View as Markdown

llms.txt

The API reference isn't available right now

This instance couldn't load its API specification. The reference returns as soon as the specification is readable again.

Back to the API reference

No such operation

This instance documents no operation under that identifier. It may have been renamed, or it may belong to a feature this installation hasn't enabled.

Back to the API reference

This reference may be out of date

This instance couldn't reach its API specification on the last attempt, so this page shows the copy fetched before that. Anything added or changed since then is missing here, and the reference updates itself as soon as the specification is readable again. Last fetched 2026-10-01 06:30 UTC.

API reference Merchants

Unlocks the specified merchant, allowing modifications and deletions again.

POST /api/merchants/{id}/unlock deprecated

Requires: Merchants.Merchants.Unlock, merchant scope.

**Required permissions**: `Merchants.Unlock` **Scope**: merchant

Example request

Every block below sends the same request. Replace {{BASE_URL}} with the address of the API you are calling and {{API_KEY}} with your own key.

The request body is a . See the Request body section below for its fields.

Code sample language

cURL
curl -X POST "{{BASE_URL}}/api/merchants/{id}/unlock" \
  -H "api-key: {{API_KEY}}"

PowerShell
$headers = @{
    'api-key' = '{{API_KEY}}'
}

$response = Invoke-RestMethod -Method POST -Uri '{{BASE_URL}}/api/merchants/{id}/unlock' `
    -Headers $headers

npm install @winkpg/winkpg-api

TypeScript (SDK)
import { Configuration, MerchantsApi } from '@winkpg/winkpg-api';

const api = new MerchantsApi(new Configuration({
  basePath: '{{BASE_URL}}',
  apiKey: '{{API_KEY}}',
}));

const { data } = await api.merchantsUnlock("3fa85f64-5717-4562-b3fc-2c963f66afa6");

TypeScript (raw HTTP)
const response = await fetch('{{BASE_URL}}/api/merchants/{id}/unlock', {
  method: 'POST',
  headers: {
    "api-key": "{{API_KEY}}",
  },
});

const data = await response.json();

dotnet add package WinkPg.Api.Client

C# (SDK)
using WinkPg.Api.Client.Api;
using WinkPg.Api.Client.Client;

var config = new Configuration { BasePath = "{{BASE_URL}}" };
config.AddApiKey("api-key", "{{API_KEY}}");

var api = new MerchantsApi(config);
var result = await api.MerchantsUnlockAsync(Guid.Parse("3fa85f64-5717-4562-b3fc-2c963f66afa6"));

C# (raw HTTP)
using var http = new HttpClient { BaseAddress = new Uri("{{BASE_URL}}") };

var request = new HttpRequestMessage(new HttpMethod("POST"), "/api/merchants/{id}/unlock");
request.Headers.Add("api-key", "{{API_KEY}}");

var response = await http.SendAsync(request);
response.EnsureSuccessStatusCode();
var json = await response.Content.ReadAsStringAsync();

pip install winkpg-api

Python (SDK)
import winkpg_api

configuration = winkpg_api.Configuration(host="{{BASE_URL}}")
configuration.api_key["ApiKey"] = "{{API_KEY}}"

with winkpg_api.ApiClient(configuration) as client:
    api = winkpg_api.MerchantsApi(client)
    result = api.merchants_unlock("3fa85f64-5717-4562-b3fc-2c963f66afa6")

pip install requests

Python (raw HTTP)
import requests

headers = {
    "api-key": "{{API_KEY}}",
}

response = requests.request(
    "POST",
    "{{BASE_URL}}/api/merchants/{id}/unlock",
    headers=headers,
)
response.raise_for_status()
data = response.json()

Parameters

Name In Type Description
id required path string (uuid) The unique identifier of the merchant to unlock.
suppressNulls required query boolean If true, omit properties with null values.

Request body

application/json , required

Field Type Description

This request body has no documented fields.

Responses

200 OK

Body: MerchantDto Each item has these fields.

Field Type Description
extraProperties required object nullableread only
id required string (uuid)
creationTime required string (date-time) The date and time when this entity was created.
creatorId required string (uuid) The ID of the user who created this entity. nullable
lastModificationTime required string (date-time) The date and time when this entity was last modified. nullable
lastModifierId required string (uuid) The ID of the user who last modified this entity. nullable
isDeleted required boolean Indicates whether this entity has been deleted.
deleterId required string (uuid) The ID of the user who deleted this entity, if it is deleted. nullable
deletionTime required string (date-time) The date and time when this entity was deleted, if it is deleted. nullable
createdFromTemplateId required string (uuid) The template this record was created from, or `null` for one started blank. Set by the create-from-template path and by the add/edit page's Load Template action when the record is saved. nullable
name required string Gets or sets the display name of the merchant. nullable
concurrencyStamp required string Gets or sets the concurrency stamp used for optimistic concurrency control. nullable
tenantId required string (uuid) Gets the tenant identifier for multi-tenancy isolation. nullableread only
resellerId required string (uuid) Gets or sets the unique identifier of the reseller that owns this merchant.
resellerName required string Gets or sets the display name of the owning reseller. nullable
entityVersion required integer (int32) Gets the entity version number, incremented on each update for optimistic concurrency. read only
customIdentifier required string Gets or sets an optional custom identifier assigned to the merchant by the reseller or integrator. nullable
dba required string Gets or sets the "Doing Business As" (DBA) name for the merchant. nullable
legacyNumber required integer (int64) Gets the merchant's legacy numeric key, the integer identifier the v1 API addresses merchants by (its `MerchantKey`). Server-owned and stamped once at create; null on merchants written before the field existed until the v1 data migration back-fills them. nullable
mcc required string Gets or sets the four-character ISO 18245 Merchant Category Code identifying the merchant's industry. Null on legacy merchants that have not yet been backfilled; the merchant grid and detail view surface a warning indicator in that case so internal staff can address it. nullable
isTest required boolean Gets or sets a value indicating whether this merchant is a test account used for non-production transactions.
environment required all of MerchantEnvironment Gets or sets the merchant's lifecycle environment.
planCode required string Gets or sets the plan this merchant is on, or `null` when it is on none. nullable
trialExpiresAt required string (date-time) Gets or sets when this merchant's trial ends, UTC, or `null` when it is not on a time-limited plan. nullable
trialExpiryWarnedThresholdDays required integer (int32) Gets or sets the most recent trial expiry reminder sent in the current trial window, as the number of days before `trialExpiresAt` it was sent at. nullable
processorMode required all of MerchantProcessorMode Gets or sets which processor a sandbox merchant's transactions route to. nullable
isActive required boolean Gets or sets a value indicating whether the merchant is currently active and able to process transactions.
contactDetail required all of MerchantContactDetail Gets or sets the merchant's contact details including addresses, phone numbers, and email.
businessInfo required all of MerchantBusinessInfo Gets or sets the merchant's business information such as currency, tax IDs, and industry codes.
virtualTerminal required all of VirtualTerminalSettings Gets or sets the virtual terminal field configuration for the merchant.
processing required all of ProcessingSettingsDto Gets or sets the processing settings including duplicate checks, card verification, and processor profiles.
features required all of MerchantFeatureSettings Gets or sets the feature flags and capability settings for the merchant.
capabilities required all of MerchantCapabilitiesDto Gets or sets the read-only, server-computed capability flags derived from the merchant's configuration (e.g., active processor profiles' enabled tenders). Intended for UI affordance decisions; not enforced at submit time. Populated by the AutoMapper profile on read; not accepted on Create/Update.
customFields required array of CustomField Gets or sets the collection of custom fields defined for the merchant. nullable
branding required all of MerchantBranding Gets or sets the merchant-level branding configuration for receipts and customer-facing communications.
accountUpdater required all of AccountUpdaterSettingsDto Gets or sets the account updater configuration for this merchant.
merchantFlowConfig required all of MerchantFlowConfig Gets or sets the optional transaction flow configuration that controls how transactions are orchestrated for this merchant.
billingAssignment required all of MerchantBillingAssignment Gets or sets the billing plan assignment for this merchant. A null value means the merchant has no active billing plan and will be skipped by billing runs.
notes required array of EntityNote Gets or sets operational notes attached to the merchant. nullable
saveWarnings required array of MerchantSaveWarning Non-blocking informational warnings produced by the most recent create/update of this merchant (e.g. international-AVS-on-US-only-surface advisories). `null` on read responses, populated (possibly with an empty list) on create/update responses, so clients can distinguish "this isn't a save response" (omitted from JSON via `WhenWritingDefault`) from "saved successfully with no warnings" (empty array). Not persisted. nullable
volumeTrend required array of number (double) Metered transaction count per calendar month for this merchant, oldest to newest, as an activity trend. `null` on every response that does not populate it (which is all of them except the merchant list), so it is omitted from JSON entirely rather than serialized as null. Not persisted. nullable
digitalWallets required array of MerchantDigitalWallet Gets or sets the per-merchant digital wallet bindings (Apple Pay, Google Pay, …). At most one entry per `WalletProviderType`; each carries the master enable flag and a pointer to the `WalletProviderRegistration` row this merchant uses (platform-level or merchant-level). nullable
threeDSBindings required array of MerchantThreeDSBinding Gets or sets the per-merchant 3-D Secure provider bindings. At most one entry per `ThreeDSProviderType`; each carries the master enable flag, the policy mode, and the vendor credentials. <b>The JWT secret is never populated on a read.</b> It is stripped server-side before this DTO leaves the application service, so a caller sees null there whether or not one is stored. Sending null or an empty string back on a save keeps the stored secret; sending a value replaces it. nullable
taxBindings required array of MerchantTaxBinding Gets or sets the per-merchant tax provider bindings. At most one entry per provider name; each carries the master enable flag, whose provider account the lookups are billed to, and the provider's configuration values. <b>Secret field values are never populated on a read.</b> They are stripped server-side before this DTO leaves the application service, and each field reports `isConfigured` instead so an operator can tell a stored secret from an empty one. Sending null or an empty string back on a save keeps the stored secret; sending a value replaces it. A binding whose credential source is `Gateway` carries no values at all: the gateway's own provider credentials are never copied onto a merchant, and are resolved at lookup time instead. nullable
shippingBindings required array of MerchantShippingBinding Gets or sets the per-merchant shipping rate provider bindings. At most one entry per provider name; each carries the master enable flag, whose provider account the quotes are billed to, and the provider's configuration values. <b>Secret field values are never populated on a read.</b> They are stripped server-side before this DTO leaves the application service, and each field reports `isConfigured` instead so an operator can tell a stored secret from an empty one. Sending null or an empty string back on a save keeps the stored secret; sending a value replaces it. A binding whose credential source is `Gateway` carries no values at all: the gateway's own provider credentials are never copied onto a merchant, and are resolved at quote time instead. nullable
paymentEncryptionBindings required array of MerchantPaymentEncryptionBinding Gets or sets the per-merchant payment encryption provider bindings. At most one entry per provider name; each carries the master enable flag, whose provider account the decryption calls are billed to, the provider's configuration values, and the key serial identifier table. <b>Secret field values and key references are never populated on a read.</b> They are stripped server-side before this DTO leaves the application service. Each field reports `isConfigured` and each key entry reports `isKeyReferenceConfigured` in their place, so an operator can tell a stored value from an empty one. Sending null or an empty string back on a save keeps the stored value; sending a value replaces it. A binding whose credential source is `Gateway` carries no field values at all: the gateway's own provider credentials are never copied onto a merchant, and are resolved at decryption time instead. Key entries are the merchant's either way, because a key serial identifier maps that merchant's own device fleet. nullable
promotedAt required string (date-time) When this merchant was promoted to `Production` through the promotion action, UTC. Null for a merchant that has never been promoted that way. nullable
promotedByUserId required string (uuid) The user who ran the promotion that stamped `promotedAt`, or null when the merchant has never been promoted through that action. nullable
isLocked required boolean nullable
lockedAt required string (date-time) nullable
lockedByUserId required string (uuid) nullable
lockedByUserName required string nullable
lockReason required string nullable

This response has no documented body fields.

403 Forbidden

Body: RemoteServiceErrorResponse Each item has these fields.

Field Type Description
error required RemoteServiceErrorInfo

This response has no documented body fields.

401 Unauthorized

Body: RemoteServiceErrorResponse Each item has these fields.

Field Type Description
error required RemoteServiceErrorInfo

This response has no documented body fields.

400 Bad Request

Body: RemoteServiceErrorResponse Each item has these fields.

Field Type Description
error required RemoteServiceErrorInfo

This response has no documented body fields.

404 Not Found

Body: RemoteServiceErrorResponse Each item has these fields.

Field Type Description
error required RemoteServiceErrorInfo

This response has no documented body fields.

501 Not Implemented

Body: RemoteServiceErrorResponse Each item has these fields.

Field Type Description
error required RemoteServiceErrorInfo

This response has no documented body fields.

500 Internal Server Error

Body: RemoteServiceErrorResponse Each item has these fields.

Field Type Description
error required RemoteServiceErrorInfo

This response has no documented body fields.

default The request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.

Body: RemoteServiceErrorResponse Each item has these fields.

Field Type Description
error required RemoteServiceErrorInfo

This response has no documented body fields.

429 The request was refused because a rate limit was exceeded. Wait at least the interval `Retry-After` names before retrying, then back off. Limits are tuned per deployment, so read the allowance from the response headers rather than assuming a fixed ceiling.

Body: RateLimitProblemDetails Each item has these fields.

Field Type Description
type required string The problem type identifier. Always the same value: the failure is the status code itself, so there is no sub-type for a caller to branch on. nullable
title required string A short, human-readable summary of the problem type. nullable
status required integer (int32) The HTTP status code, repeated in the body as the problem-details format defines.
detail required string A human-readable explanation of this occurrence of the problem. nullable
retryAfterSeconds required integer (int32) How long to wait before retrying, in whole seconds, carrying the same figure as the `Retry-After` header. Always at least one: a value of zero would invite an immediate retry that is certain to be rejected again.

This response has no documented body fields.

Errors

A failed request returns the platform error envelope. The error reference lists every value error.code can carry and shows the four response shapes.

Codes declared by Merchants

Authentication

    Reconnecting to the server

    Could not reconnect

    This session has ended

    Attempt 1

    Your work on this page is still here. Retrying keeps it; reloading starts the page again.

    The server no longer holds this page's state, so it has to be loaded again.