curl --request POST \
--url https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url \
--header 'Accept-Version: <accept-version>' \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/json' \
--data '
{
"data_request": {
"products": [
"transactions",
"statements",
"investments"
]
},
"oauth": {
"client_redirect_url": "https://{yoursite.com}",
"enable_app2app": false,
"referral_source": "APP",
"skip_aggregation": true,
"ui_message_webview_url_scheme": "<string>"
}
}
'import requests
url = "https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url"
payload = {
"data_request": { "products": ["transactions", "statements", "investments"] },
"oauth": {
"client_redirect_url": "https://{yoursite.com}",
"enable_app2app": False,
"referral_source": "APP",
"skip_aggregation": True,
"ui_message_webview_url_scheme": "<string>"
}
}
headers = {
"Accept-Version": "<accept-version>",
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'Accept-Version': '<accept-version>',
Authorization: 'Basic <encoded-value>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
data_request: {products: ['transactions', 'statements', 'investments']},
oauth: {
client_redirect_url: 'https://{yoursite.com}',
enable_app2app: false,
referral_source: 'APP',
skip_aggregation: true,
ui_message_webview_url_scheme: '<string>'
}
})
};
fetch('https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'data_request' => [
'products' => [
'transactions',
'statements',
'investments'
]
],
'oauth' => [
'client_redirect_url' => 'https://{yoursite.com}',
'enable_app2app' => false,
'referral_source' => 'APP',
'skip_aggregation' => true,
'ui_message_webview_url_scheme' => '<string>'
]
]),
CURLOPT_HTTPHEADER => [
"Accept-Version: <accept-version>",
"Authorization: Basic <encoded-value>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url"
payload := strings.NewReader("{\n \"data_request\": {\n \"products\": [\n \"transactions\",\n \"statements\",\n \"investments\"\n ]\n },\n \"oauth\": {\n \"client_redirect_url\": \"https://{yoursite.com}\",\n \"enable_app2app\": false,\n \"referral_source\": \"APP\",\n \"skip_aggregation\": true,\n \"ui_message_webview_url_scheme\": \"<string>\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Accept-Version", "<accept-version>")
req.Header.Add("Authorization", "Basic <encoded-value>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url")
.header("Accept-Version", "<accept-version>")
.header("Authorization", "Basic <encoded-value>")
.header("Content-Type", "application/json")
.body("{\n \"data_request\": {\n \"products\": [\n \"transactions\",\n \"statements\",\n \"investments\"\n ]\n },\n \"oauth\": {\n \"client_redirect_url\": \"https://{yoursite.com}\",\n \"enable_app2app\": false,\n \"referral_source\": \"APP\",\n \"skip_aggregation\": true,\n \"ui_message_webview_url_scheme\": \"<string>\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Accept-Version"] = '<accept-version>'
request["Authorization"] = 'Basic <encoded-value>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"data_request\": {\n \"products\": [\n \"transactions\",\n \"statements\",\n \"investments\"\n ]\n },\n \"oauth\": {\n \"client_redirect_url\": \"https://{yoursite.com}\",\n \"enable_app2app\": false,\n \"referral_source\": \"APP\",\n \"skip_aggregation\": true,\n \"ui_message_webview_url_scheme\": \"<string>\"\n }\n}"
response = http.request(request)
puts response.read_body{
"member": {
"guid": "MBR-df96fd60-7122-4464-b3c2-ff11d8c74f6f",
"oauth_window_uri": "https://mxbank.mx.com/oauth/authorize?client_id=b8OikQ4Ep3NuSUrQ13DdvFuwpNx-qqoAsJDVAQCyLkQ&redirect_uri=https%3A%2F%2Fint-app.moneydesktop.com%2Foauth%2Fredirect_from&response_type=code&scope=openid&state=d745bd4ee6f0f9c184757f574bcc2df2"
}
}Create OAuth Authorization URL
Generate an authorization_url for OAuth authorization of the specified member during the connection flow.
curl --request POST \
--url https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url \
--header 'Accept-Version: <accept-version>' \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/json' \
--data '
{
"data_request": {
"products": [
"transactions",
"statements",
"investments"
]
},
"oauth": {
"client_redirect_url": "https://{yoursite.com}",
"enable_app2app": false,
"referral_source": "APP",
"skip_aggregation": true,
"ui_message_webview_url_scheme": "<string>"
}
}
'import requests
url = "https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url"
payload = {
"data_request": { "products": ["transactions", "statements", "investments"] },
"oauth": {
"client_redirect_url": "https://{yoursite.com}",
"enable_app2app": False,
"referral_source": "APP",
"skip_aggregation": True,
"ui_message_webview_url_scheme": "<string>"
}
}
headers = {
"Accept-Version": "<accept-version>",
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'Accept-Version': '<accept-version>',
Authorization: 'Basic <encoded-value>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
data_request: {products: ['transactions', 'statements', 'investments']},
oauth: {
client_redirect_url: 'https://{yoursite.com}',
enable_app2app: false,
referral_source: 'APP',
skip_aggregation: true,
ui_message_webview_url_scheme: '<string>'
}
})
};
fetch('https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'data_request' => [
'products' => [
'transactions',
'statements',
'investments'
]
],
'oauth' => [
'client_redirect_url' => 'https://{yoursite.com}',
'enable_app2app' => false,
'referral_source' => 'APP',
'skip_aggregation' => true,
'ui_message_webview_url_scheme' => '<string>'
]
]),
CURLOPT_HTTPHEADER => [
"Accept-Version: <accept-version>",
"Authorization: Basic <encoded-value>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url"
payload := strings.NewReader("{\n \"data_request\": {\n \"products\": [\n \"transactions\",\n \"statements\",\n \"investments\"\n ]\n },\n \"oauth\": {\n \"client_redirect_url\": \"https://{yoursite.com}\",\n \"enable_app2app\": false,\n \"referral_source\": \"APP\",\n \"skip_aggregation\": true,\n \"ui_message_webview_url_scheme\": \"<string>\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Accept-Version", "<accept-version>")
req.Header.Add("Authorization", "Basic <encoded-value>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url")
.header("Accept-Version", "<accept-version>")
.header("Authorization", "Basic <encoded-value>")
.header("Content-Type", "application/json")
.body("{\n \"data_request\": {\n \"products\": [\n \"transactions\",\n \"statements\",\n \"investments\"\n ]\n },\n \"oauth\": {\n \"client_redirect_url\": \"https://{yoursite.com}\",\n \"enable_app2app\": false,\n \"referral_source\": \"APP\",\n \"skip_aggregation\": true,\n \"ui_message_webview_url_scheme\": \"<string>\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Accept-Version"] = '<accept-version>'
request["Authorization"] = 'Basic <encoded-value>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"data_request\": {\n \"products\": [\n \"transactions\",\n \"statements\",\n \"investments\"\n ]\n },\n \"oauth\": {\n \"client_redirect_url\": \"https://{yoursite.com}\",\n \"enable_app2app\": false,\n \"referral_source\": \"APP\",\n \"skip_aggregation\": true,\n \"ui_message_webview_url_scheme\": \"<string>\"\n }\n}"
response = http.request(request)
puts response.read_body{
"member": {
"guid": "MBR-df96fd60-7122-4464-b3c2-ff11d8c74f6f",
"oauth_window_uri": "https://mxbank.mx.com/oauth/authorize?client_id=b8OikQ4Ep3NuSUrQ13DdvFuwpNx-qqoAsJDVAQCyLkQ&redirect_uri=https%3A%2F%2Fint-app.moneydesktop.com%2Foauth%2Fredirect_from&response_type=code&scope=openid&state=d745bd4ee6f0f9c184757f574bcc2df2"
}
}Authorizations
To authenticate with the Platform API, include your Base64-encoded client_id and api_key in the Authorization header of every request:
-H 'Authorization: Basic BASE_64_ENCODING_OF{client_id:api_key}'
Headers
MX Platform API version.
"v20250224"
Path Parameters
Use either the member id you defined or the MX-defined member guid. See MX-Defined GUIDs vs IDs Defined by You.
Use either the user id you defined or the MX-defined user guid. See MX-Defined GUIDs vs IDs Defined by You.
Body
Both oauth and data_request bodies are optional, but if provided, neither can be empty.
Contains a products array that specifies the products you want to aggregate.
Hide child attributes
Hide child attributes
Contains the products you want to aggregate upon a successful connection. For accepted products, see Unified Product Ordering.
account_verification, identity_verification, transactions, transaction_history, statements, investments {
"products": ["transactions", "statements", "investments"]
}
Hide child attributes
Hide child attributes
This determines the redirect destination at the end of OAuth when used with is_mobile_webview: true or oauth_referral_source: 'APP'.
"https://{yoursite.com}"
This indicates whether OAuth app2app behavior is enabled for institutions that support it. Defaults to true. When set to false, any generated OAuth URL will not direct the end user to the institution's mobile application. This setting is not persistent and currently only affects Chase institutions.
false
"APP"
When true, the member will not be automatically aggregated after the OAuth connection completes. Deprecated and slated for removal in a future version.
A client-defined scheme used in OAuth redirects in WebViews. Defaults to mx.
Response
OK
Hide child attributes
Hide child attributes
The unique identifier for the member. Defined by MX.
"MBR-df96fd60-7122-4464-b3c2-ff11d8c74f6f"
When connecting a member using OAuth, this field will contain the URL to send the user to in order to authenticate, otherwise it will be blank.
"https://mxbank.mx.com/oauth/authorize?client_id=b8OikQ4Ep3NuSUrQ13DdvFuwpNx-qqoAsJDVAQCyLkQ&redirect_uri=https%3A%2F%2Fint-app.moneydesktop.com%2Foauth%2Fredirect_from&response_type=code&scope=openid&state=d745bd4ee6f0f9c184757f574bcc2df2"

