October 2024

In October 2024, updated the account charge off description, two PDF guides were updated, we updated the Auth API amount description, removed an endpoint, added incremental fields, updated an example URL, clarified the description of events for single-use virtual card, began instant-issue card support for mobile wallets, added a new guide, enhanced fleet data information for Mastercard, added support for a new merchant advice code, updated a deposit category code, Digital card images PCI compliance scope, clarified product switching, updated Incoming ACH simulation payload values, Activity Type descriptions and Authorization stream table, added Deposit Sweeps, enumerated some values, updated Get Call Status description, and added a new object to the Auth API. Click October 2024 to see the details.

Charge off account description

We updated the Charge Off Account description to remove the reference of using the endpoint only for card accounts as we are now able to charge off any accounts leveraging the endpoint regardless of whether there is a card associated with the account or not.

CST guide updates

The Operational Fraud Services Overview and the Customer Service Tool: ACH Debit Block Review PDF guides have both been recently updated. Reach out your Galileo representative to request the latest version.

Auth API amount field description

We updated Auth API Webhook 2.0 and Auth API Webhook 3.0 to specify that the amount fields may not display a numeric value. A string "none" might be returned instead as this is current Auth API behavior.

Removed endpoint

We have removed the Reverse Payment endpoint from our documentation, because it wasn't a good way to reverse a payment. Although the endpoint is still active on the Galileo platform, we strongly discourage its use. Instead, use Create Adjustment with a reversal otype for the payment.

Optional enhanced incremental auth reporting

By request, Galileo can enable extra fields that are populated for incremental authorizations:

  • latest_incremental_id — The auth_id of the previous authorization in the sequence.
  • original_incremental_id — The auth_id of the first authorization in the incremental sequence.

Updated sample URL for Public Config API

For the Public Config API we updated the example URL to conform to the actual URL that you will use. We also clarified that the Public Config API is separate from Program API and therefore needs a different URL and credentials.

Single-use virtual card events

We updated the descriptions and triggers of the following events to be more descriptive and precise:

Mobile wallet support for instant-issue cards

You can now support manual provisioning for instant-issue cards. These cards do not undergo address checks and can follow either the green path or the red path but not yellow.

About Card Transaction Risk Gscore

We published About Card Transaction GScore which provides info on its suite of machine learning-based risk scores that assess the risk of card and money-movement transactions in real-time.

Enhanced Fleet Data

We added enhanced fleet data information in Fleet card data and Fleet Data RDF in order to meet Mastercard's mandate. Additionally, we updated Auth API Webhook 2.0 and Auth API Webhook 3.0 with the applicable enhanced fleet data params.

Merchant advice codes

We added support for code 43 for Mastercard’s merchant advice codes (MAC). Contact Galileo if you are interested in receiving MAC decisioning and overrides via the Auth API.

Deposit category code change

The RNM deposit category code is not just for tax payments, so we corrected the enumeration guide.

Digital card images

We added information to Digital card images to specify that the PCI compliance scope must be determined with your qualified security assessor (QSA) when using this method to retrieve digital card images.

Product-category switching clarification

We clarified the instructions in the Switching Products guide to indicate that you must not switch an account to a prod_id in a different product category, even if the endpoint doesn't return an error.

Incoming ACH simulation payload values

We updated the ManualReviewNameMatching template fields.

Activity type and authorization stream

We updated the descriptions for DDand DA in Activity Type to specify that these are Program API responses only and DA can mean "Non-financial transaction" as well as "Denied auth".

Additionally, we updated Authorization stream table to add an "Expired auth" column and to clarify that for Program API responses, denied authorizations are DDA for Maestro only and DAA for all other networks. DAA can also mean "non-financial transaction".

New guide

We have published the Deposit Sweeps guide, which explains how you can offer higher interest rates to your customers on the funds they hold with your program.

raw_eci values

We have enumerated the valid values for the raw_eci field of the Auth API. This field from each network (Mastercard, Visa, Discover) indicates whether 3-D Secure authentication was successful.

Get Call Status clarification

We updated the description of Get Call Status to specify that this endpoint will only ever return data for transactions that are less that 2 days old.

Fraud results object

If you subscribe to the Mastercard Fraud Rule Management Service and you use the Auth API, ask Galileo to enable the fraud_results object, which contains DE048SE56.


Galileo Financial Technologies, LLC 2024

All documentation, including but not limited to text, graphics, images, and any other content, are the exclusive property of Galileo Financial Technologies, LLC and are protected by copyright laws. These materials may not be reproduced, distributed, transmitted, displayed, or otherwise used without the prior written permission of Galileo Financial Technologies, LLC. Any unauthorized use or reproduction of these materials are expressly prohibited.