payout / developers
API reference

Payout Banklink API

One PSD2-based API for your users' accounts at their banks:

  • Read account information and transactions
  • Initiate payments
  • Verify a user's identity through their bank account

The Banklink guide shows how the calls fit together.

Amounts are absolute values; creditDebitIndicator gives the sign or direction. Balance amounts are JSON numbers (1520.35), transaction amounts are decimal strings ("12.50") with the precision the bank reports, and Initiate payment takes instructedAmount.amount as a decimal string ("1.00").

Environments

EnvironmentBase URL
Sandboxhttps://wap-sa.payout.one/api
Productionhttps://wap.payout.one/api

Authentication

Call the API with an OAuth2 access token issued by PayoutID, from the authorization_code grant (on behalf of a user) or the client_credentials grant. Send it in the Authorization: Bearer <access_token> header.

Each endpoint requires one scope:

Scope Grants Endpoints
BLAISP Read the user's bank accounts List accounts, Retrieve account details, Retrieve account details and balances, Retrieve account balances, List transactions, List accounts by consent
BLIBAN Verify that the user has access to a bank account Verify IBAN
BLPISP Create payments on behalf of the user Initiate payment, Retrieve payment status
VERIFY Verify the user's identity. Request it with the client_credentials grant Create verification, Retrieve verification status

List integrations needs a valid access token but no specific scope.

A missing, invalid or expired token, or a token without the required scope, is rejected with 403 and error code UNAUTHORIZED.

Authorizing access to the bank account

When the account is not connected yet, or its authorization at the bank has expired, account endpoints respond with 403 and a body with consent_id and redirect_url. Then:

  1. Redirect the user to redirect_url with the query parameters redirect_uri (one of the redirect URIs registered for your application) and optionally state.
  2. The user authorizes access at the bank and is redirected back to redirect_uri together with state.
  3. Repeat the request. To get every account the user authorized, call List accounts by consent with consent_id.

Payments and verifications use the same redirect: _links.sca.href from Initiate payment and redirect_url from Create verification.

Errors

Errors use HTTP status codes and return a tppMessages array:

JSON
{
  "tppMessages": [
    {
      "category": "ERROR",
      "code": "INVALID_INPUT",
      "text": "Unsupported IBAN country",
      "xpath": "/debtorAccount/iban"
    }
  ]
}

xpath is present only for validation errors (INVALID_INPUT).

HTTP Code Meaning
400 INVALID_REQUEST Missing or invalid header or body
400 INVALID_INPUT A request body field failed validation, see xpath
400 UNSUPPORTED_BANK Bank could not be recognised from iban and bank, or unknown verification
400 INVALID_PAYMENT_PRODUCT Unknown payment_product path parameter
401 INVALID_TOKEN Token does not identify the application (aud, auu claims)
403 UNAUTHORIZED Missing, invalid or expired token, or missing scope
500 INTERNAL_SERVER_ERROR Unexpected bank response or internal error

The two authentication codes are the reverse of what their names suggest: an invalid or expired token gets 403 with UNAUTHORIZED, while 401 with INVALID_TOKEN means a valid token whose claims do not identify your application.

Two responses have a different body:

POST

List accounts

/api/v1/accounts

Lists the bank accounts the user has connected to Banklink. Banklink answers from its own records and does not call the bank.

Request
curl -X POST 'https://wap-sa.payout.one/api/v1/accounts' \
  -H "Authorization: Bearer $TOKEN"
Response 200
{
  "accounts": [
    {
      "identification": {
        "iban": "SK3112000000198742637541"
      },
      "name": "Main account",
      "baseCurrency": "EUR",
      "providerName": "tatrabanka"
    }
  ]
}

Response 200

accountsobject[]
Show 4 child attributesHide child attributes
identificationobject
Show 1 child attributeHide child attributes
ibanstring

IBAN of the account

Example SK3112000000198742637541
namestring

Account name

Example Main account
baseCurrencystring

Account currency (ISO 4217)

Example EUR
providerNamestring

Name of the bank servicing the account

Example tatrabanka

Other responses

403

Missing, invalid or expired access token, or missing scope (UNAUTHORIZED)

Example
{
  "tppMessages": [
    {
      "category": "ERROR",
      "code": "UNAUTHORIZED",
      "text": "Missing or insuficient authorization"
    }
  ]
}
POST

Retrieve account details

/api/v1/accounts/details

Retrieves the details of a connected account from the bank, without balances.

Request
curl -X POST 'https://wap-sa.payout.one/api/v1/accounts/details' \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
       "iban": "SK3112000000198742637541"
     }'
Response 200
{
  "identification": {
    "iban": "SK3112000000198742637541"
  },
  "name": "Main account",
  "productName": "superaccount",
  "type": "CACC",
  "baseCurrency": "EUR",
  "authorizationExpiration": "2026-12-31T08:37:51+00:00"
}

Parameters

PSU-IP-Addressheader · string

IP address the user is connected from

Example 203.0.113.10
PSU-Presenceheader · string

Whether the user triggered the request

  • trueThe request is a direct result of a user action
  • falseNot a direct result of a user action
Default false · Example true
PSU-User-Agentheader · string

User agent of the user's browser

Example Curl 1.2.4

Request body

iban requiredstring

IBAN of the account

Example SK3112000000198742637541
bankstring

Integration name from List integrations, for IBANs whose bank cannot be recognised from the IBAN alone

Example tatrabanka

Response 200

identificationobject
Show 1 child attributeHide child attributes
ibanstring

IBAN of the account

Example SK3112000000198742637541
namestring

Account name

Example Main account
productNamestring

The bank's product name for the account

Example superaccount
typestring

Account type, a code from the ISO 20022 ExternalCashAccountType1Code list (external code sets), for example CACC (current account) or SVGS (savings account). OTHR means another type

Example CACC
baseCurrencystring

Account currency (ISO 4217)

Example EUR
authorizationExpirationstring<date-time>

When the user's authorization of the account expires, in RFC 3339. Set to 90 days after the authorization was created

Example 2026-12-31T08:37:51+00:00

Other responses

400

Missing or invalid header or body (INVALID_REQUEST), or the bank could not be recognised (UNSUPPORTED_BANK)

Example
{
  "tppMessages": [
    {
      "category": "ERROR",
      "code": "INVALID_REQUEST",
      "text": "Missing or invalid header or body"
    }
  ]
}
403

Returned for two different reasons, told apart by the body:

  • Bank authorization needed – the account is not connected yet, or its authorization at the bank has expired. The body has consent_id and redirect_url; redirect the user, see Authorizing access to the bank account.
  • Access token rejected – the token is missing, invalid or expired, or lacks the scope. The body is an error with code UNAUTHORIZED.
Example
{
  "consent_id": 123,
  "redirect_url": "https://wap-sa.payout.one/providers/forward/Xk7pQ2"
}
500

Unexpected bank response (INTERNAL_SERVER_ERROR)

Example
{
  "tppMessages": [
    {
      "category": "ERROR",
      "code": "INTERNAL_SERVER_ERROR",
      "text": "Unexpected bank response"
    }
  ]
}
POST

Retrieve account details and balances

/api/v1/accounts/information

Retrieves a connected account's details and balances from the bank in one call. account is the same object Retrieve account details returns; the balances are those of Retrieve account balances without their type.

Request
curl -X POST 'https://wap-sa.payout.one/api/v1/accounts/information' \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
       "iban": "SK3112000000198742637541"
     }'
Response 200
{
  "account": {
    "identification": {
      "iban": "SK3112000000198742637541"
    },
    "name": "Main account",
    "productName": "superaccount",
    "type": "CACC",
    "baseCurrency": "EUR",
    "authorizationExpiration": "2026-12-31T08:37:51+00:00"
  },
  "balances": [
    {
      "amount": {
        "value": 1520.35,
        "currency": "EUR"
      },
      "creditDebitIndicator": "CRDT",
      "dateTime": "2026-10-06T08:00:00+00:00"
    }
  ]
}

Parameters

PSU-IP-Addressheader · string

IP address the user is connected from

Example 203.0.113.10
PSU-Presenceheader · string

Whether the user triggered the request

  • trueThe request is a direct result of a user action
  • falseNot a direct result of a user action
Default false · Example true
PSU-User-Agentheader · string

User agent of the user's browser

Example Curl 1.2.4

Request body

iban requiredstring

IBAN of the account

Example SK3112000000198742637541
bankstring

Integration name from List integrations, for IBANs whose bank cannot be recognised from the IBAN alone

Example tatrabanka

Response 200

accountobject
Show 6 child attributesHide child attributes
identificationobject
Show 1 child attributeHide child attributes
ibanstring

IBAN of the account

Example SK3112000000198742637541
namestring

Account name

Example Main account
productNamestring

The bank's product name for the account

Example superaccount
typestring

Account type, a code from the ISO 20022 ExternalCashAccountType1Code list (external code sets), for example CACC (current account) or SVGS (savings account). OTHR means another type

Example CACC
baseCurrencystring

Account currency (ISO 4217)

Example EUR
authorizationExpirationstring<date-time>

When the user's authorization of the account expires, in RFC 3339. Set to 90 days after the authorization was created

Example 2026-12-31T08:37:51+00:00
balancesobject[]
Show 3 child attributesHide child attributes
amountobject
Show 2 child attributesHide child attributes
valuenumber

Balance as an absolute value, creditDebitIndicator gives the sign

Example 1520.35
currencystring

Currency of the balance (ISO 4217)

Example EUR
creditDebitIndicatorstring

Sign of the balance

  • CRDTZero or positive balance
  • DBITNegative balance
Example CRDT
dateTimestring<date-time>

When the balance was checked, in RFC 3339

Example 2026-10-06T08:00:00+00:00

Other responses

400

Missing or invalid header or body (INVALID_REQUEST), or the bank could not be recognised (UNSUPPORTED_BANK)

Example
{
  "tppMessages": [
    {
      "category": "ERROR",
      "code": "INVALID_REQUEST",
      "text": "Missing or invalid header or body"
    }
  ]
}
403

Returned for two different reasons, told apart by the body:

  • Bank authorization needed – the account is not connected yet, or its authorization at the bank has expired. The body has consent_id and redirect_url; redirect the user, see Authorizing access to the bank account.
  • Access token rejected – the token is missing, invalid or expired, or lacks the scope. The body is an error with code UNAUTHORIZED.
Example
{
  "consent_id": 123,
  "redirect_url": "https://wap-sa.payout.one/providers/forward/Xk7pQ2"
}
500

Unexpected bank response (INTERNAL_SERVER_ERROR)

Example
{
  "tppMessages": [
    {
      "category": "ERROR",
      "code": "INTERNAL_SERVER_ERROR",
      "text": "Unexpected bank response"
    }
  ]
}
POST

Retrieve account balances

/api/v1/accounts/balance

Retrieves the balances of a connected account from the bank.

Request
curl -X POST 'https://wap-sa.payout.one/api/v1/accounts/balance' \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
       "iban": "SK3112000000198742637541"
     }'
Response 200
{
  "balances": [
    {
      "amount": {
        "value": 1520.35,
        "currency": "EUR"
      },
      "creditDebitIndicator": "CRDT",
      "dateTime": "2026-10-06T08:00:00+00:00",
      "type": "ITAV"
    }
  ]
}

Parameters

PSU-IP-Addressheader · string

IP address the user is connected from

Example 203.0.113.10
PSU-Presenceheader · string

Whether the user triggered the request

  • trueThe request is a direct result of a user action
  • falseNot a direct result of a user action
Default false · Example true
PSU-User-Agentheader · string

User agent of the user's browser

Example Curl 1.2.4

Request body

iban requiredstring

IBAN of the account

Example SK3112000000198742637541
bankstring

Integration name from List integrations, for IBANs whose bank cannot be recognised from the IBAN alone

Example tatrabanka

Response 200

balancesobject[]
Show 4 child attributesHide child attributes
amountobject
Show 2 child attributesHide child attributes
valuenumber

Balance as an absolute value, creditDebitIndicator gives the sign

Example 1520.35
currencystring

Currency of the balance (ISO 4217)

Example EUR
creditDebitIndicatorstring

Sign of the balance

  • CRDTZero or positive balance
  • DBITNegative balance
Example CRDT
dateTimestring<date-time>

When the balance was checked, in RFC 3339

Example 2026-10-06T08:00:00+00:00
typestring

Balance type, a code from the ISO 20022 ExternalBalanceType1Code list (external code sets), for example ITAV (interim available) or CLBD (closing booked). Some banks add their own codes ACCR, DSCR, OWRS and OWFU

Example ITAV

Other responses

400

Missing or invalid header or body (INVALID_REQUEST), or the bank could not be recognised (UNSUPPORTED_BANK)

Example
{
  "tppMessages": [
    {
      "category": "ERROR",
      "code": "INVALID_REQUEST",
      "text": "Missing or invalid header or body"
    }
  ]
}
403

Returned for two different reasons, told apart by the body:

  • Bank authorization needed – the account is not connected yet, or its authorization at the bank has expired. The body has consent_id and redirect_url; redirect the user, see Authorizing access to the bank account.
  • Access token rejected – the token is missing, invalid or expired, or lacks the scope. The body is an error with code UNAUTHORIZED.
Example
{
  "consent_id": 123,
  "redirect_url": "https://wap-sa.payout.one/providers/forward/Xk7pQ2"
}
500

Unexpected bank response (INTERNAL_SERVER_ERROR)

Example
{
  "tppMessages": [
    {
      "category": "ERROR",
      "code": "INTERNAL_SERVER_ERROR",
      "text": "Unexpected bank response"
    }
  ]
}
POST

List transactions

/api/v1/transactions

Lists the transactions of a connected account, retrieved from the bank. Each page holds up to 100 transactions.

Pagination

To get the next page, repeat the request with page_index set to pagination.next_page from the previous response. next_page is null on the last page.

Request
curl -X POST 'https://wap-sa.payout.one/api/v1/transactions' \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
       "iban": "SK3112000000198742637541",
       "date_from": "2026-09-01",
       "date_to": "2026-09-30"
     }'
Response 200
{
  "pagination": {
    "next_page": "zxQewRtveXy",
    "previous_page": null
  },
  "transactions": [
    {
      "amount": {
        "value": "12.50",
        "currency": "EUR"
      },
      "creditDebitIndicator": "CRDT",
      "valueDate": "2026-09-14",
      "bookingDate": "2026-09-14",
      "transactionDetails": {
        "reversalIndicator": false,
        "references": {
          "accountServiceReference": "7Q2K9X41",
          "endToEndIdentification": "/VS20260914/SS/KS"
        },
        "relatedParties": {
          "debtor": {
            "name": "Jan Novák"
          },
          "debtorAccount": {
            "identification": "CZ6508000000192000145399"
          },
          "creditor": {
            "name": "Example Shop, s.r.o."
          },
          "creditorAccount": {
            "identification": "SK3112000000198742637541"
          }
        },
        "remittanceInformation": "Invoice 2026-104"
      }
    }
  ]
}

Parameters

PSU-IP-Addressheader · string

IP address the user is connected from

Example 203.0.113.10
PSU-Presenceheader · string

Whether the user triggered the request

  • trueThe request is a direct result of a user action
  • falseNot a direct result of a user action
Default false · Example true
PSU-User-Agentheader · string

User agent of the user's browser

Example Curl 1.2.4

Request body

iban requiredstring

IBAN of the account

Example SK3112000000198742637541
bankstring

Integration name from List integrations, for IBANs whose bank cannot be recognised from the IBAN alone

Example tatrabanka
page_indexstring

Page to return, from pagination.next_page or pagination.previous_page of a previous response. Omit for the first page

Example zxQewRtveXy
date_fromstring

Return no transactions older than this date. Defaults to 90 days ago

Example 2026-09-01
date_tostring

Return no transactions newer than this date. Defaults to the end of today

Example 2026-09-30

Response 200

paginationobject
Show 2 child attributesHide child attributes
next_pagestring | integer | null

page_index of the next page, null on the last page

Example zxQewRtveXy
previous_pagestring | integer | null

page_index of the previous page

transactionsobject[]
Show 6 child attributesHide child attributes
amountobject
Show 2 child attributesHide child attributes
valuestring

Amount as an absolute decimal string, creditDebitIndicator gives the direction

Example 12.50
currencystring

Currency of the transaction (ISO 4217)

Example EUR
valueDatestring

Date when the funds become available to the account owner, for credits

Example 2026-09-14
bookingDatestring

Date when the transaction was posted to the account in the bank's books

Example 2026-09-14
creditDebitIndicatorstring

Direction of the transaction

  • CRDTCredit, money added to the account
  • DBITDebit, money taken from the account
Example CRDT
bankTransactionCodestring

ISO 20022 bank transaction code

transactionDetailsobject
Show 8 child attributesHide child attributes
reversalIndicatorboolean

Whether the transaction reverses a previous one

referencesobject
Show 3 child attributesHide child attributes
accountServiceReferencestring

Unique transaction id assigned by the bank

endToEndIdentificationstring

End-to-end identification of the transaction, as reported by the bank

chequeNumberstring

Masked card number of a card transaction, for example ** 1111

counterValueAmountobject
Show 1 child attributeHide child attributes
amountobject
Show 2 child attributesHide child attributes
valuestring

Counter-value amount as a decimal string

currencystring

Currency of the counter-value amount (ISO 4217)

currencyExchangeobject
Show 1 child attributeHide child attributes
exchangeRatenumber

Exchange rate applied to the transaction

relatedPartiesobject
Show 4 child attributesHide child attributes
debtorobject
Show 1 child attributeHide child attributes
namestring

Name of the debtor

debtorAccountobject
Show 1 child attributeHide child attributes
identificationstring

Debtor's account, usually an IBAN

creditorobject
Show 1 child attributeHide child attributes
namestring

Name of the creditor

creditorAccountobject
Show 1 child attributeHide child attributes
identificationstring

Creditor's account, usually an IBAN

tradingPartyobject
Show 1 child attributeHide child attributes
namestring

Name of the third party. For card transactions, the merchant

relatedAgentsobject
Show 2 child attributesHide child attributes
debtorAgentobject
Show 1 child attributeHide child attributes
financialInstitutionIdentificationstring

Debtor's bank, usually a BIC

creditorAgentobject
Show 1 child attributeHide child attributes
financialInstitutionIdentificationstring

Creditor's bank, usually a BIC

remittanceInformationstring

Payment message for the receiver

Other responses

400

Missing or invalid header or body (INVALID_REQUEST), or the bank could not be recognised (UNSUPPORTED_BANK)

Example
{
  "tppMessages": [
    {
      "category": "ERROR",
      "code": "INVALID_REQUEST",
      "text": "Missing or invalid header or body"
    }
  ]
}
403

Returned for two different reasons, told apart by the body:

  • Bank authorization needed – the account is not connected yet, or its authorization at the bank has expired. The body has consent_id and redirect_url; redirect the user, see Authorizing access to the bank account.
  • Access token rejected – the token is missing, invalid or expired, or lacks the scope. The body is an error with code UNAUTHORIZED.
Example
{
  "consent_id": 123,
  "redirect_url": "https://wap-sa.payout.one/providers/forward/Xk7pQ2"
}
500

Unexpected bank response (INTERNAL_SERVER_ERROR)

Example
{
  "tppMessages": [
    {
      "category": "ERROR",
      "code": "INTERNAL_SERVER_ERROR",
      "text": "Unexpected bank response"
    }
  ]
}
POST

Verify IBAN

/api/v1/accounts/verify-iban

Verifies that the user has access to the bank account with the given IBAN. Banklink checks the account with the bank.

Request
curl -X POST 'https://wap-sa.payout.one/api/v1/accounts/verify-iban' \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
       "iban": "SK3112000000198742637541"
     }'
Response 200
{
  "iban": "SK3112000000198742637541",
  "verified": true
}

Parameters

PSU-IP-Addressheader · string

IP address the user is connected from

Example 203.0.113.10
PSU-Presenceheader · string

Whether the user triggered the request

  • trueThe request is a direct result of a user action
  • falseNot a direct result of a user action
Default false · Example true
PSU-User-Agentheader · string

User agent of the user's browser

Example Curl 1.2.4

Request body

iban requiredstring

IBAN of the account

Example SK3112000000198742637541
bankstring

Integration name from List integrations, for IBANs whose bank cannot be recognised from the IBAN alone

Example tatrabanka

Response 200

ibanstring

IBAN of the verified account

Example SK3112000000198742637541
verifiedboolean

Always true. Without access, the response is 403 instead

Example true

Other responses

400

Missing or invalid header or body (INVALID_REQUEST), or the bank could not be recognised (UNSUPPORTED_BANK)

Example
{
  "tppMessages": [
    {
      "category": "ERROR",
      "code": "INVALID_REQUEST",
      "text": "Missing or invalid header or body"
    }
  ]
}
403

Returned for two different reasons, told apart by the body:

  • Bank authorization needed – the account is not connected yet, or its authorization at the bank has expired. The body has consent_id and redirect_url; redirect the user, see Authorizing access to the bank account.
  • Access token rejected – the token is missing, invalid or expired, or lacks the scope. The body is an error with code UNAUTHORIZED.
Example
{
  "consent_id": 123,
  "redirect_url": "https://wap-sa.payout.one/providers/forward/Xk7pQ2"
}
500

Unexpected bank response (INTERNAL_SERVER_ERROR)

Example
{
  "tppMessages": [
    {
      "category": "ERROR",
      "code": "INTERNAL_SERVER_ERROR",
      "text": "Unexpected bank response"
    }
  ]
}
POST

Initiate payment

/api/v1/payments/{integration}/{payment_product}

Creates a payment for the user to authorize at their bank. Redirect the user to _links.sca.href, see Authorizing access to the bank account, then track the payment with Retrieve payment status.

Request
curl -X POST 'https://wap-sa.payout.one/api/v1/payments/tatrabanka/sepa-credit-transfers' \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
       "endToEndIndentification": "/VS1/SS2/KS3",
       "creditorAgent": "COBADEFFXXX",
       "creditorName": "John Doe",
       "debtorName": "Test Testovic",
       "remittanceInformationUnstructured": "Testing",
       "debtorAccount": {
         "iban": "SK3112000000198742637541"
       },
       "creditorAccount": {
         "iban": "DE89370400440532013000"
       },
       "instructedAmount": {
         "amount": "1.00",
         "currency": "EUR"
       }
     }'
Response 201
{
  "paymentId": 123,
  "_links": {
    "sca": {
      "href": "https://wap-sa.payout.one/providers/forward/Xk7pQ2"
    }
  }
}

Parameters

integration requiredpath · string

name of an integration from List integrations that supports payment initiation (pisp is true)

Example tatrabanka
payment_product requiredpath · string

Payment method. Integrations support different methods, see supported_payment_methods in List integrations

  • sepa-credit-transfersSEPA credit transfer, listed as sepa
  • instant-sepa-credit-transfersInstant SEPA credit transfer, listed as sepa_ipay
Example sepa-credit-transfers

Request body

endToEndIndentificationstring

Your end-to-end identification of the payment. The key is spelled endToEndIndentification.

In the form /VS{variable symbol}/SS{specific symbol}/KS{constant symbol}, Banklink reads the variable, specific and constant symbol from it.

Max length 35 · Example /VS1/SS2/KS3
creditorAgentstring

BIC of the creditor's bank

Example COBADEFFXXX
creditorName requiredstring

Name of the creditor

Max length 70 · Example John Doe
creditorEmailstring

E-mail of the creditor, a non-standard field used by the payout integration

Max length 254 · Example [email protected]
debtorName requiredstring

Name of the debtor

Example Test Testovic
remittanceInformationUnstructuredstring

Payment message for the creditor

Max length 140 · Example Testing
purposeProprietarystring

Non-standard field, required by csob-cz for business customers

debtorAccount requiredobject
Show 1 child attributeHide child attributes
iban requiredstring

IBAN of the debtor account. Supported countries:

  • SK – Slovakia
  • CZ – Czech Republic
  • DE – Germany
  • LT – Lithuania
Example SK3112000000198742637541
creditorAccount requiredobject
Show 1 child attributeHide child attributes
iban requiredstring

IBAN of the creditor account, from the same countries as debtorAccount.iban

Example DE89370400440532013000
instructedAmount requiredobject
Show 2 child attributesHide child attributes
amount requiredstring

Amount as a decimal string

Example 1.00
currency requiredstring
One of EUR, CZK · Example EUR

Response 201

paymentIdinteger

Payment id, used by Retrieve payment status

Example 123
_linksobject
Show 1 child attributeHide child attributes
scaobject
Show 1 child attributeHide child attributes
hrefstring<uri>

URL to redirect the user to for authorizing the payment

Example https://wap-sa.payout.one/providers/forward/Xk7pQ2

Other responses

400

Invalid request body (INVALID_INPUT with xpath) or unknown payment_product (INVALID_PAYMENT_PRODUCT)

Example
{
  "tppMessages": [
    {
      "category": "ERROR",
      "code": "INVALID_INPUT",
      "text": "Unsupported IBAN country",
      "xpath": "/debtorAccount/iban"
    }
  ]
}
403

Missing, invalid or expired access token, or missing scope (UNAUTHORIZED)

Example
{
  "tppMessages": [
    {
      "category": "ERROR",
      "code": "UNAUTHORIZED",
      "text": "Missing or insuficient authorization"
    }
  ]
}
GET

Retrieve payment status

/api/v1/payments/{payment_id}/status

Retrieves the current status of a payment. Unless the payment is pending or completed, Banklink first asks the bank for its latest status.

Request
curl -X GET 'https://wap-sa.payout.one/api/v1/payments/123/status' \
  -H "Authorization: Bearer $TOKEN"
Response 200
{
  "paymentId": 123,
  "transactionStatus": "pending"
}

Parameters

payment_id requiredpath · integer

Payment id returned by Initiate payment

Example 123

Response 200

paymentIdinteger

Payment id

Example 123
transactionStatusstring

Status of the payment

  • pendingCreated in Banklink, not yet posted to the bank
  • initializedPosted to the bank, not yet validated
  • receivedValidated by the bank as technically correct
  • acceptedAccepted by the bank as valid and signed by the user, waiting to be processed
  • unknownSigned, but Banklink could not check its status afterwards
  • completedProcessed successfully
  • rejectedInvalid or declined by the user

Other responses

403

Missing, invalid or expired access token, or missing scope (UNAUTHORIZED)

Example
{
  "tppMessages": [
    {
      "category": "ERROR",
      "code": "UNAUTHORIZED",
      "text": "Missing or insuficient authorization"
    }
  ]
}
404

Unknown payment

Example
{
  "errors": {
    "detail": "Not Found"
  }
}
500

Banklink could not get the latest status from the bank (INTERNAL_SERVER_ERROR)

Example
{
  "tppMessages": [
    {
      "category": "ERROR",
      "code": "INTERNAL_SERVER_ERROR",
      "text": "Something is wrong on our side"
    }
  ]
}
POST

Create verification

/api/v1/verifications

Starts verifying the user's identity through their bank account. Redirect the user to the returned redirect_url, see Authorizing access to the bank account. Once the user is back, get the result with Retrieve verification status.

The Verification guide describes the whole flow.

Request
curl -X POST 'https://wap-sa.payout.one/api/v1/verifications' \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
       "iban": "CZ6508000000192000145399",
       "first_name": "Jan",
       "last_name": "Novák"
     }'
Response 200
{
  "id": "3f1c9a52-7d4e-4b8a-9c21-5e6f7a8b9c0d",
  "redirect_url": "https://wap-sa.payout.one/providers/forward/Xk7pQ2",
  "status": "initialized"
}

Request body

iban requiredstring

IBAN of the account to verify the user with

Example CZ6508000000192000145399
first_namestring

User's first name, compared with the names of the account owners

Example Jan
last_namestring

User's last name, compared with the names of the account owners

Example Novák
bankstring

Integration name from List integrations, for IBANs whose bank cannot be recognised from the IBAN alone

Example csas

Response 200

idstring<uuid>

Verification id

Example 3f1c9a52-7d4e-4b8a-9c21-5e6f7a8b9c0d
redirect_urlstring<uri>

URL to send the user to. There they log in to their bank and grant access to the account, which is what the verification checks

Example https://wap-sa.payout.one/providers/forward/Xk7pQ2
statusstring

Result of the verification

  • initializedCreated, the user has not finished authorizing access at the bank yet
  • verified_accessThe user accessed the account, but the bank does not provide owner names
  • verified_ownershipThe user accessed the account and an owner's name matches first_name and last_name
  • unverified_accessThe user failed to provide credentials to access the account
  • unverified_ownershipThe user accessed the account, but no owner's name matches first_name and last_name
  • errorCommunication with the bank failed

Other responses

400

Invalid request body (INVALID_INPUT with xpath)

Example
{
  "tppMessages": [
    {
      "category": "ERROR",
      "code": "INVALID_INPUT",
      "text": "Invalid IBAN format",
      "xpath": "/provider/iban"
    }
  ]
}
403

Missing, invalid or expired access token, or missing scope (UNAUTHORIZED)

Example
{
  "tppMessages": [
    {
      "category": "ERROR",
      "code": "UNAUTHORIZED",
      "text": "Missing or insuficient authorization"
    }
  ]
}
GET

Retrieve verification status

/api/v1/verifications/{verification_id}

Retrieves the result of a verification created by your application.

Request
curl -X GET 'https://wap-sa.payout.one/api/v1/verifications/3f1c9a52-7d4e-4b8a-9c21-5e6f7a8b9c0d' \
  -H "Authorization: Bearer $TOKEN"
Response 200
{
  "status": "initialized"
}

Parameters

verification_id requiredpath · string<uuid>

Verification id returned by Create verification

Example 3f1c9a52-7d4e-4b8a-9c21-5e6f7a8b9c0d

Response 200

statusstring

Result of the verification

  • initializedCreated, the user has not finished authorizing access at the bank yet
  • verified_accessThe user accessed the account, but the bank does not provide owner names
  • verified_ownershipThe user accessed the account and an owner's name matches first_name and last_name
  • unverified_accessThe user failed to provide credentials to access the account
  • unverified_ownershipThe user accessed the account, but no owner's name matches first_name and last_name
  • errorCommunication with the bank failed

Other responses

400

Unknown verification, or one created by another application (UNSUPPORTED_BANK)

Example
{
  "tppMessages": [
    {
      "category": "ERROR",
      "code": "UNSUPPORTED_BANK",
      "text": "Unsupported bank"
    }
  ]
}
403

Missing, invalid or expired access token, or missing scope (UNAUTHORIZED)

Example
{
  "tppMessages": [
    {
      "category": "ERROR",
      "code": "UNAUTHORIZED",
      "text": "Missing or insuficient authorization"
    }
  ]
}
GET

List integrations

/api/v1/integrations

Lists the banks Banklink integrates with and what each of them supports.

Request
curl -X GET 'https://wap-sa.payout.one/api/v1/integrations' \
  -H "Authorization: Bearer $TOKEN"
Response 200
[
  {
    "name": "payout",
    "aisp": true,
    "pisp": true,
    "supported_payment_methods": [
      "sepa"
    ]
  },
  {
    "name": "tatrabanka",
    "aisp": true,
    "pisp": true,
    "supported_payment_methods": [
      "sepa",
      "sepa_ipay"
    ]
  }
]

Response 200 · array

namestring

Integration name. Use it as bank in account requests and as integration in Initiate payment

Example tatrabanka
aispboolean

Whether the integration supports account information

Example true
pispboolean

Whether the integration supports payment initiation

Example true
supported_payment_methodsstring[]

Payment methods for Initiate payment. Present only when pisp is true

  • sepaSEPA credit transfer, payment product sepa-credit-transfers
  • sepa_ipayInstant SEPA credit transfer, payment product instant-sepa-credit-transfers

Other responses

403

Missing, invalid or expired access token, or missing scope (UNAUTHORIZED)

Example
{
  "tppMessages": [
    {
      "category": "ERROR",
      "code": "UNAUTHORIZED",
      "text": "Missing or insuficient authorization"
    }
  ]
}

Was this page helpful?