v2

latestOpenAPI 3.1.02026-07-262279731.3 MB
depositPreauthorizations

Create a Card Deposit Preauthorization

This endpoint creates a Deposit Preauthorization with PaymentType of CARD and returns the RedirectURL on which the user can preauthorize the debited funds.

Once authorized (Status becomes SUCCEEDED), you can capture the funds using the POST Create a Deposit Preauthorized PayIn endpoint.

<Note icon="fa-regular fa-circle-info"> **Note – Disclaimer about terminology**

The use of the term "deposit" in this feature is for convenience only and does not constitute a traditional banking deposit under applicable banking regulations, including the EU Capital Requirements Directive (Directive 2013/36/EU) or the Deposit Guarantee Schemes Directive (Directive 2014/49/EU). Accordingly, these funds are not covered by any statutory deposit protection schemes, and Mangopay does not operate as a licensed banking institution. </Note>

post/v2.01/{ClientId}/deposit-preauthorizations/card/direct

Path parameters

ClientIdstring required

Platform's API account identifier, associated with the API key.

Headers

Authorizationstring required

Bearer authentication of the form Bearer <token>, where token is your auth token.

If your platform is using a proxy to take SCA-triggering action on behalf of users, you also need to integrate mTLS authentication and use the api-mtls base URL.

Request body

AuthorIdstring required

The unique identifier of the user at the source of the transaction.

CardIdstring required

The unique identifier of the Card object, obtained during the card registration process.

PreferredCardNetworkstring

Allowed values: VISA, MASTERCARD, CB, MAESTRO

The card network to use, as chosen by the cardholder, in case of <a href="/guides/payment-methods/card/co-branded">co-branded cards</a>.

SecureModeReturnURLstring required

Max. length: 255 characters

The URL to which users are automatically returned after 3DS2 if it is triggered (i.e., if the SecureModeNeeded parameter is set to true).

StatementDescriptorstring

Max. length: 10 characters; only alphanumeric and spaces

Custom description to appear on the user’s bank statement along with the platform name. Different banks may show more or less information. See the <a href="/bank-statements">Customizing bank statement references</a> article for details.

Culturestring

Allowed values: One of the supported languages in the ISO 639-1 format: DE, EN, ES, FR, IT, NL, PL, PT.

The language in which the payment page is to be displayed.

IpAddressstring required

The IP address of the end user initiating the transaction, in IPV4 or IPV6 format.

Tagstring

Max. length: 255 characters

Custom data that you can add to this object.

ProfilingAttemptReferencestring

The unique reference generated for the profiling session, used by the <a href="/guides/fraud-prevention">fraud prevention</a> solution to produce recommendations for the transaction using the profiling data.

Note: Parameter not returned by the API. Profiling feature available on request – contact Mangopay <a href="https://hub.mangopay.com/" target="_blank">via the Dashboard</a> for more information.

Response

Success

Idstring

Max length: 128 characters (see data formats for details)

The unique identifier of the object.

CreationDateinteger

Unix timestamp (UTC) of the date and time the object was created.

ExpirationDateinteger

Unix timestamp (UTC) of the date and time the hold period ends and the preauthorized funds are released. At the expiration date, the deposit preauthorization’s PaymentStatus changes to EXPIRED if no captures were made.

AuthorizationDateinteger

Unix timestamp (UTC) of the date and time successful authorization occurred. If authorization failed, the value is null.

AuthorIdstring

The unique identifier of the user at the source of the transaction.

Statusstring

Returned values: CREATED, SUCCEEDED, FAILED

The status of the authorization.

PaymentStatusstring

Returned values: WAITING, CANCELED, CANCEL_REQUESTED, EXPIRED, VALIDATED, FAILED

The payment status of the deposit preauthorization object:

  • WAITING – The deposit preauthorization can be used: the preauthorized funds can be captured (if Status is SUCCEEDED) or the preauthorization can be canceled manually.
  • CANCELED – Value to pass to manually cancel the deposit preauthorization before use; indicates that the deposit preauthorization was canceled manually.
  • CANCEL_REQUESTED – The cancellation of the deposit preauthorization has been requested but not yet processed.
  • EXPIRED – The hold period on the preauthorized funds has ended without it being used.
  • VALIDATED – Indicates that the preauthorized funds were captured.
  • FAILED – The pay-in against the preauthorization has failed, but a retry may be possible.
ResultCodestring

The code indicating the result of the operation. This information is mostly used to <a href="/errors/codes">handle errors</a> or for filtering purposes.

ResultMessagestring

The explanation of the result code.

PaymentTypestring

Returned values: CARD

The payment type of the preauthorization.

ExecutionTypestring

Returned values: DIRECT

The execution type of the preauthorization.

StatementDescriptorstring

Max. length: 10 characters; only alphanumeric and spaces

Custom description to appear on the user’s bank statement along with the platform name. Different banks may show more or less information. See the <a href="/bank-statements">Customizing bank statement references</a> article for details.

Culturestring

Returned values: One of the supported languages in the ISO 639-1 format: DE, EN, ES, FR, IT, NL, PL, PT.

The language in which the payment page is to be displayed.

Tagstring

Max. length: 255 characters

Custom data that you can add to this object.

CardIdstring

The unique identifier of the Card object, obtained during the card registration process.

PreferredCardNetworkstring

Allowed values: VISA, MASTERCARD, CB, MAESTRO

The card network to use, as chosen by the cardholder, in case of <a href="/guides/payment-methods/card/co-branded">co-branded cards</a>.

SecureModeReturnURLstring

Max. length: 255 characters

The URL to which users are automatically returned after 3DS2 if it is triggered (i.e., if the SecureModeNeeded parameter is set to true).

SecureModeRedirectURLstring

Max. length: 255 characters

The URL to which to redirect the user to proceed to 3DS2 validation.

SecureModeNeededboolean

Whether or not the SecureMode was used.

IpAddressstring

The IP address of the end user initiating the transaction, in IPV4 or IPV6 format.

Requested3DSVersionstring

Returned values: V1, V2_1

The 3DS protocol version to be applied to the transaction.

Applied3DSVersionstring

Returned values: V1, V2_1

The 3DS protocol version applied to the transaction.