aQxL0UQRy2YJJxCS8N4m273Gm4BJFAhzlytb5T4A0QrCYmUTrxd1bYNVgGqqPndH7vHwYqHLHf9cpO1pHJxU3Nq6vUbAVhXaocnTKO5cpK+4AViLitRwf8IQdYFwBkkKW7FzZxNh/AN/g5NHqXyed5MOz45kjkvKofpLYNwBrNBR/Dz9SKpTDkGd8CApZYonT24B7un56XKnoMeXkOBNHqTDk/NOmrrwyfIWYHe51O4kn4FBnfYbnHjqKuw3AGMreKOvC07DCAebHS5lAXWq5eKVA0HjYA2xM0MYCSMnqTqpx48ZVSmPTd15tT03AF+LVBuOgJoMqc2HL6Gy8nr1/K2DU+YpmKerd45fQ2ypzSFyq8coUM2D1yBksNWqOTWnjqvLpVYPvrt17f6BP+AaQk85zR4MarfHbAlSu/XhgGCJNg6mQNmASXnGhpZY+tKp93lywaY+SjcPhroCWx1BHFAnVemR81mdjEikWlllzYNrCM27bKVt7nInLplEnef6SfPFhb19MDmCbewcjtL/d7FwAzCqmShYzMd/qaPnp0AxV+SOpq5xMCnLZJOhZCNCZuIR4BWwL6un4luF5sE9N7CKXIJ2Zecncnt3vZ0it+hN7wNC6+DU/Ene1gj+lOOr4BDGilyT3D74NZ4OlYm2Xmx9t2rJN+kb7P3A/wUzV6lSQaonIoR3DUdy7vR1WQt782CrzrbbvTOdxwu2ZKy4MZXXflPzYJoVLg6GpbIVtLSb2JxduzEg+6Mm+R3AXECaHYRjG4nH2UIak7jSm9zXNQ9OLha2yhbUCT/vOA1VHUAGXpVuhpsHE7H7O0d6d2+i7rxeI2EVVMTm4wZg5vZUV2/nBUmoG5befZ0XERKkNg9O8zR9Rexls+WgldPRmTYHp90BrAIkqqYYnkmNGfvEY1E2Ijeu/3SQLKar1Q/8AX88eDqCRe3wZKJ89sVCRdaTZfvg/u8uFhoH14J0apHvil2rFwrUNtuDcXLOruNdvRoGB9ezgJXP2OrwN+mz8jl9lPab3Ob0NwDbVteFpEuX+7ylbHGdo5Oeny8y4vJgy2DniHhzQQp3c4yCkLwZvPbXk+INwKeqj6grVB/ha+dC88LVfec3zR/q2gYnlyO5GD+Kvfp03unruKCUygJb1e8HmwdbPp2pg8fgr3XYnE6YQGUWUp20Dz6hSgReznmXY3hLJ5A2ozJT9wN/gfVIEbzBsxvdYSneL571OV279S+/jubBiuCzAL5qt5xHPNHMcHgciSuD15rXbYMtJFbE1piEkEi0fPp6AoLX5Lvjt+paBvOIRQjSEEHaCX5BSP4DBSalHh4bB/8DVeIFt2RfPhQAAAAASUVORK5CYII=", "barcode": "iVBORw0KGgoAAAANSUhEUgAAAVwAAAFcAQAAAACsbTuBAAAFDElEQVR4Xu2bQa6rOhBEGzHwMEtgKewMyM5YCkvIkAGif50yyc/Tl770piZW9HSNywzqVlW3nXcjc83cusxnvsbMjBieuelf/bzGYz1jWCKmeGS+4g5grSwlz/IaI+JgEfzcvzQZo2yhxQgW7wDutLJrvVLzEInbVHLpM/tK5T7kHmNdbxssgqSipQj/0KLA24yqNvEWWRclpJKpefNgE7YZr/lj1eZ55wMYIWkUbZb7Xj/wH+BezvPkFJhQetmD+7AI2VuSEQMevANYESzqZh49VlEXIKOT7SDtseqnpz0Iyc2DJZezkEB5aaVKSvuF5FMwaIdB7wCGOgb5fFgus2wlKhPDpUiTlogr1tsHG7lfzcqYLlVnDHq6ylYn1OE54qd5cNC6aQxL0UQRy2YJJxCS8N4m273Gm4BJFAhzlytb5T4A0QrCYmUTrxd1bYNVgGqqPndH7vHwYqHLHf9cpO1pHJxU3Nq6vUbAVhXaocnTKO5cpK+4AViLitRwf8IQdYFwBkkKW7FzZxNh/AN/g5NHqXyed5MOz45kjkvKofpLYNwBrNBR/Dz9SKpTDkGd8CApZYonT24B7un56XKnoMeXkOBNHqTDk/NOmrrwyfIWYHe51O4kn4FBnfYbnHjqKuw3AGMreKOvC07DCAebHS5lAXWq5eKVA0HjYA2xM0MYCSMnqTqpx48ZVSmPTd15tT03AF+LVBuOgJoMqc2HL6Gy8nr1/K2DU+YpmKerd45fQ2ypzSFyq8coUM2D1yBksNWqOTWnjqvLpVYPvrt17f6BP+AaQk85zR4MarfHbAlSu/XhgGCJNg6mQNmASXnGhpZY+tKp93lywaY+SjcPhroCWx1BHFAnVemR81mdjEikWlllzYNrCM27bKVt7nInLplEnef6SfPFhb19MDmCbewcjtL/d7FwAzCqmShYzMd/qaPnp0AxV+SOpq5xMCnLZJOhZCNCZuIR4BWwL6un4luF5sE9N7CKXIJ2Zecncnt3vZ0it+hN7wNC6+DU/Ene1gj+lOOr4BDGilyT3D74NZ4OlYm2Xmx9t2rJN+kb7P3A/wUzV6lSQaonIoR3DUdy7vR1WQt782CrzrbbvTOdxwu2ZKy4MZXXflPzYJoVLg6GpbIVtLSb2JxduzEg+6Mm+R3AXECaHYRjG4nH2UIak7jSm9zXNQ9OLha2yhbUCT/vOA1VHUAGXpVuhpsHE7H7O0d6d2+i7rxeI2EVVMTm4wZg5vZUV2/nBUmoG5befZ0XERKkNg9O8zR9Rexls+WgldPRmTYHp90BrAIkqqYYnkmNGfvEY1E2Ijeu/3SQLKar1Q/8AX88eDqCRe3wZKJ89sVCRdaTZfvg/u8uFhoH14J0apHvil2rFwrUNtuDcXLOruNdvRoGB9ezgJXP2OrwN+mz8jl9lPab3Ob0NwDbVteFpEuX+7ylbHGdo5Oeny8y4vJgy2DniHhzQQp3c4yCkLwZvPbXk+INwKeqj6grVB/ha+dC88LVfec3zR/q2gYnlyO5GD+Kvfp03unruKCUygJb1e8HmwdbPp2pg8fgr3XYnE6YQGUWUp20Dz6hSgReznmXY3hLJ5A2ozJT9wN/gfVIEbzBsxvdYSneL571OV279S+/jubBiuCzAL5qt5xHPNHMcHgciSuD15rXbYMtJFbE1piEkEi0fPp6AoLX5Lvjt+paBvOIRQjSEEHaCX5BSP4DBSalHh4bB/8DVeIFt2RfPhQAAAAASUVORK5CYII=",
@ -3499,7 +3559,7 @@ paths:
"barcodeTickets":[], "barcodeTickets":[],
"vouchers":[] "vouchers":[]
} }
} }
getSingleVoucherPurchasedProductForCustomer: getSingleVoucherPurchasedProductForCustomer:
summary: One voucher purchased product summary: One voucher purchased product
value: value:
@ -3523,7 +3583,7 @@ paths:
"voucherStatus": { "voucherStatus": {
"voucherStatusId": 2, "voucherStatusId": 2,
"name": "issued" "name": "issued"
}, },
"mandatoryCustomerDataItems": "mandatoryCustomerDataItems":
[ [
{ {
@ -3538,7 +3598,7 @@ paths:
} }
] ]
} }
} }
/purchasedproducts/{purchasedProductId}: /purchasedproducts/{purchasedProductId}:
parameters: parameters:
- name: X-HTM-JWT-AUTH-HEADER - name: X-HTM-JWT-AUTH-HEADER
@ -3586,7 +3646,7 @@ paths:
value: value:
{ {
"status": "Active" "status": "Active"
} }
responses: responses:
"200": "200":
description: OK description: OK
@ -3636,7 +3696,6 @@ paths:
"vouchers": [] "vouchers": []
} }
} }
/customers/devices: /customers/devices:
post: post:
summary: Add a new device to a customer profile. summary: Add a new device to a customer profile.
@ -3813,7 +3872,7 @@ components:
customerProfileId: customerProfileId:
type: integer type: integer
example: 1 example: 1
customerPreference: customerPreference:
$ref: "#/components/schemas/getCustomerPreference" $ref: "#/components/schemas/getCustomerPreference"
customerNumber: customerNumber:
type: integer type: integer
@ -4014,12 +4073,12 @@ components:
customerPreferenceId: customerPreferenceId:
type: integer type: integer
languageId: languageId:
type: integer type: integer
customerStatusEntity: customerStatusEntity:
type: object type: object
properties: properties:
customerStatusId: customerStatusId:
type: integer type: integer
OvPayTokensResponse: OvPayTokensResponse:
type: object type: object
required: required:
@ -4298,7 +4357,7 @@ components:
items: items:
type: object type: object
required: required:
- purchasedProductId - purchasedProductId
- productId - productId
- name - name
- status - status
@ -4421,13 +4480,13 @@ components:
type: string type: string
example: HTM 2 uurskaart example: HTM 2 uurskaart
description: |- description: |-
The name of the originating HTM product definition. The name of the originating HTM product definition.
Will be returned in the language as specified in the Accept-Language header or the customer profile. Otherwise defaults to NL. Will be returned in the language as specified in the Accept-Language header or the customer profile. Otherwise defaults to NL.
description: description:
type: string type: string
example: "Met deze kaart reis je 2 uur lang onbeperkt met de bussen en trams van HTM. Overstappen is natuurlijk toegestaan!" example: "Met deze kaart reis je 2 uur lang onbeperkt met de bussen en trams van HTM. Overstappen is natuurlijk toegestaan!"
description: |- description: |-
The description of the originating HTM product definition. The description of the originating HTM product definition.
Will be returned in the language as specified in the Accept-Language header or the customer profile. Otherwise defaults to NL. Will be returned in the language as specified in the Accept-Language header or the customer profile. Otherwise defaults to NL.
status: status:
type: string type: string
@ -4486,15 +4545,15 @@ components:
example: "2024-11-30" example: "2024-11-30"
description: Only present for barcode tickets that are not yet activated. Tickets can only be activated BEFORE this date. description: Only present for barcode tickets that are not yet activated. Tickets can only be activated BEFORE this date.
validityStart: validityStart:
description: |- description: |-
Only present for barcode tickets that have been activated. The date-time at which the ticket will become valid for traveling. Only present for barcode tickets that have been activated. The date-time at which the ticket will become valid for traveling.
The ticket will not be valid before this date/time. The ticket will not be valid before this date/time.
type: string type: string
format: date-time-offset format: date-time-offset
example: "2024-11-25T13:25:00+01:00" example: "2024-11-25T13:25:00+01:00"
validityEnd: validityEnd:
description: |- description: |-
Only present for barcode tickets that have been activated. The date-time at which the ticket will become invalid for traveling. Only present for barcode tickets that have been activated. The date-time at which the ticket will become invalid for traveling.
The ticket will not be valid after this date/time. The ticket will not be valid after this date/time.
type: string type: string
format: date-time-offset format: date-time-offset
@ -4603,4 +4662,3 @@ components:
customerDataItem: customerDataItem:
type: string type: string
example: emailAddress example: emailAddress

View File

@ -0,0 +1,341 @@
openapi: 3.0.1
info:
title: Service Engine APIs for TAT security
description: >-
Service Engine APIs for TAT security. These are NOT the raw GBO APIs to access TAT security at GBO directly.
To be used by touch points to get secure a TAT.
version: "2.0"
servers:
- url: https://services.acc.api.htm.nl/abt/touchpoint/2.0
tags:
- name: TAT Security
paths:
/tokens/securetoken:
parameters:
- name: X-HTM-JWT-AUTH-HEADER
in: header
schema:
type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header
schema:
type: integer
example: 323
required: false
description: The id of the customer Profile
- name: X-HTM-ROLE-HEADER
in: header
schema:
type: string
example: Customer
required: false
description: The role of the HTM employee in the case of the SMP
post:
tags:
- TAT Security
summary: Request additional OV-pas security for a token either in profile or anonymous.
description: Request additional OV-pas security for a token either in profile or anonymous
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/SecureTokenRequest"
examples:
With customer account:
value:
ovPayTokenId: 42
emailAddress: stasjo@htm.nl
Without customer account:
value:
xtat: 62914b49-2c7f-437f-b4b0-2ad61a9f902d
emailAddress: stasjo@htm.nl
responses:
"200":
description: OK
content:
application/json:
schema:
$ref: "#/components/schemas/EmailNotPreApprovedResponse"
example:
uid: 7594f3ee-cd3d-40a3-8e82-73b90d16c481
recipient: xxxxxx.user@gmail.com
key: 123456789123456789123456789abcde
description: OTP Sent
"400":
description: Bad Request
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Missing Parameters:
value:
status: 400
title: Missing Mandatory Parameter
detail: Required parameter {0} is missing.
Invalid Parameters:
value:
status: 400
title: Invalid Parameter
detail: Required parameter {0} is invalid.
"401":
description: Unauthorized
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Unauthorized:
value:
status: 401
title: Unauthorized
detail: Invalid Access Token
"404":
description: Not found
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
TAT not found:
value:
status: 404
title: Not Found
detail: TAT Account Not Found
"409":
description: Conflict
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
TAT Already Secured:
value:
status: 409
title: Conflict
detail: TAT Already Secured
"500":
description: Internal server error
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
example:
error: An unknown error has occurred
/tokens/verifyotp:
parameters:
- name: X-HTM-JWT-AUTH-HEADER
in: header
schema:
type: string
example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
required: false
description: The JWT of a customer in case of touchpoint were customer logs in themselves
- name: X-HTM-CUSTOMER-PROFILE-ID-HEADER
in: header
schema:
type: integer
example: 323
required: false
description: The id of the customer Profile
- name: X-HTM-ROLE-HEADER
in: header
schema:
type: string
example: Customer
required: false
description: The role of the HTM employee in the case of the SMP
post:
tags:
- TAT Security
summary: Submit an OTP for a triggered OTP flow.
description: |
Submit an OTP for a triggered OTP flow. This can either be result of an AGO activation, or
result of an AGO authorization flow. Since the backoffice behaves slightly different depending
on which use case is executed, the calling TP needs to provide an `action` in the request body.
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/VerifyOtpRequest"
examples:
OTP verification for TAT security activation for token in customer account:
value:
ovPayTokenId: 42
otp: 123456
action: secure
OTP verification for TAT security authorization for anonymous token:
value:
xtat: 0f0defe8-828c-48e5-97e5-26d1d0179ef0
otp: 123456
action: authorize
responses:
"200":
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/VerifyOtpResponse'
examples:
Tat Secured:
value:
status: Success
description: TAT Secured
Tat Unsecured:
value:
status: Success
description: TAT Unsecured
Tat Authorized:
value:
status: Success
description: TAT Authorized
"400":
description: Bad request
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Missing Parameters:
value:
status: 400
title: Missing Mandatory Parameter
detail: Required parameter {0} is missing.
Invalid Parameters:
value:
status: 400
title: Invalid Parameter
detail: Required parameter {0} is invalid.
"401":
description: Unauthorized
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Unauthorized:
value:
status: 401
title: Unauthorized
detail: Invalid Access Token
"500":
description: Internal server error
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
example:
error: An unknown error has occurred
components:
schemas:
unavailable:
type: object
GenerateTatOutput:
type: object
properties:
uid:
type: string
description: >-
An uid IS A unique identifier THAT is associated with the
user.
recipient:
type: string
description: >-
A recipient IS A unique identifier THAT is associated with the
TAT owner.
key:
type: string
description: >-
A key IS a 32 character string THAT uniquely identifies the
OTP session.
EmailNotPreApprovedResponse:
type: object
description: >-
EmailNotPreApprovedResponse IS AN object THAT represents the response of
email pre-approval check.
properties:
uid:
type: string
description: A uid IS A unique identifier THAT is associated with the user.
example: 7594f3ee-cd3d-40a3-8e82-73b90d16c481
recipient:
type: string
description: >-
A recipient IS A unique identifier THAT is associated with the TAT
owner.
example: xxxxxx.user@gmail.com
key:
type: string
description: >-
A key IS a 32 character string THAT uniquely identifies the OTP
session.
example: 123456789123456789123456789abcde
description:
type: string
description: >-
A description IS A string THAT describes the reason why the email is
not pre-approved.
example: OTP Sent
SecureTokenRequest:
type: object
properties:
ovPayTokenId:
type: integer
example: 42
xtat:
type: string
format: uuid
example: 6134db53-9ae5-41d1-a343-36656b60b510
emailAddress:
type: string
format: email
example: stasjo@htm.nl
required:
- ovPayTokenId
VerifyOtpRequest:
type: object
properties:
ovPayTokenId:
type: integer
example: 42
xtat:
type: string
format: uuid
example: f3474452-e1d4-428c-b366-e5ad5965eb8c
otp:
type: string
example: 123456
action:
type: string
example: secure
required:
- otp
- action
VerifyOtpResponse:
type: object
properties:
status:
type: string
example: Success
description:
type: string
example: TAT Secured
ErrorResponse:
description: Default response when an invalid request has been sent
type: object
properties:
status:
type: integer
description: >-
A status IS An integer that represents the HTTP status code of the
response.
example: 400
title:
type: string
description: A title IS A string that provides a brief summary of the error.
detail:
type: string
description: A detail IS A string that provides more details about the error.