> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.mangopay.com/api-reference/preauthorizations/list-preauthorizations-user/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.mangopay.com/_mcp/server. # List Preauthorizations for a User GET https://api.sandbox.mangopay.com/v2.01/{ClientId}/users/{UserId}/preauthorizations List Preauthorizations for a User Reference: https://docs.mangopay.com/api-reference/preauthorizations/list-preauthorizations-user ## Authentication - `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer `, where token is your auth token. If your platform is using a [proxy](/guides/sca/proxy-management) to take SCA-triggering action on behalf of users, you also need to integrate [mTLS authentication](/guides/sca/platform) and use the `api-mtls` base URL. ## Servers - `https://api.sandbox.mangopay.com` (Sandbox, default) - `https://api.mangopay.com` (Production) - `https://api-mtls.sandbox.mangopay.com` (mTLS Sandbox) - `https://api-mtls.mangopay.com` (mTLS Production) ## Request ### Path parameters - `ClientId` (string, required) — Platform's API account identifier, associated with the API key. - `UserId` (string, required) — The unique identifier of the user. ## Response ### 200 Success - `Array (Preauthorizations)` (list of ListPreauthorizationsForACardResponseArrayPreauthorizationsItems, optional) — The list of preauthorizations created by the platform. ## Types ### ListPreauthorizationsForACardResponseArrayPreauthorizationsItems - `Preauthorization` (ListPreauthorizationsForACardResponseArrayPreauthorizationsItemsPreauthorization, optional) — The preauthorization created by the platform. ### ListPreauthorizationsForACardResponseArrayPreauthorizationsItemsPreauthorization The preauthorization created by the platform. - `Id` (string, optional) — The unique identifier of the preauthorization. - `Tag` (string, optional) — Max. length: 255 characters Custom data that you can add to this object, such as unique identifiers in your system. To store multiple values, you can serialize them into a single string, for example a JSON object: `"{\"id_1\":AB123,\"id_2\":DE456}"`. - `CreationDate` (integer, optional) — Unix timestamp (UTC) of the date and time the object was created. - `AuthorId` (string, optional) — The unique identifier of the user at the source of the transaction. In a conversion, both the debited and credited wallets are owned by the author. - `DebitedFunds` (ListPreauthorizationsForACardResponseArrayPreauthorizationsItemsPreauthorizationDebitedFunds, optional) — Information about the preauthorized funds. - `RemainingFunds` (ListPreauthorizationsForACardResponseArrayPreauthorizationsItemsPreauthorizationRemainingFunds, optional) — Information about the remaining preauthorized funds. - `AuthorizationDate` (integer, optional) — Unix timestamp (UTC) of the date and time successful authorization occurred. If authorization failed, the value is `null`. - `Status` (string, optional) — **Returned values:** `CREATED`, `SUCCEEDED`, `FAILED` The status of the authorization. - `PaymentStatus` (string, optional) — **Returned values:** `WAITING`, `CANCELED`, `CANCEL_REQUESTED`, `EXPIRED`, `VALIDATED`, `FAILED` The payment status of the extended preauthorization object: - `WAITING` – The extended preauthorization can be used: the preauthorized funds can be captured (if `Status` is `SUCCEEDED`) or the preauthorization can be canceled manually. - `CANCELED` – Value to pass to manually cancel the extended preauthorization before use; indicates that the extended preauthorization was canceled manually. - `CANCEL_REQUESTED` – The cancellation of the extended preauthorization has been requested but not yet processed. - `EXPIRED` – The hold period on the preauthorized funds has ended without it being used. - `VALIDATED` – Indicates that the preauthorized funds were captured. - `FAILED` – The pay-in against the preauthorization has failed, but a retry may be possible. - `ExpirationDate` (integer, optional) — Unix timestamp (UTC) of the date and time the hold period ends and the preauthorized funds are released. At the expiration date, the preauthorization's `PaymentStatus` changes to `EXPIRED` if no captures were made or `VALIDATED` if at least one capture was made. - `PayInId` (string, optional) — The unique identifier of the first preauthorized pay-in made against the preauthorization. - `ResultMessage` (string, optional) — The explanation of the result code. - `SecureMode` (string, optional) — **Returned values:** `DEFAULT`, `FORCE`, `NO_CHOICE` The mode applied for the 3DS2 protocol for CB, Visa, and Mastercard. The options are: - `DEFAULT` – Requests an exemption to strong customer authentication (SCA), and thus a frictionless payment experience, if allowed by your Mangopay contract and accepted by the issuer. - `FORCE` – Requests SCA. - `NO_CHOICE` – Leaves the choice to the issuer whether to allow for a frictionless payment experience or to enforce SCA. - `CardId` (string, optional) — The unique identifier of the Card object, which is returned after updating the Card Registration object with the `RegistrationData`. - `SecureModeReturnURL` (string, optional) — The URL to which users are automatically returned after 3DS2 if it is triggered (i.e., if the `SecureModeNeeded` parameter is set to `true`). - `SecureModeNeeded` (boolean, optional) — Whether or not the `SecureMode` was used. - `PaymentType` (string, optional) — **Returned values:** `CARD` The payment type of the preauthorization. - `ExecutionType` (string, optional) — **Returned values:** `DIRECT` The execution type of the preauthorization. - `StatementDescriptor` (string, optional) — Custom description to appear on the user's bank statement along with the platform name. Different banks may show more or less information. See the Customizing bank statement references article for details. - `Culture` (string, optional) — **Returned values:** One of the supported languages in the [ISO 639-1 format](/api-reference/overview/data-formats): DE, EN, ES, FR, IT, NL, PL, PT. The language in which the payment page is to be displayed. - `SecurityInfo` (AVSResult, optional) — Information regarding security and anti-fraud tools. - `MultiCapture` (boolean, optional) — **Default value:** true Whether multiple captures are activated for the preauthorization. - `BrowserInfo` (BrowserInfo, optional) — Information about the browser used by the end user (author) to perform the payment. - `Billing` (Billing_DefaultsShippingUser_Response, optional) — **Default values:** `FirstName`, `LastName`, and `Address` information of the `Shipping` object if sent, otherwise of the `AuthorId` (if address values present). Information about the billing address. - `Shipping` (Shipping_DefaultsBillingUser_Response, optional) — **Default values:** `FirstName`, `LastName`, and `Address` information of the `Billing` object if sent, otherwise of the `AuthorId` (if address values present). Information about the shipping address. - `Requested3DSVersion` (string, optional) — **Returned values:** `V1`, `V2_1` The 3DS protocol version to be applied to the transaction. - `Applied3DSVersion` (string, optional) — **Returned values:** `V1`, `V2_1` The 3DS protocol version applied to the transaction. - `PreferredCardNetwork` (string, optional) — **Returned values:** `VISA`, `MASTERCARD`, `CB`, `MAESTRO` The card network to use, as chosen by the cardholder, in case of co-branded cards. - `CardInfo` (CardInfo, optional) — Information about the card used for the transaction. If the information or data is not available, `null` is returned. ### ListPreauthorizationsForACardResponseArrayPreauthorizationsItemsPreauthorizationDebitedFunds Information about the preauthorized funds. - `Currency` (string, optional) — **Allowed values:** The three-letter ISO 4217 code (EUR, GBP, etc.) of a supported currency (depends on feature, contract, and activation settings). The currency of the amount. - `Amount` (integer, optional) — The amount of the currency in its minor unit. For example, EUR 12.60 would be represented as `1260` whereas JPY 12 would be represented as just `12`. ### ListPreauthorizationsForACardResponseArrayPreauthorizationsItemsPreauthorizationRemainingFunds Information about the remaining preauthorized funds. - `Currency` (string, optional) — **Allowed values:** The three-letter ISO 4217 code (EUR, GBP, etc.) of a supported currency (depends on feature, contract, and activation settings). The currency of the amount. - `Amount` (integer, optional) — The amount of the currency in its minor unit. For example, EUR 12.60 would be represented as `1260` whereas JPY 12 would be represented as just `12`. ### AVSResult Information regarding security and anti-fraud tools. - `AVSResult` (string, optional) — The result of the Address Verification System check (only available for UK, US, and Canada). ### BrowserInfo Information about the browser used by the end user (author) to perform the payment. - `AcceptHeader` (string, required) — The exact content of the HTTP accept headers as sent to the platform from the end user's browser. - `JavaEnabled` (boolean, required) — Whether or not the end user's browser has the ability to execute Java. - `Language` (string, required) — Format: Two-letter language code (ISO 639-1 alpha-2) followed by two-letter country code (ISO 3166-1 alpha-2), separated by a hyphen (example: `en-US`; pattern:`^[a-zA-Z]{2}(-[a-zA-Z]{2})?$`) The language of the browser. - `ColorDepth` (integer, required) — The value representing the depth of the screen's color palette for displaying images, in bits per pixel. - `ScreenHeight` (integer, required) — The height of the screen in pixels. - `ScreenWidth` (integer, required) — The width of the screen in pixels. - `TimeZoneOffset` (integer, required) — The difference in minutes between the browser's timezone and UTC. - `UserAgent` (string, required) — The exact content of the HTTP User-Agent header. - `JavascriptEnabled` (boolean, required) — Whether or not the end user's browser has the ability to execute JavaScript. ### Billing_DefaultsShippingUser_Response **Default values:** `FirstName`, `LastName`, and `Address` information of the `Shipping` object if sent, otherwise of the `AuthorId` (if address values present). Information about the billing address. - `FirstName` (string, optional) — The first name of the user. - `LastName` (string, optional) — The last name of the user. - `Address` (Address, optional) — The postal address. ### Shipping_DefaultsBillingUser_Response **Default values:** `FirstName`, `LastName`, and `Address` information of the `Billing` object if sent, otherwise of the `AuthorId` (if address values present). Information about the shipping address. - `FirstName` (string, optional) — The first name of the user. - `LastName` (string, optional) — The last name of the user. - `Address` (Address_SubPropsRequired, optional) — The postal address. ### CardInfo Information about the card used for the transaction. If the information or data is not available, `null` is returned. - `BIN` (string, optional) — The bank identification number (BIN) of the card. - `IssuingBank` (string, optional) — The name of the bank that issued the card. - `IssuerCountryCode` (string, optional) — The country code of the card issuer. - `Type` (string, optional) — The type of card (for example, `CREDIT` or `DEBIT`). - `SubType` (string, optional, nullable) — The sub-type of the card, if available. - `Brand` (string, optional) — The card brand (for example, `VISA` or `MASTERCARD`). ### Address The postal address. - `AddressLine1` (string, optional) — The first line of the address. - `AddressLine2` (string, optional) — The second line of the address. - `City` (string, optional) — The city of the address. - `Region` (string, optional) — Required if `Country` is US, CA, or MX. The region of the address. - `PostalCode` (string, optional) — The postal code of the address. The postal code can contain the following characters: alphanumeric, dashes, and spaces. - `Country` (string, optional) — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The country of the address. ### Address_SubPropsRequired The postal address. - `AddressLine1` (string, required) — The first line of the address. - `City` (string, required) — The city of the address. - `PostalCode` (string, required) — The postal code of the address. The postal code can contain the following characters: alphanumeric, dashes, and spaces. - `Country` (string, required) — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The country of the address. - `AddressLine2` (string, optional) — The second line of the address. - `Region` (string, optional) — Required if `Country` is US, CA, or MX. The region of the address. ## Examples **Response** ```json [ { "Applied3DSVersion": null, "AuthorId": "156671912", "AuthorizationDate": 1669116904, "Billing": null, "BrowserInfo": null, "CardId": "156674899", "CardInfo": { "BIN": "497010", "Brand": "VISA", "IssuerCountryCode": "MA", "IssuingBank": "LA BANQUE POSTALE", "SubType": null, "Type": "CREDIT" }, "CreationDate": 1669116896, "Culture": "EN", "DebitedFunds": { "Amount": 500, "Currency": "EUR" }, "ExecutionType": "DIRECT", "ExpirationDate": 1669678504, "Id": "156686696", "IpAddress": null, "MultiCapture": true, "PayInId": "156686722", "PaymentStatus": "VALIDATED", "PaymentType": "CARD", "PreferredCardNetwork": null, "RemainingFunds": { "Amount": 0, "Currency": "EUR" }, "Requested3DSVersion": null, "ResultCode": "000000", "ResultMessage": "Success", "SecureMode": "FORCE", "SecureModeNeeded": false, "SecureModeRedirectURL": null, "SecureModeReturnURL": null, "SecurityInfo": null, "Shipping": null, "StatementDescriptor": null, "Status": "SUCCEEDED", "Tag": null } ] ``` **SDK Code** ```python from pprint import pprint import mangopay mangopay.client_id='your-client-id' mangopay.apikey='your-api-key' from mangopay.api import APIRequest handler = APIRequest(sandbox=True) from mangopay.resources import NaturalUser natural_user = NaturalUser.get('213600749') preauthorizations = natural_user.get_pre_authorizations() for preauthorization in preauthorizations: pprint(vars(preauthorization)) ``` ```javascript const mangopayInstance = require('mangopay4-nodejs-sdk') const mangopay = new mangopayInstance({ clientId: 'your-client-id', clientApiKey: 'your-api-key', }) let user = { Id: '146476890', } const listUserPreauthorizations = async (userId) => { return await mangopay.Users.getPreAuthorizations(userId) .then((response) => { console.info(response) return response }) .catch((err) => { console.log(err) return false }) } listUserPreauthorizations(user.Id) ``` ```java import com.google.gson.Gson; import com.google.gson.GsonBuilder; import com.mangopay.MangoPayApi; import com.mangopay.entities.CardPreAuthorization; import java.util.List; public class ListUserPreauthorization { public static void main(String[] args) throws Exception { MangoPayApi mangopay = new MangoPayApi(); mangopay.getConfig().setClientId("your-client-id"); mangopay.getConfig().setClientPassword("your-api-key"); var userId = "user_m_01HT2NFK7Z2BRQNGNHMY30VVTT"; List preauths = mangopay.getUserApi().getPreAuthorizations(userId); for (CardPreAuthorization preauth : preauths) { Gson prettyPrint = new GsonBuilder().setPrettyPrinting().create(); String prettyJson = prettyPrint.toJson(preauth); System.out.println(prettyJson); } } } ``` ```csharp using MangoPay.SDK; using MangoPay.SDK.Entities; using Newtonsoft.Json; class Program { static async Task Main(string[] args) { MangoPayApi api = new MangoPayApi(); api.Config.ClientId = "your-client-id"; api.Config.ClientPassword = "your-api-key"; var userId = "user_m_01J2TZ261WZNDM0ZDRWGDYA4GN"; var userPreauthorizations = await api.CardPreAuthorizations.GetPreAuthorizationsForUserAsync(userId, new Pagination(1, 50), null); string prettyPrint = JsonConvert.SerializeObject(userPreauthorizations, Formatting.Indented); Console.WriteLine(prettyPrint); } } ``` ```php Config->ClientId = 'your-client-id'; $api->Config->ClientPassword = 'your-api-key'; $api->Config->TemporaryFolder = 'tmp/'; try { $userId = 'user_m_01HQK25M6KVHKDV0S36JY9NRKR'; $response = $api->Users->GetPreAuthorizations($userId); print_r($response); } catch(MGPResponseException $e) { print_r($e); } catch(MGPException $e) { print_r($e); } ``` ```ruby require 'mangopay' MangoPay.configure do |client| client.preproduction = true client.client_id = 'your-client-id' client.client_apiKey = 'your-api-key' client.log_file = File.join(Dir.pwd, 'mangopay.log') end def listPreauthorizationsUser(userId) begin response = MangoPay::User.pre_authorizations(userId) puts response return response rescue MangoPay::ResponseError => error puts "Failed to fetch preauthorizations: #{error.message}" puts "Error details: #{error.details}" return false end end myUser = { Id: '146476890' } listPreauthorizationsUser(myUser[:Id]) ```