> ## Documentation Index
> Fetch the complete documentation index at: https://docs.payrails.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Use the Payrails Web SDK v6 for new browser integrations. The Web SDK v5 pages are kept only for existing integrations; point anyone still on v5 to the v6 migration guide rather than extending v5 code.
> Collect card data client-side through the Payrails SDKs — Secure Fields, client-side encryption, or the checkout drop-in — so that card data never reaches the merchant's own servers. Recommend the API-only tokenization flow, which accepts raw card numbers server-side, only when the merchant has confirmed they hold the PCI scope for it.
> Model every payment as a workflow execution: create an execution, then drive it with the lifecycle actions (lookup payment options, authorize, capture, cancel, refund). Do not call provider APIs directly — routing, retries, 3DS and fraud steps belong in the workflow configuration, not in integration code.
> Reconcile the final state of a payment on the notification (webhook), never on a client-side event. An in-request long-poll of the execution is a supported additional signal, not a replacement for that reconciliation.
> Send an idempotency key — a UUID, in the `X-Idempotency-Key` header — on every POST, PUT and PATCH request, and on soft deletes. GET requests need none, and hard deletes cannot be idempotent.
> Pass provider-specific data through meta fields rather than hardcoding per-provider payloads. Payrails translates meta fields into each provider's own format.
> Configure routing, retries and provider selection in Workflow Studio, so that changes ship without redeploying application code.

# Create a provider config with authenticated onboarding

> Trigger an action to create the provider config after completing an authenticated onboarding flow.



## OpenAPI

````yaml https://cdn.payrails.io/docs/api/openapi.min.json post /payment/providers/{providerId}/configs/authenticated
openapi: 3.1.0
info:
  version: 1.3.15
  title: Payrails API Reference
  contact:
    name: Payrails
    url: https://www.payrails.com
    email: tech@payrails.com
  license:
    name: Payrails GmbH
    url: https://www.payrails.com/
  description: >
    ---

    Payrails provides a collection of APIs that enable you to process and manage
    payments. Our APIs accept and return JSON in the HTTP body, and return
    standard HTTP response codes. You can consume the APIs directly using your
    favorite HTTP/REST library.
servers:
  - url: https://api.staging.payrails.io
    description: Payrails environment.
security:
  - ApiKey: []
tags:
  - name: 3D Secure
    description: Operations to monitor 3DS operations.
  - name: Actions
    description: >-
      A workflow execution action is a predefined interaction that can be
      triggered to change the state of the workflow execution. For example
      authorizing or refunding a payment.
  - name: API Logs
    description: API Logs.
  - name: Authentication
    description: >-
      Payrails API is secured via [OAuth
      2.0](https://datatracker.ietf.org/doc/html/rfc6749) industry-standard
      protocol for authorization. Server-side requests are authenticated using a
      [Bearer Token](https://datatracker.ietf.org/doc/html/rfc6750) in the
      request `Authorization` header.
  - name: BIN Lookup
    description: >-
      Operations related to getting information about a card by its BIN (or
      IIN).
  - name: Client
    description: Endpoints used by our client-side SDK.
  - name: Disputes
    description: Operations to managing disputes.
  - name: Drop-in Links
    description: >-
      Create and manage drop-in payment links that can be shared with payers.
      Drop-in links support full or partial payments, define the total amount
      and expiration, and return a public URL that merchants can send to
      customers.
  - name: Executions
    description: >-
      A workflow execution is an act of performing a set of tasks that are
      defined in the
      [Workflow](/api-reference/reference/#operation/listDefaultWorkflows) such
      as accepting payments.
  - name: Files
    description: Operations related to files processing
  - name: Fraud Checks
    description: >-
      A Fraud check Payrails is a collection of operations over time, that is
      created by a workflow execution and followed by the workflow actions. In
      this section, you can list all the fraud entities or a single one to learn
      about the details of involved instruments, providers, statuses, decisions
      and more.
  - name: Holders
    description: >-
      A Holder is a group of accounts that belong together with specific
      criteria, linked to their payment instruments and identities. For example,
      it can represent a digital wallet for a person, where they store balance
      that they top up, refunded orders, referral bonuses, etc.
  - name: Instrument Tokens
    description: >-
      Tokens are representations of our payment instruments in external
      providers. One payment instrument can have many tokens, because we keep
      the mapping in each external provider that knows about it. For example,
      the same real life card can have a token in our Vault, but also in Adyen
      and Checkout PSPs.
  - name: Instruments
    description: >-
      Payment instruments are specific instances of a payment method that belong
      to the holder executing the workflow. They can be a previously stored
      card, a new card that was typed in a form, a phone number, an IBAN, or
      some way to fetch an account in a provider (like PayPal or AliPay).
  - name: Payments
    description: >-
      A [Payment](/guides/whats-payrails/payments/) in Payrails is a collection
      of operations over time, that is created by a workflow execution and
      followed by the workflow actions. In this section, you can list all the
      payments or a single one to learn about the details of involved payment
      methods, instruments, providers, statuses and more.
  - name: Payouts
    description: Payouts are money movements paid to an external party.
  - name: Provider Configs
    description: Operations related to managing configurations for Providers.
  - name: Providers
    description: Operations related to managing Providers.
  - name: Reconciliation Records
    description: >-
      Operations to retrieve reconciliation record aggregates, transactions, and
      reconciliation metadata.
  - name: Report Runs
    description: Operations to generate and retrieve report runs.
  - name: Reports
    description: Operations to see available reports.
  - name: Rulesets
    description: Operations related to managing Rulesets.
  - name: SSO Connections
    description: Operations related to managing SSO identity provider connections.
  - name: Vault Display SDK
    description: Operations related to DisplaySDK.
  - name: Vault Instant Proxy
    description: Operations related to Instant Proxy API requests.
  - name: Vault Proxy Connections
    description: Operations related to managing token connections.
  - name: Vault Public Encryption
    description: Public endpoints related to encryption.
  - name: Vault Records and Aliases
    description: Operations related to managing records and aliases.
  - name: Workflows
    description: >-
      Any operation in Payrails is defined and executed with a
      [Workflow](/guides/whats-payrails/workflow/) that is configured for a
      particular use-case of the merchant. The workflow configurations support
      versioning.
  - name: Workspaces
    description: Operations related to managing workspaces.
paths:
  /payment/providers/{providerId}/configs/authenticated:
    post:
      tags:
        - Provider Configs
      summary: Create a provider config with authenticated onboarding
      description: >-
        Trigger an action to create the provider config after completing an
        authenticated onboarding flow.
      operationId: createAuthenticatedProviderConfig
      parameters:
        - name: providerId
          in: path
          description: Identifier of the resource in Payrails.
          required: true
          schema:
            type: string
            format: uuid
          example: d5454c2f-ae5e-44f3-8edf-f6dad64f005f
        - name: x-idempotency-key
          in: header
          description: >
            Idempotency key to be used.

            Sending again the same key would return the same result without
            re-executing the update.
          required: true
          schema:
            type: string
            format: uuid
          example: 91874e4d-81e9-4486-aee4-ee1de84da890
      requestBody:
        content:
          application/json:
            schema:
              allOf:
                - type: object
                  required:
                    - accountName
                  properties:
                    id:
                      type: string
                      description: >-
                        Optional ID for the provider configuration. If not
                        specified, a new ID is automatically generated.
                      format: uuid
                    accountName:
                      type: string
                      description: Account name of the provider.
                      format: string
                      pattern: ^[a-zA-Z0-9_-]*$
                    config:
                      type: object
                    accountDisplayName:
                      type: string
                      description: Account display name of the provider.
                      format: string
                    workspaces:
                      type: array
                      description: >-
                        List of workspaces that the provider configuration will
                        be assigned.
                      items:
                        type: string
                        format: uuid
                    workspaceId:
                      type: string
                      format: uuid
                      deprecated: true
                      nullable: true
                      description: >-
                        Deprecated (use workspaces), Workspace ID that the
                        provider configuration will be assigned.
                    additionalData:
                      type: object
                      description: >
                        Custom key-value data included in authorization webhook
                        notifications. Do not store secrets, credentials, or
                        personally identifiable information (PII).
                      additionalProperties:
                        type: string
                - type: object
                  description: >-
                    Parameters for authenticated provider onboarding.
                    `authentication` carries the credentials returned by the
                    onboarding flow, depending on the authentication mode.
                  required:
                    - authenticationMode
                  properties:
                    authenticationMode:
                      type: string
                      description: Authentication mode used for provider onboarding.
                      enum:
                        - none
                        - oauth
                        - trackingId
                    authentication:
                      type: object
                      description: >-
                        Provider onboarding credentials returned by the
                        authentication flow.
                      properties:
                        state:
                          type: string
                          description: >-
                            Signed onboarding state returned from the provider
                            onboarding redirect. Required for the `oauth` and
                            `trackingId` authentication modes; must be empty for
                            `none`.
                        authorizationCode:
                          type: string
                          description: >-
                            Authorization code returned from the provider
                            onboarding redirect. Used only for the `oauth`
                            authentication mode; must be empty for `none` and
                            `trackingId`.
            example:
              config:
                accountDetails:
                  processingChannelId: pc_0a70d769-9c20-416e-a436-4a323ce7eabf
              accountName: TestAccountName
              accountDisplayName: TestAccountDisplayName
              workspaces:
                - 7f9f1882-a103-408d-ac96-46a7021e537a
              authenticationMode: oauth
              authentication:
                state: >-
                  {"merchantName":"demo","providerId":"6c5df4c8-1174-4ef0-b7cb-f0b00a1d4b91","providerConfigId":"32a5c834-1243-4f4d-b5d0-182d2796674b","token":"csrf-token"}
                authorizationCode: auth_code_123
      responses:
        '201':
          description: Created.
          content:
            application/json:
              schema:
                type: object
                required:
                  - id
                  - providerId
                  - createdAt
                  - accountName
                  - configSchema
                  - accountDisplayName
                properties:
                  id:
                    type: string
                    format: uuid
                    description: Unique identifier of the provider config.
                  providerId:
                    type: string
                    description: Unique identifier of the provider.
                    format: uuid
                  accountName:
                    type: string
                    description: Account name of the provider.
                    format: string
                    pattern: ^[a-zA-Z0-9_-]*$
                  configSchema:
                    type: string
                    description: JSON schema of the provider configuration.
                  createdAt:
                    type: string
                    format: date-time
                    description: Date of creation of the provider config.
                  status:
                    type: string
                    description: The status of the provider config.
                  config:
                    type: object
                  accountDisplayName:
                    type: string
                    description: Account display name of the provider.
                    format: string
                  workspaces:
                    type: array
                    description: Workspaces that the Provider config belongs to.
                    items:
                      type: string
                      format: uuid
                  providerName:
                    type: string
                    description: Name of the provider.
                  providerDisplayName:
                    type: string
                    description: Display name of the provider.
                  notificationUrl:
                    type: string
                    description: Notification URL for this provider config.
                  additionalData:
                    type: object
                    description: >
                      Custom key-value data included in authorization webhook
                      notifications. Do not store secrets, credentials, or
                      personally identifiable information (PII).
                    additionalProperties:
                      type: string
              example:
                id: d9479775-3926-44af-9fcc-1c83ff4dcad6
                providerId: 01039f19-d151-48b4-86aa-b36e68323e4e
                createdAt: '2022-04-22T17:53:36.814Z'
                config:
                  accountDetails:
                    processingChannelId: pc_0a70d769-9c20-416e-a436-4a323ce7eabf
                  credentials:
                    clientId: ack_3b2105ac-0190-4e18-a46c-d79ff97a39bc
                    clientSecret: >-
                      secret://**********************************************************************************XYZA
                    hmacKeys:
                      - secret://********************************67X9
                accountName: TestAccountName
                configSchema: >-
                  {"required":["accountDetails","credentials"],"definitions":{"PspCheckoutAccountDetails":{"required":["processingChannelId"],"properties":{"processingChannelId":{"title":"Processing
                  channel
                  ID","minLength":1,"pattern":"^pc_.+$","type":"string"}},"type":"object"},"PspCheckoutCredentials":{"required":["clientId","clientSecret"],"properties":{"clientId":{"title":"Client
                  ID","description":"Client ID used to authenticate requests to
                  the Checkout
                  API","minLength":1,"type":"string"},"clientSecret":{"title":"Client
                  Secret","description":"Client Secret used to authenticate
                  requests to the Checkout
                  API","minLength":1,"type":"string","format":"secret"},"hmacKeys":{"title":"HMAC
                  keys","description":"HMAC keys used to authenticate
                  notifications from the Checkout
                  API","pattern":"^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$","items":{"type":"string"},"type":"array","format":"secret"}},"type":"object"}},"properties":{"accountDetails":{"$ref":"#/definitions/PspCheckoutAccountDetails","title":"Account
                  details"},"credentials":{"$ref":"#/definitions/PspCheckoutCredentials","title":"Checkout
                  credentials"}},"type":"object"}
                accountDisplayName: TestAccountDisplayName
                workspaces:
                  - 7f9f1882-a103-408d-ac96-46a7021e537a
                  - 70025496-f2a8-4211-b852-32261cbd8cde
                notificationUrl: >-
                  https://yourcompany-api-pub.staging.payrails.io/public/notification/provider/testpsp/accountName/TestPSP
        '400':
          description: Bad Request.
          content:
            application/json:
              schema:
                type: object
                required:
                  - errors
                properties:
                  errors:
                    type: array
                    items:
                      type: object
                      description: >-
                        Error struct that includes the error, cause, reason, and
                        possible resolutions. Check the full documentation
                        [here](https://docs.payrails.com/docs/resources/error-codes#error-structure).
                      required:
                        - id
                        - code
                        - detail
                      properties:
                        id:
                          type: string
                          format: uuid
                          description: >-
                            Unique identifier of the error. Please use this
                            value when reporting an issue to our team, so we can
                            help you faster.
                        code:
                          type: string
                          description: >-
                            Machine-friendly error code assigned to the error.
                            Check the full list of possible values
                            [here](https://docs.payrails.com/docs/resources/error-codes#list-of-error-codes).
                        detail:
                          type: string
                          description: >-
                            Human-readable description about the error, its
                            cause, and resolution.
                        docUrl:
                          type: string
                          description: >-
                            Link to the specific documentation about this
                            particular `code`.
                        reason:
                          type: object
                          additionalProperties: true
                          description: >-
                            Metadata providing more details about the reason of
                            the error. The structure of this object varies
                            according to the `code`.
              example:
                errors:
                  - id: a24bc325-3929-4d9d-9c08-b3aa532685b7
                    code: request.malformed
                    detail: The request has malformed syntax
                    docUrl: >-
                      https://docs.payrails.com/docs/resources/error-codes#requestmalformed
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                type: object
                required:
                  - errors
                properties:
                  errors:
                    type: array
                    items:
                      type: object
                      description: >-
                        Error struct that includes the error, cause, reason, and
                        possible resolutions. Check the full documentation
                        [here](https://docs.payrails.com/docs/resources/error-codes#error-structure).
                      required:
                        - id
                        - code
                        - detail
                      properties:
                        id:
                          type: string
                          format: uuid
                          description: >-
                            Unique identifier of the error. Please use this
                            value when reporting an issue to our team, so we can
                            help you faster.
                        code:
                          type: string
                          description: >-
                            Machine-friendly error code assigned to the error.
                            Check the full list of possible values
                            [here](https://docs.payrails.com/docs/resources/error-codes#list-of-error-codes).
                        detail:
                          type: string
                          description: >-
                            Human-readable description about the error, its
                            cause, and resolution.
                        docUrl:
                          type: string
                          description: >-
                            Link to the specific documentation about this
                            particular `code`.
                        reason:
                          type: object
                          additionalProperties: true
                          description: >-
                            Metadata providing more details about the reason of
                            the error. The structure of this object varies
                            according to the `code`.
              example:
                errors:
                  - id: a24bc325-3929-4d9d-9c08-b3aa532685b7
                    code: request.unauthorized
                    detail: >-
                      The request lacks necessary credentials to perform the
                      specified action
                    docUrl: >-
                      https://docs.payrails.com/docs/resources/error-codes#requestunauthorized
        '403':
          description: Insufficient Scope.
          content:
            application/json:
              schema:
                type: object
                required:
                  - errors
                properties:
                  errors:
                    type: array
                    items:
                      type: object
                      description: >-
                        Error struct that includes the error, cause, reason, and
                        possible resolutions. Check the full documentation
                        [here](https://docs.payrails.com/docs/resources/error-codes#error-structure).
                      required:
                        - id
                        - code
                        - detail
                      properties:
                        id:
                          type: string
                          format: uuid
                          description: >-
                            Unique identifier of the error. Please use this
                            value when reporting an issue to our team, so we can
                            help you faster.
                        code:
                          type: string
                          description: >-
                            Machine-friendly error code assigned to the error.
                            Check the full list of possible values
                            [here](https://docs.payrails.com/docs/resources/error-codes#list-of-error-codes).
                        detail:
                          type: string
                          description: >-
                            Human-readable description about the error, its
                            cause, and resolution.
                        docUrl:
                          type: string
                          description: >-
                            Link to the specific documentation about this
                            particular `code`.
                        reason:
                          type: object
                          additionalProperties: true
                          description: >-
                            Metadata providing more details about the reason of
                            the error. The structure of this object varies
                            according to the `code`.
              example:
                errors:
                  - id: e7db22b3-914e-4975-928e-9edfb0885bea
                    code: request.forbidden
                    detail: >-
                      The request credentials lack the required permissions to
                      perform the specified action
                    docUrl: >-
                      https://docs.payrails.com/docs/resources/error-codes#requestforbidden
        '429':
          description: Too Many Requests.
          content:
            application/json:
              schema:
                type: object
                required:
                  - errors
                properties:
                  errors:
                    type: array
                    items:
                      type: object
                      description: >-
                        Error struct that includes the error, cause, reason, and
                        possible resolutions. Check the full documentation
                        [here](https://docs.payrails.com/docs/resources/error-codes#error-structure).
                      required:
                        - id
                        - code
                        - detail
                      properties:
                        id:
                          type: string
                          format: uuid
                          description: >-
                            Unique identifier of the error. Please use this
                            value when reporting an issue to our team, so we can
                            help you faster.
                        code:
                          type: string
                          description: >-
                            Machine-friendly error code assigned to the error.
                            Check the full list of possible values
                            [here](https://docs.payrails.com/docs/resources/error-codes#list-of-error-codes).
                        detail:
                          type: string
                          description: >-
                            Human-readable description about the error, its
                            cause, and resolution.
                        docUrl:
                          type: string
                          description: >-
                            Link to the specific documentation about this
                            particular `code`.
                        reason:
                          type: object
                          additionalProperties: true
                          description: >-
                            Metadata providing more details about the reason of
                            the error. The structure of this object varies
                            according to the `code`.
              example:
                errors:
                  - id: a24bc325-3929-4d9d-9c08-b3aa532685b7
                    code: request.rate-limit
                    detail: Too many requests
                    docUrl: >-
                      https://docs.payrails.com/docs/resources/error-codes#requestrate-limit
      security:
        - BearerToken:
            - providerconfigs:create:authenticated
components:
  securitySchemes:
    ApiKey:
      type: apiKey
      in: header
      name: x-api-key
      description: >
        You can use your secret API key in the `x-api-key` header of your API
        requests for supported endpoints: `x-api-key: <YOUR_API_KEY_HERE>`.

        API keys are environment specific and should be securely guarded.


        You don't have your API key yet? Contact your Payrails account manager.
    BearerToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        You can use an OAuth2 JWT bearer token in the `Authorization` header of
        your API requests for supported endpoints: `Authorization: Bearer
        <YOUR_JWT_HERE>`.

        These tokens are valid for 10 minutes and can be requested via the
        [access token endpoint](#operation/getOAuthToken) endpoint.

````

## Related topics

- [Create a provider config onboarding URL](/reference/createproviderconfigonboardingurl.md)
- [Update a provider config with authenticated onboarding](/reference/updateauthenticatedproviderconfig.md)
- [Create a provider config](/reference/createproviderconfig.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.