v1

latestOpenAPI 3.0.32026-07-26208618579.9 KB
PIN Control handling

Request PIN Control access token by plasticId.

This operation is used to create the PIN control access token.

The successful response from this call returns an id, a pinURL for mobile device webview and pinFrameURL for an iframe in desktop browser flow. Id is valid for 30 seconds.

For mobile webview, device should be instructed to do a POST call to the pinURL with the content of the id in a form field named controlId.

For desktop browser flow, iframe should be opened to pinFrameURL with query parameter key, which needs to be agreed with Enfuce beforehand. After iframe has been loaded, browser should make a window.postMessage() call to the iframe. The message object should contain fields operation (with value view-pin or set-pin) and controlId.

post/v2/plastic/{plasticId}

Path parameters

plasticIdstring biginteger required

The id of the plastic for which the PIN should be accessed

Query parameters

auditUserstring required

The audit user to log the request

Request body

scope'VIEW_PIN' | 'SET_PIN' required

Describes the scope of the operation that is authorized by the user.

Response

Successful creation of the access token

idstring required

The ID of this PIN Control access token.

pinURLstring

The URL that the cardholder's mobile device webview should browse to for accessing the PIN.

pinFrameURLstring

The URL of the iframe for desktop browser based flows for accessing PIN.