v2
latestOpenAPI 3.1.02026-07-262279731.3 MBCreate a Preauthorization
Create a Preauthorization
Path parameters
Platform's API account identifier, associated with the API key.
Headers
Bearer authentication of the form Bearer <token>, where token is your auth token.
If your platform is using a proxy to take SCA-triggering action on behalf of users, you also need to integrate mTLS authentication and use the api-mtls base URL.
Request body
Max. length: 255 characters
Custom data that you can add to this object.
The unique identifier of the user at the source of the transaction.
Allowed values: DEFAULT, FORCE, NO_CHOICE
Default value: DEFAULT
The mode applied for the 3DS2 protocol for CB, Visa, and Mastercard. The options are:
- DEFAULT – Requests an exemption to strong customer authentication (SCA), and thus a frictionless payment experience, if allowed by your Mangopay contract and accepted by the issuer.
- FORCE – Requests SCA.
- NO_CHOICE – Leaves the choice to the issuer whether to allow for a frictionless payment experience or to enforce SCA.
The unique identifier of the Card object, obtained during the card registration process.
Max. length: 255 characters
The URL to which users are automatically returned after 3DS2 if it is triggered (i.e., if the SecureModeNeeded parameter is set to true).
Max. length: 10 characters; only alphanumeric and spaces
Custom description to appear on the user’s bank statement along with the platform name. Different banks may show more or less information. See the <a href="/bank-statements">Customizing bank statement references</a> article for details.
Allowed values: One of the supported languages in the ISO 639-1 format: DE, EN, ES, FR, IT, NL, PL, PT.
The language in which the payment page is to be displayed.
The IP address of the end user initiating the transaction, in IPV4 or IPV6 format.
Allowed values: VISA, MASTERCARD, CB, MAESTRO
The card network to use, as chosen by the cardholder, in case of <a href="/guides/payment-methods/card/co-branded">co-branded cards</a>.
Default value: ECommerce
Allowed values: ECommerce, TelephoneOrder
The channel through which the user provided their card details, used to indicate mail-order and telephone-order (MOTO) payments:
- ECommerce – Payment received online.
- TelephoneOrder – Payment received via mail order or telephone order (MOTO).
The unique reference generated for the profiling session, used by the <a href="/guides/fraud-prevention">fraud prevention</a> solution to produce recommendations for the transaction using the profiling data.
Note: Parameter not returned by the API. Profiling feature available on request – contact Mangopay <a href="https://hub.mangopay.com/" target="_blank">via the Dashboard</a> for more information.
Response
Success
Max. length: 255 characters
The unique identifier of the preauthorization.
Max. length: 255 characters
Custom data that you can add to this object.
Unix timestamp (UTC) of the date and time the object was created.
The unique identifier of the user at the source of the transaction.
Unix timestamp (UTC) of the date and time successful authorization occurred. If authorization failed, the value is null.
Returned values: CREATED, SUCCEEDED, FAILED
The status of the authorization.
Returned values: WAITING, CANCELED, EXPIRED, VALIDATED
The status of the preauthorization object:
- WAITING – The remaining preauthorized funds can be captured by making one or several preauthorized pay-ins. Pay-ins can only be made against a preauthorization with the WAITING status.
- CANCELED – The preauthorization was canceled manually before any preauthorized pay-ins were made, or it was canceled automatically because the authorization failed.
- EXPIRED – The hold period on the preauthorized funds has ended without any preauthorized pay-ins taking place.
- VALIDATED – During the hold period: Indicates that all the preauthorized funds have been captured (RemainingFunds is zero) and no more preauthorized pay-ins can be made. After the hold period: Indicates that at least one capture was made during the hold period.
Unix timestamp (UTC) of the date and time the hold period ends and the preauthorized funds are released. At the expiration date, the preauthorization’s PaymentStatus changes to EXPIRED if no captures were made or VALIDATED if at least one capture was made.
The unique identifier of the pay-in.
The code indicating the result of the operation. This information is mostly used to <a href="/errors/codes">handle errors</a> or for filtering purposes.
The explanation of the result code.
Returned values: DEFAULT, FORCE, NO_CHOICE
The mode applied for the 3DS2 protocol for CB, Visa, and Mastercard. The options are:
- DEFAULT – Requests an exemption to strong customer authentication (SCA), and thus a frictionless payment experience, if allowed by your Mangopay contract and accepted by the issuer.
- FORCE – Requests SCA.
- NO_CHOICE – Leaves the choice to the issuer whether to allow for a frictionless payment experience or to enforce SCA.
The unique identifier of the Card object, obtained during the card registration process.
Max. length: 255 characters
The URL to which users are automatically returned after 3DS2 if it is triggered (i.e., if the SecureModeNeeded parameter is set to true).
Max. length: 255 characters
The URL to which to redirect the user to proceed to 3DS2 validation.
Whether or not the SecureMode was used.
Returned values: CARD
The payment type of the preauthorization.
Returned values: DIRECT
The execution type of the preauthorization.
Max. length: 10 characters; only alphanumeric and spaces
Custom description to appear on the user’s bank statement along with the platform name. Different banks may show more or less information. See the <a href="/bank-statements">Customizing bank statement references</a> article for details.
Returned values: One of the supported languages in the ISO 639-1 format: DE, EN, ES, FR, IT, NL, PL, PT.
The language in which the payment page is to be displayed.
Default value: true
Whether multiple captures are activated for the preauthorization.
The IP address of the end user initiating the transaction, in IPV4 or IPV6 format.
Returned values: V1, V2_1
The 3DS protocol version to be applied to the transaction.
Returned values: V1, V2_1
The 3DS protocol version applied to the transaction.
Allowed values: VISA, MASTERCARD, CB, MAESTRO
The card network to use, as chosen by the cardholder, in case of <a href="/guides/payment-methods/card/co-branded">co-branded cards</a>.
Default value: ECommerce
Allowed values: ECommerce, TelephoneOrder
The channel through which the user provided their card details, used to indicate mail-order and telephone-order (MOTO) payments:
- ECommerce – Payment received online.
- TelephoneOrder – Payment received via mail order or telephone order (MOTO).