# Manage Consumer Profiles and Credentials
source: https://developer.mastercard.com/issuer-enrollment/documentation/use-cases/auto-enrollment/life_cycle/index.md

After enabling a consumer and one or more credentials, issuers can use the [Lifecycle Management APIs](https://developer.mastercard.com/issuer-enrollment/documentation/api-reference/index.md#lifecycle-management-apis) to maintain the information stored in their credential directory. These APIs support retrieving, updating, and deleting consumer profiles and individual credentials.

You can also add a credential to an existing consumer profile by submitting an asynchronous batch enablement request or a synchronous single enablement request. Mastercard processes the request and returns the resulting profile or credential data, or confirms the requested change.

## Before you Begin {#before-you-begin}

Before managing a consumer profile or credential:

1. Enable the consumer profile and at least one credential in the issuer credential directory.
2. Retain the `externalConsumerId` you assigned to the consumer.
3. Retain the `externalCredentialId` you assigned to each credential.
4. Identify the `directoryId` for the issuer-specific credential directory.
5. Complete the required authentication and encryption configuration.

The Lifecycle Management APIs use the following identifiers:

|       Parameter        |                                     Description                                     |
|------------------------|-------------------------------------------------------------------------------------|
| `directoryId`          | Identifies the issuer credential directory that contains the profile or credential. |
| `externalConsumerId`   | Identifies the consumer in the issuer's system.                                     |
| `externalCredentialId` | Identifies the credential in the issuer's system.                                   |

Note: Retain the relationship between each `externalConsumerId`, `externalCredentialId`, and the corresponding entities in your system. Use these identifiers to manage the profile and credentials after enablement.

## Manage a Consumer Profile {#manage-a-consumer-profile}

Use the profile management operations to retrieve current consumer information, update consumer details, or remove a consumer profile from your credential directory. Retrieving and updating a profile begins in the issuer system. A consumer opt-out or profile-removal request can initiate the deletion flow.
Diagram manage-consumer-profile

### Retrieve a consumer profile {#retrieve-a-consumer-profile}

Retrieve a consumer profile when you need to review the consumer information and associated credentials stored in the issuer credential directory. The API response contains the current consumer profile and information about its associated credentials. Use this information to review the data stored for the consumer and determine whether any updates are required.

See the endpoint structure:


API Reference: `GET /client-directories/{directoryId}/profiles/{externalConsumerId}`

<br />

1. Send a GET request to the [/profiles/{externalConsumerId}](https://developer.mastercard.com/issuer-enrollment/documentation/api-reference/apis/index.md#getProfileByExternalConsumerId) endpoint.
2. Review the returned consumer information.
3. Review the associated credential information.
4. Reconcile the response with the corresponding consumer and credential records in your system.

### Update a consumer profile {#update-a-consumer-profile}

Update a consumer profile when the consumer's information changes. The update replaces the profile information stored in the issuer credential directory. Mastercard replaces the stored profile information with the complete information provided in the request. The updated profile remains associated with its existing credentials.

Retrieve the current profile, apply the required changes, and submit the complete updated profile using the `externalConsumerId`.

See the endpoint structure:


API Reference: `PUT /client-directories/{directoryId}/profiles/{externalConsumerId}`

<br />

Note: The Update Consumer Profile operation replaces the stored profile information. Include all required profile information in the request, including values that have not changed.
1. Retrieve the current consumer profile.
2. Review the current profile information.
3. Apply the required changes.
4. Include all required profile information in the update request.
5. Send a PUT request to the [/profiles/{externalConsumerId}](https://developer.mastercard.com/issuer-enrollment/documentation/api-reference/apis/index.md#updateProfileByExternalConsumerId) endpoint.
6. Review the response to confirm that Mastercard processed the update.
7. Retrieve the profile again if you need to validate the stored information.

### Delete a consumer profile {#delete-a-consumer-profile}

Delete a consumer profile when the consumer opts out of the services associated with the issuer credential directory or when an applicable business process requires removal of the complete profile. If a consumer deletes all their cards from their profile, we recommend deleting the associated profile. Mastercard removes the consumer profile from the issuer credential directory. The response confirms the result of the deletion request.

See the endpoint structure:


API Reference: `DELETE /client-directories/{directoryId}/profiles/{externalConsumerId}`

<br />

Warning: Deleting a consumer profile removes the profile and its associated data from the issuer credential directory. Confirm the scope and downstream program impact before sending the request.
1. Receive and validate the consumer's profile deletion or opt-out request.
2. Confirm that deleting the complete profile is the appropriate action.
3. Confirm that deleting one credential would not satisfy the request.
4. Identify the profile using the `directoryId` and `externalConsumerId`.
5. Send a DELETE request to the [/profiles/{externalConsumerId}](https://developer.mastercard.com/issuer-enrollment/documentation/api-reference/apis/index.md#deleteProfileByExternalConsumerId) endpoint.
6. Review the response to confirm that Mastercard processed the deletion.
7. Update your system to show that the profile is no longer active in the issuer credential directory.
8. Complete any applicable consumer notification or confirmation process.

## Manage a Credential {#manage-a-credential}

Use the credential management operations to retrieve current credential information, update supported information, or remove an individual credential without deleting the complete consumer profile.

You can manage credentials associated with single-identifier and multi-identifier consumer profiles.

Diagram manage-credential

### Retrieve a credential {#retrieve-a-credential}

Retrieve a credential when you need to review its information in the issuer credential directory.

See the endpoint structure:


API Reference: `GET /client-directories/{directoryId}/credentials/{externalCredentialId}`

<br />

Identify the credential using the `directoryId` and `externalCredentialId`.
1. Sent a GET request to to the [/credentials/{externalConsumerId}](https://developer.mastercard.com/issuer-enrollment/documentation/api-reference/apis/index.md#getCredentialByExternalCredentialId) endpoint.
2. Review the returned masked credential information.
3. Review the billing address and any other supported credential information.
4. Reconcile the response with the corresponding credential in your system.

### Update the billing address of a credential (only??) {#update-the-billing-address-of-a-credential-only}

Update a credential when supported information associated with the credential changes. Current implementation guidance identifies the billing address as information that can be updated.

See the endpoint structure:


API Reference: `PUT /client-directories/{directoryId}/credentials/{externalCredentialId}`

<br />

Retrieve the credential first if you need to review its current information before submitting the update.
1. Retrieve the current credential information.
2. Review the existing information.
3. Prepare the supported updated information.
4. Send a PUT request to the [/credentials/{externalConsumerId}](https://developer.mastercard.com/issuer-enrollment/documentation/api-reference/apis/index.md#updateCredentialsByExternalCredentialId) endpoint.
5. Review the response to confirm that Mastercard processed the update.
6. Retrieve the credential again if you need to validate the stored information.

### Delete a credential {#delete-a-credential}

Delete an individual credential when the consumer removes it or when the credential is no longer eligible for use.

Expired, suspended, or deactivated credentials are examples of credentials that may require removal. Deleting one credential allows the consumer profile and any other associated credentials to remain in the issuer credential directory.

See the endpoint structure:


API Reference: `DELETE /client-directories/{directoryId}/credentials/{externalCredentialId}`

<br />

Warning: Deleting a credential removes it from all associated programs. The credential cannot be used through those programs unless it is added to the issuer credential directory again.
1. Receive and validate the request to remove the credential.
2. Confirm that removing only the specified credential is the appropriate action.
3. Confirm that the consumer profile should remain in the issuer credential directory.
4. Identify the credential using the `directoryId` and `externalCredentialId`.
5. Send a DELETE request to the [/credentials/{externalConsumerId}](https://developer.mastercard.com/issuer-enrollment/documentation/api-reference/apis/index.md#deleteCredentialByExternalCredentialId) endpoint.
6. Review the response to confirm that Mastercard processed the deletion.
7. Update your system to show that the credential is no longer active in the issuer credential directory.
8. Complete any applicable consumer notification or confirmation process.

To add the credential again, use the applicable enrollment flow. See [Next steps](https://developer.mastercard.com/issuer-enrollment/documentation/use-cases/auto-enrollment/life_cycle/index.md#next-steps).

### Related credential management options {#related-credential-management-options}

Depending on the integration and credential management scenario, you may also manage credentials through:

* [MDES Customer Service APIs](https://developer.mastercard.com/mdes-customer-service/documentation/api-reference/)
* [Automatic Billing Updater](https://developer.mastercard.com/automatic-billing-updater/documentation/)

<br />

Use the guidance for each service to determine which option applies to your integration.

## Error Resolution {#error-resolution}

For details on error resolution please visit our [codes and formats](https://developer.mastercard.com/issuer-enrollment/documentation/code-and-formats/index.md) section.

## Next Steps {#next-steps}

* To associate a new credential with an existing consumer profile, include the existing `externalConsumerId` in the applicable enrollment request:
  * Use the [Batch Enroll API](https://developer.mastercard.com/issuer-enrollment/documentation/use-cases/auto-enrollment/enroll_api_async/index.md) to enable one or more credentials asynchronously.
  * Use the [Enroll Credential API](https://developer.mastercard.com/issuer-enrollment/documentation/use-cases/auto-enrollment/enroll_api_sync/index.md) to enable one credential and receive the result in the same API interaction.
* To re-enable a previously deleted credential, submit the credential through the applicable enrollment flow using the existing consumer profile.
* After submitting an asynchronous request, use the [Batch Status API](https://developer.mastercard.com/issuer-enrollment/documentation/use-cases/auto-enrollment/batch_status/index.md) to retrieve the processing result.
* To validate profile and credential management scenarios, see the [Auto Enablement](https://developer.mastercard.com/issuer-enrollment/documentation/testing/auto-enrollment/index.md) testing page.
