> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mx.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Request oauth window uri

> Use [Create Oauth Authorization URL](/api-reference/platform-api/v20260929/reference/widgets/create-oauth-authorization-url) instead. For more information, reference the [Upgrade Guide](/api-reference/platform-api/v20260929/overview/upgrade-guide).

Generate an `authorization_url` for OAuth authorization of the specified member during the connection flow.




## OpenAPI

````yaml /openapi/platform-api/v20260929.yaml get /users/{user_identifier}/members/{member_identifier}/oauth_window_uri
openapi: 3.0.0
info:
  contact:
    name: Platform API v20260929
    url: https://www.mx.com/products/platform-api
  description: >
    The MX Platform API is a powerful, fully-featured API designed to make
    aggregating and enhancing financial data easy and reliable. It can
    seamlessly connect your app or website to tens of thousands of financial
    institutions.


    ## Version Header

    Versions are set in the `Accept-Version` header of API requests. Version
    numbers correspond with the date associated with that version. The example
    below uses the version `v20260929`.


    ```

    -H 'Accept: application/json'

    -H 'Accept-Version: v20260929'

    ```


    ---
  title: Platform API 2026
  version: '2026'
servers:
  - url: https://int-api.mx.com
  - url: https://api.mx.com
security:
  - basicAuth: []
tags:
  - name: authorization
  - name: accounts
    description: >
      The Accounts endpoints represent a user's checking, savings, mortgage,
      401(k), or other types of accounts held by a financial institution.


      An account belongs to a `member`, which represents the user's overall
      relationship with a particular financial institution. A checking account
      may be just one part of a larger relationship that could also include a
      car loan and a savings account.


      Accounts—and the transactions associated with them—are updated every 24
      hours, unless the associated `user` is disabled.


      You can also create manual accounts. Since a manual account has no
      credentials tied to the member, the account will never aggregate or
      include data from a data feed. All manual accounts are automatically
      created under the Manual Institution member.
  - name: ach return
    description: >
      The features documented here are in a beta state, and this documentation
      is considered draft material subject to frequent change.


      Using our Platform API, you can securely submit ACH Returns to reduce your
      ACH return rates and automate your ACH return process.


      You can query the status and outcomes of your submitted ACH returns to
      track progress and access resolution details.
  - name: budgets
    description: >
      Use these endpoints to create and manage budgets for your end users.


      You can create a budget for a specific category or autogenerate a budget
      for several categories based on existing transactions.


      Each budget has a `category_guid`, relating to one of the
      [categories](/api-reference/platform-api/v20260929/reference/categories#default-categories-and-subcategories).
  - name: categories
    description: >
      A `transaction` can have its `category` set to one of MX’s default
      categories or a custom category for a specific `user`. 


      See [Default Categories and
      Subcategories](/api-reference/platform-api/v20260929/reference/categories#default-categories-and-subcategories)
      for a complete list.
  - name: data exchange
    description: >
      Data Exchange provides a secure mechanism for MX clients to share
      financial data with authorized service providers, external partners, and
      vendors. Access is controlled through client grants, which define the
      scope of data an MX client (issuer) makes available to one or more
      grantees.
                                                                                                                                                                                                                                         
      Each data exchange request requires both standard Platform API
      authentication and a valid token passed in the `MX-3DX-TOKEN` request
      header.
  - name: deprecated
  - name: goals
    description: >
      Use these endpoints to create and manage goals for a `user`. You can also
      reposition goals to adjust their priority levels.


      Every goal has a track type and a meta type.


      The track type (`track_type_name`) is the overall classification of the
      goal (debt, savings, retirement, or emergency fund) while the meta type
      (`meta_type_name`) is the specific classification (like college, house,
      vacation, and so on).
  - name: insights
    description: >
      Use these endpoints to build customizable user experiences in UIs powered
      by our Financial Insights data.


      With Financial Insights, your users will receive personalized insights
      based on their transaction history.


      Want to learn more about the product? See [Financial
      Insights](/products/experience/insights).


      Looking for a guide to use these endpoints? See [Build Your Own Insights
      UI](/products/experience/insights/integration-guides/insights-api-guide).
  - name: institutions
    description: >
      Institutions represent a financial institution.


      A single real-world financial institution may have several `institution`
      objects on the MX platform.


      For example, the mortgage division of a financial institution might use a
      separate system than its everyday banking division, which is different
      from its credit card division.


      For more info, see [Institutions
      Overview](/api-reference/platform-api/v20260929/reference/institutions).
  - name: investment holdings
    description: >
      Investment Data Enhancement lets you connect to an end user's financial
      institution and retrieve cleansed and enhanced investment data. By
      combining investment data with retail banking information, you get
      comprehensive insights into customer financial behaviors, risk tolerance,
      and investment strategies.


      You can [read a user's
      holding](/api-reference/platform-api/v20260929/reference/investment-holdings/read-holding),
      [list all their
      holdings](/api-reference/platform-api/v20260929/reference/investment-holdings/list-holdings-by-user),
      or list their holdings by
      [account](/api-reference/platform-api/v20260929/reference/investment-holdings/list-holdings-by-account)
      or
      [member](/api-reference/platform-api/v20260929/reference/investment-holdings/list-holdings-by-member).


      You can also [deactivate a
      user](/api-reference/platform-api/v20260929/reference/investment-holdings/deactivate-user-from-investment-holdings)
      from the Investment Data Enhancement. This is non-billable.
  - name: members
    description: >
      Members represent the connection between an end user and a financial
      institution. This institution may represent your institution or another
      one from which MX is aggregating data.


      For more info, see [Members
      Overview](/api-reference/platform-api/v20260929/reference/members).
  - name: merchants
    description: >
      Merchants are representations of a transaction’s origin. For example, if
      you buy a coffee at Starbucks, the transaction merchant will be
      `Starbucks`.


      Use the `merchant_guid` and a `merchant_location_guidon` any `transaction`
      object to access Merchant endpoints for details like the merchant’s name,
      logo URL, website, street address, and more.
  - name: microdeposits
    description: >
      Microdeposits is an additional verification method that allows you to
      verify account details and navigate the process of using microdeposits and
      the automated clearing house (ACH) system. 


      Make two, small ACH deposits into a consumer's account using the provided
      account and routing number. You can then require that the end user confirm
      the exact amount of each deposit to verify that they own the account and
      meet NACHA’s account verification.


      For more info, including process flows, setting block lists, and more, see
      [Microdeposits](/products/connectivity/microdeposits).
  - name: identity_match
    description: >
      Verify user identity by comparing personal information with account owner
      data from connected financial accounts.
  - name: monthly cash flow profile
  - name: notifications
    description: >
      You can only use notifications endpoints if you’re using the MX mobile
      application.


      All notifications created through the API will be of notification type
      `API_NOTIFICATION`, channel `PUSH`, and will not be associated to an
      entity. No other channels are supported.


      The read and list endpoints can return any notification associated with
      the `user`, including notifications created by MX for other channels
      besides `PUSH`.
  - name: processor token
  - name: rewards
  - name: spending plan
    description: >
      Use the Spending Plan endpoints to create your own version of our
      [Spending Plan
      Widget](/products/experience/pfm/legacy-widget-overviews/spending-plan),
      which helps end users track their spending throughout the month.


      To understand key terms and how to best use these endpoints, see [Build
      Your Own Spending Plan
      UI](/products/experience/pfm/integration-guides/build-your-own-spending-plan-ui).
  - name: statements
    description: >
      With Statements, you can retrieve a user's monthly account statements in
      PDF format. This data can be used for solutions like personal financial
      management or risk analysis.
  - name: taggings
    description: >
      Tags and taggings are two resources in the MX Platform API that, when used
      together, give end users more control over organizing their transactions. 


      A tag is a custom label that can be applied to a transaction.


      After you create a tag, use it for tagging. This means you should actually
      apply the tag to a particular transaction.


      Together, they're a powerful tool for personalization, customization, and
      money management.


      For a guide on creating a tag and then applying it to a specific
      transaction with a tagging, see [Custom Tags and
      Taggings](/products/experience/pfm/integration-guides/personalization/).
  - name: tags
    description: >
      Tags and taggings are two resources in the MX Platform API that, when used
      together, give end users more control over organizing their transactions. 


      A tag is a custom label that can be applied to a transaction.


      After you create a tag, use it for tagging. This means you should actually
      apply the tag to a particular transaction.


      Together, they're a powerful tool for personalization, customization, and
      money management.


      For a guide on creating a tag and then applying it to a specific
      transaction with a tagging, see [Custom Tags and
      Taggings](/products/experience/pfm/integration-guides/personalization/).
  - name: transaction rules
    description: >
      Transaction Rules allow users to automatically recategorize or rename all
      similar transactions according to their preferences. This only applies to
      future transactions.


      When recategorizing or renaming a transaction, the user will be asked
      whether they want the new data to apply to the selected transaction or to
      all future transactions. If they choose to apply it to all future
      transactions, it will create a transaction rule which will automatically
      apply the changes going forward.
  - name: transactions
    description: >
      Transactions represent any instance in which money moves into or out of an
      account. This could be a purchase at a business, a payroll deposit, a
      transfer from one account to another, an ATM withdrawal, and so on.


      Transactions are created automatically when a member is successfully
      aggregated.


      Each `transaction` belongs to only one `account`.


      For more info, see [Transactions
      Overview](/api-reference/platform-api/v20260929/reference/transactions).
  - name: users
    description: >
      Users represent an end user using the Platform API through your web or
      mobile app.


      Users are created by MX clients and belong to a specific
      [client](/products/connectivity/overview/data-architecture#resources) on
      the platform.
  - name: verifiable credentials
    description: >
      MX provides Verifiable Credential endpoints that comply with web5
      standards. 


      For more info, see [Verifiable Credentials
      Overview](/api-reference/platform-api/v20260929/reference/verifiable-credentials).
  - name: widgets
    description: >
      Use the [Request Widget
      URL](/api-reference/platform-api/v20260929/reference/widgets/request-widget-url)
      endpoint to generate a URL that loads one of our widgets.


      Many request body parameters only work for some widgets.


      For more info, including widget types, see [Widgets
      Overview](/api-reference/platform-api/v20260929/reference/widgets).
paths:
  /users/{user_identifier}/members/{member_identifier}/oauth_window_uri:
    get:
      tags:
        - widgets
      summary: Request oauth window uri
      description: >
        Use [Create Oauth Authorization
        URL](/api-reference/platform-api/v20260929/reference/widgets/create-oauth-authorization-url)
        instead. For more information, reference the [Upgrade
        Guide](/api-reference/platform-api/v20260929/overview/upgrade-guide).


        Generate an `authorization_url` for OAuth authorization of the specified
        member during the connection flow.
      operationId: requestOAuthWindowURI
      parameters:
        - $ref: '#/components/parameters/acceptVersion'
        - $ref: '#/components/parameters/clientRedirectUrl'
        - $ref: '#/components/parameters/enableApp2app'
        - $ref: '#/components/parameters/memberIdentifier'
        - $ref: '#/components/parameters/referralSource'
        - $ref: '#/components/parameters/uiMessageWebviewUrlScheme'
        - $ref: '#/components/parameters/userIdentifier'
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OauthAuthorizationUrlResponseBody'
          description: OK
      deprecated: true
components:
  parameters:
    acceptVersion:
      name: Accept-Version
      in: header
      required: true
      schema:
        type: string
        default: v20260929
        example: v20260929
      description: MX Platform API version.
    clientRedirectUrl:
      description: >-
        A URL that MX will redirect to at the end of OAuth with additional query
        parameters. Only available with `referral_source=APP`.
      example: https://{yoursite.com}
      in: query
      name: client_redirect_url
      schema:
        type: string
    enableApp2app:
      description: >-
        This indicates whether OAuth app2app behavior is enabled for
        institutions that support it. Defaults to `true`. When set to `false`,
        any `oauth_window_uri` generated will **not** direct the end user to the
        institution's mobile application. This setting is not persistent. This
        setting currently only affects Chase institutions.
      example: 'false'
      in: query
      name: enable_app2app
      schema:
        type: string
    memberIdentifier:
      description: >-
        Use either the member `id` you defined or the MX-defined member `guid`.
        See [Assigning Resource
        IDs](/products/connectivity/overview/held-data#assigning-resource-ids).
      name: member_identifier
      in: path
      required: true
      schema:
        type: string
    referralSource:
      description: >-
        Must be either `BROWSER` or `APP` depending on the implementation.
        Defaults to `BROWSER`.
      example: APP
      in: query
      name: referral_source
      schema:
        type: string
    uiMessageWebviewUrlScheme:
      description: >-
        A scheme for routing the user back to the application state they were
        previously in. Only available with `referral_source=APP`.
      in: query
      name: ui_message_webview_url_scheme
      schema:
        type: string
    userIdentifier:
      description: >-
        Use either the user `id` you defined or the MX-defined user `guid`. See
        [Assigning Resource
        IDs](/products/connectivity/overview/held-data#assigning-resource-ids).
      in: path
      required: true
      name: user_identifier
      schema:
        type: string
  schemas:
    OauthAuthorizationUrlResponseBody:
      properties:
        oauth:
          $ref: '#/components/schemas/OauthAuthorizationUrlResponse'
      type: object
    OauthAuthorizationUrlResponse:
      allOf:
        - $ref: '#/components/schemas/OauthBaseResponse'
        - type: object
          properties:
            member:
              $ref: '#/components/schemas/MemberBaseResponse'
            user:
              $ref: '#/components/schemas/UserBaseResponse'
      type: object
    OauthBaseResponse:
      properties:
        is_oauth:
          description: >-
            Indicates whether the member uses OAuth to authenticate. Defaults to
            `false`.
          example: true
          nullable: true
          type: boolean
        authorization_url:
          description: >-
            When connecting a member using OAuth, this field will contain the
            URL to send the user to in order to authenticate, otherwise it will
            be blank.
          example: https://mxbank.mx.com/oauth/authorize?client_id=b8OikQ4Ep
          nullable: true
          type: string
        self:
          description: The API URI path to generate a new OAuth Authorization URL.
          example: >-
            /users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c/members/MBR-7c6f361b-e582-15b6-60c0-358f12466b4b/oauth/authorization_url
          nullable: false
          type: string
    MemberBaseResponse:
      description: >-
        The base fields for a member, which is a user's connection to an
        institution. Returned as the `member` companion on related resources
        such as accounts and transactions, and as the foundation of full member
        responses.
      properties:
        guid:
          description: The unique identifier for the member. Defined by MX.
          example: MBR-7c6f361b-e582-15b6-60c0-358f12466b4b
          nullable: false
          type: string
        id:
          description: The unique partner-defined identifier for the member.
          example: unique_id
          nullable: true
          type: string
        metadata:
          description: Additional information you can store about the member.
          example: some metadata
          nullable: true
          type: string
        name:
          description: The name of the member.
          example: MX Bank
          nullable: true
          type: string
        self:
          description: The API URI path for the member.
          example: >-
            /users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c/members/MBR-7c6f361b-e582-15b6-60c0-358f12466b4b
          nullable: false
          type: string
    UserBaseResponse:
      description: >-
        The base fields for a user. Returned as the `user` companion on related
        resources such as members, accounts, and transactions, and as the
        foundation of full user responses.
      properties:
        guid:
          description: The unique identifier for the user. Defined by MX.
          example: USR-11141024-90b3-1bce-cac9-c06ced52ab4c
          nullable: false
          type: string
        id:
          description: The unique partner-defined identifier for the user.
          example: unique_id
          nullable: true
          type: string
        metadata:
          description: Additional information you can store about the user.
          example: some metadata
          nullable: true
          type: string
        self:
          description: The API URI path for the `user`.
          example: /users/USR-11141024-90b3-1bce-cac9-c06ced52ab4c
          nullable: false
          type: string
  securitySchemes:
    basicAuth:
      scheme: basic
      type: http
      description: >
        To authenticate with the Platform API, include your Base64-encoded
        `client_id` and `api_key` in the Authorization header of every request:


        ```

        -H 'Authorization: Basic BASE_64_ENCODING_OF{client_id:api_key}'

        ```

````