Mastercard Users API is one of 172 APIs that Mastercard publishes on the APIs.io network, described by a machine-readable OpenAPI specification.
Tagged areas include User. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, code examples, a changelog, a support channel, and a getting-started guide.
This API exposes
25 operations
across 15 paths,
and defines 96 schemas.
It is described by OpenAPI 3.2.0, at version 1.0.
Requests are made against 12 base URLs: https://mtf.api.identity.mastercard.co.in/aes, https://mtf.api.identity.mastercard.com/aes, https://api.identity.mastercard.co.in/aes, https://api.identity.mastercard.com/aes, https://api.mastercard.com/idservice, https://sandbox.api.mastercard.com/idservice, https://api.mastercard.com.au/idservice, https://sandbox.api.mastercard.com.au/idservice, https://apiedge.mastercard.com/commercial, https://mtf.apiedge.mastercard.com/commercial, https://sandbox.api.mastercard.com/loyalty/mrs, https://api.mastercard.com/loyalty/mrs.
25 operations15 paths96 schemas5 DELETE6 GET10 POST4 PUT
Metadata
The identity and technical contract details declared by the specification.
Specification
OpenAPI 3.2.0
API Version
1.0
Base URL
https://api.example.com
Resource Areas
1
Paths & Operations 25
Across 15 paths, the API surfaces 25 operations — 5 DELETE, 6 GET, 10 POST, 4 PUT. Each is listed below with its method, path, parameters, and response codes.
Delete a token linked to a user and a virtual card
deleteTokenById3 params→ 204400401403404
POST
/users/{id}/verifications
Verifies user
verifyUser2 paramsbody→ 200400
GET
/users/{id}
Retrieves a cardholder's information, including their name, address…
getUser4 params→ 200400
Schemas 96
The contract defines 96 schemas that model the data the API accepts and returns. The most detailed are UserUpdate (42 properties), UserDetails (33 properties), UserEnroll (27 properties), AccountBase (23 properties). Each schema is shown below with its type and property counts.
ErrorResponse
object
1 property1 required
Error
object
5 properties3 required
Errors
array
UserConsent
object
The user consent resource
3 properties3 required
GovtIdImage
RPClaimsUserData
object
6 properties4 required
LegalName
object
2 properties2 required
CountryCode
string
The country code of the country where the transaction originates from.
UserAccountActivitySearch
object
5 properties4 required
Address
1 required
Scopes
object
An object that represents a list of requested scopes and values.
2 properties
IdentityAttributesByName
object
Identity attributes keyed by IdentitySearch.scopedFields enum.
Phone
object
2 properties2 required
PDS
string
Encrypted Personal Device Storage (PDS) which hosts the users identity attributes. The PDS can be retrieved from the MIDS Core SDK, please refer to the SDK gui…
UserAccountActivityItemContents
object
4 properties1 required
Cpf
string
CPF Number. This will only be available when the Brazilian DL is scanned.
FathersName
object
2 properties2 required
IdentityAttributeDeleted
object
1 property1 required
RPClaimsUserConsentData
object
4 properties4 required
UserProfile
object
6 properties2 required
DriverLicenseIdentity
object
3 properties
DriverLicenseCardNumber
string
Document number.
PassportImage
object
Passport License Images.
1 property
UserAccountActivities
object
2 properties1 required
Cnh
DriverLicenseDetails
object
3 properties
IdentityAttributeDeletions
object
7 properties4 required
AuditEventsItem
object
12 properties
ARID
string
A unique identifier for any activity being executed arising out of a Claim Share request. This value is passed as a parameter in the URL redirecting a User to…
IdentityAttributesById
object
Identity attributes are keyed by attribute IDs.
VisaMatched
boolean
Flag indicating if the documentDetails are to be checked against a visa for a particular country.
DriverLicenseImage
object
Driver License Images.
2 properties
GovtId
TpAuditMetadata
object
Object containing metadata related to the request.
2 properties2 required
Selfie
object
2 properties2 required
IdentitySearch
object
4 properties3 required
ClientIdentities
object
2 properties1 required
UserConsent_2
string
Confirmation provided by the TP that the user has consented that the ID-Network can have access to their identity for the purposes of the API call. Should be A…
Rg
string
RG Number. This will only be available when the Brazilian DL is scanned.
Locale
string
IETF BCP 47 code which identifies the language to be used in any dialogs being shown to the user during the flow. The default value is "en-US".
AddressData
object
6 properties
GovtIdDetails
SdkVersion
string
Mastercard SDK version integrated with TP App, it is a constant extracted from MIDS SDK Configurations (generated while bundling SDK artifacts). If the TP app…
IdentityAttribute
Email
object
2 properties2 required
MothersName
object
2 properties2 required
DateOfBirth
object
2 properties2 required
ErrorResponse_2
object
The error response model used by all the API endpoints.
1 property1 required
RPClaimsUserConsent
object
8 properties3 required
PassportIdentity
object
3 properties
UserAccountActivityItems
object
3 properties2 required
RPClaimsUserDetails
object
7 properties2 required
ClaimsData
object
2 properties
MobileIdEligibility
object
2 properties2 required
PassportDetails
object
3 properties
Vcn
ErrorList
array
UserDetail
object
4 properties4 required
VcnUserDetail
object
3 properties3 required
ResourceIdentifier
string
A UUID which uniquely identifies a resource
UpdateVirtualCardAccount
object
1 required
VirtualCardAccount
object
2 required
AmountRangeControl
object
The exact amount range control will approve a transaction only if the requested amount is equal or greater than MinAmount and less than or equal to MaxAmount.…
6 properties4 required
Error_2
object
5 properties
Errors_2
object
1 property1 required
Card
object
2 properties2 required
ValidityPeriodControl
object
The ValidityPeriod control provides the ability to limit authorization activity to a defined time period
4 properties3 required
Control
object
In Control Rule
12 properties2 required
TimeOfDay
object
3 properties3 required
Token
object
4 properties
TokenUpdate
object
1 property
MerchantIdControl
object
The Merchant ID control provides the ability to limit authorizations to particular merchants
3 properties3 required
VelocityControl
object
The VelocityControl can limit the frequency, and the total cumulative amount of authorizations performed on the cardholders account within a specified time per…
8 properties2 required
MccControl
object
The Card Acceptor Business Codes (MCC) control can control the type of purchases for which a card is used
2 properties2 required
UpdateVCN
object
2 properties
TransactionLimitControl
object
The TransactionLimit control provides the ability to limit individual transaction authorizations to a maximum amount
2 properties2 required
ErrorWrapper
object
1 property1 required
GeographyControl
object
The GeographicControl provides the ability to control where a card is physically used
2 properties2 required
AgeingVelocityControl
object
The AgingVelocityControl provides the requester with the ability to set a notional credit line through the CumulativeControl. This control keeps track of the c…
7 properties4 required
Controls
array
In Control Card Controls
TimeOfDayControl
object
The TimeOfDayControl provides the ability to limit authorization activity to defined time periods for each day
3 properties3 required
CurfewControl
object
Curfew Control
5 properties4 required
UserDetails
object
33 properties
EnrolledUser
object
4 properties
UserVerificationDetails
object
2 properties
AccountBase
object
This object will define the users initial account that is being enrolled at the same time as the user.
23 properties5 required
ErrorsWrapper
object
1 property1 required
ErrorItem
object
Error Details
5 properties
UserUpdate
object
42 properties2 required
Errors_3
object
1 property1 required
PCLOUser
object
This object should only be used by Personal Card Linked Offers (PCLO) users. This object will define the users communications preferences for PCLO.
3 properties
UserAddress
object
This object will define the users default shipping/mailing address.
8 properties
VerificationDetails
object
3 properties
VerifyUser
object
1 property1 required
UserEnroll
object
27 properties4 required
VerifiedUser
object
1 property
Specification
The full machine-readable OpenAPI contract behind this narrative.
Every API here is available over the API and to AI agents over MCP. APIs is not yet its own endpoint on the v1 API. Reach this content through network search and the tag graph, or the MCP server below.
Installs https://mcp.apievangelist.com/mcp in Claude, Cursor, VS Code and the rest — one button, every client.
MCP tools for apis
4 tools reach this content
search_api_evangelistSearch every content type across the network at once.
find_relatedThe shared-tag relevance graph — what else covers this.
get_tagEverything one tag labels, across all content types.
guide_topicPRO — a curated bundle for a topic: area, guidance, rules, papers, stories, services.
A second provider on the same verified email joins the account you already have.
Your account
ⓘWhere this information came from
This is an independent, third-party profile of Mastercard Users API, published by
API Evangelist. We do not operate, host, resell, or
support these APIs, and we are not affiliated with or endorsed by the company unless stated above.
Everything here is built from publicly available information — the company's own site,
developer portal, documentation, public repositories, and the specifications it publishes for public use.
Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's
public API artifacts, scored against a published rubric. They are not certifications,
endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and
you do not need to justify the request. A removed company is recorded as unrated, never scored
zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy → On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.