How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

SIX Debi X API

REST API for card issuers on the debiX debit and mobile payment platform - transaction processing, card token lifecycle, push notifications, and bulk operations - with publicly downloadable OpenAPI 3.1 definitions for the bank-to-SIX and cardtoken surfaces and documented production and preprod hosts on api.six-group.com.

SIX Debi X API is one of 11 APIs that SIX publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Debit Cards, Payments, Card Tokens, and Banking. The published artifact set on APIs.io includes API documentation, an API reference, an OpenAPI specification, and a changelog.

This API exposes 25 operations across 23 paths, and defines 119 schemas. It is described by OpenAPI 3.2.0, at version 2.36.0.

Requests are made against 12 base URLs: https://api.six-group.com/api/debix/bank/cardtoken/v2, https://api-preprod.np.six-group.com/api/debix/bank/cardtoken/v2, https://api.six.ssfn.ch/api/debix/bank/cardtoken/v2, https://api-preprod.np.six.ssfn.ch/api/debix/bank/cardtoken/v2, https://api.p2p.six-group.com/api/debix/bank/cardtoken/v2, https://api-preprod.np.p2p.six-group.com/api/debix/bank/cardtoken/v2, https://api.six-group.com/api/debix/bank/v2, https://api-preprod.np.six-group.com/api/debix/bank/v2, https://api.six.ssfn.ch/api/debix/bank/v2, https://api-preprod.np.six.ssfn.ch/api/debix/bank/v2, https://api.p2p.six-group.com/api/debix/bank/v2, https://api-preprod.np.p2p.six-group.com/api/debix/bank/v2.

25 operations 23 paths 119 schemas 1 GET20 POST4 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
2.36.0
Base URL
https://api.six-group.com/api/debix/bank/v2
Resource Areas
1

Paths & Operations 25

Across 23 paths, the API surfaces 25 operations — 1 GET, 20 POST, 4 PUT. Each is listed below with its method, path, parameters, and response codes.

Card Management 25

Allows card lifecycle, PIN management, retrieval of sensitive card data.

POST
/cards
Orders a new card
orderCard 2 params body → 202400404default
PUT
/cards
Modifies the data of a card
mutateCardDetails 2 params body → 202400404default
POST
/cards/{cardToken}/reverse-order
Reverses a card order
reverseCardOrder 3 params body → 202400404default
POST
/cards/{cardToken}
Returns the card's details
getCardDetails 3 params body → 200400404default
PUT
/cards/{cardToken}
Modifies the data of a card
putCardsByCardToken 3 params body → 202400404default
PUT
/cards/{cardToken}/status
Modifies the status of a card
updateCardStatus 3 params body → 202400404default
POST
/cards/{cardToken}/credentials
Gets card credentials
getCardCredentials 3 params body → 200400404default
POST
/cards/{cardToken}/pin
Gets the PIN for the given card
getPin 3 params body → 200400404default
POST
/cards/{cardToken}/start-set-pin
Starts a PIN set operation
startSetPin 3 params body → 200400404default
POST
/cards/start-set-pin
Starts a PIN set operation
startSetPinByCardId 2 params body → 200400default
POST
/cards/{cardToken}/set-pin
Sets the PIN for the given card
setPin 3 params body → 204400404default
POST
/cards/{cardToken}/pin-datamailer
Orders a PIN datamailer for the specified card
orderPinDatamailer 3 params body → 202400default
POST
/cards/{cardToken}/reset-pin-try-counter
Resets the PIN try counter for the given card
resetPinTryCounter 3 params body → 202400404default
POST
/cards/card-token
Returns the card token
getCardToken 2 params body → 200400404default
POST
/cards/{cardToken}/card-instance-token
Returns the card instance token
getCardInstanceToken 3 params body → 200400404default
POST
/cards/card-instance-token
Returns the card instance token
getCardInstanceTokenByCardId 2 params body → 200400404default
GET
/cards/{cardToken}/short-card-id
Returns the card identifier
getCardIdentifier 3 params → 200400404default
POST
/cards/reverse-order
Reverses a card order
postCardsReverseOrder 2 params body → 202400404default
PUT
/cards/status
Modifies the status of a card
putCardsStatus 2 params body → 202400404default
POST
/cards/details
Returns the card's details
postCardsDetails 2 params body → 200400404default
POST
/cards/credentials
Gets card credentials
postCardsCredentials 2 params body → 200400default
POST
/cards/pin
Gets the PIN for the specified card
postCardsPin 2 params body → 200400404default
POST
/cards/set-pin
Sets the PIN for the specified card
postCardsSetPin 2 params body → 204400default
POST
/cards/pin-datamailer
Orders a PIN datamailer for the specified card
postCardsPinDatamailer 2 params body → 202400default
POST
/cards/reset-pin-try-counter
Resets the PIN try counter for the specified card
postCardsResetPinTryCounter 2 params body → 202400404default

Schemas 119

The contract defines 119 schemas that model the data the API accepts and returns. The most detailed are CardOrderData (36 properties), CardMutationBccData (16 properties), BccData (16 properties), FeatureToggles (16 properties). Each schema is shown below with its type and property counts.

CardLine
string
This line will be printed on the front side of the card. At least the first card line is required for a physical card order.
CardCredentialsResponse
string
JSON Web Token containing the encrypted card credentials and an ephemeral public key to complete the Diffie-Hellman key exchange. The algorithm of the JWS sign…
CardBlockOriginViaBank
string
Initiator and channel of the card blocking when the card is blocked via the bank.
CardOrderReason
string
This setting determines the priority in which a physical card is ordered. Daily business orders are processed with higher priority and sent to the producer aft…
SubCardType
string
Sub card type that is linked to a dedicated BIN range and specifies a product like 'Platinum', 'EUR' or 'Student'. It must be configured in bank master data, o…
Birthdate
string
Date of birth.
BlockedCardReplacement
string
Indicates the need of a card replacement when the card has been blocked. This is only an indicator and does not trigger the actual card replacement.
DatamailerExpressCode
string
Defines the express code of OTRC and PIN datamailer delivery.
ContactlessActivationStatus
string
Describes the contactless activation status of the card.
UseBankCardWithPin
boolean
Bank card specific field. Indicator of whether the bank card is used with or without PIN.
RestrictedRegions
array
A list of regions from which authorizations will be declined.
FamilyName
string
Family name
CardholderDataTrack
string
A formatted combination of family name, name and title. Must only be set for a Mastercard physical card order. Valid formats include: - FAMILYNAME/ - FAMILYNAM…
CardMutationCardApplication
object
Controls card application settings for the EMV-Profile, online limits and transaction authorizer.
3 properties
CardTokenResponse
object
Contains the card token of the card.
1 property 1 required
ThreeDsInformation
object
Contains 3DS data provided by Worldline.
2 properties 1 required
PinDatamailerOrderRequest
object
Details of the PIN datamailer order request. The referenced card must be a physical card.
5 properties 3 required
CardTokenRequest
object
Contains the identifier of the card for which to return the card token.
1 property 1 required
UnstructuredAddress
array
Unstructured address of simple address lines.
CommonCardInformation
object
Common information about the card.
14 properties 5 required
CardBlockInterface
string
The interface used for blocking the card.
CardStatus
string
The status of the card.
BankCardLine
string
Bank card specific field. The content of this field has to be agreed with the card producer and will not be checked by SIX.
CardBlockInformation
object
Contains information about blocked cards.
5 properties
StartSetPinResponse
string
JSON Web Token signed by debiX containing an ephemeral public key to complete the Diffie-Hellman key exchange, used to encrypt the new PIN to be set for this c…
CardBlockOrigin
string
Initiator and channel of the card blocking.
GetPinRequest
string
JSON Web Token signed by the issuer, containing all parameters for securely retrieving the PIN. The algorithm of the JWS signature can be one of RS256/384/512,…
CardOrderReversalRequest
object
1 property 1 required
CardBlockReason
string
The reason why the card was blocked.
AccountNumber
string
Unique number identifying a bank account.
PhoneNumber
string
Mobile or landline phone number. Note: phoneNumber is a mandatory parameter which must be provided to register a card with authentication method SMSONLY, PIN,…
CardOrderData
object
Card data needed to order the card. Online limits are required if they should not be taken over from the parent card. EMV-Profile must be set for a physical ca…
36 properties 8 required
ChipApplication
string
Indicates what chip will be applied to the card. If no chipApplication is provided, EMVI20 will be applied in the order.
VisaC2PCustomerId
string
Unique identifier for the customer.
Region
string
Region from where an authorization is requested.
CardOrderResponse
object
Contains the card token and the card instance token for the newly created card. These tokens can be used immediately to perform subsequent card-related operati…
2 properties 2 required
GetPinResponse
string
JSON Web Token signed by debiX containing the encrypted PIN and an ephemeral public key to complete the Diffie-Hellman key exchange. The algorithm of the JWS s…
BccData
object
Information about the cardholder from the bank card central.
16 properties 7 required
CardMutationBccData
object
Information about the cardholder to mutate.
16 properties 7 required
UpdateCardStatusRequest
object
Contains the request to update the status of the card. The card block reason is required when blocking the card. Only when blocking a card, the information in…
6 properties 3 required
ProducerInfo
string
Information for the producer of the card. E.g. to print the EUR-label on the card.
CardExpressCode
string
Defines the express code of the card delivery. Must be set for a physical card order and CardDelivery is DELIVERTOCARDHOLDER.
Language
string
Correspondence language.
CardMutationRequest
object
Fields to modify. Fields that are set will be modified. Others will be ignored.
6 properties 1 required
CardMailerText
string
Text which will be printed on the letter onto which the card is attached.
YearMonth
object
2 properties 2 required
BankApiError
object
Information about an error on API requests.
5 properties 2 required
MailerTextCode
integer
Reference to a predefined text container that will be printed on the datamailer.
ParentCardReference
object
Reference to a card from which settings can be inherited.
8 properties 8 required
StartSetPinRequest
string
JSON Web Token signed by the issuer to get an ephemeral public key from debiX for the given card. The algorithm of the JWS signature can be one of RS256/384/51…
BranchNumber
integer
Branch number of the site where the account was initially created.
AuthenticationMethodStatus
string
Status of an authentication method.
CardOrderRequest
object
Configuration specifying the new card to be ordered.
5 properties 1 required
Iban
string
IBAN of the bank account for which the card was issued.
DatamailerDeliveryDestination
string
Specifies the delivery destination for OTRC, PIN, and card datamailer.
SetPinRequest
string
JSON Web Token signed by the issuer to set the PIN for the given card. The algorithm of the JWS signature can be one of RS256/384/512, PS256/384/512, ES256/384…
OnlineLimits
object
The monthly and daily retail and cash transactions limits.
4 properties 4 required
BankClearingNumber
integer
Unique number used to identify each bank agency or branch in the bank directory.
CardStatusUpdateReason
string
The reason for the status update of the card.
CardOrderPinData
string
JSON Web Token signed by the issuer to set the PIN for the ordered card. The algorithm of the JWS signature can be one of RS256/384/512, PS256/384/512, ES256/3…
OtrcDelivery
string
Deprecated and will be ignored. Delivery type of OTRC.
CardMaterial
string
Distinguishes physical from virtual cards. VIRTUAL not allowed for bank cards.
CardInstanceTokenRequest
object
Contains the identifier of the card for which to return the card instance token.
1 property 1 required
CardTokenExtension
object
Extension to card token to identify a card.
2 properties 2 required
GamblingAndBettingAllowance
string
Defines condition when gambling and betting transactions are allowed.
Country
string
Country code in format ISO 3166-1 alpha 2.
ErrorDetail
object
2 properties 1 required
EmvProfile
object
Information about the EMV-Profile. Must be set for a physical card order.
2 properties 1 required
FraudConfiguration
object
The fraud configuration, containing restrictions for countries and regions. Authorizations from a country will be declined if the country itself, or the region…
3 properties
CardDetailsRequest
object
Contains identifiers of the card for which to return the details.
1 property 1 required
CardMutationFeatureToggles
object
Feature Toggles to mutate.
15 properties
UpdateCardStatusAction
string
Distinguishes the type of the card update.
PaymentAuthenticationMethods
object
Container for the available authentication methods.
4 properties 4 required
CardInstanceTokenResponse
object
Contains the card instance token of the card.
1 property 1 required
ContactlessActivationMode
string
Describes the contactless activation mode used during card ordering.
ShortCardIdResponse
object
Contains the identifier of the card that corresponds to the given card token.
1 property 1 required
ShortCardId
object
Complex object representing a card consisting of bank clearing number, card number and card type.
3 properties 3 required
CardCredentialsRequest
string
JSON Web Token signed by the issuer, containing all parameters for securely retrieving sensitive card credentials. The algorithm of the JWS signature can be on…
FeatureToggles
object
Contains the values of the feature toggles for the card. In card order requests, the contactlessActivationStatus will be ignored. Will be ignored in card order…
16 properties 14 required
CardInstanceToken
string
Unique card instance token of the card.
VisaADAliasId
string
The UUID generated by Alias Directory which identifies the alias.
DeliveryInformation
object
Delivery address of card, PIN and OTRC.
3 properties 2 required
CardType
integer
A single digit that distinguishes the card types of the schemes. - 1: Debit mastercard - 3: Visa debit - 6: Bank card
RiskShieldList
string
- "EXCLUSIONLIST": General whitelist, i.e. all rules that lead to RiskShield declines and automatic blockings are overridden. - "GREYLISTCNP": The non-secure c…
TransactionAuthorizer
string
Authorizer for retail and ATM transactions.
AccountAuthority
object
Indicates who has the right to draw on the account.
3 properties
CardSequenceNumber
integer
Sequence number of the card.
CardMutationFraudConfiguration
object
Controls the fraud configuration of a card.
2 properties 1 required
CardInstanceTokenByCardIdRequest
object
Contains the identifier of the card for which to return the card instance token.
1 property 1 required
CardMutationContactlessActivationStatus
boolean
Controls whether contactless is enabled.
ResetPinTryCounterRequest
object
Contains the cardTokenExtension used together with the cardToken path parameter for card identification.
1 property 1 required
ProducerCode
string
Defines the producer of the ordered card. Must only be set for a physical card order.
FirstName
string
First name
CardToken
string
Unique card token of a card.
CardId
object
Complex object representing a card consisting of bank clearing number, card number, card type, card sequence number and card expiry.
5 properties 5 required
CardDetailsResponse
object
Contains detailed information about the card.
9 properties 3 required
CardNumber
integer
Card number of the card.
CardPlasticCode
string
Plastic code of the card.
PinRecoveryStatus
string
The status of the PIN recovery.
RestrictedCountries
array
A list of countries from which authorizations will be declined. Country code values are expected in ISO 3166-1 alpha-2 format. The option to define a restricti…
Currency
string
The currency according to ISO 4217.
Salutation
string
Salutation code of a cardholder.
StartSetPinByCardIdRequest
string
JSON Web Token signed by the issuer to get an ephemeral public key from debiX for the given cardId. The algorithm of the JWS signature can be one of RS256/384/…
MerchantCategoryCode
integer
The merchant category code. In a whitelist, the presence of 0 signifies that all merchant category codes are allowed.
MoneySendReceiveAllowance
string
Defines conditions if money send to and receive from another cardholder is allowed.
PinDatamailerOrderRequest_2
object
Details of the PIN datamailer order request. The referenced card must be a physical card.
5 properties 3 required
CardOrderReversalRequest_2
object
1 property 1 required
CardSeqNumber
integer
Sequence number of the card.
UpdateCardStatusRequest_2
object
Contains the request to update the status of the card. The card block reason is required when blocking the card. Only when blocking a card, the information in…
6 properties 3 required
CardMutationRequest_2
object
Fields to modify. Fields that are set will be modified. Others will be ignored.
6 properties 1 required
ParentCardReference_2
object
Reference to a card from which settings can be inherited.
7 properties 7 required
StartSetPinRequest_2
string
JSON Web Token signed by the issuer to get an ephemeral public key from debiX for the given cardId. The algorithm of the JWS signature can be one of RS256/384/…
CardInstanceTokenRequest_2
object
Contains the identifier of the card for which to return the card instance token.
1 property 1 required
EmvProfile_2
object
Information about the EMV-Profile.
2 properties 1 required
CardDetailsRequest_2
object
Contains the identifier of the card for which to return the details.
1 property 1 required
VisaADAliasId_2
string
The UUID generated by Alias Directory which identifies the alias
ResetPinTryCounterRequest_2
object
Contains the identifier of the card for which to request the reset of the PIN try counter.
1 property 1 required
CardId_2
object
Complex object representing a card consisting of bank clearing number, card number, card type, card sequence number and card expiry.
5 properties 5 required
CardDetailsResponse_2
object
Contains detailed information about the card.
10 properties 4 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

six-group-card-management-api-openapi.yml Raw ↑

Other APIs SIX publishes across the network.

SIX Web API
SIX Bulk API
SIX bLink API
SIX debiX Auth Provider API
Swiss Bank Master API
SIC Service Status API
SIC Clearing Day Calendar API
Settlement Info Reporting API
SIX 3 DS API
SIX Bank Master API
Where this information came from

This is an independent, third-party profile of SIX Debi X API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.