curl --request PUT \
--url https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/resume \
--header 'Accept-Version: <accept-version>' \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/json' \
--data '
{
"member": {
"challenges": [
{
"guid": "CRD-27d0edb8-1d50-5b90-bcbc-be270ca42b9f",
"value": "password"
}
]
}
}
'import requests
url = "https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/resume"
payload = { "member": { "challenges": [
{
"guid": "CRD-27d0edb8-1d50-5b90-bcbc-be270ca42b9f",
"value": "password"
}
] } }
headers = {
"Accept-Version": "<accept-version>",
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {
'Accept-Version': '<accept-version>',
Authorization: 'Basic <encoded-value>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
member: {
challenges: [{guid: 'CRD-27d0edb8-1d50-5b90-bcbc-be270ca42b9f', value: 'password'}]
}
})
};
fetch('https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/resume', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/resume",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'member' => [
'challenges' => [
[
'guid' => 'CRD-27d0edb8-1d50-5b90-bcbc-be270ca42b9f',
'value' => 'password'
]
]
]
]),
CURLOPT_HTTPHEADER => [
"Accept-Version: <accept-version>",
"Authorization: Basic <encoded-value>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/resume"
payload := strings.NewReader("{\n \"member\": {\n \"challenges\": [\n {\n \"guid\": \"CRD-27d0edb8-1d50-5b90-bcbc-be270ca42b9f\",\n \"value\": \"password\"\n }\n ]\n }\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Accept-Version", "<accept-version>")
req.Header.Add("Authorization", "Basic <encoded-value>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/resume")
.header("Accept-Version", "<accept-version>")
.header("Authorization", "Basic <encoded-value>")
.header("Content-Type", "application/json")
.body("{\n \"member\": {\n \"challenges\": [\n {\n \"guid\": \"CRD-27d0edb8-1d50-5b90-bcbc-be270ca42b9f\",\n \"value\": \"password\"\n }\n ]\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/resume")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Accept-Version"] = '<accept-version>'
request["Authorization"] = 'Basic <encoded-value>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"member\": {\n \"challenges\": [\n {\n \"guid\": \"CRD-27d0edb8-1d50-5b90-bcbc-be270ca42b9f\",\n \"value\": \"password\"\n }\n ]\n }\n}"
response = http.request(request)
puts response.read_body{
"member": {
"guid": "MBR-7c6f361b-e582-15b6-60c0-358f12466b4b",
"id": "unique_id",
"metadata": "some metadata",
"name": "MX Bank",
"self": "/users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c/members/MBR-7c6f361b-e582-15b6-60c0-358f12466b4b",
"institution": {
"code": "mxbank",
"guid": "INS-1572a04c-912b-59bf-5841-332c7dfafaef",
"iso_country_code": "US",
"name": "MX Bank",
"products": [
"account_verification",
"identity_verification",
"transactions",
"transaction_history",
"statements",
"investments",
"rewards"
],
"self": "/institutions/INS-1572a04c-912b-59bf-5841-332c7dfafaef",
"supports_oauth": true
},
"member_status": {
"status": "CONNECTED",
"error": {
"error_type": "MEMBER",
"error_code": "REQUEST_FAILED",
"error_message": "There was an error attempting to process your request. The Member was created but we were unable to fulfill the data request.",
"user_message": "We're having trouble connecting right now. Please try again later."
},
"self": "/users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c/members/MBR-7c6f361b-e582-15b6-60c0-358f12466b4b/status"
},
"oauth": {
"is_oauth": true,
"authorization_url": "https://mxbank.mx.com/oauth/authorize?client_id=b8OikQ4Ep",
"self": "/users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c/members/MBR-7c6f361b-e582-15b6-60c0-358f12466b4b/oauth/authorization_url"
},
"user": {
"guid": "USR-11141024-90b3-1bce-cac9-c06ced52ab4c",
"id": "unique_id",
"metadata": "some metadata",
"self": "/users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c"
},
"mx_record": {
"created_at": "2025-05-10T18:08:00Z",
"updated_at": "2026-02-12T22:48:21Z"
}
}
}Resume aggregation
This endpoint answers the challenges needed when a member has been challenged by multi-factor authentication.
curl --request PUT \
--url https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/resume \
--header 'Accept-Version: <accept-version>' \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/json' \
--data '
{
"member": {
"challenges": [
{
"guid": "CRD-27d0edb8-1d50-5b90-bcbc-be270ca42b9f",
"value": "password"
}
]
}
}
'import requests
url = "https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/resume"
payload = { "member": { "challenges": [
{
"guid": "CRD-27d0edb8-1d50-5b90-bcbc-be270ca42b9f",
"value": "password"
}
] } }
headers = {
"Accept-Version": "<accept-version>",
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {
'Accept-Version': '<accept-version>',
Authorization: 'Basic <encoded-value>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
member: {
challenges: [{guid: 'CRD-27d0edb8-1d50-5b90-bcbc-be270ca42b9f', value: 'password'}]
}
})
};
fetch('https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/resume', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/resume",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'member' => [
'challenges' => [
[
'guid' => 'CRD-27d0edb8-1d50-5b90-bcbc-be270ca42b9f',
'value' => 'password'
]
]
]
]),
CURLOPT_HTTPHEADER => [
"Accept-Version: <accept-version>",
"Authorization: Basic <encoded-value>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/resume"
payload := strings.NewReader("{\n \"member\": {\n \"challenges\": [\n {\n \"guid\": \"CRD-27d0edb8-1d50-5b90-bcbc-be270ca42b9f\",\n \"value\": \"password\"\n }\n ]\n }\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Accept-Version", "<accept-version>")
req.Header.Add("Authorization", "Basic <encoded-value>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/resume")
.header("Accept-Version", "<accept-version>")
.header("Authorization", "Basic <encoded-value>")
.header("Content-Type", "application/json")
.body("{\n \"member\": {\n \"challenges\": [\n {\n \"guid\": \"CRD-27d0edb8-1d50-5b90-bcbc-be270ca42b9f\",\n \"value\": \"password\"\n }\n ]\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/resume")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Accept-Version"] = '<accept-version>'
request["Authorization"] = 'Basic <encoded-value>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"member\": {\n \"challenges\": [\n {\n \"guid\": \"CRD-27d0edb8-1d50-5b90-bcbc-be270ca42b9f\",\n \"value\": \"password\"\n }\n ]\n }\n}"
response = http.request(request)
puts response.read_body{
"member": {
"guid": "MBR-7c6f361b-e582-15b6-60c0-358f12466b4b",
"id": "unique_id",
"metadata": "some metadata",
"name": "MX Bank",
"self": "/users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c/members/MBR-7c6f361b-e582-15b6-60c0-358f12466b4b",
"institution": {
"code": "mxbank",
"guid": "INS-1572a04c-912b-59bf-5841-332c7dfafaef",
"iso_country_code": "US",
"name": "MX Bank",
"products": [
"account_verification",
"identity_verification",
"transactions",
"transaction_history",
"statements",
"investments",
"rewards"
],
"self": "/institutions/INS-1572a04c-912b-59bf-5841-332c7dfafaef",
"supports_oauth": true
},
"member_status": {
"status": "CONNECTED",
"error": {
"error_type": "MEMBER",
"error_code": "REQUEST_FAILED",
"error_message": "There was an error attempting to process your request. The Member was created but we were unable to fulfill the data request.",
"user_message": "We're having trouble connecting right now. Please try again later."
},
"self": "/users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c/members/MBR-7c6f361b-e582-15b6-60c0-358f12466b4b/status"
},
"oauth": {
"is_oauth": true,
"authorization_url": "https://mxbank.mx.com/oauth/authorize?client_id=b8OikQ4Ep",
"self": "/users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c/members/MBR-7c6f361b-e582-15b6-60c0-358f12466b4b/oauth/authorization_url"
},
"user": {
"guid": "USR-11141024-90b3-1bce-cac9-c06ced52ab4c",
"id": "unique_id",
"metadata": "some metadata",
"self": "/users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c"
},
"mx_record": {
"created_at": "2025-05-10T18:08:00Z",
"updated_at": "2026-02-12T22:48:21Z"
}
}
}Authorizations
To authenticate with the Platform API, include your Base64-encoded client_id and api_key in the Authorization header of every request:
-H 'Authorization: Basic BASE_64_ENCODING_OF{client_id:api_key}'
Headers
MX Platform API version.
"v20260929"
Path Parameters
Use either the member id you defined or the MX-defined member guid. See Assigning Resource IDs.
Use either the user id you defined or the MX-defined user guid. See Assigning Resource IDs.
Body
Member object with MFA challenge answers
Response
Accepted
The base fields for a member, which is a user's connection to an institution. Returned as the member companion on related resources such as accounts and transactions, and as the foundation of full member responses.
Hide child attributes
Hide child attributes
The unique identifier for the member. Defined by MX.
"MBR-7c6f361b-e582-15b6-60c0-358f12466b4b"
The unique partner-defined identifier for the member.
"unique_id"
Additional information you can store about the member.
"some metadata"
The name of the member.
"MX Bank"
The API URI path for the member.
"/users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c/members/MBR-7c6f361b-e582-15b6-60c0-358f12466b4b"
Hide child attributes
Hide child attributes
The code identifying a financial institution.
"mxbank"
The unique identifier for the institution. Defined by MX.
"INS-1572a04c-912b-59bf-5841-332c7dfafaef"
The ISO country code associated with the institution.
US, CA "US"
The name of the institution.
"MX Bank"
The products the institution supports.
account_verification, identity_verification, transactions, transaction_history, statements, investments, rewards [
"account_verification",
"identity_verification",
"transactions",
"transaction_history",
"statements",
"investments",
"rewards"
]
The API URI path for the institution.
"/institutions/INS-1572a04c-912b-59bf-5841-332c7dfafaef"
If true, this indicates that the institution supports OAuth and that you have been properly registered for OAuth with that institution.
true
Hide child attributes
Hide child attributes
The status of a user's connection to an institution. See Member Connection Status.
CREATED, PREVENTED, DENIED, CHALLENGED, REJECTED, LOCKED, CONNECTED, IMPEDED, RECONNECTED, DEGRADED, DISCONNECTED, DISCONTINUED, CLOSED, DELAYED, FAILED, UPDATED, DISABLED, IMPORTED, RESUMED, EXPIRED, IMPAIRED, PENDING "CONNECTED"
Hide child attributes
Hide child attributes
The type of error that occurred.
"MEMBER"
The specific error code.
"REQUEST_FAILED"
A human-readable message describing the error.
"There was an error attempting to process your request. The Member was created but we were unable to fulfill the data request."
A human-readable message intended for the end user.
"We're having trouble connecting right now. Please try again later."
The API URI path for the member's status.
"/users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c/members/MBR-7c6f361b-e582-15b6-60c0-358f12466b4b/status"
Hide child attributes
Hide child attributes
Indicates whether the member uses OAuth to authenticate. Defaults to false.
true
When connecting a member using OAuth, this field will contain the URL to send the user to in order to authenticate, otherwise it will be blank.
"https://mxbank.mx.com/oauth/authorize?client_id=b8OikQ4Ep"
The API URI path to generate a new OAuth Authorization URL.
"/users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c/members/MBR-7c6f361b-e582-15b6-60c0-358f12466b4b/oauth/authorization_url"
The base fields for a user. Returned as the user companion on related resources such as members, accounts, and transactions, and as the foundation of full user responses.
Hide child attributes
Hide child attributes
The unique identifier for the user. Defined by MX.
"USR-11141024-90b3-1bce-cac9-c06ced52ab4c"
The unique partner-defined identifier for the user.
"unique_id"
Additional information you can store about the user.
"some metadata"
The API URI path for the user.
"/users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c"
Timestamps for when MX created and last updated the record. Returned as the mx_record companion on all resources persisted by MX. These describe the MX record, not the underlying resource at the institution.
Hide child attributes
Hide child attributes
The date and time the resource was created in MX Platform, represented in ISO 8601 format with a timestamp.
"2025-05-10T18:08:00Z"
The date and time the resource was last updated in MX Platform, represented in ISO 8601 format with a timestamp.
For categories, this field will always be null when is_default is true.
"2026-02-12T22:48:21Z"

