curl --request GET \
--url https://int-api.mx.com/data_exchange/grant \
--header 'Accept-Version: <accept-version>' \
--header 'Authorization: Basic <encoded-value>'import requests
url = "https://int-api.mx.com/data_exchange/grant"
headers = {
"Accept-Version": "<accept-version>",
"Authorization": "Basic <encoded-value>"
}
response = requests.get(url, headers=headers)
print(response.text)const options = {
method: 'GET',
headers: {'Accept-Version': '<accept-version>', Authorization: 'Basic <encoded-value>'}
};
fetch('https://int-api.mx.com/data_exchange/grant', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://int-api.mx.com/data_exchange/grant",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Accept-Version: <accept-version>",
"Authorization: Basic <encoded-value>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://int-api.mx.com/data_exchange/grant"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Accept-Version", "<accept-version>")
req.Header.Add("Authorization", "Basic <encoded-value>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://int-api.mx.com/data_exchange/grant")
.header("Accept-Version", "<accept-version>")
.header("Authorization", "Basic <encoded-value>")
.asString();require 'uri'
require 'net/http'
url = URI("https://int-api.mx.com/data_exchange/grant")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Accept-Version"] = '<accept-version>'
request["Authorization"] = 'Basic <encoded-value>'
response = http.request(request)
puts response.read_body{
"grant": {
"data_scope": "HELD",
"expires_at": "2025-02-13T18:08:00+00:00",
"guid": "CLG-7c6f361b-e582-15b6-60c0-358f12466b4b",
"revoked_at": "2025-02-13T18:08:00+00:00",
"status": "GRANTED",
"grantees": [
{
"client_guid": "CLT-7be56761-e582-15b6-60c0-358f12466b4b",
"role": "RECIPIENT"
}
],
"issuer": {
"client_guid": "CLT-7c6f361b-e582-15b6-60c0-358f12466b4b"
},
"mx_record": {
"created_at": "2025-05-10T18:08:00Z",
"updated_at": "2026-02-12T22:48:21Z"
}
}
}Read data exchange grant
Use this endpoint to read the details of a grant with the given issuer_guid and grantee GUIDs. For a grant to return, you must pass each grantee_guid belonging to the grant. If a grant has two grantees on it and you only include one grantee_guid, the grant will not be returned. This endpoint requires standard Platform API authentication.
curl --request GET \
--url https://int-api.mx.com/data_exchange/grant \
--header 'Accept-Version: <accept-version>' \
--header 'Authorization: Basic <encoded-value>'import requests
url = "https://int-api.mx.com/data_exchange/grant"
headers = {
"Accept-Version": "<accept-version>",
"Authorization": "Basic <encoded-value>"
}
response = requests.get(url, headers=headers)
print(response.text)const options = {
method: 'GET',
headers: {'Accept-Version': '<accept-version>', Authorization: 'Basic <encoded-value>'}
};
fetch('https://int-api.mx.com/data_exchange/grant', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://int-api.mx.com/data_exchange/grant",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Accept-Version: <accept-version>",
"Authorization: Basic <encoded-value>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://int-api.mx.com/data_exchange/grant"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Accept-Version", "<accept-version>")
req.Header.Add("Authorization", "Basic <encoded-value>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://int-api.mx.com/data_exchange/grant")
.header("Accept-Version", "<accept-version>")
.header("Authorization", "Basic <encoded-value>")
.asString();require 'uri'
require 'net/http'
url = URI("https://int-api.mx.com/data_exchange/grant")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Accept-Version"] = '<accept-version>'
request["Authorization"] = 'Basic <encoded-value>'
response = http.request(request)
puts response.read_body{
"grant": {
"data_scope": "HELD",
"expires_at": "2025-02-13T18:08:00+00:00",
"guid": "CLG-7c6f361b-e582-15b6-60c0-358f12466b4b",
"revoked_at": "2025-02-13T18:08:00+00:00",
"status": "GRANTED",
"grantees": [
{
"client_guid": "CLT-7be56761-e582-15b6-60c0-358f12466b4b",
"role": "RECIPIENT"
}
],
"issuer": {
"client_guid": "CLT-7c6f361b-e582-15b6-60c0-358f12466b4b"
},
"mx_record": {
"created_at": "2025-05-10T18:08:00Z",
"updated_at": "2026-02-12T22:48:21Z"
}
}
}Authorizations
To authenticate with the Platform API, include your Base64-encoded client_id and api_key in the Authorization header of every request:
-H 'Authorization: Basic BASE_64_ENCODING_OF{client_id:api_key}'
Headers
MX Platform API version.
"v20260929"
Query Parameters
The unique identifier for the issuing client.
"CLT-7829f71c-2e8c-afa5-2f55-fa3634b89874"
The unique identifier for each grantee client on a grant.
For example, ?issuer_guid=CLT-7829f71c-2e8c-afa5-2f55-fa3634b89874&grantee_guids[]=CLT-7829f71c-afa5-2e8c-fa36-34b82f559874&grantee_guids[]=CLT-372c33f9-c316-433b-b081-b7b314bef4b5.
Response
OK
Hide child attributes
Hide child attributes
Determines the source of the data that is shared through the grant. HELD is data owned by the issuing client, AGGREGATED is data MX collected through end user-authorized institution connections, and ALL is both.
HELD, AGGREGATED, ALL "HELD"
The timestamp when the grant expires, in ISO 8601 format.
"2025-02-13T18:08:00+00:00"
The unique identifier for the grant. Defined by MX.
"CLG-7c6f361b-e582-15b6-60c0-358f12466b4b"
The timestamp when the grant was revoked, in ISO 8601 format.
"2025-02-13T18:08:00+00:00"
The status of the grant.
GRANTED, EXPIRED, REVOKED "GRANTED"
A list of grantees associated with the grant.
Hide child attributes
Hide child attributes
The unique identifier for the grant grantee. Defined by MX.
"CLT-7be56761-e582-15b6-60c0-358f12466b4b"
The role assigned to the grantee for the grant. A RECIPIENT receives data and delivers the service. A DATA_COLLECTOR pulls data from MX and passes it to the recipient without storing it.
RECIPIENT, DATA_COLLECTOR "RECIPIENT"
Timestamps for when MX created and last updated the record. Returned as the mx_record companion on all resources persisted by MX. These describe the MX record, not the underlying resource at the institution.
Hide child attributes
Hide child attributes
The date and time the resource was created in MX Platform, represented in ISO 8601 format with a timestamp.
"2025-05-10T18:08:00Z"
The date and time the resource was last updated in MX Platform, represented in ISO 8601 format with a timestamp.
For categories, this field will always be null when is_default is true.
"2026-02-12T22:48:21Z"

