Shift4 OCT API declares
2 security schemes
for authenticating requests.
An API key is passed in the header as AccessToken (AccessToken).
It uses HTTP hmac-sha256 authentication (HMAC-SHA256).
AccessToken — A security credential used to authenticate API requests and all [i4Go®](https://s4-myportal.s3.amazonaws.com/downloads/documentation/i4go/i4go%20technical%20re…
HMAC-SHA256 — Authentication using HMAC-256 signatures as the authorization scheme. Sent in the Authorization header in the following format: Authorization: HMAC-SHA256 Cred…
Paths & Operations 2
Across 2 paths, the API surfaces 2 operations — 2 POST. Each is listed below with its method, path, parameters, and response codes.
OCT 2
POST
/oct/payout
OCT Payout
octpayout4 paramsbody→ 200400504
POST
/oct/updaterecipient
OCT Update Recipient
octupdaterecipient4 paramsbody→ 200400504
Schemas 43
The contract defines 43 schemas that model the data the API accepts and returns. The most detailed are oct_payout_token_gtv (7 properties), oct_payout_unencryptedcard (7 properties), ErrorNoPrimarySecondary (4 properties), HostResponseOCT (2 properties). Each schema is shown below with its type and property counts.
TransactionRetrievalReferenceOCT
string
Reference retrieval number assigned by the authorizing agency. This value is printed on some receipts.
CardPresent
string
Conditional: Send in the initial authorization/sale request Indicates whether a card was present (‘Y’) or not (‘N’) at the time a transaction took place. This…
CustomerFirstNameAPM
string
Customer first name
HostResponseReasonDescription
string
Returns a description from the host.
MerchantMID
number
The merchant ID associated with the merchant account.
HostResponseOCT
object
Returns the response code detailing why the transaction was declined.
2 properties
CustomerEmailAddress
string
Customer email address.
CustomerLastNameResponse
string
Specifies a consumer’s last name. This field is returned whenever the customer name is supplied in the request or if the track/EMV data contains the cardholder…
ErrorCodeNoCondition
integer
Code indicating the type of error that occurred. Refer to the [Error Codes](/guides/appendices/error-codes) section of this document for more details.
CardNumber
string
The payment card number entered in an initial authorization/sale request. This field will always be masked when returned in a response.
CustomerLastNameAPM
string
Customer last name
CardTokenResponse
object
1 property
oct_payout_unencryptedcard
object
7 properties6 required
CustomerFirstNameResponse
string
Specifies a consumer’s first name. This field is returned whenever the customer name is supplied in the request or if the track/EMV data contains the cardholde…
ErrorNoPrimarySecondary
object
4 properties
ServerName
string
The name of the server that processed the request.
TransactionInvoiceAlphanumeric
string
10 character invoice number assigned by the interface to identify a transaction. An invoice number serves as a unique key that identifies a transaction within…
MerchantName
string
The merchant’s business name as configured with Shift4.
MerchantResponse
object
2 properties
CustomerIpAddress
string
Public source IP Address where the request originates, not the IP Address of the web server.
CardTypeResp
string
An abbreviation used to specify the type of card that was used when processing a transaction. Value| Description -----|------------ AX | American Express AP |…
TransactionVendorReference
string
Optional field for information that can be searched in the merchant portal.
ErrorSeverity
string
Severity level of the error. | Severity | Description | | -------- | ---------------------------------------------------------------- | | Info | Action not req…
HostResponseReasonCode
string
Returns a response code from the host. Value |Category|Description ------|--------|----------- 04 | 1 | Pick Up Card 07 | 1 | Pick Up Card, Special Condition 1…
DateTime
string
The date and time in ISO 8601 format including the timezone offset (yyyy-mm-ddThh:mm:ss.nnn+hh:mm). Must be sent as the local date/time of the merchant. For ex…
TransactionAuthSourceAPM
string
In a response, a code returned by the processor to indicate which host issued the response. Value | Description -------|---------------------------- A | APM (O…
ErrorLongText
string
Extended error message that is returned if an error condition exists.
CardMaskedNumber
string
The card number field will always be masked when returned in a response.
CardTokenRequired
object
1 property1 required
oct_payout_token_gtv
object
7 properties6 required
CardEntryModeManual
string
The method used to capture a payment card. Value|Description -----|----------- M | Manual Entry
ErrorShortText
string
Abbreviated error message that is always returned if an error condition exists
AmountTotal
number
The amount being charged for a particular transaction. If other amount fields are sent, they must be included in the total amount. Amount cannot be zero.
CustomerCompanyName
string
Customer Company name
CardExpirationDate
integer
Conditional: Send only when card data is manually entered or when using a token. This field should not be specified when using an encrypted device. Card expira…
SourceIP
string
Public source IP Address where the request originates, not the IP Address of the web server.
CardTokenValue
string
This field is used to specify a card token. Whenever CHD is sent in a request, a card token will be returned in this field. Your interface should be designed t…
AmountFeeOCT
number
The fee charged to process the OCT transaction.
AmountTotalOnly
object
Object containing information regarding the amount being requested. The total field within the object is required and specifies the amount being requested. Not…
1 property1 required
TransactionNotes
string
A free-form notes field that supports the use of HTML tags. This can be used for reference in [Lighthouse Transaction Manager](https://ltm.shift4test.com/) and…
CustomerNewEmailAddress
string
Customer's new email address.
CurrencyCode
string
Transaction currency code. See the [Currency Codes](/guides/appendices/currency-codes) section for details. Note: This is currently supported when processing f…
Server
object
1 property
Specification
The full machine-readable OpenAPI contract behind this narrative.
Every API here is available over the API and to AI agents over MCP. APIs is not yet its own endpoint on the v1 API. Reach this content through network search and the tag graph, or the MCP server below.
Installs https://mcp.apievangelist.com/mcp in Claude, Cursor, VS Code and the rest — one button, every client.
MCP tools for apis
4 tools reach this content
search_api_evangelistSearch every content type across the network at once.
find_relatedThe shared-tag relevance graph — what else covers this.
get_tagEverything one tag labels, across all content types.
guide_topicPRO — a curated bundle for a topic: area, guidance, rules, papers, stories, services.
A second provider on the same verified email joins the account you already have.
Your account
ⓘWhere this information came from
This is an independent, third-party profile of Shift4 OCT API, published by
API Evangelist. We do not operate, host, resell, or
support these APIs, and we are not affiliated with or endorsed by the company unless stated above.
Everything here is built from publicly available information — the company's own site,
developer portal, documentation, public repositories, and the specifications it publishes for public use.
Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's
public API artifacts, scored against a published rubric. They are not certifications,
endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and
you do not need to justify the request. A removed company is recorded as unrated, never scored
zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy → On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.