How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Shift4 Rule API

The Rule API from Shift4 — 1 operation(s) for rule.

Shift4 Rule API is one of 21 APIs that Shift4 publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include rule. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 1 operation across 1 path, and defines 57 schemas. It is described by OpenAPI 3.2.0, at version 1.7.57.

Requests are made against 2 base URLs: https://api.shift4test.com/api/rest/v1, https://api.shift4api.net/api/rest/v1.

1 operations 1 paths 57 schemas 1 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.7.57
Base URL
https://api.shift4api.net/api/rest/v1
Authentication
API Key, HTTP Hmac-Sha256
Resource Areas
1

Authentication & Security 2

Shift4 Rule API declares 2 security schemes for authenticating requests. An API key is passed in the header as AccessToken (AccessToken). It uses HTTP hmac-sha256 authentication (HMAC-SHA256).

  • AccessToken — A security credential used to authenticate API requests and all [i4Go®](https://s4-myportal.s3.amazonaws.com/downloads/documentation/i4go/i4go%20technical%20re…
  • HMAC-SHA256 — Authentication using HMAC-256 signatures as the authorization scheme. Sent in the Authorization header in the following format: Authorization: HMAC-SHA256 Cred…

Paths & Operations 1

Across 1 path, the API surfaces 1 operation — 1 POST. Each is listed below with its method, path, parameters, and response codes.

Rule 1
POST
/rule/verify
Rule Verification
ruleverify 4 params body → 200400504

Schemas 57

The contract defines 57 schemas that model the data the API accepts and returns. The most detailed are rules_verify_p2pe_tdesdukpt_emv (7 properties), Error (6 properties), rules_verify_token_gtv (6 properties), rules_verify_unencryptedcard (6 properties). Each schema is shown below with its type and property counts.

P2PEType0102IDTECH
object
2 properties 2 required
P2PEType03OnguardSDEMSR
object
See [P2PE Format 03 Ingenico On-Guard SDE](/guides/core-concepts/p2pe-formatingenico-on-guard-sde---format-03) for more information.
2 properties 2 required
MerchantMID
number
The merchant ID associated with the merchant account.
rules_verify_p2pe_onguardsde_msr
object
6 properties 5 required
P2PEKSN
string
The key serial number which was used to encrypt the P2PE data.
SurchargePercentage
number
The surcharge percentage that can be applied to a transaction.
Error
object
6 properties
CardNumber
string
The payment card number entered in an initial authorization/sale request. This field will always be masked when returned in a response.
P2PEFormatType05
string
Classifies the type of payment device being used for P2PE. Value|Description -----|----------- 05 | [Shift4 TDES DUKPT format](/guides/core-concepts/p2pe-forma…
CardTokenResponse
object
1 property
EMVEncryptedTagsOnly
object
Encrypted EMV tags
1 property 1 required
LighthouseResponse
object
1 property
ServerName
string
The name of the server that processed the request.
MerchantName
string
The merchant’s business name as configured with Shift4.
rules_verify_token_gtv
object
6 properties 5 required
P2PEFormatOnguardSDE
string
Classifies the type of payment device being used for P2PE. Value|Description -----|----------- 03 | Ingenico Onguard SDE Format
MerchantResponse
object
2 properties
CardTypeResp
string
An abbreviation used to specify the type of card that was used when processing a transaction. Value| Description -----|------------ AX | American Express AP |…
P2PEType03OnguardSDEEMV
object
See [P2PE Format 03 Ingenico On-Guard SDE](/guides/core-concepts/p2pe-formatingenico-on-guard-sde---format-03) for more information.
2 properties 2 required
rules_verify_unencryptedcard
object
6 properties 5 required
Server
object
1 property
P2PEData
string
The full output of a P2PE keypad/magnetic swipe reader (MSR).
rules_verify_p2pe_idtech
object
6 properties 5 required
TransactionVendorReference
string
Optional field for information that can be searched in the merchant portal.
ErrorSeverity
string
Severity level of the error. | Severity | Description | | -------- | ---------------------------------------------------------------- | | Info | Action not req…
P2PEType05TDESDUKPTMSR
object
See [P2PE Format 05 TDES DUKPT](/guides/core-concepts/p2pe-formattdes-dukpt---format-05) for more information.
3 properties 3 required
P2PEDataOnguardSDEMSR
string
Track information encrypted with AES 256 DUKPT. Contains the following information, separated by colons: |Value | Description |----------------|------------ |k…
DateTime
string
The date and time in ISO 8601 format including the timezone offset (yyyy-mm-ddThh:mm:ss.nnn+hh:mm). Must be sent as the local date/time of the merchant. For ex…
TransactionInvoice
string
10-digit invoice number assigned by the interface to identify a transaction. An invoice number serves as a unique key that identifies a transaction within a ba…
UniversalToken
object
1 property
ErrorLongText
string
Extended error message that is returned if an error condition exists.
CardMaskedNumber
string
The card number field will always be masked when returned in a response.
CardTokenRequired
object
1 property 1 required
TransactionRuleVerify
object
2 properties 1 required
P2PEType05TDESDUKPTEMV
object
See [P2PE Format 05 TDES DUKPT](/guides/core-concepts/p2pe-formattdes-dukpt---format-05) for more information.
2 properties 2 required
ErrorShortText
string
Abbreviated error message that is always returned if an error condition exists
LighthouseDataResponse
string
Base64 encoded JSON formatted data that will be returned from Lighthouse to be passed back to SkyTab. This data will contain variable information.
ErrorPrimaryCode
integer
Code indicating the type of error that occurred. Refer to the [Error Codes](/guides/appendices/error-codes) section of this document for more details.
AmountTotal
number
The amount being charged for a particular transaction. If other amount fields are sent, they must be included in the total amount. Amount cannot be zero.
SurchargeResult
string
Result of the surcharge eligibility check: | Value | Description | |-------|---------------------------------------------| | P | Pass - Card is eligible for su…
TransactionAuthSource
string
In a response, a code returned by the processor to indicate which host issued the response. Value | Description -------|---------------------------- E | Engine…
ClerkNumericId
integer
A number used to identify the point-of-sale (POS) or property management system (PMS) clerk or user. The value cannot be 0. An interface must be able to dynami…
rules_verify_p2pe_onguardsde_emv
object
6 properties 5 required
CardExpirationDate
integer
Conditional: Send only when card data is manually entered or when using a token. This field should not be specified when using an encrypted device. Card expira…
UniversalTokenValue
string
An identifier for a card or payment account across all Shift4 merchants.
P2PEFormatIDTech
string
Classifies the type of payment device being used for P2PE. Value|Description -----|----------- 01 | IDTech Enhanced Encryption format (Keyboard Mode) 02 | IDTe…
CardTokenValue
string
This field is used to specify a card token. Whenever CHD is sent in a request, a card token will be returned in this field. Your interface should be designed t…
ErrorCode
integer
Code indicating the type of error that occurred. Refer to the [Error Codes](/guides/appendices/error-codes) section of this document for more details. Note: Th…
RuleCheck
array
Specifies which rule checks are being requested: | Value | Description | |-----------|-------------------------------------------------------------------------…
rules_verify_p2pe_tdesdukpt_emv
object
7 properties 6 required
rules_verify_p2pe_tdesdukpt_msr
object
6 properties 5 required
P2PEDataOnguardSDEEMV
string
EMV TLV Data for tags 5A and 57 encrypted with AES 256 DUKPT. Contains the following information, separated by colons: Value | Description ----------------|---…
AmountTotalOnly
object
Object containing information regarding the amount being requested. The total field within the object is required and specifies the amount being requested. Not…
1 property 1 required
ErrorSecondaryCode
integer
This code supplements the code specified in the error.primaryCode field to provide additional information about the error that occurred.
CurrencyCode
string
Transaction currency code. See the [Currency Codes](/guides/appendices/currency-codes) section for details. Note: This is currently supported when processing f…
RulesTransactionId
string
Transaction ID for the rule check
ClerkOptional
object
1 property

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

shift4-rule-api-openapi.yml Raw ↑

Other APIs Shift4 publishes across the network.

Shift4 3D Secure API
Shift4 ACH API
Shift4 Batches API
Shift4 Cards API
Shift4 Checkout Sessions API
Shift4 Credentials API
Shift4 DCC API
Shift4 Devices API
Shift4 Gift Cards API
Shift4 Merchants API
Shift4 Mode API
Shift4 OCT API
Where this information came from

This is an independent, third-party profile of Shift4 Rule API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.