Endpoint
POST /v3/med/list
Authentication and target
Use an account credential for its bound account, or a user credential with bothX-ISPB and X-Account-Number. If an account credential sends those headers, both must be present and must match its bound account. Platform credentials are not accepted. All requests require the standard HMAC-SHA256 headers. The selected account determines payer-side MED owner scope; receiver-side operations are not exposed by these routes.
The curl example below uses an ACCOUNT credential bound to the operated account, so it omits X-ISPB and X-Account-Number. If X-Client-ID identifies a USER credential, add both target headers and include their exact trimmed values in the canonical header set before calculating X-Signature.
Request body
Every field is optional: numericpage, page_size, status, original_fraud_situation, and flow_type; string case_id, funds_recovery_id, dict_funds_recovery_id, and end_to_end_id; numeric Unix-millisecond start_time and end_time.
Success data
items[] with case/recovery/root IDs, decimal-string amount, numeric status, display text, numeric opened_at, can_cancel, and transaction ID; plus numeric pagination fields.