Payout Intel API
Run AML checks on people and look up AML limits by country.
Environments
| Environment | Base URL |
|---|---|
| Sandbox (for test purposes only) | https://sandbox.payout.one |
| Production | https://app.payout.one |
Authentication
Send a Bearer token in the Authorization header of every request except
Get API token:
Authorization: Bearer SFMyNTY.EXAMPLE-TOKEN.dGhpcy1pcy1hLWZha2Utc2lnbmF0dXJlLWV4YW1wbGU
Get the token from Get API token with the client_id and
client_secret of an API key generated in the Admin section of your account. The token is valid
for valid_for seconds (6000); then request a new one.
Errors
Errors are JSON objects with an errors message. Send Accept: application/json with every
request.
{
"errors": "Unauthorized access. Check your token."
}
| Status | Message | When |
|---|---|---|
| 401 | Bad credentials. Check your credentials or contact support. |
Wrong or missing client_id or client_secret at Get API token |
| 401 | Unauthorized access. Check your token. |
The token is missing or invalid |
| 401 | Unauthorized access. Token is expired. |
The token has expired |
| 429 | Too many failed authentication attempts for this client. Try again in a few minutes. |
5 failed token requests for the same client_id within 5 minutes. Retry after the number of seconds in the Retry-After header |
Get AML limit returns its 400 errors
under an error key instead.
Exchanges the client_id and client_secret of your API key for a Bearer token. Send the
token in the Authorization header of all other requests. The token is valid for valid_for
seconds; then request a new one.
After 5 failed attempts for the same client_id within 5 minutes, the endpoint responds with
429. Retry after the number of seconds in the Retry-After header.
curl -X POST 'https://sandbox.payout.one/api/v1/authorize' \
-H "Content-Type: application/json" \
-d '{
"client_id": "8b0f3c52-6d1e-4a7b-9c2d-5e4f3a2b1c0d",
"client_secret": "example-client-secret-not-real"
}'const res = await fetch("https://sandbox.payout.one/api/v1/authorize", {
method: "POST",
headers: {
"Content-Type": "application/json",
},
body: JSON.stringify({
"client_id": "8b0f3c52-6d1e-4a7b-9c2d-5e4f3a2b1c0d",
"client_secret": "example-client-secret-not-real"
}),
});
const data = await res.json();import os, requests
res = requests.post(
"https://sandbox.payout.one/api/v1/authorize",
json={
"client_id": "8b0f3c52-6d1e-4a7b-9c2d-5e4f3a2b1c0d",
"client_secret": "example-client-secret-not-real",
},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://sandbox.payout.one/api/v1/authorize");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "POST");
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode([
"client_id" => "8b0f3c52-6d1e-4a7b-9c2d-5e4f3a2b1c0d",
"client_secret" => "example-client-secret-not-real"
]));
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Content-Type: application/json"]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"token": "SFMyNTY.EXAMPLE-TOKEN.dGhpcy1pcy1hLWZha2Utc2lnbmF0dXJlLWV4YW1wbGU",
"valid_for": 6000
}Request body
API key (client ID)
API key secret
Response 200
Bearer token for the Authorization header
Token validity in seconds
Other responses
Wrong client_id or client_secret, or one of them is missing.
Example
{
"errors": "Bad credentials. Check your credentials or contact support."
}5 failed attempts for this client_id within 5 minutes. Retry after Retry-After seconds.
Example
{
"errors": "Too many failed authentication attempts for this client. Try again in a few minutes."
}Returns the AML limit of a country, converted to the requested currency.
If no limit of that check_type is set for the country, the response has only a message.
curl -X GET 'https://sandbox.payout.one/api/v1/intel/limits?currency=PLN&country=SK&check_type=AML5' \
-H "Authorization: Bearer $TOKEN"const res = await fetch("https://sandbox.payout.one/api/v1/intel/limits?currency=PLN&country=SK&check_type=AML5", {
method: "GET",
headers: {
Authorization: `Bearer ${process.env.PAYOUT_TOKEN}`,
},
});
const data = await res.json();import os, requests
res = requests.get(
"https://sandbox.payout.one/api/v1/intel/limits?currency=PLN&country=SK&check_type=AML5",
headers={"Authorization": f"Bearer {os.environ['PAYOUT_TOKEN']}"},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://sandbox.payout.one/api/v1/intel/limits?currency=PLN&country=SK&check_type=AML5");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "GET");
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Authorization: Bearer " . getenv("PAYOUT_TOKEN")]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"check_type": "AML5",
"country": "SK",
"currency": "PLN",
"limit": 4284.784
}Parameters
ISO 4217 currency code, case-insensitive. Must be a currency with an exchange rate for today.
ISO 3166-1 alpha-2 country code, case-insensitive
Limit type, case-insensitive
Response 200
The limit in currency. Limits are set in EUR and converted at today's exchange rate.
ISO 3166-1 alpha-2 country code
ISO 4217 currency code
Limit type
Returned instead of all other fields when no limit is set
Other responses
currency has no exchange rate for today, or country is not an ISO 3166-1 alpha-2 code. The body has an error key, not errors.
Example
{
"error": "Invalid currency code"
}Missing, invalid or expired bearer token.
Example
{
"errors": "Unauthorized access. Check your token."
}Runs an AML check on a person and checks their identity document number (see valid_id).
Payout stores the search; open url to see the people it found.
Repeated searches
If the same name, surname and birthdate were searched before, the people found by the
latest such search are returned again, without a new lookup.
PEP alerts
When a new lookup finds a politically exposed person (PEP), every user of your account gets an e-mail alert.
curl -X POST 'https://sandbox.payout.one/api/v1/intel' \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "Juraj",
"surname": "Novak",
"birthdate": "1980-05-14",
"id": "AB1234"
}'const res = await fetch("https://sandbox.payout.one/api/v1/intel", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.PAYOUT_TOKEN}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
"name": "Juraj",
"surname": "Novak",
"birthdate": "1980-05-14",
"id": "AB1234"
}),
});
const data = await res.json();import os, requests
res = requests.post(
"https://sandbox.payout.one/api/v1/intel",
headers={"Authorization": f"Bearer {os.environ['PAYOUT_TOKEN']}"},
json={
"name": "Juraj",
"surname": "Novak",
"birthdate": "1980-05-14",
"id": "AB1234",
},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://sandbox.payout.one/api/v1/intel");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "POST");
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode([
"name" => "Juraj",
"surname" => "Novak",
"birthdate" => "1980-05-14",
"id" => "AB1234"
]));
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Authorization: Bearer " . getenv("PAYOUT_TOKEN"), "Content-Type: application/json"]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"id": "5a395a80-5e9a-4691-9674-28d0c91755b9",
"url": "https://sandbox.payout.one/intelboard/requests/5a395a80-5e9a-4691-9674-28d0c91755b9",
"valid_id": "valid",
"aml": "not_found"
}Request body
First name
Last name
Date of birth, YYYY-MM-DD
Number of the person's identity document, checked for valid_id. It is not stored with the search and is not the response id.
Response 200
ID of the stored search (not the identity document number). url ends with it.
Page with the search details in Payout
Result of the check of the request id. No identity document registry is connected yet, so real document numbers return unknown.
validThe document number is valid; currently only for the test valueAB1234not_validThe document number is not valid; currently only for the test valueXY1234unknownThe document number could not be checked; currently every other value, or noid
Result of the AML check
foundExactly one person foundfound_manyMore than one person foundnot_foundNo person found
Other responses
Missing, invalid or expired bearer token.
Example
{
"errors": "Unauthorized access. Check your token."
}The AML lookup timed out.
Example
{
"errors": "Timeout"
}The search could not be completed, for example because birthdate is not a valid YYYY-MM-DD date (the message then starts with Bad Date format.).
Example
{
"errors": "Couldn't save intel request"
}- Need help? Contact support.
- Questions? Contact sales.
- Service status? status.payout.one.
- LLM? Read llms.txt.