# GET /api/merchants/{id}/custom-fields

Reads one merchant's custom field definitions.

The narrow counterpart to `GET /api/merchants/{id}` for a caller that wants only the
definitions. That route answers with the whole merchant, decrypting processor and screening
provider secrets on the way, so using it to read a handful of field names pulls material the
caller never asked for across the wire and pays a per-profile decryption for it.

Takes the merchant as a parameter rather than resolving it from the caller, unlike
`self/custom-fields`: definition numbering is per merchant, so a caller acting for
several of them has to be able to name the one it means. The caller must have access to the
merchant it names: a merchant outside the caller's scope is reported as not found.

**Operation ID:** `merchantsGetCustomFieldsForMerchant`

## Authorization

No permission required.

## Parameters

| Name | In | Required | Type | Description |
| --- | --- | --- | --- | --- |
| id | path | yes | string(uuid) | The merchant whose definitions to read. |
| suppressNulls | query | no | boolean | If true, omit properties with null values. |

## Responses

### 200

OK

**Content type:** `application/json`

Schema type: `array<CustomField>`

Item properties:
- `id` (string(uuid))
- `name` (string) required
- `notes` (array<EntityNote>)
- `tags` (array<EntityTag>)
- `isNumeric` (boolean): Conditional: When IsMultiValue is true.
- `decimalPlaces` (integer(int32)): Conditional: When IsNumeric is true. Range: 0 to 2.
- `maxLength` (integer(int32)): Conditional: When IsNumeric is false. Range: 0 to 300.
- `regEx` (string): Conditional: When RegEx is not empty.
- `regExErrorMessage` (string): Conditional: When RegExErrorMessage is not empty. Max length: 100.
- `isRequired` (boolean)
- `isEnabled` (boolean)
- `description` (string): Conditional: When Description is not empty. Max length: 100.
- `numericMinValue` (number(double)): For numeric fields, the minimum value allowed. Negative minimums are permitted: a custom  field is merchant-defined metadata rather than a monetary amount, so ranges that span or sit  below zero (adjustments, offsets, deltas, temperatures) are legitimate. The value is inert  unless `isNumeric` is set, and is validated only in that case. Conditional: When IsNumeric is true. Range: -1000000000 to 1000000000.
- `numericMaxValue` (number(double)): For numeric fields, the maximum value allowed. It must be greater than or equal to  `numericMinValue` but is not required to be positive, since a field whose whole  range is negative is valid. The value is inert unless `isNumeric` is set, and is  validated only in that case. Conditional: When IsNumeric is true. Range: -1000000000 to 1000000000.
- `position` (integer(int32))
- `virtualTerminal` (object): Presence settings for the Virtual Terminal, which collects this field from the operator when  `visible` is set.
- `hostedPaymentPage` (CustomFieldPresence)
- `transactionReports` (object): Presence settings for the surfaces that list a transaction's captured custom fields: the  transaction detail page and the receipt. Only `visible` is  honoured.
- `showOnSaveCardSessions` (boolean): Whether this field is offered on a save-card hosted payment page session (one that stores the  card without charging it). Defaults to off: most custom fields carry charge metadata (invoice  number, purchase order, department) that is meaningless on a page whose only outcome is a  stored card, so a field is suppressed on those sessions unless the merchant opts it in.
- `legacyNumber` (integer(int64)): The integer key the v1 API addresses this definition by. Server-owned: allocated once, when  the definition is first saved, and never reassigned afterwards.
- `isMultiValue` (boolean): Whether a transaction carries a list of values for this field rather than a single value.  A multi-value field is submitted through `TrxCustomField.Values`, prefilled on a hosted  page session through `prefilledListFields`, and captured one value per line on the  Virtual Terminal. The single `value` member keeps working on a multi-value definition:  it is carried unchanged and mirrored into the list as its one item.
- `maxValues` (integer(int32)): For a multi-value field, the largest number of values a transaction may carry. Unset reads as  `DefaultMaxValues`; the platform ceiling is  `MaxValuesCeiling`. Inert unless `isMultiValue` is set,  and validated only in that case. Conditional: When IsMultiValue is true and MaxValues is not null. Range: 1 to 250.

### 403

Forbidden

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 401

Unauthorized

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 400

Bad Request

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 404

Not Found

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 501

Not Implemented

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 500

Internal Server Error

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### default

The request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 429

The request was refused because a rate limit was exceeded, or because something a later retry can clear stopped it. A rate limit refusal carries an `application/problem+json` body: wait at least the interval `Retry-After` names before retrying, then back off. Limits are tuned per deployment, so read the allowance from the response headers rather than assuming a fixed ceiling. Any other refusal carries the standard error envelope as `application/json`, and its `error.code` names the cause.

**Content type:** `application/problem+json`

Schema: `RateLimitProblemDetails`

Properties:
- `type` (string) required: The problem type identifier. Always the same value: the failure is the status code itself,  so there is no sub-type for a caller to branch on.
- `title` (string) required: A short, human-readable summary of the problem type.
- `status` (integer(int32)) required: The HTTP status code, repeated in the body as the problem-details format defines.
- `detail` (string) required: A human-readable explanation of this occurrence of the problem.
- `retryAfterSeconds` (integer(int32)) required: How long to wait before retrying, in whole seconds, carrying the same figure as the  `Retry-After` header. Always at least one: a value of zero would invite an immediate  retry that is certain to be rejected again.

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

## Example request

Every block below sends the same request. Replace {{BASE_URL}} with the address of the API you are calling and {{API_KEY}} with your own key.

### cURL

```bash
curl -X GET "{{BASE_URL}}/api/merchants/{id}/custom-fields" \
  -H "api-key: {{API_KEY}}"
```

### PowerShell

```powershell
$headers = @{
    'api-key' = '{{API_KEY}}'
}

$response = Invoke-RestMethod -Method GET -Uri '{{BASE_URL}}/api/merchants/{id}/custom-fields' `
    -Headers $headers
```

### TypeScript (SDK)

```bash
npm install @winkpg/winkpg-api
```

```typescript
import { Configuration, MerchantsApi } from '@winkpg/winkpg-api';

const api = new MerchantsApi(new Configuration({
  basePath: '{{BASE_URL}}',
  apiKey: '{{API_KEY}}',
}));

const { data } = await api.merchantsGetCustomFieldsForMerchant("3fa85f64-5717-4562-b3fc-2c963f66afa6");
```

### TypeScript (raw HTTP)

```typescript
const response = await fetch('{{BASE_URL}}/api/merchants/{id}/custom-fields', {
  method: 'GET',
  headers: {
    "api-key": "{{API_KEY}}",
  },
});

const data = await response.json();
```

### C# (SDK)

```bash
dotnet add package WinkPg.Api.Client
```

```csharp
using WinkPg.Api.Client.Api;
using WinkPg.Api.Client.Client;

var config = new Configuration { BasePath = "{{BASE_URL}}" };
config.AddApiKey("api-key", "{{API_KEY}}");

var api = new MerchantsApi(config);
var result = await api.MerchantsGetCustomFieldsForMerchantAsync(Guid.Parse("3fa85f64-5717-4562-b3fc-2c963f66afa6"));
```

### C# (raw HTTP)

```csharp
using var http = new HttpClient { BaseAddress = new Uri("{{BASE_URL}}") };

var request = new HttpRequestMessage(new HttpMethod("GET"), "/api/merchants/{id}/custom-fields");
request.Headers.Add("api-key", "{{API_KEY}}");

var response = await http.SendAsync(request);
response.EnsureSuccessStatusCode();
var json = await response.Content.ReadAsStringAsync();
```

### Python (SDK)

```bash
pip install winkpg-api
```

```python
import winkpg_api

configuration = winkpg_api.Configuration(host="{{BASE_URL}}")
configuration.api_key["ApiKey"] = "{{API_KEY}}"

with winkpg_api.ApiClient(configuration) as client:
    api = winkpg_api.MerchantsApi(client)
    result = api.merchants_get_custom_fields_for_merchant("3fa85f64-5717-4562-b3fc-2c963f66afa6")
```

### Python (raw HTTP)

```bash
pip install requests
```

```python
import requests

headers = {
    "api-key": "{{API_KEY}}",
}

response = requests.request(
    "GET",
    "{{BASE_URL}}/api/merchants/{id}/custom-fields",
    headers=headers,
)
response.raise_for_status()
data = response.json()
```

## See also

- [All documentation](https://devportal-simpay-sbx.winkpg.io/llms.txt): the machine-readable index of every public page on this site.
