{
  "openapi": "3.0.3",
  "info": {
    "title": "sondahub Authorize.net sandbox",
    "version": "0.8.0",
    "description": "An independent imitation of Authorize.net’s API for testing, run by sondahub — not affiliated with or endorsed by Authorize.net, Visa or Cybersource. Nothing is charged and no Authorize.net account is involved.\n\nThe API is one endpoint, POST /xml/v1/request.api, taking XML or JSON; the answer comes back in the same format, starting with a byte order mark. Credentials ride in the body: merchantAuthentication with any API Login ID and a 16-character Transaction Key — sondahub / SandboxKey123456 works. Each call here has a path of its own after /xml/v1/request.api so an API client imports one request per call; the sandbox reads only the body.\n\nElements must come in schema order, in JSON too, as the real API checks (E00003 names the element it expected). Test cards from the testing guide work; ZIP 46282 declines; the AVS ZIPs and card codes 900–904 set those results; over $5,000 is held for review.\n\nWrites live in the X-Sondahub-Session token each answer carries: send the newest one back as a header and the next request sees what you made; without it every request starts from the seed account. More at https://sondahub.com/sandboxes/authorizenet/",
    "contact": {
      "name": "sondahub",
      "url": "https://sondahub.com/sandboxes/authorizenet/"
    }
  },
  "externalDocs": {
    "description": "The sandbox, in full",
    "url": "https://sondahub.com/sandboxes/authorizenet/"
  },
  "servers": [
    {
      "url": "https://api.sondahub.com"
    }
  ],
  "security": [
    {
      "anetBasic": []
    }
  ],
  "tags": [
    {
      "name": "Merchant",
      "description": "The credentials and the account."
    },
    {
      "name": "Payment Transactions",
      "description": "createTransactionRequest: charge, authorize, capture, void and refund cards, eChecks, Accept nonces and stored payment profiles. ZIP 46282 declines; AVS ZIPs and card codes 900–904 set those results."
    },
    {
      "name": "Transaction Reporting",
      "description": "Transactions, batches and statistics. Batches close every minute (the seed’s close daily), so a capture is settled about a minute later."
    },
    {
      "name": "Accept",
      "description": "Payment nonces and the hosted payment form."
    },
    {
      "name": "Customer Profiles",
      "description": "Customer Information Manager: profiles, payment profiles (masked on the way out) and shipping addresses. validationMode testMode checks the card; liveMode runs a zero-dollar authorization the triggers apply to."
    },
    {
      "name": "Recurring Billing",
      "description": "Automated Recurring Billing: subscriptions, with the schedule checks the real service makes. The sandbox keeps and reports them; it doesn’t run their payments."
    },
    {
      "name": "Webhooks",
      "description": "The REST API under /rest/v1 (Basic auth: API Login ID and Transaction Key). Notifications are signed with X-ANET-Signature: sha512=HMAC-SHA512 of the body with the Signature Key."
    },
    {
      "name": "Sandbox tools",
      "description": "sondahub’s own: not part of Authorize.net’s API."
    }
  ],
  "paths": {
    "/xml/v1/request.api/authenticateTest": {
      "post": {
        "tags": [
          "Merchant"
        ],
        "summary": "Test the credentials",
        "operationId": "AuthenticateTest",
        "description": "Ok when the API Login ID and Transaction Key are good: the sandbox takes any login of up to 25 characters with a 16-character key.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "authenticateTestRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "authenticateTestRequest"
                ],
                "example": {
                  "authenticateTestRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    }
                  }
                }
              },
              "example": {
                "authenticateTestRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/getMerchantDetails": {
      "post": {
        "tags": [
          "Merchant"
        ],
        "summary": "Get the merchant’s details",
        "operationId": "GetMerchantDetails",
        "description": "Payment methods, currencies, the time zone, and publicClientKey for Accept.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "getMerchantDetailsRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "getMerchantDetailsRequest"
                ],
                "example": {
                  "getMerchantDetailsRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    }
                  }
                }
              },
              "example": {
                "getMerchantDetailsRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/createTransaction/charge": {
      "post": {
        "tags": [
          "Payment Transactions"
        ],
        "summary": "Charge a credit card",
        "operationId": "CreateTransactionCharge",
        "description": "authCaptureTransaction: approved, captured, and settled in the batch that closes a minute later. duplicateWindow 0 lets you send it again; by default the same charge within 120 s is a duplicate (reason 11).\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "createTransactionRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "createTransactionRequest"
                ],
                "example": {
                  "createTransactionRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "refId": "123456",
                    "transactionRequest": {
                      "transactionType": "authCaptureTransaction",
                      "amount": "24.00",
                      "payment": {
                        "creditCard": {
                          "cardNumber": "4111111111111111",
                          "expirationDate": "2030-12",
                          "cardCode": "999"
                        }
                      },
                      "order": {
                        "invoiceNumber": "INV-1001",
                        "description": "Sandbox socks"
                      },
                      "lineItems": {
                        "lineItem": [
                          {
                            "itemId": "1",
                            "name": "Sandbox socks",
                            "description": "Two pairs",
                            "quantity": "2",
                            "unitPrice": "12.00"
                          }
                        ]
                      },
                      "customer": {
                        "type": "individual",
                        "id": "CUST-42",
                        "email": "ada@example.com"
                      },
                      "billTo": {
                        "firstName": "Ada",
                        "lastName": "Lovelace",
                        "company": "Example Labs",
                        "address": "14 Main Street",
                        "city": "Pecan Springs",
                        "state": "TX",
                        "zip": "44628",
                        "country": "US"
                      },
                      "shipTo": {
                        "firstName": "Ada",
                        "lastName": "Lovelace",
                        "address": "12 Dock Street",
                        "city": "Pecan Springs",
                        "state": "TX",
                        "zip": "44628",
                        "country": "US"
                      },
                      "customerIP": "192.0.2.10",
                      "transactionSettings": {
                        "setting": [
                          {
                            "settingName": "duplicateWindow",
                            "settingValue": "0"
                          }
                        ]
                      },
                      "userFields": {
                        "userField": [
                          {
                            "name": "cart",
                            "value": "web"
                          }
                        ]
                      }
                    }
                  }
                }
              },
              "example": {
                "createTransactionRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "refId": "123456",
                  "transactionRequest": {
                    "transactionType": "authCaptureTransaction",
                    "amount": "24.00",
                    "payment": {
                      "creditCard": {
                        "cardNumber": "4111111111111111",
                        "expirationDate": "2030-12",
                        "cardCode": "999"
                      }
                    },
                    "order": {
                      "invoiceNumber": "INV-1001",
                      "description": "Sandbox socks"
                    },
                    "lineItems": {
                      "lineItem": [
                        {
                          "itemId": "1",
                          "name": "Sandbox socks",
                          "description": "Two pairs",
                          "quantity": "2",
                          "unitPrice": "12.00"
                        }
                      ]
                    },
                    "customer": {
                      "type": "individual",
                      "id": "CUST-42",
                      "email": "ada@example.com"
                    },
                    "billTo": {
                      "firstName": "Ada",
                      "lastName": "Lovelace",
                      "company": "Example Labs",
                      "address": "14 Main Street",
                      "city": "Pecan Springs",
                      "state": "TX",
                      "zip": "44628",
                      "country": "US"
                    },
                    "shipTo": {
                      "firstName": "Ada",
                      "lastName": "Lovelace",
                      "address": "12 Dock Street",
                      "city": "Pecan Springs",
                      "state": "TX",
                      "zip": "44628",
                      "country": "US"
                    },
                    "customerIP": "192.0.2.10",
                    "transactionSettings": {
                      "setting": [
                        {
                          "settingName": "duplicateWindow",
                          "settingValue": "0"
                        }
                      ]
                    },
                    "userFields": {
                      "userField": [
                        {
                          "name": "cart",
                          "value": "web"
                        }
                      ]
                    }
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/createTransaction/authorize": {
      "post": {
        "tags": [
          "Payment Transactions"
        ],
        "summary": "Authorize a credit card",
        "operationId": "CreateTransactionAuthorize",
        "description": "authOnlyTransaction: held for 30 days for a prior-auth capture. Card code 900 answers cvvResultCode M.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "createTransactionRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "createTransactionRequest"
                ],
                "example": {
                  "createTransactionRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "transactionRequest": {
                      "transactionType": "authOnlyTransaction",
                      "amount": "75.00",
                      "payment": {
                        "creditCard": {
                          "cardNumber": "5424000000000015",
                          "expirationDate": "2031-06",
                          "cardCode": "900"
                        }
                      },
                      "billTo": {
                        "firstName": "Ada",
                        "lastName": "Lovelace",
                        "company": "Example Labs",
                        "address": "14 Main Street",
                        "city": "Pecan Springs",
                        "state": "TX",
                        "zip": "44628",
                        "country": "US"
                      }
                    }
                  }
                }
              },
              "example": {
                "createTransactionRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "transactionRequest": {
                    "transactionType": "authOnlyTransaction",
                    "amount": "75.00",
                    "payment": {
                      "creditCard": {
                        "cardNumber": "5424000000000015",
                        "expirationDate": "2031-06",
                        "cardCode": "900"
                      }
                    },
                    "billTo": {
                      "firstName": "Ada",
                      "lastName": "Lovelace",
                      "company": "Example Labs",
                      "address": "14 Main Street",
                      "city": "Pecan Springs",
                      "state": "TX",
                      "zip": "44628",
                      "country": "US"
                    }
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/createTransaction/capture": {
      "post": {
        "tags": [
          "Payment Transactions"
        ],
        "summary": "Capture a prior authorization",
        "operationId": "CreateTransactionCapture",
        "description": "priorAuthCaptureTransaction: answers with the authorization’s own transId. The seed’s authorization is $129.00; more than that is reason 47, a second capture is reason 311.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "createTransactionRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "createTransactionRequest"
                ],
                "example": {
                  "createTransactionRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "transactionRequest": {
                      "transactionType": "priorAuthCaptureTransaction",
                      "amount": "100.00",
                      "refTransId": "63486784401"
                    }
                  }
                }
              },
              "example": {
                "createTransactionRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "transactionRequest": {
                    "transactionType": "priorAuthCaptureTransaction",
                    "amount": "100.00",
                    "refTransId": "63486784401"
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/createTransaction/void": {
      "post": {
        "tags": [
          "Payment Transactions"
        ],
        "summary": "Void a transaction",
        "operationId": "CreateTransactionVoid",
        "description": "voidTransaction: anything not yet settled (an authorization, a capture waiting for its batch, a held payment). A settled one is reason 16; voiding twice is reason 310.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "createTransactionRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "createTransactionRequest"
                ],
                "example": {
                  "createTransactionRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "transactionRequest": {
                      "transactionType": "voidTransaction",
                      "refTransId": "66973568802"
                    }
                  }
                }
              },
              "example": {
                "createTransactionRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "transactionRequest": {
                    "transactionType": "voidTransaction",
                    "refTransId": "66973568802"
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/createTransaction/refund": {
      "post": {
        "tags": [
          "Payment Transactions"
        ],
        "summary": "Refund a settled transaction",
        "operationId": "CreateTransactionRefund",
        "description": "refundTransaction: a new transaction against a settled one, naming its card by the last four digits. Unsettled is reason 54 (void it instead); more than is left is reason 55. The seed’s refundable payment is $49.99 on card 1111.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "createTransactionRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "createTransactionRequest"
                ],
                "example": {
                  "createTransactionRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "transactionRequest": {
                      "transactionType": "refundTransaction",
                      "amount": "5.00",
                      "payment": {
                        "creditCard": {
                          "cardNumber": "1111",
                          "expirationDate": "XXXX"
                        }
                      },
                      "refTransId": "67433922005"
                    }
                  }
                }
              },
              "example": {
                "createTransactionRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "transactionRequest": {
                    "transactionType": "refundTransaction",
                    "amount": "5.00",
                    "payment": {
                      "creditCard": {
                        "cardNumber": "1111",
                        "expirationDate": "XXXX"
                      }
                    },
                    "refTransId": "67433922005"
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/createTransaction/captureOnly": {
      "post": {
        "tags": [
          "Payment Transactions"
        ],
        "summary": "Capture funds authorized elsewhere",
        "operationId": "CreateTransactionCaptureOnly",
        "description": "captureOnlyTransaction: needs the authCode the other channel gave (reason 12 without it).\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "createTransactionRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "createTransactionRequest"
                ],
                "example": {
                  "createTransactionRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "transactionRequest": {
                      "transactionType": "captureOnlyTransaction",
                      "amount": "18.00",
                      "payment": {
                        "creditCard": {
                          "cardNumber": "4007000000027",
                          "expirationDate": "2030-08"
                        }
                      },
                      "authCode": "ROHNFQ"
                    }
                  }
                }
              },
              "example": {
                "createTransactionRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "transactionRequest": {
                    "transactionType": "captureOnlyTransaction",
                    "amount": "18.00",
                    "payment": {
                      "creditCard": {
                        "cardNumber": "4007000000027",
                        "expirationDate": "2030-08"
                      }
                    },
                    "authCode": "ROHNFQ"
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/createTransaction/echeck": {
      "post": {
        "tags": [
          "Payment Transactions"
        ],
        "summary": "Debit a bank account (eCheck)",
        "operationId": "CreateTransactionEcheck",
        "description": "An eCheck: the routing number must pass the ABA check (reason 9). Over $100 declines, as the testing guide says. eChecks settle in batches of their own.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "createTransactionRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "createTransactionRequest"
                ],
                "example": {
                  "createTransactionRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "transactionRequest": {
                      "transactionType": "authCaptureTransaction",
                      "amount": "45.00",
                      "payment": {
                        "bankAccount": {
                          "accountType": "checking",
                          "routingNumber": "121042882",
                          "accountNumber": "123456789",
                          "nameOnAccount": "Ada Lovelace",
                          "echeckType": "WEB"
                        }
                      }
                    }
                  }
                }
              },
              "example": {
                "createTransactionRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "transactionRequest": {
                    "transactionType": "authCaptureTransaction",
                    "amount": "45.00",
                    "payment": {
                      "bankAccount": {
                        "accountType": "checking",
                        "routingNumber": "121042882",
                        "accountNumber": "123456789",
                        "nameOnAccount": "Ada Lovelace",
                        "echeckType": "WEB"
                      }
                    }
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/createTransaction/profile": {
      "post": {
        "tags": [
          "Payment Transactions"
        ],
        "summary": "Charge a customer profile",
        "operationId": "CreateTransactionProfile",
        "description": "Charge a stored payment profile (and ship to a stored address). payment and billTo can’t come with it (E00090, E00093).\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "createTransactionRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "createTransactionRequest"
                ],
                "example": {
                  "createTransactionRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "transactionRequest": {
                      "transactionType": "authCaptureTransaction",
                      "amount": "32.00",
                      "profile": {
                        "customerProfileId": "1986784401",
                        "paymentProfile": {
                          "paymentProfileId": "1886784401"
                        },
                        "shippingProfileId": "1786784401"
                      }
                    }
                  }
                }
              },
              "example": {
                "createTransactionRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "transactionRequest": {
                    "transactionType": "authCaptureTransaction",
                    "amount": "32.00",
                    "profile": {
                      "customerProfileId": "1986784401",
                      "paymentProfile": {
                        "paymentProfileId": "1886784401"
                      },
                      "shippingProfileId": "1786784401"
                    }
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/createTransaction/createProfile": {
      "post": {
        "tags": [
          "Payment Transactions"
        ],
        "summary": "Charge and save the card as a profile",
        "operationId": "CreateTransactionCreateProfile",
        "description": "profile.createProfile: the answer adds profileResponse with the new customer profile’s ids.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "createTransactionRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "createTransactionRequest"
                ],
                "example": {
                  "createTransactionRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "transactionRequest": {
                      "transactionType": "authCaptureTransaction",
                      "amount": "19.00",
                      "payment": {
                        "creditCard": {
                          "cardNumber": "6011000000000012",
                          "expirationDate": "2032-03"
                        }
                      },
                      "profile": {
                        "createProfile": true
                      },
                      "customer": {
                        "id": "CUST-NEW-1",
                        "email": "grace@example.com"
                      },
                      "billTo": {
                        "firstName": "Ada",
                        "lastName": "Lovelace",
                        "company": "Example Labs",
                        "address": "14 Main Street",
                        "city": "Pecan Springs",
                        "state": "TX",
                        "zip": "44628",
                        "country": "US"
                      }
                    }
                  }
                }
              },
              "example": {
                "createTransactionRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "transactionRequest": {
                    "transactionType": "authCaptureTransaction",
                    "amount": "19.00",
                    "payment": {
                      "creditCard": {
                        "cardNumber": "6011000000000012",
                        "expirationDate": "2032-03"
                      }
                    },
                    "profile": {
                      "createProfile": true
                    },
                    "customer": {
                      "id": "CUST-NEW-1",
                      "email": "grace@example.com"
                    },
                    "billTo": {
                      "firstName": "Ada",
                      "lastName": "Lovelace",
                      "company": "Example Labs",
                      "address": "14 Main Street",
                      "city": "Pecan Springs",
                      "state": "TX",
                      "zip": "44628",
                      "country": "US"
                    }
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/createTransaction/decline": {
      "post": {
        "tags": [
          "Payment Transactions"
        ],
        "summary": "A declined charge (ZIP 46282)",
        "operationId": "CreateTransactionDecline",
        "description": "billTo.zip 46282 declines: responseCode 2, errors [{errorCode 2}], messages E00027. 46205 (AVS N) and 46203 (AVS E) decline with reason 27; card code 901 declines with reason 65.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "createTransactionRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "createTransactionRequest"
                ],
                "example": {
                  "createTransactionRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "transactionRequest": {
                      "transactionType": "authCaptureTransaction",
                      "amount": "9.00",
                      "payment": {
                        "creditCard": {
                          "cardNumber": "4111111111111111",
                          "expirationDate": "2030-12",
                          "cardCode": "999"
                        }
                      },
                      "billTo": {
                        "firstName": "Ada",
                        "lastName": "Lovelace",
                        "company": "Example Labs",
                        "address": "14 Main Street",
                        "city": "Pecan Springs",
                        "state": "TX",
                        "zip": "46282",
                        "country": "US"
                      }
                    }
                  }
                }
              },
              "example": {
                "createTransactionRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "transactionRequest": {
                    "transactionType": "authCaptureTransaction",
                    "amount": "9.00",
                    "payment": {
                      "creditCard": {
                        "cardNumber": "4111111111111111",
                        "expirationDate": "2030-12",
                        "cardCode": "999"
                      }
                    },
                    "billTo": {
                      "firstName": "Ada",
                      "lastName": "Lovelace",
                      "company": "Example Labs",
                      "address": "14 Main Street",
                      "city": "Pecan Springs",
                      "state": "TX",
                      "zip": "46282",
                      "country": "US"
                    }
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/createTransaction/held": {
      "post": {
        "tags": [
          "Payment Transactions"
        ],
        "summary": "A payment held for review",
        "operationId": "CreateTransactionHeld",
        "description": "Over $5,000 the sandbox’s Amount Filter authorizes and holds it: responseCode 4, reason 252, FDSAuthorizedPendingReview. Approve or decline it with updateHeldTransaction.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "createTransactionRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "createTransactionRequest"
                ],
                "example": {
                  "createTransactionRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "transactionRequest": {
                      "transactionType": "authCaptureTransaction",
                      "amount": "6000.00",
                      "payment": {
                        "creditCard": {
                          "cardNumber": "4111111111111111",
                          "expirationDate": "2030-12",
                          "cardCode": "999"
                        }
                      }
                    }
                  }
                }
              },
              "example": {
                "createTransactionRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "transactionRequest": {
                    "transactionType": "authCaptureTransaction",
                    "amount": "6000.00",
                    "payment": {
                      "creditCard": {
                        "cardNumber": "4111111111111111",
                        "expirationDate": "2030-12",
                        "cardCode": "999"
                      }
                    }
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/updateHeldTransaction": {
      "post": {
        "tags": [
          "Payment Transactions"
        ],
        "summary": "Approve or decline a held payment",
        "operationId": "UpdateHeldTransaction",
        "description": "action approve or decline. The seed has a $6,250.00 payment held for review.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "updateHeldTransactionRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "updateHeldTransactionRequest"
                ],
                "example": {
                  "updateHeldTransactionRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "heldTransactionRequest": {
                      "action": "approve",
                      "refTransId": "63947137604"
                    }
                  }
                }
              },
              "example": {
                "updateHeldTransactionRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "heldTransactionRequest": {
                    "action": "approve",
                    "refTransId": "63947137604"
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/sendCustomerTransactionReceipt": {
      "post": {
        "tags": [
          "Payment Transactions"
        ],
        "summary": "Email a receipt",
        "operationId": "SendCustomerTransactionReceipt",
        "description": "Answers Ok. The sandbox sends no email.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "sendCustomerTransactionReceiptRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "sendCustomerTransactionReceiptRequest"
                ],
                "example": {
                  "sendCustomerTransactionReceiptRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "transId": "67433922005",
                    "customerEmail": "ada@example.com",
                    "emailSettings": {
                      "setting": [
                        {
                          "settingName": "headerEmailReceipt",
                          "settingValue": "Thanks for your order"
                        }
                      ]
                    }
                  }
                }
              },
              "example": {
                "sendCustomerTransactionReceiptRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "transId": "67433922005",
                  "customerEmail": "ada@example.com",
                  "emailSettings": {
                    "setting": [
                      {
                        "settingName": "headerEmailReceipt",
                        "settingValue": "Thanks for your order"
                      }
                    ]
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/getTransactionDetails": {
      "post": {
        "tags": [
          "Transaction Reporting"
        ],
        "summary": "Get a transaction",
        "operationId": "GetTransactionDetails",
        "description": "Status, amounts, the masked payment, the batch it settled in, the profile it came from.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "getTransactionDetailsRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "getTransactionDetailsRequest"
                ],
                "example": {
                  "getTransactionDetailsRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "transId": "67433922005"
                  }
                }
              },
              "example": {
                "getTransactionDetailsRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "transId": "67433922005"
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/getUnsettledTransactionList": {
      "post": {
        "tags": [
          "Transaction Reporting"
        ],
        "summary": "List unsettled transactions",
        "operationId": "GetUnsettledTransactionList",
        "description": "Everything not yet in a settled batch. status pendingApproval lists only the ones held for review.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "getUnsettledTransactionListRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "getUnsettledTransactionListRequest"
                ],
                "example": {
                  "getUnsettledTransactionListRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "sorting": {
                      "orderBy": "submitTimeUTC",
                      "orderDescending": true
                    },
                    "paging": {
                      "limit": "20",
                      "offset": "1"
                    }
                  }
                }
              },
              "example": {
                "getUnsettledTransactionListRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "sorting": {
                    "orderBy": "submitTimeUTC",
                    "orderDescending": true
                  },
                  "paging": {
                    "limit": "20",
                    "offset": "1"
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/getSettledBatchList": {
      "post": {
        "tags": [
          "Transaction Reporting"
        ],
        "summary": "List settled batches",
        "operationId": "GetSettledBatchList",
        "description": "Without dates, the last 24 hours. Up to 31 days at once.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "getSettledBatchListRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "getSettledBatchListRequest"
                ],
                "example": {
                  "getSettledBatchListRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "includeStatistics": true,
                    "firstSettlementDate": "2026-09-25T01:32:26",
                    "lastSettlementDate": "2026-10-02T01:32:26"
                  }
                }
              },
              "example": {
                "getSettledBatchListRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "includeStatistics": true,
                  "firstSettlementDate": "2026-09-25T01:32:26",
                  "lastSettlementDate": "2026-10-02T01:32:26"
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/getTransactionList": {
      "post": {
        "tags": [
          "Transaction Reporting"
        ],
        "summary": "List a batch’s transactions",
        "operationId": "GetTransactionList",
        "description": "Batch ids come from getSettledBatchList; this one is the seed’s latest.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "getTransactionListRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "getTransactionListRequest"
                ],
                "example": {
                  "getTransactionListRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "batchId": "298470000",
                    "sorting": {
                      "orderBy": "id",
                      "orderDescending": false
                    },
                    "paging": {
                      "limit": "100",
                      "offset": "1"
                    }
                  }
                }
              },
              "example": {
                "getTransactionListRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "batchId": "298470000",
                  "sorting": {
                    "orderBy": "id",
                    "orderDescending": false
                  },
                  "paging": {
                    "limit": "100",
                    "offset": "1"
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/getBatchStatistics": {
      "post": {
        "tags": [
          "Transaction Reporting"
        ],
        "summary": "Get a batch’s statistics",
        "operationId": "GetBatchStatistics",
        "description": "Charges, refunds, voids, declines and errors per card type.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "getBatchStatisticsRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "getBatchStatisticsRequest"
                ],
                "example": {
                  "getBatchStatisticsRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "batchId": "298470000"
                  }
                }
              },
              "example": {
                "getBatchStatisticsRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "batchId": "298470000"
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/getTransactionListForCustomer": {
      "post": {
        "tags": [
          "Transaction Reporting"
        ],
        "summary": "List a customer profile’s transactions",
        "operationId": "GetTransactionListForCustomer",
        "description": "Transactions charged to the profile’s payment profiles.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "getTransactionListForCustomerRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "getTransactionListForCustomerRequest"
                ],
                "example": {
                  "getTransactionListForCustomerRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "customerProfileId": "1986784401",
                    "paging": {
                      "limit": "100",
                      "offset": "1"
                    }
                  }
                }
              },
              "example": {
                "getTransactionListForCustomerRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "customerProfileId": "1986784401",
                  "paging": {
                    "limit": "100",
                    "offset": "1"
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/securePaymentContainer": {
      "post": {
        "tags": [
          "Accept"
        ],
        "summary": "Make a payment nonce",
        "operationId": "SecurePaymentContainer",
        "description": "What Accept.js does from the browser: card details in, opaqueData out (COMMON.ACCEPT.INAPP.PAYMENT), good once within 15 minutes as payment.opaqueData. Authenticates with the API Login ID and the public client key (getMerchantDetails); the sandbox takes any client key.\n\nThe path after /xml/v1/request.api is sondahub’s label for importing: the sandbox reads only the body.",
        "responses": {
          "200": {
            "description": "Always 200: opaqueData, or messages with the error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "securePaymentContainerRequest": {
                    "type": "object",
                    "description": "merchantAuthentication (name, clientKey), refId, data."
                  }
                },
                "required": [
                  "securePaymentContainerRequest"
                ],
                "example": {
                  "securePaymentContainerRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "clientKey": "any-public-client-key"
                    },
                    "refId": "12345",
                    "data": {
                      "type": "TOKEN",
                      "id": "4be4d6d7-6a2e-4b7a-9f0a-1c2d3e4f5a6b",
                      "token": {
                        "cardNumber": "5424000000000015",
                        "expirationDate": "1230",
                        "cardCode": "999",
                        "zip": "98004",
                        "fullName": "Ada Lovelace"
                      }
                    }
                  }
                }
              },
              "example": {
                "securePaymentContainerRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "clientKey": "any-public-client-key"
                  },
                  "refId": "12345",
                  "data": {
                    "type": "TOKEN",
                    "id": "4be4d6d7-6a2e-4b7a-9f0a-1c2d3e4f5a6b",
                    "token": {
                      "cardNumber": "5424000000000015",
                      "expirationDate": "1230",
                      "cardCode": "999",
                      "zip": "98004",
                      "fullName": "Ada Lovelace"
                    }
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/getHostedPaymentPage": {
      "post": {
        "tags": [
          "Accept"
        ],
        "summary": "Get a hosted payment form token",
        "operationId": "GetHostedPaymentPage",
        "description": "A token (good for 15 minutes) for the browser to post, in a form field named token, to the hosted form — in the sandbox /sandbox/authorizenet/payment/payment. No payment details may come with it (E00119).\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "getHostedPaymentPageRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "getHostedPaymentPageRequest"
                ],
                "example": {
                  "getHostedPaymentPageRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "transactionRequest": {
                      "transactionType": "authCaptureTransaction",
                      "amount": "20.00",
                      "order": {
                        "invoiceNumber": "INV-2001",
                        "description": "Workshop seat"
                      },
                      "customer": {
                        "email": "ada@example.com"
                      },
                      "billTo": {
                        "firstName": "Ada",
                        "lastName": "Lovelace",
                        "company": "Example Labs",
                        "address": "14 Main Street",
                        "city": "Pecan Springs",
                        "state": "TX",
                        "zip": "44628",
                        "country": "US"
                      }
                    },
                    "hostedPaymentSettings": {
                      "setting": [
                        {
                          "settingName": "hostedPaymentReturnOptions",
                          "settingValue": "{\"showReceipt\": true, \"url\": \"https://example.com/receipt\", \"urlText\": \"Continue\", \"cancelUrl\": \"https://example.com/cancel\", \"cancelUrlText\": \"Cancel\"}"
                        },
                        {
                          "settingName": "hostedPaymentButtonOptions",
                          "settingValue": "{\"text\": \"Pay\"}"
                        },
                        {
                          "settingName": "hostedPaymentPaymentOptions",
                          "settingValue": "{\"cardCodeRequired\": false}"
                        }
                      ]
                    }
                  }
                }
              },
              "example": {
                "getHostedPaymentPageRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "transactionRequest": {
                    "transactionType": "authCaptureTransaction",
                    "amount": "20.00",
                    "order": {
                      "invoiceNumber": "INV-2001",
                      "description": "Workshop seat"
                    },
                    "customer": {
                      "email": "ada@example.com"
                    },
                    "billTo": {
                      "firstName": "Ada",
                      "lastName": "Lovelace",
                      "company": "Example Labs",
                      "address": "14 Main Street",
                      "city": "Pecan Springs",
                      "state": "TX",
                      "zip": "44628",
                      "country": "US"
                    }
                  },
                  "hostedPaymentSettings": {
                    "setting": [
                      {
                        "settingName": "hostedPaymentReturnOptions",
                        "settingValue": "{\"showReceipt\": true, \"url\": \"https://example.com/receipt\", \"urlText\": \"Continue\", \"cancelUrl\": \"https://example.com/cancel\", \"cancelUrlText\": \"Cancel\"}"
                      },
                      {
                        "settingName": "hostedPaymentButtonOptions",
                        "settingValue": "{\"text\": \"Pay\"}"
                      },
                      {
                        "settingName": "hostedPaymentPaymentOptions",
                        "settingValue": "{\"cardCodeRequired\": false}"
                      }
                    ]
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/createCustomerProfile": {
      "post": {
        "tags": [
          "Customer Profiles"
        ],
        "summary": "Create a customer profile",
        "operationId": "CreateCustomerProfile",
        "description": "With payment profiles and shipping addresses in one go. A second profile with the same merchantCustomerId is E00039 (its text names the existing profile’s id).\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "createCustomerProfileRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "createCustomerProfileRequest"
                ],
                "example": {
                  "createCustomerProfileRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "profile": {
                      "merchantCustomerId": "CUST-5001",
                      "description": "Grace Hopper",
                      "email": "grace@example.com",
                      "paymentProfiles": [
                        {
                          "customerType": "individual",
                          "billTo": {
                            "firstName": "Ada",
                            "lastName": "Lovelace",
                            "company": "Example Labs",
                            "address": "14 Main Street",
                            "city": "Pecan Springs",
                            "state": "TX",
                            "zip": "44628",
                            "country": "US"
                          },
                          "payment": {
                            "creditCard": {
                              "cardNumber": "370000000000002",
                              "expirationDate": "2031-09"
                            }
                          },
                          "defaultPaymentProfile": true
                        }
                      ],
                      "shipToList": [
                        {
                          "firstName": "Ada",
                          "lastName": "Lovelace",
                          "address": "12 Dock Street",
                          "city": "Pecan Springs",
                          "state": "TX",
                          "zip": "44628",
                          "country": "US"
                        }
                      ]
                    },
                    "validationMode": "testMode"
                  }
                }
              },
              "example": {
                "createCustomerProfileRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "profile": {
                    "merchantCustomerId": "CUST-5001",
                    "description": "Grace Hopper",
                    "email": "grace@example.com",
                    "paymentProfiles": [
                      {
                        "customerType": "individual",
                        "billTo": {
                          "firstName": "Ada",
                          "lastName": "Lovelace",
                          "company": "Example Labs",
                          "address": "14 Main Street",
                          "city": "Pecan Springs",
                          "state": "TX",
                          "zip": "44628",
                          "country": "US"
                        },
                        "payment": {
                          "creditCard": {
                            "cardNumber": "370000000000002",
                            "expirationDate": "2031-09"
                          }
                        },
                        "defaultPaymentProfile": true
                      }
                    ],
                    "shipToList": [
                      {
                        "firstName": "Ada",
                        "lastName": "Lovelace",
                        "address": "12 Dock Street",
                        "city": "Pecan Springs",
                        "state": "TX",
                        "zip": "44628",
                        "country": "US"
                      }
                    ]
                  },
                  "validationMode": "testMode"
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/getCustomerProfile": {
      "post": {
        "tags": [
          "Customer Profiles"
        ],
        "summary": "Get a customer profile",
        "operationId": "GetCustomerProfile",
        "description": "By customerProfileId, merchantCustomerId or email. Cards come back as XXXX1111; unmaskExpirationDate shows the date, includeIssuerInfo the first six digits.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "getCustomerProfileRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "getCustomerProfileRequest"
                ],
                "example": {
                  "getCustomerProfileRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "customerProfileId": "1986784401",
                    "unmaskExpirationDate": true,
                    "includeIssuerInfo": true
                  }
                }
              },
              "example": {
                "getCustomerProfileRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "customerProfileId": "1986784401",
                  "unmaskExpirationDate": true,
                  "includeIssuerInfo": true
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/getCustomerProfileIds": {
      "post": {
        "tags": [
          "Customer Profiles"
        ],
        "summary": "List customer profile ids",
        "operationId": "GetCustomerProfileIds",
        "description": "Every profile id.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "getCustomerProfileIdsRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "getCustomerProfileIdsRequest"
                ],
                "example": {
                  "getCustomerProfileIdsRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    }
                  }
                }
              },
              "example": {
                "getCustomerProfileIdsRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/updateCustomerProfile": {
      "post": {
        "tags": [
          "Customer Profiles"
        ],
        "summary": "Update a customer profile",
        "operationId": "UpdateCustomerProfile",
        "description": "merchantCustomerId, description and email: the ones you leave out are cleared, as with the real call.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "updateCustomerProfileRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "updateCustomerProfileRequest"
                ],
                "example": {
                  "updateCustomerProfileRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "profile": {
                      "merchantCustomerId": "CUST-1001",
                      "description": "Updated from the sandbox",
                      "email": "updated@example.com",
                      "customerProfileId": "1986784401"
                    }
                  }
                }
              },
              "example": {
                "updateCustomerProfileRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "profile": {
                    "merchantCustomerId": "CUST-1001",
                    "description": "Updated from the sandbox",
                    "email": "updated@example.com",
                    "customerProfileId": "1986784401"
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/deleteCustomerProfile": {
      "post": {
        "tags": [
          "Customer Profiles"
        ],
        "summary": "Delete a customer profile",
        "operationId": "DeleteCustomerProfile",
        "description": "With its payment profiles and addresses. One an active subscription uses is E00106.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "deleteCustomerProfileRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "deleteCustomerProfileRequest"
                ],
                "example": {
                  "deleteCustomerProfileRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "customerProfileId": "1920706406"
                  }
                }
              },
              "example": {
                "deleteCustomerProfileRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "customerProfileId": "1920706406"
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/createCustomerPaymentProfile": {
      "post": {
        "tags": [
          "Customer Profiles"
        ],
        "summary": "Add a payment profile",
        "operationId": "CreateCustomerPaymentProfile",
        "description": "liveMode answers validationDirectResponse (the comma-delimited direct response); a decline is E00027 and nothing is saved. The same card, date and billing address again is E00039.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "createCustomerPaymentProfileRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "createCustomerPaymentProfileRequest"
                ],
                "example": {
                  "createCustomerPaymentProfileRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "customerProfileId": "1986784401",
                    "paymentProfile": {
                      "customerType": "individual",
                      "billTo": {
                        "firstName": "Ada",
                        "lastName": "Lovelace",
                        "company": "Example Labs",
                        "address": "14 Main Street",
                        "city": "Pecan Springs",
                        "state": "TX",
                        "zip": "44628",
                        "country": "US"
                      },
                      "payment": {
                        "creditCard": {
                          "cardNumber": "6011000000000012",
                          "expirationDate": "2032-01",
                          "cardCode": "900"
                        }
                      }
                    },
                    "validationMode": "liveMode"
                  }
                }
              },
              "example": {
                "createCustomerPaymentProfileRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "customerProfileId": "1986784401",
                  "paymentProfile": {
                    "customerType": "individual",
                    "billTo": {
                      "firstName": "Ada",
                      "lastName": "Lovelace",
                      "company": "Example Labs",
                      "address": "14 Main Street",
                      "city": "Pecan Springs",
                      "state": "TX",
                      "zip": "44628",
                      "country": "US"
                    },
                    "payment": {
                      "creditCard": {
                        "cardNumber": "6011000000000012",
                        "expirationDate": "2032-01",
                        "cardCode": "900"
                      }
                    }
                  },
                  "validationMode": "liveMode"
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/getCustomerPaymentProfile": {
      "post": {
        "tags": [
          "Customer Profiles"
        ],
        "summary": "Get a payment profile",
        "operationId": "GetCustomerPaymentProfile",
        "description": "Masked card or bank account, billing address, subscriptions that use it.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "getCustomerPaymentProfileRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "getCustomerPaymentProfileRequest"
                ],
                "example": {
                  "getCustomerPaymentProfileRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "customerProfileId": "1986784401",
                    "customerPaymentProfileId": "1886784401",
                    "unmaskExpirationDate": true
                  }
                }
              },
              "example": {
                "getCustomerPaymentProfileRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "customerProfileId": "1986784401",
                  "customerPaymentProfileId": "1886784401",
                  "unmaskExpirationDate": true
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/getCustomerPaymentProfileList": {
      "post": {
        "tags": [
          "Customer Profiles"
        ],
        "summary": "List cards expiring in a month",
        "operationId": "GetCustomerPaymentProfileList",
        "description": "searchType cardsExpiringInMonth with month YYYY-MM.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "getCustomerPaymentProfileListRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "getCustomerPaymentProfileListRequest"
                ],
                "example": {
                  "getCustomerPaymentProfileListRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "searchType": "cardsExpiringInMonth",
                    "month": "2028-06",
                    "sorting": {
                      "orderBy": "id",
                      "orderDescending": false
                    },
                    "paging": {
                      "limit": "100",
                      "offset": "1"
                    }
                  }
                }
              },
              "example": {
                "getCustomerPaymentProfileListRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "searchType": "cardsExpiringInMonth",
                  "month": "2028-06",
                  "sorting": {
                    "orderBy": "id",
                    "orderDescending": false
                  },
                  "paging": {
                    "limit": "100",
                    "offset": "1"
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/updateCustomerPaymentProfile": {
      "post": {
        "tags": [
          "Customer Profiles"
        ],
        "summary": "Update a payment profile",
        "operationId": "UpdateCustomerPaymentProfile",
        "description": "The masked number keeps the card; a real date replaces its expiration (XXXX keeps it). The billing address is replaced.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "updateCustomerPaymentProfileRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "updateCustomerPaymentProfileRequest"
                ],
                "example": {
                  "updateCustomerPaymentProfileRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "customerProfileId": "1986784401",
                    "paymentProfile": {
                      "customerType": "individual",
                      "billTo": {
                        "firstName": "Ada",
                        "lastName": "Lovelace",
                        "company": "Example Labs",
                        "address": "14 Main Street",
                        "city": "Pecan Springs",
                        "state": "TX",
                        "zip": "44628",
                        "country": "US"
                      },
                      "payment": {
                        "creditCard": {
                          "cardNumber": "XXXX1111",
                          "expirationDate": "2033-12"
                        }
                      },
                      "defaultPaymentProfile": true,
                      "customerPaymentProfileId": "1886784401"
                    }
                  }
                }
              },
              "example": {
                "updateCustomerPaymentProfileRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "customerProfileId": "1986784401",
                  "paymentProfile": {
                    "customerType": "individual",
                    "billTo": {
                      "firstName": "Ada",
                      "lastName": "Lovelace",
                      "company": "Example Labs",
                      "address": "14 Main Street",
                      "city": "Pecan Springs",
                      "state": "TX",
                      "zip": "44628",
                      "country": "US"
                    },
                    "payment": {
                      "creditCard": {
                        "cardNumber": "XXXX1111",
                        "expirationDate": "2033-12"
                      }
                    },
                    "defaultPaymentProfile": true,
                    "customerPaymentProfileId": "1886784401"
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/deleteCustomerPaymentProfile": {
      "post": {
        "tags": [
          "Customer Profiles"
        ],
        "summary": "Delete a payment profile",
        "operationId": "DeleteCustomerPaymentProfile",
        "description": "One an active subscription bills is E00105.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "deleteCustomerPaymentProfileRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "deleteCustomerPaymentProfileRequest"
                ],
                "example": {
                  "deleteCustomerPaymentProfileRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "customerProfileId": "1920706406",
                    "customerPaymentProfileId": "1894275208"
                  }
                }
              },
              "example": {
                "deleteCustomerPaymentProfileRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "customerProfileId": "1920706406",
                  "customerPaymentProfileId": "1894275208"
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/validateCustomerPaymentProfile": {
      "post": {
        "tags": [
          "Customer Profiles"
        ],
        "summary": "Validate a payment profile",
        "operationId": "ValidateCustomerPaymentProfile",
        "description": "A zero-dollar authorization; answers directResponse.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "validateCustomerPaymentProfileRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "validateCustomerPaymentProfileRequest"
                ],
                "example": {
                  "validateCustomerPaymentProfileRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "customerProfileId": "1986784401",
                    "customerPaymentProfileId": "1886784401",
                    "cardCode": "900",
                    "validationMode": "liveMode"
                  }
                }
              },
              "example": {
                "validateCustomerPaymentProfileRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "customerProfileId": "1986784401",
                  "customerPaymentProfileId": "1886784401",
                  "cardCode": "900",
                  "validationMode": "liveMode"
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/createCustomerShippingAddress": {
      "post": {
        "tags": [
          "Customer Profiles"
        ],
        "summary": "Add a shipping address",
        "operationId": "CreateCustomerShippingAddress",
        "description": "The same address twice is E00039.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "createCustomerShippingAddressRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "createCustomerShippingAddressRequest"
                ],
                "example": {
                  "createCustomerShippingAddressRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "customerProfileId": "1986784401",
                    "address": {
                      "firstName": "Ada",
                      "lastName": "Lovelace",
                      "address": "12 Dock Street",
                      "city": "Pecan Springs",
                      "state": "TX",
                      "zip": "44628",
                      "country": "US",
                      "phoneNumber": "512-555-0100"
                    },
                    "defaultShippingAddress": true
                  }
                }
              },
              "example": {
                "createCustomerShippingAddressRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "customerProfileId": "1986784401",
                  "address": {
                    "firstName": "Ada",
                    "lastName": "Lovelace",
                    "address": "12 Dock Street",
                    "city": "Pecan Springs",
                    "state": "TX",
                    "zip": "44628",
                    "country": "US",
                    "phoneNumber": "512-555-0100"
                  },
                  "defaultShippingAddress": true
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/getCustomerShippingAddress": {
      "post": {
        "tags": [
          "Customer Profiles"
        ],
        "summary": "Get a shipping address",
        "operationId": "GetCustomerShippingAddress",
        "description": "With defaultShippingAddress and the subscriptions that ship to it.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "getCustomerShippingAddressRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "getCustomerShippingAddressRequest"
                ],
                "example": {
                  "getCustomerShippingAddressRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "customerProfileId": "1986784401",
                    "customerAddressId": "1786784401"
                  }
                }
              },
              "example": {
                "getCustomerShippingAddressRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "customerProfileId": "1986784401",
                  "customerAddressId": "1786784401"
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/updateCustomerShippingAddress": {
      "post": {
        "tags": [
          "Customer Profiles"
        ],
        "summary": "Update a shipping address",
        "operationId": "UpdateCustomerShippingAddress",
        "description": "Replaces the address.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "updateCustomerShippingAddressRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "updateCustomerShippingAddressRequest"
                ],
                "example": {
                  "updateCustomerShippingAddressRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "customerProfileId": "1986784401",
                    "address": {
                      "firstName": "Ada",
                      "lastName": "Lovelace",
                      "address": "99 New Street",
                      "city": "Pecan Springs",
                      "state": "TX",
                      "zip": "44628",
                      "country": "US",
                      "customerAddressId": "1786784401"
                    },
                    "defaultShippingAddress": true
                  }
                }
              },
              "example": {
                "updateCustomerShippingAddressRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "customerProfileId": "1986784401",
                  "address": {
                    "firstName": "Ada",
                    "lastName": "Lovelace",
                    "address": "99 New Street",
                    "city": "Pecan Springs",
                    "state": "TX",
                    "zip": "44628",
                    "country": "US",
                    "customerAddressId": "1786784401"
                  },
                  "defaultShippingAddress": true
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/deleteCustomerShippingAddress": {
      "post": {
        "tags": [
          "Customer Profiles"
        ],
        "summary": "Delete a shipping address",
        "operationId": "DeleteCustomerShippingAddress",
        "description": "One a subscription ships to is E00107.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "deleteCustomerShippingAddressRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "deleteCustomerShippingAddressRequest"
                ],
                "example": {
                  "deleteCustomerShippingAddressRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "customerProfileId": "1920706406",
                    "customerAddressId": "1720706406"
                  }
                }
              },
              "example": {
                "deleteCustomerShippingAddressRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "customerProfileId": "1920706406",
                  "customerAddressId": "1720706406"
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/createCustomerProfileFromTransaction": {
      "post": {
        "tags": [
          "Customer Profiles"
        ],
        "summary": "Create a profile from a transaction",
        "operationId": "CreateCustomerProfileFromTransaction",
        "description": "The transaction’s card, billing and shipping become a profile (or, with customerProfileId, are added to one).\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "createCustomerProfileFromTransactionRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "createCustomerProfileFromTransactionRequest"
                ],
                "example": {
                  "createCustomerProfileFromTransactionRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "transId": "63486784401",
                    "customer": {
                      "merchantCustomerId": "CUST-FROM-TX",
                      "email": "from-tx@example.com"
                    }
                  }
                }
              },
              "example": {
                "createCustomerProfileFromTransactionRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "transId": "63486784401",
                  "customer": {
                    "merchantCustomerId": "CUST-FROM-TX",
                    "email": "from-tx@example.com"
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/ARBCreateSubscription": {
      "post": {
        "tags": [
          "Recurring Billing"
        ],
        "summary": "Create a subscription",
        "operationId": "ARBCreateSubscription",
        "description": "Paid by card or bank account it makes a customer profile too (profile in the answer); or name one with profile. The start date can’t be in the past (E00017); an interval is 7–365 days or 1–12 months; the same subscription twice is E00012.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "ARBCreateSubscriptionRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "ARBCreateSubscriptionRequest"
                ],
                "example": {
                  "ARBCreateSubscriptionRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "subscription": {
                      "name": "Monthly beans",
                      "paymentSchedule": {
                        "interval": {
                          "length": "1",
                          "unit": "months"
                        },
                        "startDate": "2026-10-02",
                        "totalOccurrences": "12",
                        "trialOccurrences": "1"
                      },
                      "amount": "32.00",
                      "trialAmount": "0.00",
                      "payment": {
                        "creditCard": {
                          "cardNumber": "4111111111111111",
                          "expirationDate": "2031-12"
                        }
                      },
                      "order": {
                        "invoiceNumber": "SUB-1001",
                        "description": "Coffee club"
                      },
                      "customer": {
                        "id": "CUST-77",
                        "email": "ada@example.com"
                      },
                      "billTo": {
                        "firstName": "Ada",
                        "lastName": "Lovelace",
                        "address": "14 Main Street",
                        "city": "Pecan Springs",
                        "state": "TX",
                        "zip": "44628",
                        "country": "US"
                      }
                    }
                  }
                }
              },
              "example": {
                "ARBCreateSubscriptionRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "subscription": {
                    "name": "Monthly beans",
                    "paymentSchedule": {
                      "interval": {
                        "length": "1",
                        "unit": "months"
                      },
                      "startDate": "2026-10-02",
                      "totalOccurrences": "12",
                      "trialOccurrences": "1"
                    },
                    "amount": "32.00",
                    "trialAmount": "0.00",
                    "payment": {
                      "creditCard": {
                        "cardNumber": "4111111111111111",
                        "expirationDate": "2031-12"
                      }
                    },
                    "order": {
                      "invoiceNumber": "SUB-1001",
                      "description": "Coffee club"
                    },
                    "customer": {
                      "id": "CUST-77",
                      "email": "ada@example.com"
                    },
                    "billTo": {
                      "firstName": "Ada",
                      "lastName": "Lovelace",
                      "address": "14 Main Street",
                      "city": "Pecan Springs",
                      "state": "TX",
                      "zip": "44628",
                      "country": "US"
                    }
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/ARBGetSubscription": {
      "post": {
        "tags": [
          "Recurring Billing"
        ],
        "summary": "Get a subscription",
        "operationId": "ARBGetSubscription",
        "description": "Schedule, amounts, status and the profile it bills.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "ARBGetSubscriptionRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "ARBGetSubscriptionRequest"
                ],
                "example": {
                  "ARBGetSubscriptionRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "subscriptionId": "96784401",
                    "includeTransactions": true
                  }
                }
              },
              "example": {
                "ARBGetSubscriptionRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "subscriptionId": "96784401",
                  "includeTransactions": true
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/ARBGetSubscriptionStatus": {
      "post": {
        "tags": [
          "Recurring Billing"
        ],
        "summary": "Get a subscription’s status",
        "operationId": "ARBGetSubscriptionStatus",
        "description": "active, canceled… (The XML answer also carries the obsolete capital-S Status, as the real one does.)\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "ARBGetSubscriptionStatusRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "ARBGetSubscriptionStatusRequest"
                ],
                "example": {
                  "ARBGetSubscriptionStatusRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "subscriptionId": "96784401"
                  }
                }
              },
              "example": {
                "ARBGetSubscriptionStatusRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "subscriptionId": "96784401"
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/ARBUpdateSubscription": {
      "post": {
        "tags": [
          "Recurring Billing"
        ],
        "summary": "Update a subscription",
        "operationId": "ARBUpdateSubscription",
        "description": "Name, amount, occurrences, payment, billing. The interval can’t change (E00034).\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "ARBUpdateSubscriptionRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "ARBUpdateSubscriptionRequest"
                ],
                "example": {
                  "ARBUpdateSubscriptionRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "subscriptionId": "96784401",
                    "subscription": {
                      "name": "Coffee club — two bags",
                      "amount": "58.00"
                    }
                  }
                }
              },
              "example": {
                "ARBUpdateSubscriptionRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "subscriptionId": "96784401",
                  "subscription": {
                    "name": "Coffee club — two bags",
                    "amount": "58.00"
                  }
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/ARBCancelSubscription": {
      "post": {
        "tags": [
          "Recurring Billing"
        ],
        "summary": "Cancel a subscription",
        "operationId": "ARBCancelSubscription",
        "description": "Cancelling again is I00002 (resultCode Ok).\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "ARBCancelSubscriptionRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "ARBCancelSubscriptionRequest"
                ],
                "example": {
                  "ARBCancelSubscriptionRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "subscriptionId": "96784401"
                  }
                }
              },
              "example": {
                "ARBCancelSubscriptionRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "subscriptionId": "96784401"
                }
              }
            }
          }
        }
      }
    },
    "/xml/v1/request.api/ARBGetSubscriptionList": {
      "post": {
        "tags": [
          "Recurring Billing"
        ],
        "summary": "Search subscriptions",
        "operationId": "ARBGetSubscriptionList",
        "description": "searchType subscriptionActive, subscriptionInactive, cardExpiringThisMonth or subscriptionExpiringThisMonth.\n\nThe path after /xml/v1/request.api is sondahub's label for importing: the sandbox reads only the body. Your code posts to /xml/v1/request.api.",
        "responses": {
          "200": {
            "description": "Always 200, starting with a byte order mark: messages.resultCode says Ok or Error.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "ARBGetSubscriptionListRequest": {
                    "type": "object",
                    "description": "The call: merchantAuthentication first, then its elements in schema order (the API checks the order, for JSON too)."
                  }
                },
                "required": [
                  "ARBGetSubscriptionListRequest"
                ],
                "example": {
                  "ARBGetSubscriptionListRequest": {
                    "merchantAuthentication": {
                      "name": "sondahub",
                      "transactionKey": "SandboxKey123456"
                    },
                    "searchType": "subscriptionActive",
                    "sorting": {
                      "orderBy": "id",
                      "orderDescending": false
                    },
                    "paging": {
                      "limit": "100",
                      "offset": "1"
                    }
                  }
                }
              },
              "example": {
                "ARBGetSubscriptionListRequest": {
                  "merchantAuthentication": {
                    "name": "sondahub",
                    "transactionKey": "SandboxKey123456"
                  },
                  "searchType": "subscriptionActive",
                  "sorting": {
                    "orderBy": "id",
                    "orderDescending": false
                  },
                  "paging": {
                    "limit": "100",
                    "offset": "1"
                  }
                }
              }
            }
          }
        }
      }
    },
    "/rest/v1/eventtypes": {
      "get": {
        "tags": [
          "Webhooks"
        ],
        "summary": "List event types",
        "operationId": "ListEventTypes",
        "description": "23 events: payments, fraud holds, customer and payment profiles, subscriptions.",
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "401": {
            "$ref": "#/components/responses/E401"
          }
        }
      }
    },
    "/rest/v1/webhooks": {
      "get": {
        "tags": [
          "Webhooks"
        ],
        "summary": "List webhooks",
        "operationId": "ListWebhooks",
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "401": {
            "$ref": "#/components/responses/E401"
          }
        }
      },
      "post": {
        "tags": [
          "Webhooks"
        ],
        "summary": "Create a webhook",
        "operationId": "CreateWebhook",
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "name": {
                    "type": "string",
                    "description": "A name.",
                    "example": "My webhook"
                  },
                  "url": {
                    "type": "string",
                    "description": "Where notifications go (a public http or https address).",
                    "example": "https://your-app.example/authorizenet/webhooks"
                  },
                  "eventTypes": {
                    "type": "array",
                    "description": "Event names, from GET /rest/v1/eventtypes.",
                    "items": {},
                    "example": [
                      "net.authorize.payment.authcapture.created"
                    ]
                  },
                  "status": {
                    "type": "string",
                    "description": "active or inactive.",
                    "example": "active"
                  }
                },
                "required": [
                  "url",
                  "eventTypes"
                ],
                "example": {
                  "name": "My webhook",
                  "url": "https://your-app.example/authorizenet/webhooks",
                  "eventTypes": [
                    "net.authorize.payment.authcapture.created",
                    "net.authorize.payment.refund.created",
                    "net.authorize.payment.void.created"
                  ],
                  "status": "active"
                }
              },
              "example": {
                "name": "My webhook",
                "url": "https://your-app.example/authorizenet/webhooks",
                "eventTypes": [
                  "net.authorize.payment.authcapture.created",
                  "net.authorize.payment.refund.created",
                  "net.authorize.payment.void.created"
                ],
                "status": "active"
              }
            }
          }
        }
      }
    },
    "/rest/v1/webhooks/{webhookId}": {
      "get": {
        "tags": [
          "Webhooks"
        ],
        "summary": "Get a webhook",
        "operationId": "GetWebhook",
        "parameters": [
          {
            "name": "webhookId",
            "in": "path",
            "required": true,
            "description": "A webhook id: the seed has one (inactive).",
            "schema": {
              "type": "string"
            },
            "example": "9e3779b1-a372-fbae-b58a-fd26482bb4f8"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          }
        }
      },
      "put": {
        "tags": [
          "Webhooks"
        ],
        "summary": "Update a webhook",
        "operationId": "UpdateWebhook",
        "parameters": [
          {
            "name": "webhookId",
            "in": "path",
            "required": true,
            "description": "A webhook id: the seed has one (inactive).",
            "schema": {
              "type": "string"
            },
            "example": "9e3779b1-a372-fbae-b58a-fd26482bb4f8"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          }
        },
        "requestBody": {
          "required": false,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "name": {
                    "type": "string",
                    "description": "A name.",
                    "example": "My webhook"
                  },
                  "url": {
                    "type": "string",
                    "description": "Where notifications go (a public http or https address).",
                    "example": "https://your-app.example/authorizenet/webhooks"
                  },
                  "eventTypes": {
                    "type": "array",
                    "description": "Event names, from GET /rest/v1/eventtypes.",
                    "items": {},
                    "example": [
                      "net.authorize.payment.authcapture.created"
                    ]
                  },
                  "status": {
                    "type": "string",
                    "description": "active or inactive.",
                    "example": "active"
                  }
                },
                "example": {
                  "name": "My webhook",
                  "url": "https://your-app.example/authorizenet/webhooks",
                  "eventTypes": [
                    "net.authorize.payment.authcapture.created",
                    "net.authorize.payment.refund.created",
                    "net.authorize.payment.void.created"
                  ],
                  "status": "inactive"
                }
              },
              "example": {
                "name": "My webhook",
                "url": "https://your-app.example/authorizenet/webhooks",
                "eventTypes": [
                  "net.authorize.payment.authcapture.created",
                  "net.authorize.payment.refund.created",
                  "net.authorize.payment.void.created"
                ],
                "status": "inactive"
              }
            }
          }
        }
      },
      "delete": {
        "tags": [
          "Webhooks"
        ],
        "summary": "Delete a webhook",
        "operationId": "DeleteWebhook",
        "parameters": [
          {
            "name": "webhookId",
            "in": "path",
            "required": true,
            "description": "A webhook id: the seed has one (inactive).",
            "schema": {
              "type": "string"
            },
            "example": "9e3779b1-a372-fbae-b58a-fd26482bb4f8"
          }
        ],
        "responses": {
          "200": {
            "description": "Deleted, no body."
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          }
        }
      }
    },
    "/rest/v1/webhooks/{webhookId}/pings": {
      "post": {
        "tags": [
          "Webhooks"
        ],
        "summary": "Ping a webhook",
        "operationId": "PingWebhook",
        "description": "Sends a sample notification of the webhook’s first event type, signed, and answers 200 when the URL answered 2xx (500 PING_FAILED otherwise — the seed’s example.com address doesn’t take posts).",
        "parameters": [
          {
            "name": "webhookId",
            "in": "path",
            "required": true,
            "description": "A webhook id.",
            "schema": {
              "type": "string"
            },
            "example": "9e3779b1-a372-fbae-b58a-fd26482bb4f8"
          }
        ],
        "responses": {
          "200": {
            "description": "The URL answered 2xx."
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          },
          "500": {
            "$ref": "#/components/responses/E500"
          }
        }
      }
    },
    "/rest/v1/notifications": {
      "get": {
        "tags": [
          "Webhooks"
        ],
        "summary": "Notification history",
        "operationId": "ListNotifications",
        "description": "What was sent, newest first: Delivered or Failed (the sandbox sends each one once, while answering the call that raised it, and keeps the result in the session).",
        "parameters": [
          {
            "name": "offset",
            "in": "query",
            "required": false,
            "description": "Skip this many.",
            "schema": {
              "type": "integer"
            },
            "example": 0
          },
          {
            "name": "limit",
            "in": "query",
            "required": false,
            "description": "Up to 1000.",
            "schema": {
              "type": "integer"
            },
            "example": 100
          },
          {
            "name": "deliveryStatus",
            "in": "query",
            "required": false,
            "description": "Delivered or Failed.",
            "schema": {
              "type": "string"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "401": {
            "$ref": "#/components/responses/E401"
          }
        }
      }
    },
    "/rest/v1/notifications/{notificationId}": {
      "get": {
        "tags": [
          "Webhooks"
        ],
        "summary": "Get a notification",
        "operationId": "GetNotification",
        "description": "With the payload and the delivery attempt.",
        "parameters": [
          {
            "name": "notificationId",
            "in": "path",
            "required": true,
            "description": "A notification id: the seed has two.",
            "schema": {
              "type": "string"
            },
            "example": "9e3779b1-0d2b-4403-1ee7-5180208b4d13"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          },
          "401": {
            "$ref": "#/components/responses/E401"
          },
          "404": {
            "$ref": "#/components/responses/E404"
          }
        }
      }
    },
    "/sandbox/authorizenet/payment/payment": {
      "post": {
        "tags": [
          "Sandbox tools"
        ],
        "summary": "The hosted payment form",
        "operationId": "HostedPaymentForm",
        "description": "Where the browser posts the getHostedPaymentPage token (the real form lives at test.authorize.net/payment/payment). Answers the form as HTML; paying runs the same checks and triggers as the API and sends the webhooks the account had when the token was made.",
        "responses": {
          "200": {
            "description": "The form (HTML).",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        },
        "security": [],
        "requestBody": {
          "required": true,
          "content": {
            "application/x-www-form-urlencoded": {
              "schema": {
                "type": "object",
                "properties": {
                  "token": {
                    "type": "string",
                    "description": "The token from getHostedPaymentPage.",
                    "example": "paste-a-token-from-getHostedPaymentPage"
                  }
                },
                "required": [
                  "token"
                ],
                "example": {
                  "token": "paste-a-token-from-getHostedPaymentPage"
                }
              },
              "example": {
                "token": "paste-a-token-from-getHostedPaymentPage"
              }
            }
          }
        }
      }
    }
  },
  "components": {
    "securitySchemes": {
      "anetBasic": {
        "type": "http",
        "scheme": "basic",
        "description": "For the webhooks REST API: API Login ID and Transaction Key — sondahub / SandboxKey123456."
      }
    },
    "responses": {
      "E400": {
        "description": "{status, reason, message, correlationId}: what is wrong with the webhook.",
        "content": {
          "application/json": {
            "schema": {
              "type": "object",
              "properties": {
                "status": {
                  "type": "integer"
                },
                "reason": {
                  "type": "string"
                },
                "message": {
                  "type": "string"
                },
                "correlationId": {
                  "type": "string"
                }
              }
            }
          }
        }
      },
      "E401": {
        "description": "No Basic credentials, or a key that is not 16 characters.",
        "content": {
          "application/json": {
            "schema": {
              "type": "object",
              "properties": {
                "status": {
                  "type": "integer"
                },
                "reason": {
                  "type": "string"
                },
                "message": {
                  "type": "string"
                },
                "correlationId": {
                  "type": "string"
                }
              }
            }
          }
        }
      },
      "E404": {
        "description": "No such webhook or notification.",
        "content": {
          "application/json": {
            "schema": {
              "type": "object",
              "properties": {
                "status": {
                  "type": "integer"
                },
                "reason": {
                  "type": "string"
                },
                "message": {
                  "type": "string"
                },
                "correlationId": {
                  "type": "string"
                }
              }
            }
          }
        }
      },
      "E500": {
        "description": "PING_FAILED: the webhook URL did not answer 2xx.",
        "content": {
          "application/json": {
            "schema": {
              "type": "object",
              "properties": {
                "status": {
                  "type": "integer"
                },
                "reason": {
                  "type": "string"
                },
                "message": {
                  "type": "string"
                },
                "correlationId": {
                  "type": "string"
                }
              }
            }
          }
        }
      }
    }
  }
}