How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

JPMorgan Chase Token Lifecycle Management API

Manage or request token state information.

JPMorgan Chase Token Lifecycle Management API is one of 65 APIs that JPMorgan Chase publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Token Lifecycle Management. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 2 operations across 1 path, and defines 25 schemas. It is described by OpenAPI 3.2.0, at version 1.5.0.

Requests are made against 3 base URLs: https://api.merchant.jpmorgan.com/payments/v1/, https://api-test.merchant.jpmorgan.com/payments/v1/, https://api-mock.payments.jpmorgan.com/payments/v1.

2 operations 1 paths 25 schemas 1 GET1 PATCH

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.5.0
Base URL
https://api.payments.jpmorgan.com/onboarding/v1
Authentication
HTTP Bearer
Resource Areas
1

Authentication & Security 1

JPMorgan Chase Token Lifecycle Management API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (JWT) (BearerAuth). By default, every request must be authenticated.

Paths & Operations 2

Across 1 path, the API surfaces 2 operations — 1 GET, 1 PATCH. Each is listed below with its method, path, parameters, and response codes.

Token Lifecycle Management 2

Manage or request token state information.

PATCH
/tokens/{token-reference-id}/lifecycle-states
Token lifecycle management request
v1UpdateTokenStateByTokenReferenceId 3 params body → 200400401403412500503504
GET
/tokens/{token-reference-id}/lifecycle-states
Request token states
v1GetTokenStateByTokenReferenceId 4 params → 200400401403404500503504

Schemas 25

The contract defines 25 schemas that model the data the API accepts and returns. The most detailed are tokenLifecycleResponse (11 properties), tokenInformationResponse (8 properties), tokenInfoPaymentInstrument (6 properties), messages (4 properties). Each schema is shown below with its type and property counts.

tokenLifecycleRequest
object
Manage the lifecycle of a token on file.
2 properties
validationMessage
object
Object containing information about transaction validation.
3 properties 2 required
adfsError
object
Object containing information about the active directory file system error.
3 properties 3 required
tokenLifecyclePaymentInstrument
object
Manage the lifecycle of a token on file
1 property
tokenInfoMerchant
object
Current information and status of a token
1 property
messages
object
A list of errors and warnings.
4 properties 2 required
tokenLifecycleMercant
object
Manage the lifecycle of a token on file
2 properties 1 required
identifier
string
It is the resource identifier for a given merchant request, provided/generated by JPMC.
lifecycleManagementAction
object
Manage the lifecycle of a token on file
2 properties
merchantDoingBusinessAs
string
Alternate name for the merchant if it exists (trading name).
tokenInformationResponse
object
Current information and status of a token.
8 properties
tokenReferenceIdentifier
string
Identifier given to a token at the time of provisioning. Can be used as a reference to the token number.
tokenRequestorIdentifier
string
Identifier for the merchant given by payment networks or token provider.
responseCode
string
Short explanation of the response code.
timestamp
string
Designates the date, hour, minute and second when response was provided for a request. Using ISO 8601 date-time format.
code
string
Codifies a raised exception encountered by an internal or external system, sub-system, interface, job, module, system component with which the web service appl…
tokenLifecycleResponse
object
Response to a lifecycle request.
11 properties 2 required
responseStatus
string
Request result status.
message
string
Provides textual description of a problem that has occurred and is preventing the system from completing a task. Messages can be a confirmation, warning or not…
cardTokenStatus
string
Current state of the token.
tokenInfoPaymentInstrument
object
Current information and status of a token
6 properties 1 required
responseMessage
string
Long explanation of the response message.
requestIdentifier
string
Merchant identifier for the request. The value must be unique.
stateChangeReason
string
Lifecycle action requested by merchant for a token.
stateChangeReasonCode
string
Codifies the reason code for Token account level change.

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

jp-morgan-chase-token-lifecycle-management-api-openapi.yml Raw ↑

Other APIs JPMorgan Chase publishes across the network.

Notifications API
Accounts API
Recipients API
Webhooks API
Transactions API
Documents API
JPMorgan Chase Account Information API
JPMorgan Chase Account Restrictions API
JPMorgan Chase Account Services API
JPMorgan Chase Account Statements API
JPMorgan Chase Account Transactions API
JPMorgan Chase Account Updates API
Where this information came from

This is an independent, third-party profile of JPMorgan Chase Token Lifecycle Management API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.