curl --request POST \
--url https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url \
--header 'Accept-Version: <accept-version>' \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/json' \
--data '
{
"data_request": {
"products": [
"transactions"
]
},
"oauth": {
"client_redirect_url": "https://{yoursite.com}",
"enable_app2app": false,
"referral_source": "APP"
}
}
'import requests
url = "https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url"
payload = {
"data_request": { "products": ["transactions"] },
"oauth": {
"client_redirect_url": "https://{yoursite.com}",
"enable_app2app": False,
"referral_source": "APP"
}
}
headers = {
"Accept-Version": "<accept-version>",
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'Accept-Version': '<accept-version>',
Authorization: 'Basic <encoded-value>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
data_request: {products: ['transactions']},
oauth: {
client_redirect_url: 'https://{yoursite.com}',
enable_app2app: false,
referral_source: 'APP'
}
})
};
fetch('https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'data_request' => [
'products' => [
'transactions'
]
],
'oauth' => [
'client_redirect_url' => 'https://{yoursite.com}',
'enable_app2app' => false,
'referral_source' => 'APP'
]
]),
CURLOPT_HTTPHEADER => [
"Accept-Version: <accept-version>",
"Authorization: Basic <encoded-value>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url"
payload := strings.NewReader("{\n \"data_request\": {\n \"products\": [\n \"transactions\"\n ]\n },\n \"oauth\": {\n \"client_redirect_url\": \"https://{yoursite.com}\",\n \"enable_app2app\": false,\n \"referral_source\": \"APP\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Accept-Version", "<accept-version>")
req.Header.Add("Authorization", "Basic <encoded-value>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url")
.header("Accept-Version", "<accept-version>")
.header("Authorization", "Basic <encoded-value>")
.header("Content-Type", "application/json")
.body("{\n \"data_request\": {\n \"products\": [\n \"transactions\"\n ]\n },\n \"oauth\": {\n \"client_redirect_url\": \"https://{yoursite.com}\",\n \"enable_app2app\": false,\n \"referral_source\": \"APP\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Accept-Version"] = '<accept-version>'
request["Authorization"] = 'Basic <encoded-value>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"data_request\": {\n \"products\": [\n \"transactions\"\n ]\n },\n \"oauth\": {\n \"client_redirect_url\": \"https://{yoursite.com}\",\n \"enable_app2app\": false,\n \"referral_source\": \"APP\"\n }\n}"
response = http.request(request)
puts response.read_body{
"oauth": {
"is_oauth": true,
"authorization_url": "https://mxbank.mx.com/oauth/authorize?client_id=b8OikQ4Ep",
"self": "/users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c/members/MBR-7c6f361b-e582-15b6-60c0-358f12466b4b/oauth/authorization_url",
"member": {
"guid": "MBR-7c6f361b-e582-15b6-60c0-358f12466b4b",
"id": "unique_id",
"metadata": "some metadata",
"name": "MX Bank",
"self": "/users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c/members/MBR-7c6f361b-e582-15b6-60c0-358f12466b4b"
},
"user": {
"guid": "USR-11141024-90b3-1bce-cac9-c06ced52ab4c",
"id": "unique_id",
"metadata": "some metadata",
"self": "/users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c"
}
}
}Create OAuth Authorization URL
Generate an authorization_url for OAuth authorization of the specified member during the connection flow.
curl --request POST \
--url https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url \
--header 'Accept-Version: <accept-version>' \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/json' \
--data '
{
"data_request": {
"products": [
"transactions"
]
},
"oauth": {
"client_redirect_url": "https://{yoursite.com}",
"enable_app2app": false,
"referral_source": "APP"
}
}
'import requests
url = "https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url"
payload = {
"data_request": { "products": ["transactions"] },
"oauth": {
"client_redirect_url": "https://{yoursite.com}",
"enable_app2app": False,
"referral_source": "APP"
}
}
headers = {
"Accept-Version": "<accept-version>",
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'Accept-Version': '<accept-version>',
Authorization: 'Basic <encoded-value>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
data_request: {products: ['transactions']},
oauth: {
client_redirect_url: 'https://{yoursite.com}',
enable_app2app: false,
referral_source: 'APP'
}
})
};
fetch('https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'data_request' => [
'products' => [
'transactions'
]
],
'oauth' => [
'client_redirect_url' => 'https://{yoursite.com}',
'enable_app2app' => false,
'referral_source' => 'APP'
]
]),
CURLOPT_HTTPHEADER => [
"Accept-Version: <accept-version>",
"Authorization: Basic <encoded-value>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url"
payload := strings.NewReader("{\n \"data_request\": {\n \"products\": [\n \"transactions\"\n ]\n },\n \"oauth\": {\n \"client_redirect_url\": \"https://{yoursite.com}\",\n \"enable_app2app\": false,\n \"referral_source\": \"APP\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Accept-Version", "<accept-version>")
req.Header.Add("Authorization", "Basic <encoded-value>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url")
.header("Accept-Version", "<accept-version>")
.header("Authorization", "Basic <encoded-value>")
.header("Content-Type", "application/json")
.body("{\n \"data_request\": {\n \"products\": [\n \"transactions\"\n ]\n },\n \"oauth\": {\n \"client_redirect_url\": \"https://{yoursite.com}\",\n \"enable_app2app\": false,\n \"referral_source\": \"APP\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://int-api.mx.com/users/{user_identifier}/members/{member_identifier}/oauth/authorization_url")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Accept-Version"] = '<accept-version>'
request["Authorization"] = 'Basic <encoded-value>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"data_request\": {\n \"products\": [\n \"transactions\"\n ]\n },\n \"oauth\": {\n \"client_redirect_url\": \"https://{yoursite.com}\",\n \"enable_app2app\": false,\n \"referral_source\": \"APP\"\n }\n}"
response = http.request(request)
puts response.read_body{
"oauth": {
"is_oauth": true,
"authorization_url": "https://mxbank.mx.com/oauth/authorize?client_id=b8OikQ4Ep",
"self": "/users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c/members/MBR-7c6f361b-e582-15b6-60c0-358f12466b4b/oauth/authorization_url",
"member": {
"guid": "MBR-7c6f361b-e582-15b6-60c0-358f12466b4b",
"id": "unique_id",
"metadata": "some metadata",
"name": "MX Bank",
"self": "/users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c/members/MBR-7c6f361b-e582-15b6-60c0-358f12466b4b"
},
"user": {
"guid": "USR-11141024-90b3-1bce-cac9-c06ced52ab4c",
"id": "unique_id",
"metadata": "some metadata",
"self": "/users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c"
}
}
}Authorizations
To authenticate with the Platform API, include your Base64-encoded client_id and api_key in the Authorization header of every request:
-H 'Authorization: Basic BASE_64_ENCODING_OF{client_id:api_key}'
Headers
MX Platform API version.
"v20260929"
Path Parameters
Use either the member id you defined or the MX-defined member guid. See Assigning Resource IDs.
Use either the user id you defined or the MX-defined user guid. See Assigning Resource IDs.
Body
The data_request body is required. The oauth body is optional, but if provided, it can't be empty.
Contains a products array that specifies the products you want to aggregate.
Hide child attributes
Hide child attributes
Contains the products you want to aggregate upon a successful connection.
account_verification, identity_verification, transactions, transaction_history, statements, investments {
"products": ["transactions", "statements", "investments"]
}
Hide child attributes
Hide child attributes
This determines the redirect destination at the end of OAuth when used with is_mobile_webview: true or oauth_referral_source: 'APP'.
"https://{yoursite.com}"
This indicates whether OAuth app2app behavior is enabled for institutions that support it. Defaults to true. When set to false, any oauth_window_uri generated will not direct the end user to the institution's mobile application. This setting is not persistent. This setting currently only affects Chase institutions.
true
"APP"
A client-defined scheme used in OAuth redirects in WebViews. Defaults to mx.
Response
OK
Hide child attributes
Hide child attributes
Indicates whether the member uses OAuth to authenticate. Defaults to false.
true
When connecting a member using OAuth, this field will contain the URL to send the user to in order to authenticate, otherwise it will be blank.
"https://mxbank.mx.com/oauth/authorize?client_id=b8OikQ4Ep"
The API URI path to generate a new OAuth Authorization URL.
"/users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c/members/MBR-7c6f361b-e582-15b6-60c0-358f12466b4b/oauth/authorization_url"
The base fields for a member, which is a user's connection to an institution. Returned as the member companion on related resources such as accounts and transactions, and as the foundation of full member responses.
Hide child attributes
Hide child attributes
The unique identifier for the member. Defined by MX.
"MBR-7c6f361b-e582-15b6-60c0-358f12466b4b"
The unique partner-defined identifier for the member.
"unique_id"
Additional information you can store about the member.
"some metadata"
The name of the member.
"MX Bank"
The API URI path for the member.
"/users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c/members/MBR-7c6f361b-e582-15b6-60c0-358f12466b4b"
The base fields for a user. Returned as the user companion on related resources such as members, accounts, and transactions, and as the foundation of full user responses.
Hide child attributes
Hide child attributes
The unique identifier for the user. Defined by MX.
"USR-11141024-90b3-1bce-cac9-c06ced52ab4c"
The unique partner-defined identifier for the user.
"unique_id"
Additional information you can store about the user.
"some metadata"
The API URI path for the user.
"/users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c"

