---
title: "List Deposit Preauthorizations for a Card"
method: GET
path: "/v2.01/{ClientId}/cards/{CardId}/deposit-preauthorizations"
tags: ["depositPreauthorizations"]
---

# List Deposit Preauthorizations for a Card

`GET /v2.01/{ClientId}/cards/{CardId}/deposit-preauthorizations`

<Note icon="fa-regular fa-circle-info">
**Note – Disclaimer about terminology**

The use of the term "deposit" in this feature is for convenience only and does not constitute a traditional banking deposit under applicable banking regulations, including the EU Capital Requirements Directive (Directive 2013/36/EU) or the Deposit Guarantee Schemes Directive (Directive 2014/49/EU). Accordingly, these funds are not covered by any statutory deposit protection schemes, and Mangopay does not operate as a licensed banking institution.
</Note>

## Path parameters

- `ClientId` string, required
- `CardId` string, required

## Query parameters

- `ResultCode` string
- `Status` string
- `PaymentStatus` string, required

## Headers

- `Authorization` string, required

## Response `200`

Success

- DepositPreauthorizationResponse[] — List of deposit preauthorizations created by the platform.
  - union
    - CardDepositPreauthorizationResponse — Response if Deposit Preauthorization's `PaymentType` is `CARD`.
      - `Id` string — Max length: 128 characters (see [data formats](/api-reference/overview/data-formats) for details) The unique identifier of the object.
      - `CreationDate` integer — Unix timestamp (UTC) of the date and time the object was created.
      - `ExpirationDate` integer — Unix timestamp (UTC) of the date and time the hold period ends and the preauthorized funds are released. At the expiration date, the deposit preauthorization’s `PaymentStatus` changes to `EXPIRED` if no captures were made.
      - `AuthorizationDate` integer — Unix timestamp (UTC) of the date and time successful authorization occurred. If authorization failed, the value is `null`.
      - `AuthorId` string — The unique identifier of the user at the source of the transaction.
      - `FlowDescriptor` FlowDescriptorResponse — Information about the Owner beneficiaries targeted by the pay-in and its subsequent transfers, who must all be KYC/KYB verified when the pay-in request is made ([read more](/guides/payin-beneficiaries)). If the `FlowDescriptor.Beneficiaries` is sent in the API request, then: - The transaction’s `CreditedWalletId` holder is disregarded in KYC/KYB checks. - **ALL** `UserId` values in the array must be one of: - `OWNER` whose `KYCLevel` is `REGULAR` - `PLATFORM` The pay-in `Status` becomes `FAILED` with `ResultCode` [002951](/errors/codes/002951) if at least one `FlowDescriptor.Beneficiaries.UserId` is: - `PAYER` - `OWNER` whose `KYCLevel` is `LIGHT` If the `FlowDescriptor.Beneficiaries` is not sent in the API request, then the `CreditedWalletId` holder is subject to KYC/KYB checks. This property is optional for backwards compatibility but is recommended for all pay-in flows, even when the `CreditedWalletId` holder is a `PAYER` or the same value as one of the `FlowDescriptor.Beneficiaries`.
        - `FlowId` string — Unique identifier of the payment flow, used by Mangopay for internal purposes.
        - `Beneficiaries` FlowDescriptorResponseBeneficiariesItems[], nullable — Max. length: 5 items The list of up to 5 Natural or Legal Users declared as beneficiaries of the pay-in, who must all be KYC/KYB verified when the pay-in request is made. The pay-in also fails if the `Beneficiaries` array contains nulled objects or invalid `UserId` values.
          - `UserId` string — The unique identifier of the Natural User or Legal User declared as a beneficiary of the pay-in.
      - `DebitedFunds` CardDepositPreauthorizationResponseDebitedFunds — Information about the preauthorized funds.
        - `Currency` string — **Allowed values:** The three-letter <a href="/api-reference/overview/data-formats" target="_blank">ISO 4217 code</a> (EUR, GBP, etc.) of a <a href="/guides/currencies" target="_blank">supported currency</a> (depends on feature, contract, and activation settings). The currency of the amount.
        - `Amount` integer — The amount of the currency in its minor unit. For example, EUR 12.60 would be represented as `1260` whereas JPY 12 would be represented as just `12`.
      - `Status` string — **Returned values:** `CREATED`, `SUCCEEDED`, `FAILED` The status of the authorization.
      - `PaymentStatus` string — **Returned values:** `WAITING`, `CANCELED`, `CANCEL_REQUESTED`, `EXPIRED`, `VALIDATED`, `FAILED` The payment status of the deposit preauthorization object: - `WAITING` – The deposit preauthorization can be used: the preauthorized funds can be captured (if `Status` is `SUCCEEDED`) or the preauthorization can be canceled manually. - `CANCELED` – Value to pass to manually cancel the deposit preauthorization before use; indicates that the deposit preauthorization was canceled manually. - `CANCEL_REQUESTED` – The cancellation of the deposit preauthorization has been requested but not yet processed. - `EXPIRED` – The hold period on the preauthorized funds has ended without it being used. - `VALIDATED` – Indicates that the preauthorized funds were captured. - `FAILED` – The pay-in against the preauthorization has failed, but a retry may be possible.
      - `PayinsLinked` CardDepositPreauthorizationResponsePayinsLinked — Information about the deposit preauthorized pay-ins made against the deposit preauthorization.
        - `PayinCaptureId` string — The unique identifier of the preauthorized pay-in (capture) made against the deposit preauthorization to debit the preauthorized funds.
        - `PayinComplementId` string — This deprecated parameter is always returned `null`.
      - `ResultCode` string — The code indicating the result of the operation. This information is mostly used to <a href="/errors/codes">handle errors</a> or for filtering purposes.
      - `ResultMessage` string — The explanation of the result code.
      - `PaymentType` string — **Returned values:** `CARD` The payment type of the preauthorization.
      - `ExecutionType` string — **Returned values:** `DIRECT` The execution type of the preauthorization.
      - `StatementDescriptor` string — Max. length: 10 characters; only alphanumeric and spaces Custom description to appear on the user’s bank statement along with the platform name. Different banks may show more or less information. See the <a href="/bank-statements">Customizing bank statement references</a> article for details.
      - `Culture` string — **Returned values:** One of the supported languages in the [ISO 639-1 format](/api-reference/overview/data-formats): DE, EN, ES, FR, IT, NL, PL, PT. The language in which the payment page is to be displayed.
      - `Shipping` ShippingDefaultsBillingUserResponse — **Default values:** `FirstName`, `LastName`, and `Address` information of the `Billing` object if sent, otherwise of the `AuthorId` (if address values present). Information about the shipping address.
        - `FirstName` string — The first name of the user.
        - `LastName` string — The last name of the user.
        - `Address` AddressSubPropsRequired — The postal address.
          - `AddressLine1` string, required — The first line of the address.
          - `AddressLine2` string — The second line of the address.
          - `City` string, required — The city of the address.
          - `Region` string — Required if `Country` is US, CA, or MX. The region of the address.
          - `PostalCode` string, required — The postal code of the address. The postal code can contain the following characters: alphanumeric, dashes, and spaces.
          - `Country` string, required — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The country of the address.
      - `Tag` string — Max. length: 255 characters Custom data that you can add to this object.
      - `CardId` string — The unique identifier of the Card object, obtained during the card registration process.
      - `PreferredCardNetwork` string — **Allowed values:** `VISA`, `MASTERCARD`, `CB`, `MAESTRO` The card network to use, as chosen by the cardholder, in case of <a href="/guides/payment-methods/card/co-branded">co-branded cards</a>.
      - `SecureModeReturnURL` string — Max. length: 255 characters The URL to which users are automatically returned after 3DS2 if it is triggered (i.e., if the `SecureModeNeeded` parameter is set to `true`).
      - `SecureModeRedirectURL` string — Max. length: 255 characters The URL to which to redirect the user to proceed to 3DS2 validation.
      - `SecureModeNeeded` boolean — Whether or not the `SecureMode` was used.
      - `BrowserInfo` BrowserInfo — Information about the browser used by the end user (author) to perform the payment.
        - `AcceptHeader` string, required — The exact content of the HTTP accept headers as sent to the platform from the end user’s browser.
        - `JavaEnabled` boolean, required — Whether or not the end user’s browser has the ability to execute Java.
        - `Language` string, required — Format: Two-letter language code (ISO 639-1 alpha-2) followed by two-letter country code (ISO 3166-1 alpha-2), separated by a hyphen (example: `en-US`; pattern:`^[a-zA-Z]{2}(-[a-zA-Z]{2})?$`) The language of the browser.
        - `ColorDepth` integer, required — The value representing the depth of the screen’s color palette for displaying images, in bits per pixel.
        - `ScreenHeight` integer, required — The height of the screen in pixels.
        - `ScreenWidth` integer, required — The width of the screen in pixels.
        - `TimeZoneOffset` integer, required — The difference in minutes between the browser’s timezone and UTC.
        - `UserAgent` string, required — The exact content of the HTTP User-Agent header.
        - `JavascriptEnabled` boolean, required — Whether or not the end user’s browser has the ability to execute JavaScript.
      - `IpAddress` string — The IP address of the end user initiating the transaction, in IPV4 or IPV6 format.
      - `Billing` BillingDefaultsShippingUserResponse — **Default values:** `FirstName`, `LastName`, and `Address` information of the `Shipping` object if sent, otherwise of the `AuthorId` (if address values present). Information about the billing address.
        - `FirstName` string — The first name of the user.
        - `LastName` string — The last name of the user.
        - `Address` Address — The postal address.
          - `AddressLine1` string — The first line of the address.
          - `AddressLine2` string — The second line of the address.
          - `City` string — The city of the address.
          - `Region` string — Required if `Country` is US, CA, or MX. The region of the address.
          - `PostalCode` string — The postal code of the address. The postal code can contain the following characters: alphanumeric, dashes, and spaces.
          - `Country` string — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The country of the address.
      - `Requested3DSVersion` string — **Returned values:** `V1`, `V2_1` The 3DS protocol version to be applied to the transaction.
      - `Applied3DSVersion` string — **Returned values:** `V1`, `V2_1` The 3DS protocol version applied to the transaction.
      - `CardInfo` CardInfo — Information about the card used for the transaction. If the information or data is not available, `null` is returned.
        - `BIN` string — The bank identification number (BIN) of the card.
        - `IssuingBank` string — The name of the bank that issued the card.
        - `IssuerCountryCode` string — The country code of the card issuer.
        - `Type` string — The type of card (for example, `CREDIT` or `DEBIT`).
        - `SubType` string, nullable — The sub-type of the card, if available.
        - `Brand` string — The card brand (for example, `VISA` or `MASTERCARD`).
      - `AuthenticationResult` AuthenticationResult — Information about the authentication result, based on the request made by Mangopay and the decision of the issuer regarding the type of authentication to be enforced (if applicable).
        - `AuthenticationType` string, nullable — **Returned values:** `CHALLENGE`, `FRICTIONLESS`, `DIRECT_AUTHORIZATION` The type of authentication: - `CHALLENGE` – The issuer requested SCA to be enforced (for example, using 3DS). - `FRICTIONLESS` – The transaction was exempted from SCA because an exemption was granted by the issuer. - `DIRECT_AUTHORIZATION` – The transaction was sent to the issuer for authorization without any frictionless or challenge (for example, if SCA doesn't apply). A `null` value typically indicates that authentication was not requested (for example, because the request failed before being sent) or a decision was not received. A `null` value typically indicates that authentication was not requested (for example, because the request failed before being sent) or a decision was not received.
    - PayPalDepositPreauthorizationResponse — Response if Deposit Preauthorization's `PaymentType` is `PAYPAL`.
      - `Id` string — Max length: 128 characters (see [data formats](/api-reference/overview/data-formats) for details) The unique identifier of the object.
      - `CreationDate` integer — Unix timestamp (UTC) of the date and time the object was created.
      - `ExpirationDate` integer — Unix timestamp (UTC) of the date and time the hold period ends and the preauthorized funds are released. At the expiration date, the deposit preauthorization’s `PaymentStatus` changes to `EXPIRED` if no captures were made.
      - `AuthorizationDate` integer — Unix timestamp (UTC) of the date and time successful authorization occurred. If authorization failed, the value is `null`.
      - `AuthorId` string — The unique identifier of the user at the source of the transaction.
      - `FlowDescriptor` FlowDescriptorResponse — Information about the Owner beneficiaries targeted by the pay-in and its subsequent transfers, who must all be KYC/KYB verified when the pay-in request is made ([read more](/guides/payin-beneficiaries)). If the `FlowDescriptor.Beneficiaries` is sent in the API request, then: - The transaction’s `CreditedWalletId` holder is disregarded in KYC/KYB checks. - **ALL** `UserId` values in the array must be one of: - `OWNER` whose `KYCLevel` is `REGULAR` - `PLATFORM` The pay-in `Status` becomes `FAILED` with `ResultCode` [002951](/errors/codes/002951) if at least one `FlowDescriptor.Beneficiaries.UserId` is: - `PAYER` - `OWNER` whose `KYCLevel` is `LIGHT` If the `FlowDescriptor.Beneficiaries` is not sent in the API request, then the `CreditedWalletId` holder is subject to KYC/KYB checks. This property is optional for backwards compatibility but is recommended for all pay-in flows, even when the `CreditedWalletId` holder is a `PAYER` or the same value as one of the `FlowDescriptor.Beneficiaries`.
        - `FlowId` string — Unique identifier of the payment flow, used by Mangopay for internal purposes.
        - `Beneficiaries` FlowDescriptorResponseBeneficiariesItems[], nullable — Max. length: 5 items The list of up to 5 Natural or Legal Users declared as beneficiaries of the pay-in, who must all be KYC/KYB verified when the pay-in request is made. The pay-in also fails if the `Beneficiaries` array contains nulled objects or invalid `UserId` values.
          - `UserId` string — The unique identifier of the Natural User or Legal User declared as a beneficiary of the pay-in.
      - `DebitedFunds` PayPalDepositPreauthorizationResponseDebitedFunds — Information about the preauthorized funds.
        - `Currency` string — **Allowed values:** The three-letter <a href="/api-reference/overview/data-formats" target="_blank">ISO 4217 code</a> (EUR, GBP, etc.) of a <a href="/guides/currencies" target="_blank">supported currency</a> (depends on feature, contract, and activation settings). The currency of the amount.
        - `Amount` integer — The amount of the currency in its minor unit. For example, EUR 12.60 would be represented as `1260` whereas JPY 12 would be represented as just `12`.
      - `Status` string — **Returned values:** `CREATED`, `SUCCEEDED`, `FAILED` The status of the authorization.
      - `PaymentStatus` string — **Returned values:** `WAITING`, `CANCELED`, `CANCEL_REQUESTED`, `EXPIRED`, `VALIDATED`, `FAILED` The payment status of the deposit preauthorization object: - `WAITING` – The deposit preauthorization can be used: the preauthorized funds can be captured (if `Status` is `SUCCEEDED`) or the preauthorization can be canceled manually. - `CANCELED` – Value to pass to manually cancel the deposit preauthorization before use; indicates that the deposit preauthorization was canceled manually. - `CANCEL_REQUESTED` – The cancellation of the deposit preauthorization has been requested but not yet processed. - `EXPIRED` – The hold period on the preauthorized funds has ended without it being used. - `VALIDATED` – Indicates that the preauthorized funds were captured. - `FAILED` – The pay-in against the preauthorization has failed, but a retry may be possible.
      - `PayinsLinked` PayPalDepositPreauthorizationResponsePayinsLinked — Information about the deposit preauthorized pay-ins made against the deposit preauthorization.
        - `PayinCaptureId` string — The unique identifier of the preauthorized pay-in (capture) made against the deposit preauthorization to debit the preauthorized funds.
        - `PayinComplementId` string — This deprecated parameter is always returned `null`.
      - `ResultCode` string — The code indicating the result of the operation. This information is mostly used to <a href="/errors/codes">handle errors</a> or for filtering purposes.
      - `ResultMessage` string — The explanation of the result code.
      - `PaymentType` string — **Returned values:** `PAYPAL` The payment type of the preauthorization.
      - `ExecutionType` string — **Returned values:** `WEB` The execution type of the preauthorization.
      - `StatementDescriptor` string — Max. length: 10 characters; only alphanumeric and spaces Custom description to appear on the user’s bank statement along with the platform name. Different banks may show more or less information. See the <a href="/bank-statements">Customizing bank statement references</a> article for details.
      - `Shipping` ShippingDefaultsBillingUserResponse — **Default values:** `FirstName`, `LastName`, and `Address` information of the `Billing` object if sent, otherwise of the `AuthorId` (if address values present). Information about the shipping address.
        - `FirstName` string — The first name of the user.
        - `LastName` string — The last name of the user.
        - `Address` AddressSubPropsRequired — The postal address.
          - `AddressLine1` string, required — The first line of the address.
          - `AddressLine2` string — The second line of the address.
          - `City` string, required — The city of the address.
          - `Region` string — Required if `Country` is US, CA, or MX. The region of the address.
          - `PostalCode` string, required — The postal code of the address. The postal code can contain the following characters: alphanumeric, dashes, and spaces.
          - `Country` string, required — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The country of the address.
      - `Tag` string — Max. length: 255 characters Custom data that you can add to this object.
      - `ShippingPreference` string — **Returned values:** `SET_PROVIDED_ADDRESS`, `GET_FROM_FILE`, `NO_SHIPPING` Information about the shipping address behavior on the PayPal payment page: - `SET_PROVIDED_ADDRESS` - The `Shipping` parameter becomes required and its values are displayed to the end user, who is not able to modify them. - `GET_FROM_FILE` – The `Shipping` parameter is ignored and the end user can choose from registered addresses. - `NO_SHIPPING` – No shipping address section is displayed.
      - `PaypalBuyerAccountEmail` string — The email address registered on the PayPal account used to make the payment.
      - `Reference` string — Max. length: 127 characters (truncated after) The platform’s order reference for the transaction.
      - `CancelURL` string — The URL to which the user is returned after canceling the payment. If not provided, the Cancel button returns the user to the `RedirectURL`.
      - `PaypalOrderID` string — PayPal's unique identifier for the order.
      - `BuyerCountry` string — The country of the buyer.
      - `BuyerFirstname` string — The first name of the buyer.
      - `BuyerPhone` string — The mobile phone number of the buyer.
      - `BuyerLastname` string — The last name of the buyer.
      - `PaypalPayerID` string — The PayPal identifier of the buyer.
      - `Trackings` PayPalDepositPreauthorizationResponseTrackingsItems[] — Shipping information of the `LineItems` added to the pay-in object.
        - `TrackingNumber` string — The shipment’s tracking number provided by the carrier.
        - `Carrier` string — The carrier for the shipment. Use the country-specific version of the carrier if it exists, otherwise use its global version.
        - `NotifyBuyer` boolean — **Default value:** false If `true`, sends an email notification to the `PaypalBuyerAccountEmail` containing the `TrackingNumber` and `Carrier`, which allows the end user to track their shipment with the carrier.
      - `LineItems` PayPalDepositPreauthorizationResponseLineItemsItems[] — Information about the items purchased in the transaction. The total of all line items’ `UnitAmount` and `TaxAmount` must equal the `DebitedFunds` amount (negative amounts not allowed).
        - `Name` string — The name of the item.
        - `Quantity` integer — The quantity of the item.
        - `UnitAmount` integer — The cost of the item, excluding tax.
        - `TaxAmount` integer — The tax amount applied to the item.
        - `Description` string — The platform’s unique reference for the seller. This value must be consistently used for the given seller. You can use, for example, the Mangopay `UserId` or the seller’s business name or first name and last name. **Caution:** Failure to use a unique seller identifier may result in PayPal restricting your service.
        - `Category` string — **Allowed values:** PHYSICAL_GOODS, DIGITAL_GOODS, DONATION The category of the item: - `PHYSICAL_GOODS` – Tangible items that can be physically shipped and received with proof of delivery upon arrival. - `DIGITAL_GOODS` – Products or services that are distributed and consumed via digital platforms or devices. - `DONATION` – Voluntary contribution made without any goods or services received in return. Multiple line items can be categorized as `DONATION` within a single transaction, however it is not possible to combine `DONATION` other line item categories within the same transaction.
        - `Sku` string — The SKU or reference for the item on your platform.
        - `Discount` integer — The discount applied to the item, in the smallest currency sub-division.
      - `Culture` string — **Returned values:** One of the supported languages in the [ISO 639-1 format](/api-reference/overview/data-formats): AT, BR, CA, CH, CN, DE, DK, ES, FR, GB, ID, IL, IT, JK, JP, NL, NO, PL, PT, RU, SE, TH, TR, TW, US. The language in which the PayPal payment page is to be displayed.
      - `Billing` unknown
      - `RedirectURL` string — The URL to which to redirect the user to complete the payment. **Caution:** This variable URL is specific to each payment. You must rely on the returned URL in full (host, path, and queries) and not hardcode any part of it.
      - `ReturnURL` string — Max. length: 255 characters The URL to which the user is returned after the payment, whether the transaction is successful or not.

---

[API](https://skmtc.net/mangopay/apis/api-reference.md) · [All operations](https://skmtc.net/mangopay/apis/api-reference/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/mangopay/api-reference/versions/795281070285/schema)
