How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Lightspark Strong Customer Authentication API

Endpoints for authorizing money-movement operations that require Strong Customer Authentication. Relevant only for customers in a region where SCA is required (e.g. EU); customers outside SCA-regulated regions never see an SCA challenge and these endpoints return 409.

Lightspark Strong Customer Authentication API is one of 22 APIs that Lightspark publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Strong Customer Authentication. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 16 operations across 15 paths, and defines 180 schemas. It is described by OpenAPI 3.1.0, at version 2025-10-13.

Requests are made against a single base URL, https://api.lightspark.com/grid/2025-10-13.

16 operations 15 paths 180 schemas 1 DELETE2 GET13 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.1.0
API Version
2025-10-13
Base URL
https://api.lightspark.com/grid/2025-10-13
Authentication
HTTP Basic, HTTP Bearer, API Key
Resource Areas
1

Authentication & Security 3

Lightspark Strong Customer Authentication API declares 3 security schemes for authenticating requests. It accepts HTTP basic authentication (BasicAuth). It accepts HTTP bearer tokens (AgentAuth). An API key is passed in the header as X-Grid-Signature (WebhookSignature). By default, every request must be authenticated.

  • BasicAuth — API token authentication using format :
  • AgentAuth — Bearer token authentication for agent-scoped endpoints. The token is the accessToken returned when redeeming a device code via POST /agents/device-codes/{code}…
  • WebhookSignature — Secp256r1 (P-256) asymmetric signature of the webhook payload, which can be used to verify that the webhook was sent by Grid. To verify the signature: 1. Get t…

Paths & Operations 16

Across 15 paths, the API surfaces 16 operations — 1 DELETE, 2 GET, 13 POST. Each is listed below with its method, path, parameters, and response codes.

Strong Customer Authentication 16

Endpoints for authorizing money-movement operations that require Strong Customer Authentication. Relevant only for customers in a region where SCA is required (e.g. EU); customers…

GET
/sca/factors
List enrolled SCA factors
listScaFactors 1 param → 200401404409500
POST
/sca/factors
Start SCA factor enrollment
startScaFactorEnrollment 1 param body → 200400401404409500
POST
/sca/factors/confirm
Confirm SCA factor enrollment
confirmScaFactorEnrollment 1 param body → 200400401404409500
DELETE
/sca/factors/{credentialId}
Delete an enrolled SCA factor
deleteScaFactor 2 params → 204401404409500
POST
/sca/login/start
Start an SCA login
startScaLogin 1 param body → 200400401404409500
POST
/sca/login/complete
Complete an SCA login
completeScaLogin 1 param body → 200400401404409423500
POST
/sca/record-event
Record a security event
recordSecurityEvent 1 param body → 200400401404409423500
POST
/sca/factors/reset
Start a 2FA reset
startTwoFactorReset 1 param body → 201400401404409429500
GET
/sca/factors/reset/{resetId}
Get 2FA reset status
getTwoFactorResetStatus 2 params → 200401404409500
POST
/sca/factors/reset/{resetId}/complete
Complete a 2FA reset
completeTwoFactorReset 2 params body → 204400401404409500
POST
/customers/external-accounts/{externalAccountId}/trust
Start trusting a beneficiary
startBeneficiaryTrust 1 param → 200400401404409500
POST
/customers/external-accounts/{externalAccountId}/trust/confirm
Confirm trusting a beneficiary
confirmBeneficiaryTrust 1 param body → 200400401404409500
POST
/customers/external-accounts/{externalAccountId}/untrust
Start untrusting a beneficiary
startBeneficiaryUntrust 1 param → 200400401404409500
POST
/customers/external-accounts/{externalAccountId}/untrust/confirm
Confirm untrusting a beneficiary
confirmBeneficiaryUntrust 1 param body → 200400401404409500
POST
/quotes/{quoteId}/authorize
Authorize a quote's SCA challenge
authorizeQuote 1 param body → 200400401404409429500
POST
/quotes/{quoteId}/authorize/resend
Resend a quote's SCA challenge code
resendQuoteScaCode 1 param → 204401404409429500

Schemas 180

The contract defines 180 schemas that model the data the API accepts and returns. The most detailed are Quote (18 properties), ScaChallenge (7 properties), SwiftAccountInfoBase (6 properties), ScaLoginStart (6 properties). Each schema is shown below with its type and property counts.

ScaLoginStartRequest
object
Selects which enrolled factor to start an SCA login with. The factor must already be enrolled (or, for SMSOTP, the phone verified).
1 property 1 required
PaymentEmbeddedWalletInfo
EurAccountInfoBase
object
3 properties 2 required
PaymentBwpAccountInfo
QuoteSourceType
string
Type of quote funding source
PaymentSlvAccountInfo
PaymentVndAccountInfo
ScaFactorView
object
An enrolled Strong Customer Authentication factor.
3 properties 1 required
TzsAccountInfo
PaymentBrlAccountInfo
TotpEnrollmentConfirmRequest
object
The shared secret returned by the TOTP enrollment start, plus the first code the customer's authenticator app produces, submitted to confirm and finalize the T…
3 properties 3 required
PaymentJmdAccountInfo
PaymentHkdAccountInfo
InrAccountInfo
RecordSecurityEventRequest
object
Records a client-side security event for the customer so Grid can maintain the customer's login-security state (SCA session revocation and failed-login lockout…
1 property 1 required
Error404
object
4 properties 3 required
GtqAccountInfoBase
object
4 properties 4 required
CadAccountInfoBase
object
4 properties 4 required
EgpAccountInfo
PaymentNgnAccountInfo
QuoteDestinationOneOf
PaymentHtgAccountInfo
BaseWalletInfo
object
2 properties 2 required
PaymentEgpAccountInfo
GbpAccountInfoBase
object
3 properties 3 required
PaymentRail
string
The payment rail used for the transfer. Payment rails represent the underlying payment network or system used to move funds between accounts.
PaymentSparkWalletInfo
ThbAccountInfo
MwkAccountInfo
TotpFactorEnrollRequest
object
Start enrolling a time-based one-time-password (TOTP) authenticator factor.
1 property 1 required
OutgoingRateDetails
object
Details about the rate and fees for an outgoing transaction or quote. Note: counterpartyFixedFee is denominated in the receiving currency, so its equivalent va…
6 properties 6 required
XafAccountInfo
PaymentPhpAccountInfo
PaymentKesAccountInfo
DkkAccountInfo
Error409
object
4 properties 3 required
TwoFactorResetStartRequest
object
Selects which enrolled factor to reset via the liveness-gated recovery flow.
1 property 1 required
PaymentBdtAccountInfo
HtgAccountInfo
MyrAccountInfoBase
object
4 properties 4 required
PaymentSwiftAccountInfo
Error400
object
4 properties 3 required
HtgAccountInfoBase
object
2 properties 2 required
IdrAccountInfoBase
object
5 properties 5 required
PaymentThbAccountInfo
Error500
object
4 properties 3 required
RwfAccountInfo
HkdAccountInfoBase
object
4 properties 4 required
SwiftAccountInfoBase
object
6 properties 4 required
EurAccountInfo
PaymentZarAccountInfo
PaymentInstructions
object
3 properties 1 required
BasePaymentAccountInfo
object
1 property 1 required
ZarAccountInfo
ZmwAccountInfo
PaymentXofAccountInfo
BaseQuoteSource
object
1 property 1 required
KesAccountInfoBase
object
3 properties 3 required
PaymentSolanaWalletInfo
ScaFactorEnrollStartOneOf
The factor-specific material needed to complete enrollment, keyed by type: a TOTP shared secret + provisioning URI, or the WebAuthn registration options for a…
TwoFactorResetStatus
object
The status of an in-progress 2FA reset, polled until it reaches a terminal value.
5 properties 3 required
UgxAccountInfoBase
object
3 properties 3 required
MxnAccountInfoBase
object
2 properties 2 required
InrAccountInfoBase
object
Required fields depend on the selected paymentRails: - NEFT: accountNumber, ifsc, rail - RTGS: accountNumber, ifsc, rail - UPI: vpa
6 properties 1 required
PolygonWalletInfo
object
2 properties 2 required
PaymentTzsAccountInfo
Error429
object
4 properties 3 required
IdrAccountInfo
PaymentCadAccountInfo
BeneficiaryTrustConfirm
object
The result of a confirm-trust / confirm-untrust call. trusted is true after a successful trust and false after a successful untrust.
1 property 1 required
PaymentZmwAccountInfo
PaymentUsdAccountInfo
PasskeyEnrollmentConfirmResponse
object
The enrolled passkey factor returned after a successful confirmation.
2 properties 2 required
AccountDestination
Quote
object
18 properties 13 required
MwkAccountInfoBase
object
3 properties 3 required
Error401
object
4 properties 3 required
ScaLoginComplete
object
The status of a completed SCA login session.
1 property 1 required
SolanaWalletInfo
object
2 properties 2 required
ScaFactorConfirmResponseOneOf
The enrollment result, keyed by type.
RwfAccountInfoBase
object
3 properties 3 required
PaymentAedAccountInfo
SlvAccountInfoBase
object
Required fields depend on the selected paymentRails: - BANKTRANSFER: bankAccountType, accountNumber - MOBILEMONEY: phoneNumber
5 properties 1 required
TotpEnrollmentStart
object
The shared secret a customer's authenticator app needs to enroll a TOTP factor. Returned by POST /sca/factors for a TOTP request; the customer scans totpUri (a…
4 properties 4 required
JmdAccountInfo
PhpAccountInfoBase
object
3 properties 3 required
GhsAccountInfoBase
object
Required fields depend on the selected paymentRails: - BANKTRANSFER: accountNumber, bankName - MOBILEMONEY: bankName, phoneNumber
4 properties 2 required
AedAccountInfoBase
object
3 properties 2 required
MxnAccountInfo
ScaAuthorization
object
Proof that satisfies an ScaChallenge. Provide exactly one of code (for SMSOTP / TOTP) or passkeyAssertion (for PASSKEY). When supplying a passkeyAssertion, ori…
3 properties
PaymentPolygonWalletInfo
TwoFactorResetStart
object
The reset handle plus the opaque liveness handles a caller relays to the end-user device to complete the liveness check. resetId threads the ceremony together…
4 properties 1 required
GhsAccountInfo
PaymentRwfAccountInfo
BdtAccountInfo
EthereumWalletInfo
object
2 properties 2 required
TronWalletInfo
object
2 properties 2 required
PaymentInrAccountInfo
PaymentAccountType
string
Type of payment account or wallet
UmaAddressDestination
TotpEnrollmentConfirmResponse
object
The one-time recovery codes issued once a TOTP factor is enrolled. These are shown to the customer only once; store them somewhere safe to recover access if th…
2 properties 2 required
PaymentEurAccountInfo
CnyAccountInfoBase
object
Required fields depend on the selected paymentRails: - BANKTRANSFER: accountNumber, bankName - MOBILEMONEY: bankName, phoneNumber
4 properties 2 required
CounterpartyInformation
object
Additional information about the counterparty, if available and relevant to the transaction and platform.
DestinationType
string
Type of payment destination
KesAccountInfo
QuoteSourceOneOf
GbpAccountInfo
BeneficiaryTrustConfirmRequest
object
Confirms trusting or untrusting a beneficiary by submitting the SCA proof. Carries the same proof fields as an ScaAuthorization (code for SMSOTP / TOTP, or pas…
4 properties
JmdAccountInfoBase
object
5 properties 5 required
TwoFactorResetCompleteRequest
object
Optional body for completing a 2FA reset. Only needed when resetting the SMSOTP factor to a new phone number; omit the body entirely otherwise.
1 property
CnyAccountInfo
UgxAccountInfo
SwiftAccountInfo
BwpAccountInfo
PaymentMwkAccountInfo
NgnAccountInfoBase
object
3 properties 3 required
BaseDestination
object
1 property 1 required
PaymentIdrAccountInfo
SlvAccountInfo
PaymentLightningInvoiceInfo
BeneficiaryTrustStart
object
The SCA challenge (if any) a caller authorizes to finish trusting (or untrusting) a beneficiary. The beneficiary is identified by its externalAccountId, so the…
1 property
AedAccountInfo
TzsAccountInfoBase
object
3 properties 3 required
PaymentSgdAccountInfo
PasskeyEnrollmentStart
object
Opaque WebAuthn registration options relayed to the end user's device to enroll a passkey factor. Grid performs no crypto; pass options to the device's WebAuth…
4 properties 4 required
ThbAccountInfoBase
object
4 properties 4 required
PhpAccountInfo
PaymentCnyAccountInfo
PaymentGtqAccountInfo
NgnAccountInfo
XafAccountInfoBase
object
4 properties 4 required
ScaChallenge
object
A Strong Customer Authentication challenge that must be satisfied before a money-movement operation can complete. This object is only present when the customer…
7 properties 4 required
PaymentEthereumWalletInfo
PaymentPkrAccountInfo
BdtAccountInfoBase
object
Required fields depend on the selected paymentRails: - BANKTRANSFER: accountNumber, bankName - MOBILEMONEY: bankName, phoneNumber
6 properties 2 required
ScaLoginStart
object
The factor-specific material a customer needs to complete an SCA login. Each factor surfaces only the fields it issues: SMSOTP carries challengeId and expiresA…
6 properties 1 required
PaymentUgxAccountInfo
MyrAccountInfo
RealtimeFundingQuoteSource
UsdAccountInfoBase
object
3 properties 3 required
XofAccountInfoBase
object
4 properties 4 required
PaymentBaseWalletInfo
VndAccountInfo
PkrAccountInfo
PkrAccountInfoBase
object
Required fields depend on the selected paymentRails: - BANKTRANSFER: accountNumber, bankName - MOBILEMONEY: bankName, phoneNumber
5 properties 2 required
PaymentMxnAccountInfo
EgpAccountInfoBase
object
Required fields depend on the selected paymentRails: - BANKTRANSFER: bankName, iban - MOBILEMONEY: bankName, phoneNumber
4 properties 2 required
ScaFactor
string
A Strong Customer Authentication factor. | Factor | Description | |--------|-------------| | SMSOTP | One-time code sent by SMS to the customer's verified phon…
PaymentXafAccountInfo
SparkWalletInfo
object
2 properties 2 required
DkkAccountInfoBase
object
3 properties 2 required
PaymentCopAccountInfo
ZmwAccountInfoBase
object
3 properties 3 required
VndAccountInfoBase
object
4 properties 4 required
PaymentGhsAccountInfo
PaymentDkkAccountInfo
PaymentMyrAccountInfo
AccountQuoteSource
PaymentGbpAccountInfo
HkdAccountInfo
ScaLoginCompleteRequest
object
Completes an SCA login by submitting the proof for the started factor. Carries the same proof fields as an ScaAuthorization (code for SMSOTP / TOTP, or passkey…
5 properties 1 required
ScaFactorEnrollRequestOneOf
Which SCA factor to begin enrolling, selected by type. SMSOTP is not enrollable (it uses the customer's verified phone), so only TOTP and PASSKEY are valid her…
Currency
object
4 properties
Error423
object
4 properties 3 required
BwpAccountInfoBase
object
3 properties 3 required
PasskeyFactorEnrollRequest
object
Start enrolling a WebAuthn passkey factor.
1 property 1 required
ScaFactorConfirmRequestOneOf
The proof that finalizes enrollment, keyed by type: the TOTP shared secret + code, or the passkey origin + credential.
SgdAccountInfo
PasskeyEnrollmentConfirmRequest
object
The WebAuthn credential a device produced for a passkey registration challenge, submitted to enroll the passkey factor.
3 properties 3 required
ZarAccountInfoBase
object
3 properties 3 required
ScaFactorList
object
The Strong Customer Authentication factors a customer has enrolled.
1 property 1 required
PaymentArsAccountInfo
RecordSecurityEventResponse
object
The customer's login-security state after recording the event, so the integrator can surface a lockout to the end user.
4 properties 3 required
SgdAccountInfoBase
object
4 properties 3 required
CadAccountInfo
UsdAccountInfo
XofAccountInfo
GtqAccountInfo
PaymentTronWalletInfo

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

lightspark-strong-customer-authentication-api-openapi.yml Raw ↑

Other APIs Lightspark publishes across the network.

Lightspark Agent Management API
Lightspark Agent Operations API
Lightspark API Tokens API
Lightspark Available UMA Providers API
Lightspark Cards API
Lightspark Contact Verification API
Lightspark Cross-Currency Transfers API
Lightspark Customers API
Lightspark Discoveries API
Lightspark Documents API
Lightspark Embedded Wallet Auth API
Lightspark Exchange Rates API
Where this information came from

This is an independent, third-party profile of Lightspark Strong Customer Authentication API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.