> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.mangopay.com/api-reference/extended-preauthorizations/create-card-extended-preauthorization/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.mangopay.com/_mcp/server. # Create a Card Extended Preauthorization POST https://api.sandbox.mangopay.com/v2.01/{ClientId}/extended-preauthorizations/card/direct Content-Type: application/json This endpoint creates an [Extended Preauthorization](/api-reference/extended-preauthorizations/extended-preauthorization-object) with `PaymentType` of `CARD` and returns the `RedirectURL` on which the user can preauthorize the debited funds. Once authorized (`Status` becomes `SUCCEEDED`), you can capture the funds using the [POST Create an Extended Preauthorized PayIn](/api-reference/extended-preauthorizations/create-extended-preauthorized-payin) endpoint. Reference: https://docs.mangopay.com/api-reference/extended-preauthorizations/create-card-extended-preauthorization ## Authentication - `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer `, where token is your auth token. If your platform is using a [proxy](/guides/sca/proxy-management) to take SCA-triggering action on behalf of users, you also need to integrate [mTLS authentication](/guides/sca/platform) and use the `api-mtls` base URL. ## Servers - `https://api.sandbox.mangopay.com` (Sandbox, default) - `https://api.mangopay.com` (Production) - `https://api-mtls.sandbox.mangopay.com` (mTLS Sandbox) - `https://api-mtls.mangopay.com` (mTLS Production) ## Request ### Path parameters - `ClientId` (string, required) — Platform's API account identifier, associated with the API key. ### Body (application/json) This endpoint expects a CreateACardExtendedPreauthorizationRequest. - `AuthorId` (string, required) — The unique identifier of the user at the source of the transaction. - `DebitedFunds` (CreateACardExtendedPreauthorizationRequestDebitedFunds, required) — Information about the preauthorized funds. - `CardId` (string, required) — The unique identifier of the Card object, obtained during the card registration process. - `SecureModeReturnURL` (string, required) — Max. length: 255 characters The URL to which users are automatically returned after 3DS2 if it is triggered (i.e., if the `SecureModeNeeded` parameter is set to `true`). - `BrowserInfo` (BrowserInfo, required) — Information about the browser used by the end user (author) to perform the payment. - `IpAddress` (string, required) — The IP address of the end user initiating the transaction, in IPV4 or IPV6 format. - `FlowDescriptor` (FlowDescriptorRequest, optional) — Information about the Owner beneficiaries targeted by the pay-in and its subsequent transfers, who must all be KYC/KYB verified when the pay-in request is made ([read more](/guides/payin-beneficiaries)). If the `FlowDescriptor.Beneficiaries` is sent in the API request, then: - The transaction's `CreditedWalletId` holder is disregarded in KYC/KYB checks. - **ALL** `UserId` values in the array must be one of: - `OWNER` whose `KYCLevel` is `REGULAR` - `PLATFORM` The pay-in `Status` becomes `FAILED` with `ResultCode` [002951](/errors/codes/002951) if at least one `FlowDescriptor.Beneficiaries.UserId` is: - `PAYER` - `OWNER` whose `KYCLevel` is `LIGHT` If the `FlowDescriptor.Beneficiaries` is not sent in the API request, then the `CreditedWalletId` holder is subject to KYC/KYB checks. This property is optional for backwards compatibility but is recommended for all pay-in flows, even when the `CreditedWalletId` holder is a `PAYER` or the same value as one of the `FlowDescriptor.Beneficiaries`. - `PreferredCardNetwork` (string, optional) — **Allowed values:** `VISA`, `MASTERCARD`, `CB`, `MAESTRO` The card network to use, as chosen by the cardholder, in case of co-branded cards. - `StatementDescriptor` (string, optional) — Max. length: 22 characters; only alphanumeric and spaces Custom description to appear on the user’s bank statement along with the platform name. Different banks may show more or less information. See the Customizing bank statement references article for details. - `Culture` (string, optional) — **Allowed values:** One of the supported languages in the [ISO 639-1 format](/api-reference/overview/data-formats): DE, EN, ES, FR, IT, NL, PL, PT. The language in which the payment page is to be displayed. - `Billing` (Billing_DefaultsShippingUser_Request, optional) — **Default values:** `FirstName`, `LastName`, and `Address` information of the `Shipping` object if sent, otherwise of the `AuthorId` (if address values present). Information about the billing address. - `Shipping` (Shipping_DefaultsBillingUser_Request, optional) — **Default values:** `FirstName`, `LastName`, and `Address` information of the `Billing` object if sent, otherwise of the `AuthorId` (if address values present). Information about the shipping address. - `Tag` (string, optional) — Max. length: 255 characters Custom data that you can add to this object, such as unique identifiers in your system. To store multiple values, you can serialize them into a single string, for example a JSON object: `"{\"id_1\":AB123,\"id_2\":DE456}"`. - `ProfilingAttemptReference` (string, optional) — The unique reference generated for the profiling session, used by the fraud prevention solution to produce recommendations for the transaction using the profiling data. **Note:** Parameter not returned by the API. Profiling feature available on request – contact Mangopay via the Dashboard for more information. ## Response ### 200 Success - `Id` (string, optional) — Max length: 128 characters (see [data formats](/api-reference/overview/data-formats) for details) The unique identifier of the object. - `CreationDate` (integer, optional) — Unix timestamp (UTC) of the date and time the object was created. - `ExpirationDate` (integer, optional) — Unix timestamp (UTC) of the date and time the hold period ends and the preauthorized funds are released. At the expiration date, the extended preauthorization's `PaymentStatus` changes to `EXPIRED` if no captures were made. - `AuthorizationDate` (integer, optional) — Unix timestamp (UTC) of the date and time successful authorization occurred. If authorization failed, the value is `null`. - `AuthorId` (string, optional) — The unique identifier of the user at the source of the transaction. - `FlowDescriptor` (FlowDescriptorResponse, optional) — Information about the Owner beneficiaries targeted by the pay-in and its subsequent transfers, who must all be KYC/KYB verified when the pay-in request is made ([read more](/guides/payin-beneficiaries)). If the `FlowDescriptor.Beneficiaries` is sent in the API request, then: - The transaction's `CreditedWalletId` holder is disregarded in KYC/KYB checks. - **ALL** `UserId` values in the array must be one of: - `OWNER` whose `KYCLevel` is `REGULAR` - `PLATFORM` The pay-in `Status` becomes `FAILED` with `ResultCode` [002951](/errors/codes/002951) if at least one `FlowDescriptor.Beneficiaries.UserId` is: - `PAYER` - `OWNER` whose `KYCLevel` is `LIGHT` If the `FlowDescriptor.Beneficiaries` is not sent in the API request, then the `CreditedWalletId` holder is subject to KYC/KYB checks. This property is optional for backwards compatibility but is recommended for all pay-in flows, even when the `CreditedWalletId` holder is a `PAYER` or the same value as one of the `FlowDescriptor.Beneficiaries`. - `DebitedFunds` (CardExtendedPreauthorizationResponseDebitedFunds, optional) — Information about the preauthorized funds. - `Status` (string, optional) — **Returned values:** `CREATED`, `SUCCEEDED`, `FAILED` The status of the authorization. - `PaymentStatus` (string, optional) — **Returned values:** `WAITING`, `CANCELED`, `CANCEL_REQUESTED`, `EXPIRED`, `VALIDATED`, `FAILED` The payment status of the extended preauthorization object: - `WAITING` – The extended preauthorization can be used: the preauthorized funds can be captured (if `Status` is `SUCCEEDED`) or the preauthorization can be canceled manually. - `CANCELED` – Value to pass to manually cancel the extended preauthorization before use; indicates that the extended preauthorization was canceled manually. - `CANCEL_REQUESTED` – The cancellation of the extended preauthorization has been requested but not yet processed. - `EXPIRED` – The hold period on the preauthorized funds has ended without it being used. - `VALIDATED` – Indicates that the preauthorized funds were captured. - `FAILED` – The pay-in against the preauthorization has failed, but a retry may be possible. - `PayinsLinked` (CardExtendedPreauthorizationResponsePayinsLinked, optional) — Information about the extended preauthorized pay-ins made against the extended preauthorization. - `ResultCode` (string, optional) — The code indicating the result of the operation. This information is mostly used to handle errors or for filtering purposes. - `ResultMessage` (string, optional) — The explanation of the result code. - `PaymentType` (string, optional) — **Returned values:** `CARD` The payment type of the preauthorization. - `ExecutionType` (string, optional) — **Returned values:** `DIRECT` The execution type of the preauthorization. - `StatementDescriptor` (string, optional) — Max. length: 22 characters; only alphanumeric and spaces Custom description to appear on the user’s bank statement along with the platform name. Different banks may show more or less information. See the Customizing bank statement references article for details. - `Culture` (string, optional) — **Returned values:** One of the supported languages in the [ISO 639-1 format](/api-reference/overview/data-formats): DE, EN, ES, FR, IT, NL, PL, PT. The language in which the payment page is to be displayed. - `Shipping` (Shipping_DefaultsBillingUser_Response, optional) — **Default values:** `FirstName`, `LastName`, and `Address` information of the `Billing` object if sent, otherwise of the `AuthorId` (if address values present). Information about the shipping address. - `Tag` (string, optional) — Max. length: 255 characters Custom data that you can add to this object, such as unique identifiers in your system. To store multiple values, you can serialize them into a single string, for example a JSON object: `"{\"id_1\":AB123,\"id_2\":DE456}"`. - `CardId` (string, optional) — The unique identifier of the Card object, obtained during the card registration process. - `PreferredCardNetwork` (string, optional) — **Allowed values:** `VISA`, `MASTERCARD`, `CB`, `MAESTRO` The card network to use, as chosen by the cardholder, in case of co-branded cards. - `SecureModeReturnURL` (string, optional) — Max. length: 255 characters The URL to which users are automatically returned after 3DS2 if it is triggered (i.e., if the `SecureModeNeeded` parameter is set to `true`). - `SecureModeRedirectURL` (string, optional) — Max. length: 255 characters The URL to which to redirect the user to proceed to 3DS2 validation. - `SecureModeNeeded` (boolean, optional) — Whether or not the `SecureMode` was used. - `BrowserInfo` (BrowserInfo, optional) — Information about the browser used by the end user (author) to perform the payment. - `IpAddress` (string, optional) — The IP address of the end user initiating the transaction, in IPV4 or IPV6 format. - `Billing` (Billing_DefaultsShippingUser_Response, optional) — **Default values:** `FirstName`, `LastName`, and `Address` information of the `Shipping` object if sent, otherwise of the `AuthorId` (if address values present). Information about the billing address. - `Requested3DSVersion` (string, optional) — **Returned values:** `V1`, `V2_1` The 3DS protocol version to be applied to the transaction. - `Applied3DSVersion` (string, optional) — **Returned values:** `V1`, `V2_1` The 3DS protocol version applied to the transaction. - `CardInfo` (CardInfo, optional) — Information about the card used for the transaction. If the information or data is not available, `null` is returned. - `AuthenticationResult` (AuthenticationResult, optional) — Information about the authentication result, based on the request made by Mangopay and the decision of the issuer regarding the type of authentication to be enforced (if applicable). ## Types ### CreateACardExtendedPreauthorizationRequestDebitedFunds Information about the preauthorized funds. - `Currency` (string, required) — **Allowed values:** The three-letter ISO 4217 code (EUR, GBP, etc.) of a supported currency (depends on feature, contract, and activation settings). The currency of the amount. - `Amount` (integer, required) — The amount of the currency in its minor unit. For example, EUR 12.60 would be represented as `1260` whereas JPY 12 would be represented as just `12`. ### BrowserInfo Information about the browser used by the end user (author) to perform the payment. - `AcceptHeader` (string, required) — The exact content of the HTTP accept headers as sent to the platform from the end user's browser. - `JavaEnabled` (boolean, required) — Whether or not the end user's browser has the ability to execute Java. - `Language` (string, required) — Format: Two-letter language code (ISO 639-1 alpha-2) followed by two-letter country code (ISO 3166-1 alpha-2), separated by a hyphen (example: `en-US`; pattern:`^[a-zA-Z]{2}(-[a-zA-Z]{2})?$`) The language of the browser. - `ColorDepth` (integer, required) — The value representing the depth of the screen's color palette for displaying images, in bits per pixel. - `ScreenHeight` (integer, required) — The height of the screen in pixels. - `ScreenWidth` (integer, required) — The width of the screen in pixels. - `TimeZoneOffset` (integer, required) — The difference in minutes between the browser's timezone and UTC. - `UserAgent` (string, required) — The exact content of the HTTP User-Agent header. - `JavascriptEnabled` (boolean, required) — Whether or not the end user's browser has the ability to execute JavaScript. ### FlowDescriptorRequest Information about the Owner beneficiaries targeted by the pay-in and its subsequent transfers, who must all be KYC/KYB verified when the pay-in request is made ([read more](/guides/payin-beneficiaries)). If the `FlowDescriptor.Beneficiaries` is sent in the API request, then: - The transaction's `CreditedWalletId` holder is disregarded in KYC/KYB checks. - **ALL** `UserId` values in the array must be one of: - `OWNER` whose `KYCLevel` is `REGULAR` - `PLATFORM` The pay-in `Status` becomes `FAILED` with `ResultCode` [002951](/errors/codes/002951) if at least one `FlowDescriptor.Beneficiaries.UserId` is: - `PAYER` - `OWNER` whose `KYCLevel` is `LIGHT` If the `FlowDescriptor.Beneficiaries` is not sent in the API request, then the `CreditedWalletId` holder is subject to KYC/KYB checks. This property is optional for backwards compatibility but is recommended for all pay-in flows, even when the `CreditedWalletId` holder is a `PAYER` or the same value as one of the `FlowDescriptor.Beneficiaries`. - `Beneficiaries` (list of FlowDescriptorRequestBeneficiariesItems, optional, nullable) — Max. length: 5 items The list of up to 5 Natural or Legal Users declared as beneficiaries of the pay-in and its subsequent transfers, who must all be KYC/KYB verified when the pay-in request is made. The pay-in also fails if the `Beneficiaries` array contains nulled objects or invalid `UserId` values. ### Billing_DefaultsShippingUser_Request **Default values:** `FirstName`, `LastName`, and `Address` information of the `Shipping` object if sent, otherwise of the `AuthorId` (if address values present). Information about the billing address. - `FirstName` (string, optional) — The first name of the user. - `LastName` (string, optional) — The last name of the user. - `Address` (Address_SubPropsRequired, optional) — The postal address. ### Shipping_DefaultsBillingUser_Request **Default values:** `FirstName`, `LastName`, and `Address` information of the `Billing` object if sent, otherwise of the `AuthorId` (if address values present). Information about the shipping address. - `FirstName` (string, optional) — The first name of the user. - `LastName` (string, optional) — The last name of the user. - `Address` (Address_SubPropsRequired, optional) — The postal address. ### FlowDescriptorResponse Information about the Owner beneficiaries targeted by the pay-in and its subsequent transfers, who must all be KYC/KYB verified when the pay-in request is made ([read more](/guides/payin-beneficiaries)). If the `FlowDescriptor.Beneficiaries` is sent in the API request, then: - The transaction's `CreditedWalletId` holder is disregarded in KYC/KYB checks. - **ALL** `UserId` values in the array must be one of: - `OWNER` whose `KYCLevel` is `REGULAR` - `PLATFORM` The pay-in `Status` becomes `FAILED` with `ResultCode` [002951](/errors/codes/002951) if at least one `FlowDescriptor.Beneficiaries.UserId` is: - `PAYER` - `OWNER` whose `KYCLevel` is `LIGHT` If the `FlowDescriptor.Beneficiaries` is not sent in the API request, then the `CreditedWalletId` holder is subject to KYC/KYB checks. This property is optional for backwards compatibility but is recommended for all pay-in flows, even when the `CreditedWalletId` holder is a `PAYER` or the same value as one of the `FlowDescriptor.Beneficiaries`. - `FlowId` (string, optional) — Unique identifier of the payment flow, used by Mangopay for internal purposes. - `Beneficiaries` (list of FlowDescriptorResponseBeneficiariesItems, optional, nullable) — Max. length: 5 items The list of up to 5 Natural or Legal Users declared as beneficiaries of the pay-in, who must all be KYC/KYB verified when the pay-in request is made. The pay-in also fails if the `Beneficiaries` array contains nulled objects or invalid `UserId` values. ### CardExtendedPreauthorizationResponseDebitedFunds Information about the preauthorized funds. - `Currency` (string, optional) — **Allowed values:** The three-letter ISO 4217 code (EUR, GBP, etc.) of a supported currency (depends on feature, contract, and activation settings). The currency of the amount. - `Amount` (integer, optional) — The amount of the currency in its minor unit. For example, EUR 12.60 would be represented as `1260` whereas JPY 12 would be represented as just `12`. ### CardExtendedPreauthorizationResponsePayinsLinked Information about the extended preauthorized pay-ins made against the extended preauthorization. - `PayinCaptureId` (string, optional) — The unique identifier of the preauthorized pay-in (capture) made against the extended preauthorization to debit the preauthorized funds. - `PayinComplementId` (string, optional) — This deprecated parameter is always returned `null`. ### Shipping_DefaultsBillingUser_Response **Default values:** `FirstName`, `LastName`, and `Address` information of the `Billing` object if sent, otherwise of the `AuthorId` (if address values present). Information about the shipping address. - `FirstName` (string, optional) — The first name of the user. - `LastName` (string, optional) — The last name of the user. - `Address` (Address_SubPropsRequired, optional) — The postal address. ### Billing_DefaultsShippingUser_Response **Default values:** `FirstName`, `LastName`, and `Address` information of the `Shipping` object if sent, otherwise of the `AuthorId` (if address values present). Information about the billing address. - `FirstName` (string, optional) — The first name of the user. - `LastName` (string, optional) — The last name of the user. - `Address` (Address, optional) — The postal address. ### CardInfo Information about the card used for the transaction. If the information or data is not available, `null` is returned. - `BIN` (string, optional) — The bank identification number (BIN) of the card. - `IssuingBank` (string, optional) — The name of the bank that issued the card. - `IssuerCountryCode` (string, optional) — The country code of the card issuer. - `Type` (string, optional) — The type of card (for example, `CREDIT` or `DEBIT`). - `SubType` (string, optional, nullable) — The sub-type of the card, if available. - `Brand` (string, optional) — The card brand (for example, `VISA` or `MASTERCARD`). ### AuthenticationResult Information about the authentication result, based on the request made by Mangopay and the decision of the issuer regarding the type of authentication to be enforced (if applicable). - `AuthenticationType` (string, optional, nullable) — **Returned values:** `CHALLENGE`, `FRICTIONLESS`, `DIRECT_AUTHORIZATION` The type of authentication: - `CHALLENGE` – The issuer requested SCA to be enforced (for example, using 3DS). - `FRICTIONLESS` – The transaction was exempted from SCA because an exemption was granted by the issuer. - `DIRECT_AUTHORIZATION` – The transaction was sent to the issuer for authorization without any frictionless or challenge (for example, if SCA doesn't apply). A `null` value typically indicates that authentication was not requested (for example, because the request failed before being sent) or a decision was not received. A `null` value typically indicates that authentication was not requested (for example, because the request failed before being sent) or a decision was not received. ### FlowDescriptorRequestBeneficiariesItems - `UserId` (string, optional) — The unique identifier of the Natural User or Legal User declared as a beneficiary of the pay-in. ### Address_SubPropsRequired The postal address. - `AddressLine1` (string, required) — The first line of the address. - `City` (string, required) — The city of the address. - `PostalCode` (string, required) — The postal code of the address. The postal code can contain the following characters: alphanumeric, dashes, and spaces. - `Country` (string, required) — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The country of the address. - `AddressLine2` (string, optional) — The second line of the address. - `Region` (string, optional) — Required if `Country` is US, CA, or MX. The region of the address. ### FlowDescriptorResponseBeneficiariesItems - `UserId` (string, optional) — The unique identifier of the Natural User or Legal User declared as a beneficiary of the pay-in. ### Address The postal address. - `AddressLine1` (string, optional) — The first line of the address. - `AddressLine2` (string, optional) — The second line of the address. - `City` (string, optional) — The city of the address. - `Region` (string, optional) — Required if `Country` is US, CA, or MX. The region of the address. - `PostalCode` (string, optional) — The postal code of the address. The postal code can contain the following characters: alphanumeric, dashes, and spaces. - `Country` (string, optional) — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The country of the address. ## Examples **Request** ```json { "body": { "AuthorId": "user_m_01KHXAHEBRWSZXJY85TPPR56TK", "Billing": { "Address": { "AddressLine1": "6 rue de la Cité", "AddressLine2": "Appartement 3", "City": "Paris", "Country": "FR", "PostalCode": "75004", "Region": "Île-de-France" }, "FirstName": "Alex", "LastName": "Smith" }, "BrowserInfo": { "AcceptHeader": "text/html, application/xhtml+xml, application/xml;q=0.9, /;q=0.8", "ColorDepth": 4, "JavaEnabled": true, "JavascriptEnabled": true, "Language": "FR-FR", "ScreenHeight": 1800, "ScreenWidth": 400, "TimeZoneOffset": 60, "UserAgent": "Mozilla/5.0 (iPhone; CPU iPhone OS 13_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148" }, "CardId": "card_wt_HodULFWKVRMEecCa", "Culture": "EN", "DebitedFunds": { "Amount": 20000, "Currency": "EUR" }, "FlowDescriptor": { "Beneficiaries": [ { "UserId": "user_m_02APAYTWSDYXHXN1FRTKX9WMA2" } ] }, "IpAddress": "4ce4:e138:803f:eb1c:9c5b:7316:ec84:3d00", "SecureModeReturnURL": "http://example.com", "Shipping": { "Address": { "AddressLine1": "6 rue de la Cité", "AddressLine2": "Appartement 3", "City": "Paris", "Country": "FR", "PostalCode": "75004", "Region": "Île-de-France" }, "FirstName": "Alex", "LastName": "Smith" }, "StatementDescriptor": null, "Tag": "Created using Mangopay API Postman Collection" } } ``` **Response** ```json { "Id": "ext_auth_wt_073099a9-4e14-42b7-9bc7-d1978f65d8ba", "CreationDate": 1771585135, "ExpirationDate": 1774177135, "AuthorizationDate": null, "AuthorId": "user_m_01KHXAHEBRWSZXJY85TPPR56TK", "FlowDescriptor": { "FlowId": "flow_wt_97448e0a-5bc6-4b83-ac29-cdfcadf60a08", "Beneficiaries": [ { "UserId": "user_m_02APAYTWSDYXHXN1FRTKX9WMA2" } ] }, "DebitedFunds": { "Currency": "EUR", "Amount": 20000 }, "Status": "CREATED", "PaymentStatus": "WAITING", "PayinsLinked": { "PayinCaptureId": null, "PayinComplementId": null }, "ResultCode": null, "ResultMessage": null, "PaymentType": "CARD", "ExecutionType": "DIRECT", "StatementDescriptor": null, "Culture": "EN", "Shipping": { "FirstName": "Alex", "LastName": "Smith", "Address": { "AddressLine1": "6 rue de la Cité", "City": "Paris", "PostalCode": "75004", "Country": "FR", "AddressLine2": "Appartement 3", "Region": "Île-de-France" } }, "Tag": "Created using the Mangopay API Postman collection", "CardId": "card_wt_HodULFWKVRMEecCa", "PreferredCardNetwork": null, "SecureModeReturnURL": "http://example.com?extendedPreauthorizationId=ext_auth_wt_073099a9-4e14-42b7-9bc7-d1978f65d8ba", "SecureModeRedirectURL": "https://api.sandbox.whenthen.co/payment-gateway/whenthen/threeDS/54b0c206-0a67-43d4-ace6-14a25697cf85/challenge?id=073099a9-4e14-42b7-9bc7-d1978f65d8ba&url=aHR0cHM6Ly9hcGkuc2FuZGJveC53aGVudGhlbi5jby9wYXltZW50cy8zRFNlY3VyZS81NGIwYzIwNi0wYTY3LTQzZDQtYWNlNi0xNGEyNTY5N2NmODUvMDk5MzBkYzAtZWMwMi00MTlhLTkxZmQtZDdiZjU2M2RjNjNl&amount=MjAwMDA¤cy=RVVS", "SecureModeNeeded": true, "BrowserInfo": { "AcceptHeader": "text/html, application/xhtml+xml, application/xml;q=0.9, /;q=0.8", "JavaEnabled": true, "Language": "FR-FR", "ColorDepth": 4, "ScreenHeight": 1800, "ScreenWidth": 400, "TimeZoneOffset": 60, "UserAgent": "Mozilla/5.0 (iPhone; CPU iPhone OS 13_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148", "JavascriptEnabled": true }, "IpAddress": "4ce4:e138:803f:eb1c:9c5b:7316:ec84:3d00", "Billing": { "FirstName": "Alex", "LastName": "Smith", "Address": { "AddressLine1": "6 rue de la Cité", "AddressLine2": "Appartement 3", "City": "Paris", "Region": "Île-de-France", "PostalCode": "75004", "Country": "FR" } }, "Requested3DSVersion": null, "Applied3DSVersion": null, "CardInfo": { "BIN": "497010", "IssuingBank": "LA BANQUE POSTALE", "IssuerCountryCode": "MA", "Type": "CREDIT", "SubType": null, "Brand": "VISA" }, "AuthenticationResult": { "AuthenticationType": "CHALLENGE" } } ``` **SDK Code** ```python from pprint import pprint import mangopay mangopay.client_id='your-client-id' mangopay.apikey='your-api-key' from mangopay.api import APIRequest handler = APIRequest(sandbox=True) from mangopay.resources import NaturalUser, CardExtendedPreauthorization from mangopay.utils import Money, BrowserInfo natural_user = NaturalUser.get('213753890') card_extended_preauthorization = CardExtendedPreauthorization( author_id = natural_user.id, debited_funds = Money(amount=20000, currency='EUR'), card_id = '213944219', secure_mode_return_url = 'https://docs.mangopay.com/please-ignore', browser_info = BrowserInfo( user_agent = 'Mozilla/5.0 (iPhone; CPU iPhone OS 13_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148', screen_width = 375, screen_height = 667, color_depth = 32, language = 'EN', accept_header = 'application/json,text/javascript,*/*;q=0.01', timezone_offset = '-120', java_enabled = True, javascript_enabled = True ), ip_address = '159.180.248.187', tag = 'Created using the Mangopay Python SDK' ) create_card_extended_preauthorization = card_extended_preauthorization.save() pprint(create_card_extended_preauthorization) ``` ```javascript const mangopay = require('mangopay4-nodejs-sdk'); const api = new mangopay({ clientId: 'your-client-id', clientApiKey: 'your-api-key', baseUrl: 'https://api.sandbox.mangopay.com' }); api.ExtendedPreauthorizations.create({ AuthorId: 'user_m_01HT2NFK7Z2BRQNGNHMY30VVTT', CardId: 'card_m_01HY0MA4E2WQ0NRYQJP8X8SXMB', DebitedFunds: { Currency: 'EUR', Amount: 20000 }, SecureModeReturnURL: 'https://docs.mangopay.com/please-ignore', BrowserInfo: { AcceptHeader: 'text/html, application/xhtml+xml, application/xml;q=0.9, /;q=0.8', JavaEnabled: true, Language: 'EN', ColorDepth: 4, ScreenHeight: 1800, ScreenWidth: 400, TimeZoneOffset: 60, UserAgent: 'Mozilla/5.0 (iPhone; CPU iPhone OS 13_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148', JavascriptEnabled: true }, IpAddress: '192.158.1.38', Tag: 'Created using the Mangopay Node.js SDK' }, (data) => { console.log(data); }); ``` ```java import com.google.gson.Gson; import com.google.gson.GsonBuilder; import com.mangopay.MangoPayApi; import com.mangopay.core.Money; import com.mangopay.core.enumerations.CultureCode; import com.mangopay.core.enumerations.CurrencyIso; import com.mangopay.entities.ExtendedPreauthorization; import com.mangopay.entities.subentities.BrowserInfo; public class CreateCardExtendedPreauthorization { public static void main(String[] args) throws Exception { MangoPayApi mangopay = new MangoPayApi(); mangopay.getConfig().setClientId("your-client-id"); mangopay.getConfig().setClientPassword("your-api-key"); var userId = "user_m_01HT2NFK7Z2BRQNGNHMY30VVTT"; var cardId = "card_m_01HY0MA4E2WQ0NRYQJP8X8SXMB"; ExtendedPreauthorization extendedPreauthorization = new ExtendedPreauthorization(); extendedPreauthorization.setAuthorId(userId); extendedPreauthorization.setCardId(cardId); extendedPreauthorization.setDebitedFunds(new Money(CurrencyIso.EUR, 20000)); extendedPreauthorization.setSecureModeReturnUrl("https://docs.mangopay.com/please-ignore"); extendedPreauthorization.setCulture(CultureCode.EN); extendedPreauthorization.setIpAddress("192.158.1.38"); extendedPreauthorization.setBrowserInfo(new BrowserInfo()); extendedPreauthorization.getBrowserInfo().setAcceptHeader("text/html, application/xhtml+xml, application/xml;q=0.9, /;q=0.8"); extendedPreauthorization.getBrowserInfo().setJavaEnabled(true); extendedPreauthorization.getBrowserInfo().setLanguage("EN"); extendedPreauthorization.getBrowserInfo().setColorDepth(4); extendedPreauthorization.getBrowserInfo().setScreenHeight(1800); extendedPreauthorization.getBrowserInfo().setScreenWidth(400); extendedPreauthorization.getBrowserInfo().setTimeZoneOffset("60"); extendedPreauthorization.getBrowserInfo().setUserAgent("Mozilla/5.0 (iPhone; CPU iPhone OS 13_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148"); extendedPreauthorization.getBrowserInfo().setJavascriptEnabled(true); ExtendedPreauthorization createExtendedPreauthorization = mangopay.getExtendedPreauthorizationApi().create(extendedPreauthorization, null); Gson prettyPrint = new GsonBuilder().setPrettyPrinting().create(); String prettyJson = prettyPrint.toJson(createExtendedPreauthorization); System.out.println(prettyJson); } } ``` ```csharp using MangoPay.SDK; using MangoPay.SDK.Entities.POST; using Newtonsoft.Json; class Program { static async Task Main(string[] args) { MangoPayApi api = new MangoPayApi(); api.Config.ClientId = "your-client-id"; api.Config.ClientPassword = "your-api-key"; var userId = "user_m_01J2TZ261WZNDM0ZDRWGDYA4GN"; var cardId = "card_m_01J3049JBA2XPA7GC7GEFJRQG4"; var extendedPreauthorization = new ExtendedPreauthorizationPostDTO ( userId, new Money { Amount = 20000, Currency = CurrencyIso.EUR }, cardId, "http://www.mangopay.com/docs/please-ignore", "2001:0620:0000:0000:0211:24FF:FE80:C12C", new BrowserInfo { AcceptHeader = "text/html, application/xhtml+xml, application/xml;q=0.9, /;q=0.8", JavaEnabled = true, Language = "FR-FR", ColorDepth = 4, ScreenHeight = 1800, ScreenWidth = 400, JavascriptEnabled = true, TimeZoneOffset = "+60", UserAgent = "Mozilla/5.0 (iPhone; CPU iPhone OS 13_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148" } ) { Tag = "Created using the Mangopay .NET SDK" }; var createExtendedPreauthorization = await api.ExtendedPreauthorizations.CreateAsync(extendedPreauthorization); string prettyPrint = JsonConvert.SerializeObject(createExtendedPreauthorization, Formatting.Indented); Console.WriteLine(prettyPrint); } } ``` ```php Config->ClientId = 'your-client-id'; $api->Config->ClientPassword = 'your-api-key'; $api->Config->TemporaryFolder = 'tmp/'; try { $userId = 'user_m_01HQK25M6KVHKDV0S36JY9NRKR'; $cardId = 'card_m_01J420XC7KAW655XPP12SC28HS'; $extendedPreauth = new MangoPay\ExtendedPreauthorization; $extendedPreauth->AuthorId = $userId; $extendedPreauth->CardId = $cardId; $extendedPreauth->DebitedFunds = new Money(); $extendedPreauth->DebitedFunds->Amount = 20000; $extendedPreauth->DebitedFunds->Currency = 'EUR'; $extendedPreauth->BrowserInfo = new BrowserInfo(); $extendedPreauth->BrowserInfo->AcceptHeader = "text/html, application/xhtml+xml, application/xml;q=0.9, /;q=0.8"; $extendedPreauth->BrowserInfo->JavaEnabled = true; $extendedPreauth->BrowserInfo->Language = "en"; $extendedPreauth->BrowserInfo->ColorDepth = 4; $extendedPreauth->BrowserInfo->ScreenHeight = 1800; $extendedPreauth->BrowserInfo->ScreenWidth = 400; $extendedPreauth->BrowserInfo->TimeZoneOffset = 60; $extendedPreauth->BrowserInfo->UserAgent = "Mozilla/5.0 (iPhone; CPU iPhone OS 13_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148"; $extendedPreauth->BrowserInfo->JavascriptEnabled = true; $extendedPreauth->IpAddress = "192.158.1.38"; $extendedPreauth->Culture = "FR"; $extendedPreauth->SecureModeReturnURL = "https://docs.mangopay.com/please-ignore"; $createExtendedPreauth = $api->ExtendedPreauthorizations->Create($extendedPreauth); print_r($createExtendedPreauth); } catch(MGPResponseException $e) { print_r($e); } catch(MGPException $e) { print_r($e); } ``` ```ruby require 'mangopay' MangoPay.configure do |c| c.client_id = 'your-client-id' c.client_apiKey = 'your-api-key' end extended_preauthorization = MangoPay::ExtendedPreauthorization.create( AuthorId: 'user_m_01HT2NFK7Z2BRQNGNHMY30VVTT', CardId: 'card_m_01HY0MA4E2WQ0NRYQJP8X8SXMB', DebitedFunds: { Currency: 'EUR', Amount: 20000 }, SecureModeReturnURL: 'https://docs.mangopay.com/please-ignore', Culture: 'EN', IpAddress: '2001:0620:0000:0000:0211:24FF:FE80:C12C', BrowserInfo: { AcceptHeader: 'text/html, application/xhtml+xml, application/xml;q=0.9, */*;q=0.8', JavaEnabled: true, JavascriptEnabled: true, Language: 'EN', ColorDepth: 4, ScreenHeight: 1800, ScreenWidth: 400, TimeZoneOffset: '+60', UserAgent: 'Mozilla/5.0 (iPhone; CPU iPhone OS 13_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148' } ) pp extended_preauthorization ```