How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

token-io Tokens API

These endpoints retrieve all tokens, a filtered list of tokens, or a specific token, as well as allowing you to cancel an existing token.

token-io Tokens API is one of 29 APIs that Token.io publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

This API exposes 3 JSON Schema definitions.

Tagged areas include Tokens. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, an API reference, a getting-started guide, a JSON-LD context, and 3 JSON Schemas.

This API exposes 3 operations across 3 paths, and defines 105 schemas. It is described by OpenAPI 3.2.0, at version 1.0.

Requests are made against a single base URL, https://api.token.io.

3 operations 3 paths 105 schemas 2 GET1 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0
Base URL
https://api.token.io
Authentication
HTTP Bearer, API Key
Resource Areas
1

Authentication & Security 2

token-io Tokens API declares 2 security schemes for authenticating requests. It accepts HTTP bearer tokens (JWT) (Bearer). An API key is passed in the header as Authorization (BasicAuth).

  • Bearer — For Production and Sandbox environments. When using curl samples the authorization header is given as -H 'Authorization: Bearer + JWT' Please substitute your B…
  • BasicAuth — For Sandbox environment only. When using curl samples the authorization header is given as -H 'Authorization: YOURAPIKEYHERE' Please substitute your Basic key…

Paths & Operations 3

Across 3 paths, the API surfaces 3 operations — 2 GET, 1 PUT. Each is listed below with its method, path, parameters, and response codes.

Tokens 3

These endpoints retrieve all tokens, a filtered list of tokens, or a specific token, as well as allowing you to cancel an existing token.

GET
/tokens
Get tokens
GatewayService.GetTokens 9 params → 200400401403404429500501
GET
/tokens/{tokenId}
Get a token
GatewayService.GetToken 1 param → 200400401403404429500501
PUT
/tokens/{tokenId}/cancel
Cancel a token
GatewayService.CancelToken 4 params → 200400401403404429500501

Schemas 105

The contract defines 105 schemas that model the data the API accepts and returns. The most detailed are AddressInfo (16 properties), TokenPayload (14 properties), DeliveryAddress (10 properties), TransferBody (9 properties). Each schema is shown below with its type and property counts.

EUIbanAccount
object
Account details where the iban is required and the bic is optional.
2 properties 1 required
TokenSignature
object
Contains the respective verified digital signatures for the payload.
2 properties
refId
string
The TPP-generated reference identifier for the token. This is not to be confused with the requestId. The refId maps to the tppRefId in the bank's consentReques…
FasterPaymentsAccount
object
A UK or Irish account where the sort code and account number are required.
2 properties 2 required
StetAccountIdentification
object
Bank-defined account identifiers.
2 properties
TransferDestinationToken
object
The primary account number. The cCard identifier found on payment cards, such as credit and debit cards, as well as stored-value cards, gift cards and other si…
2 properties
inline_response_429
object
1 property 1 required
AccountIdentifierPlusgiro
object
The domestic transaction clearing system in Sweden. The credit transfer function, which is part of Nordea , and used for mediating payments between accounts he…
1 property
Signature
object
Contains information about the signing party. This is only present if a tokenId is present. It can be used to validate that the provided tokenId corresponds to…
3 properties
GatewayTimeoutError
object
The deadline expired before the operation could complete.
2 properties 1 required
inline_response_403
object
1 property 1 required
inline_response_503
object
1 property 1 required
TransferDebtorEndpoint
object
Contains information about the payer account.
4 properties 1 required
AccessBodyResourceFundsConfirmation
object
1 property
PermissionDeniedError
object
The error returned when the member is not authorized to perform the given operation: PermissionDenied. This error message will be accompanied by the reason fro…
1 property
SENoBankIdAccount
object
Account details where the iban and bban are required and the bic and clearing number are optional. This is ONLY allowed for an HP flow if there is no bankId pr…
4 properties 2 required
Attachment
object
Contains optional provider blob objects supporting the transfer/transaction.
3 properties
AccountIdentifierBban
object
2 properties
AccountIdentifierMsisdn
object
The Mobile Station International Subscriber Director Number (MSISDN) is the user's mobile phone number, used as a unique identifier to enable routing of voice…
1 property
StetRegulatoryReportingCodes
object
Contains the list of needed regulatory reporting codes for international payments.
1 property
Cma9Risk
object
This object specifies additional details for risk scoring of payments.
7 properties
inline_response_504
object
1 property 1 required
AccessBodyResourceAccountBalance
object
1 property
TransferInstructions
object
Contains the transfer instructions for each payment.
3 properties 1 required
TransferDestinationSepa
TransferDestinationType
string
Specifies the type of transfer destination.
ChargeBearer
string
The bearer of the charge, if any, for international transfers. CRED - all charges are borne by the creditor. DEBT - all charges are borne by the debtor. SHAR -…
NotImplementedError
object
The operation was not implemented, supported or enabled by the bank.
2 properties 1 required
inline_response_400
object
1 property
AccountIdentifier
object
Account numbers and other strings that identify this as a unique bank account.
8 required
StetGenericIdentification
object
Bank-defined account information.
3 properties
TransferDestinationVirtualAccount
object
The details of the transfer destination for the settlement account. This destination is mandatory for unregulated TPPs.
2 properties 2 required
TransferDestinationFasterPayments
TransferDestinationEuDomesticNonEuroInstant
The instant payment system within a country using that country's non-Euro domestic currency. An IBAN account will require an iban and an optional bic, a BBAN a…
ProviderTransferMetadata
object
The transfer metadata required under the Open Banking API standard adopted by the bank.
TokenOperationResult
object
Contains details about the canceled token.
2 properties
StandingOrderBody
object
Contains the request payload for a token representing a standing order/recurring payment.
8 properties 3 required
ServiceUnavailableError
object
Service is unavailable, likely due to a transient condition; this is usually corrected with a retry.
2 properties 1 required
StetFinancialInstitutionIdentification
object
The unique and unambiguous identification of a financial institution, as assigned under an internationally recognised or proprietary identification scheme.
4 properties
ActingAs
object
Specifies another party for whom the token was created 'on behalf of'.
3 properties
AccessBodyResourceAccount
object
Specifies the account and resource for which access is being requested.
1 property
AccessBodyResourceAccountTransactions
object
1 property
TokenOperationResultStatus
string
Specifies the success or failure of the cancellation, the condition can be avoided by using a PRIVILEGED signature, rather than LOW or STANDARD.
StetPaymentTypeInformation
object
A set of elements used to further specify the type of transaction.
4 properties
Cma9BeneficiaryAccountType
string
To be provided if the AccountType is known.
StetClearingSystemMemberIdentification
object
Identifies a member within a clearing system; to be used for certain international credit transfers in order to identify the beneficiary bank.
2 properties
TransferDestination
object
The beneficiary account specifying the transfer destination, i.e. TPP/merchant/creditor bank.
2 properties 10 required
TokenPayload
object
Contains the details about the token specified by id.
14 properties
instructionIdentification
string
The TPP-generated, unique transaction id passed to the bank (mandatory) but does not have to go any further in the payment flow. The expectation is that this i…
StetTransferMetadata
object
Transfer metadata required under the French PSD2 API standard .
6 properties
CancelTokenResponse
object
1 property
TokenMember
object
Contains information identifying the Token.io member.
2 properties 1 required
AccountIdentifierIban
object
The International Bank Account Number, used when sending interbank transfers or wiring money from one bank to another, especially across international borders.
1 property
StetPostalAddressCreditor
object
Contains the mailing address of the creditor.
2 properties
inline_response_401
object
1 property
GetTokensResponse
object
2 properties
StetPartyIdentification
object
The ISO 20022 information about the party; this can be either a person or an organisation.
4 properties
PaymentNotFoundError
object
The error object returned when given payment cannot be found: ResourceNotFound.
2 properties 1 required
TokenPayloadAuthorizationMetadataEntry
object
Bank-defined additional authorization properties.
AccountIdentifierToken
object
The primary account number; the card identifier found on payment cards, such as credit cards and debit cards, as well as stored-value cards, gift cards and oth…
2 properties
AccountIdentifierBankgiro
object
The identifier for domestic bank accounts in Sweden.
1 property
AccessBodyResourceTransferDestinations
object
1 property
DeliveryAddress
object
Specifies the recipient's delivery address details.
10 properties
AccessBodyResourceAccountStandingOrders
object
1 property
BankGiroAccount
object
Account details where the bankgiroNumber is required and the bic is optional.
2 properties 1 required
ServerError
object
This could refer to either an error by the payment service provider or the bank. When the bank reports a 5xx error, "token-external-error": "true" is set as a…
2 properties
TransferDestinationSepaInstant
inline_response_500
object
1 property
id
string
The Token.io-assigned memberId of the TPP.
TransferDestinationBankgiro
PlusGiroAccount
object
Account details where the plusgiroNumber is required and the bic is optional.
2 properties 1 required
ClearingNumberAccount
object
Account details where the bban is required and the clearing number is optional.
2 properties 1 required
NextGenPsd2TransferMetadata
object
The transfer metadata required under the NextGenPSD2 standard .
4 properties
AddressInfo
object
The complete postal address of a party.
16 properties
AccountIdentifierGbDomestic
object
A domestic bank account in the UK.
2 properties
Alias
object
Alternate or additional member identification information.
3 properties
TransferDestinationEuDomesticNonEuro
The payment system within a country using that country's non-Euro domestic currency. An IBAN account will require an iban and an optional bic, a BBAN account w…
ResourceExhaustedError
object
Resource exhausted. Too many requests.
2 properties 1 required
Error
object
The request does not have valid authentication credentials needed to perform the operation.
2 properties
StetBeneficiary
object
The creditor or payee receiving the transfer.
4 properties
PolishApiDeliveryMode
string
The urgency classification for delivery.
inline_response_404
object
1 property 1 required
TransferDestinationElixir
object
The interbank payment system in Poland.
1 property 1 required
Token
object
Contains the details of each requested token returned according to the request's filtering parameters
5 properties
TransferBody
object
Contains the request payload for a transfer token representing a one-time payment.
9 properties 3 required
Metadata
object
Information governing or otherwise related to the transfer instructions.
5 properties
PolishApiTransferMetadata
object
Transfer metadata required under the Polish API standard .
2 properties
PaymentContextCode
string
This field describes the context of the payment context. This field is an OBIE standard and also maps to NextGenPsd2 's purposeCode and categoryPurposeCode fie…
AccessBodyResource
object
The body case seeking access to one or more resources for a single account.
6 properties
CustomerDataCreditor
object
Specifies the legal identity information for the payee. This information is not required for settlement accounts.
2 properties 1 required
Cma9TransferMetadata
object
Transfer metadata required under the CMA9 API standard .
3 properties
AccountIdentifierPan
object
The Primary Account Number (PAN). The card identifier found on payment cards, such as credit cards and debit cards, as well as stored-value cards, gift cards a…
1 property
SepaAccount
object
SEPA account details where the iban is required and the bic is optional.
2 properties 1 required
CustomerDataDebtor
object
Specifies the legal identity information for the payer/customer.
2 properties 1 required
TokenSignatureAction
string
Specifies the signature validation action.
TransferDestinationPlusgiro
StetPostalAddress
object
Contains the mailing address of the creditor.
2 properties
GetTokenResponse
object
1 property
Type
string
The types of alias available.
AccessBody
object
Contains the request payload for a token representing account information access permissions.
2 properties
inline_response_501
object
1 property 1 required
BbanAccount
object
Account details where the bban is required and the bic is optional.
2 properties 1 required
bankId
string
The Token.io id of the bank where the consent is created. This field is required if the customer is not using Token.io's Hosted Pages for bank selection, i.e.…
ErrorWithCode
object
Error object providing details about the error.
2 properties 2 required
SepaInstantAccount
object
SEPA Instant account details where the iban is required and the bic is optional.
2 properties 1 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

token-io-tokens-api-openapi.yml Raw ↑

Other APIs Token.io publishes across the network.

Token.io JavaScript SDK
Token.io PHP SDK
Token.io C# SDK
Token.io Objective-C SDK
Token.io iOS Webview SDK
Token.io Android Webview SDK
Merchant Sample (Java)
Merchant Sample (JavaScript)
Bank Sample (Java)
Personal Finance Management Sample (Java)
Merchant Integration Workshop
token-io Account on File API
Where this information came from

This is an independent, third-party profile of token-io Tokens API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.