payout / developers
API reference

Payout OpenBanking PSD2 API

PSD2 API for third-party providers (TPPs). Read the accounts and transactions a user granted to you, confirm funds and initiate payments from Payout accounts. The API follows the SBA standard.

The API accepts and returns JSON only. Send request bodies with Content-Type: application/json.

Amounts in responses are decimal strings, such as "3055.8500". In requests, instructedAmount.value is a JSON number and the balance check amount.amount an integer or a decimal string.

Timestamps in responses are RFC 3339 in UTC with microseconds. statusDatetime ends in Z, the others in +00:00.

Every response has these headers:

  • response-id – a unique UUID of the response
  • correlation-id – your Correlation-ID request header, or a new UUID when you did not send one
  • process-id – your Process-ID request header, or a new UUID when you did not send one

Environments

EnvironmentBase URL
Sandbox, for testing onlyhttps://sandbox.payout.one
Productionhttps://app.payout.one

Authentication

Every endpoint except Enrol needs an OAuth 2.0 access token (JWT) issued by PayoutID to your TPP client. Send it in the Authorization header:

HTTP
Authorization: Bearer <access_token>

Get the tokens from PayoutID in the same environment as the API:

Their parameters are described at Authorize user and Get access token.

The token must be issued to a TPP client registered with Payout and carry the scope the endpoint requires:

Scope Grant Endpoints
AISP authorization_code, on behalf of the user List accounts, Retrieve account details and balances, List transactions
PIISP authorization_code, on behalf of the user Check balance
PISP client_credentials Create payment order, Retrieve payment order status
PISPSUBMIT authorization_code for one payment order, see Payment flow Submit payment order

Request AISP, PIISP and PISPSUBMIT as the only scope of an authorization request: PayoutID refuses to combine them with other scopes.

Account information endpoints return data only for the accounts the user granted to your TPP.

Payment flow

  1. Get a PISP token with the client_credentials grant at the token URL.

  2. Create the payment order with Create payment order. Keep its orderId.

  3. Send the user to the authorization URL with scope=PISPSUBMIT and the orderId as resource, in sandbox:

    HTTP
    GET https://id-sa.payout.one/oauth/authorize?response_type=code&client_id=<client_id>&redirect_uri=<redirect_uri>&scope=PISPSUBMIT&resource=<orderId>
    

    Exchange the code PayoutID returns to redirect_uri for a PISPSUBMIT token at the token URL.

  4. Submit the payment order with Submit payment order and the PISPSUBMIT token.

Errors

Authentication failures return 401:

JSON
{
  "status": 401,
  "reason": "Unauthorized"
}

You get it when the token:

  • is missing, invalid or expired
  • lacks the required scope or user
  • was issued to an unknown client

Other errors use this shape:

JSON
{
  "errors": {
    "message": "Resource not found"
  }
}
Status Message When
400 Bad request The body is not valid JSON, a required attribute is missing, or the payment order ID is not a UUID
404 Resource not found The account or payment order does not exist, or the account was not granted to your TPP
406 Request is not acceptable The Accept header does not allow JSON
500 Internal server error Unexpected error

Enrol validation errors and refused payment order submissions also return 400, with the bodies described at those endpoints.

POST

Enrol

/api/psd2/v1/enrol

Registers your TPP as a new client and returns its client credentials. This endpoint does not need an access token.

Payout is notified of the enrolment. The client stays inactive until Payout activates it.

Request
curl -X POST 'https://sandbox.payout.one/api/psd2/v1/enrol' \
  -H "Content-Type: application/json" \
  -d '{
       "licenseNumber": "12345",
       "clientName": "Example TPP, s.r.o.",
       "logoUri": "https://tpp.example.com/logo.png",
       "certificate": "MIIDdzCCAl+gAwIBAgIURXhhbXBsZVBTRDJDZXJ0aWZpY2F0ZQ==",
       "scopes": [
         "AISP"
       ],
       "contacts": [
         "[email protected]"
       ],
       "redirectUris": [
         "https://tpp.example.com/oauth/callback"
       ]
     }'
Response 201
{
  "licenseNumber": "12345",
  "clientId": "a1b2c3d4e5f60718293a4b5c6d7e8f90a1b2c3d4e5f60718293a4b5c6d7e8f90",
  "clientSecret": "0f1e2d3c4b5a69788796a5b4c3d2e1f00f1e2d3c4b5a69788796a5b4c3d2e1f0",
  "cleintName": "Example TPP, s.r.o.",
  "logoUri": "https://tpp.example.com/logo.png",
  "scopes": [
    "AISP"
  ],
  "contacts": [
    "[email protected]"
  ],
  "redirectsUris": [
    "https://tpp.example.com/oauth/callback"
  ]
}

Parameters

Correlation-IDheader · string

Your ID to match a request to its response. Echoed back in the correlation-id response header.

Example 5f0c7b9e-2a41-4d3b-8e6f-1a2b3c4d5e6f
Process-IDheader · string

Your ID to group several requests into one process. Echoed back in the process-id response header.

Example 7c1d2e3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f

Request body

licenseNumber requiredstring

PSD2 license number of your TPP. Each license number can be enrolled only once.

Max length 255 · Example 12345
clientName requiredstring

Client name of your TPP

Max length 255 · Example Example TPP, s.r.o.
logoUristring

URL of a publicly accessible logo of your TPP

Max length 255 · Example https://tpp.example.com/logo.png
scopes requiredstring[]

Scopes your TPP will request. See Authentication for the grant and endpoints of each.

  • AISPRead granted accounts, their balances and transactions
  • PISPCreate payment orders and read their status
  • PISPSUBMITSubmit a payment order
  • PIISPCheck whether an account has enough balance
  • profileDefault OAuth scope, not required by any endpoint of this API
contacts requiredstring<email>[]

E-mail addresses to contact your TPP. At least one is required.

Example ["[email protected]"]
redirectUris requiredstring<uri>[]

Redirect URIs your TPP will use. Each must be an absolute HTTPS URL without a fragment.

Example ["https://tpp.example.com/oauth/callback"]
certificate requiredstring

Base64-encoded PSD2 certificate of your TPP

Example MIIDdzCCAl+gAwIBAgIURXhhbXBsZVBTRDJDZXJ0aWZpY2F0ZQ==

Response 201

licenseNumberstring

PSD2 license number, as sent

Example 12345
clientIdstring

Client ID generated for your TPP, 64 hexadecimal characters

Example a1b2c3d4e5f60718293a4b5c6d7e8f90a1b2c3d4e5f60718293a4b5c6d7e8f90
clientSecretstring

Client secret generated for your TPP. It is returned only in this response and cannot be retrieved again, so store it securely.

Example 0f1e2d3c4b5a69788796a5b4c3d2e1f00f1e2d3c4b5a69788796a5b4c3d2e1f0
cleintNamestring

Client name of your TPP, as sent in clientName. The key is spelled cleintName.

Example Example TPP, s.r.o.
logoUristring | null

Logo URL, as sent. null when you sent none

Example https://tpp.example.com/logo.png
scopesstring[]

Scopes, as sent

Example ["AISP"]
contactsstring[]

Contact e-mail addresses, as sent

Example ["[email protected]"]
redirectsUrisstring[]

Redirect URIs, as sent in redirectUris. The key is spelled redirectsUris.

Example ["https://tpp.example.com/oauth/callback"]

Other responses

400

Validation failed (for example, the license number is already enrolled), or a required attribute is missing.

Example
{
  "status": 400,
  "errors": {
    "license_number": "has already been taken"
  }
}
GET

List accounts

/api/psd2/v1/accounts

Lists the user's accounts that the user granted to your TPP.

Request
curl -X GET 'https://sandbox.payout.one/api/psd2/v1/accounts' \
  -H "Authorization: Bearer $TOKEN"
Response 200
{
  "creationDateTime": "2026-10-06T08:15:30.123456+00:00",
  "accounts": [
    {
      "identification": {
        "identifier": "Q7v_K2mNp4Xs"
      },
      "name": "Example Shop, s.r.o.",
      "productName": "Payout Account",
      "type": "CACC",
      "baseCurrency": "EUR",
      "servicer": {
        "financialInstitutionIdentification": "Payout, s.r.o."
      },
      "consent": [
        "AISP"
      ]
    }
  ]
}

Parameters

Correlation-IDheader · string

Your ID to match a request to its response. Echoed back in the correlation-id response header.

Example 5f0c7b9e-2a41-4d3b-8e6f-1a2b3c4d5e6f
Process-IDheader · string

Your ID to group several requests into one process. Echoed back in the process-id response header.

Example 7c1d2e3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f

Response 200

creationDateTimestring<date-time>

When the list was created, in RFC 3339 format

Example 2026-10-06T08:15:30.123456+00:00
accountsobject[]
Show 7 child attributesHide child attributes
identificationobject
Show 1 child attributeHide child attributes
identifierstring

Account identifier. Send it as identifier to the other endpoints.

Example Q7v_K2mNp4Xs
namestring

Account name

Example Example Shop, s.r.o.
productNamestring

Product name, always Payout Account

Example Payout Account
typestring

ISO 20022 cash account type code, always CACC

Example CACC
baseCurrencystring

ISO 4217 base currency of the account, always EUR

Example EUR
servicerobject

Institution that services the account

Show 1 child attributeHide child attributes
financialInstitutionIdentificationstring

Name of the institution

Example Payout, s.r.o.
consentstring[]

Scopes of the access token used for the request

Example ["AISP"]

Other responses

401

Missing or invalid bearer token, or the token lacks the required scope.

Example
{
  "status": 401,
  "reason": "Unauthorized"
}
POST

Retrieve account details and balances

/api/psd2/v1/accounts/information

Retrieves the details of one granted account and its balance in each currency.

Request
curl -X POST 'https://sandbox.payout.one/api/psd2/v1/accounts/information' \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
       "identifier": "Q7v_K2mNp4Xs"
     }'
Response 200
{
  "account": {
    "name": "Example Shop, s.r.o.",
    "productName": "Payout Account",
    "baseCurrency": "EUR",
    "type": "CACC"
  },
  "balances": [
    {
      "name": "Example Shop, s.r.o.",
      "typeCodeOrProprietary": "ITAV",
      "amount": {
        "value": "3055.8500",
        "currency": "EUR"
      },
      "creditDebitIndicator": "CRDT",
      "dateTime": "2026-10-06T08:15:30.123456+00:00"
    }
  ]
}

Parameters

Correlation-IDheader · string

Your ID to match a request to its response. Echoed back in the correlation-id response header.

Example 5f0c7b9e-2a41-4d3b-8e6f-1a2b3c4d5e6f
Process-IDheader · string

Your ID to group several requests into one process. Echoed back in the process-id response header.

Example 7c1d2e3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f

Request body

identifier requiredstring

Account identifier (identification.identifier from List accounts)

Example Q7v_K2mNp4Xs

Response 200

accountobject
Show 4 child attributesHide child attributes
namestring

Account name

Example Example Shop, s.r.o.
productNamestring

Product name, always Payout Account

Example Payout Account
baseCurrencystring

ISO 4217 base currency of the account, always EUR

Example EUR
typestring

ISO 20022 cash account type code, always CACC

Example CACC
balancesobject[]

One balance per currency

Show 5 child attributesHide child attributes
namestring

Account name

Example Example Shop, s.r.o.
typeCodeOrProprietarystring

Balance type, always ITAV

Example ITAV
amountobject

Amount of money with its currency

Show 2 child attributesHide child attributes
valuestring

Decimal amount, serialized as a string

Example 3055.8500
currencystring

ISO 4217 currency code

Example EUR
creditDebitIndicatorstring

Whether incoming or outgoing funds prevail

  • CRDTIncoming funds exceed outgoing funds
  • DBITOutgoing funds equal or exceed incoming funds
Example CRDT
dateTimestring<date-time>

When the balance was read, in RFC 3339 format

Example 2026-10-06T08:15:30.123456+00:00

Other responses

400

The body is not valid JSON or has no identifier.

Example
{
  "errors": {
    "message": "Bad request"
  }
}
401

Missing or invalid bearer token, or the token lacks the required scope.

Example
{
  "status": 401,
  "reason": "Unauthorized"
}
404

None of the accounts the user granted to your TPP has this identifier.

Example
{
  "errors": {
    "message": "Resource not found"
  }
}
POST

List transactions

/api/psd2/v1/accounts/transactions

Lists the transactions of the accounts the user granted to your TPP, newest first. All filters are optional; without a body you get the first page across all granted accounts.

Warning

In this API, status BOOKED means pending and INFO means executed, the reverse of their usual ISO 20022 meaning. This applies to the status filter and to the status of each transaction.

Request
curl -X POST 'https://sandbox.payout.one/api/psd2/v1/accounts/transactions' \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
       "page": 2,
       "identifier": "Q7v_K2mNp4Xs"
     }'
Response 200
{
  "pageCount": 3,
  "transactions": [
    {
      "amount": {
        "value": "25.0000",
        "currency": "EUR"
      },
      "creditDebitIndicator": "CRDT",
      "reversalIndicator": false,
      "status": "INFO",
      "bookingDate": "2026-09-15",
      "valueDate": "2026-09-15",
      "bankTransactionCode": "PM",
      "transactionDetails": {
        "references": {
          "accountServicerReference": "184512",
          "endToEndIdentification": "/VS20260915/SS/KS"
        },
        "relatedParties": {
          "debtor": {
            "name": "Example Customer"
          },
          "debtorAccount": {
            "identification": "CZ6508000000192000145399"
          },
          "creditor": {
            "name": "Example Shop, s.r.o."
          },
          "creditorAccount": {
            "identification": "Q7v_K2mNp4Xs"
          }
        },
        "relatedDates": {
          "acceptanceDateTime": "2026-09-15"
        }
      }
    }
  ]
}

Parameters

Correlation-IDheader · string

Your ID to match a request to its response. Echoed back in the correlation-id response header.

Example 5f0c7b9e-2a41-4d3b-8e6f-1a2b3c4d5e6f
Process-IDheader · string

Your ID to group several requests into one process. Echoed back in the process-id response header.

Example 7c1d2e3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f

Request body

identifierstring

Return only transactions of this account (identification.identifier from List accounts)

Example Q7v_K2mNp4Xs
dateFromstring<date>

Return transactions created on or after this date, YYYY-MM-DD. Other formats are ignored.

Example 2026-09-01
dateTostring<date>

Return transactions created before this date, YYYY-MM-DD. Other formats are ignored.

Example 2026-09-30
statusstring

Return only transactions with this status. Note that BOOKED means pending and INFO means executed, the reverse of their usual ISO 20022 meaning.

  • BOOKEDOnly pending transactions
  • INFOOnly executed transactions
Example BOOKED
pageSizeinteger

Number of transactions per page

Default 50 · Example 20
pageinteger

Page number, starting at 0

Default 0 · Example 4

Response 200

pageCountinteger

Total number of pages for the given filters

Example 3
transactionsobject[]
Show 8 child attributesHide child attributes
amountobject

Amount of money with its currency

Show 2 child attributesHide child attributes
valuestring

Decimal amount, serialized as a string

Example 3055.8500
currencystring

ISO 4217 currency code

Example EUR
creditDebitIndicatorstring

Direction of the transaction

  • CRDTCredit, money into the account
  • DBITDebit, money out of the account
Example CRDT
reversalIndicatorboolean

Whether the transaction reverses an earlier transaction

Example false
statusstring

Execution state of the transaction. Note that INFO means executed and BOOKED means pending, the reverse of their usual ISO 20022 meaning.

  • INFOExecuted
  • BOOKEDPending, not executed yet
Example INFO
bookingDatestring<date>

Date the transaction was created

Example 2026-09-15
valueDatestring<date>

Same as bookingDate

Example 2026-09-15
bankTransactionCodestring

Transaction type code

  • PMAny other transaction
  • GHCAccount management, support, monthly minimum or receipts fee
Example PM
transactionDetailsobject
Show 3 child attributesHide child attributes
referencesobject

References that identify the transaction

Show 2 child attributesHide child attributes
accountServicerReferencestring

Payout's transaction ID

Example 184512
endToEndIdentificationstring | null

Transaction reference in the form /VS{variable symbol}/SS/KS, or null when the transaction has none

Example /VS20260915/SS/KS
relatedPartiesobject

The account is the debtor of a debit and the creditor of a credit. When the transaction has no counterparty, the other party is Payout, s.r.o. with identification PAYOUT.

Show 4 child attributesHide child attributes
debtorobject
Show 1 child attributeHide child attributes
namestring

Name of the party

Example Example Customer
debtorAccountobject
Show 1 child attributeHide child attributes
identificationstring

Account identifier for the account, IBAN for the counterparty

Example CZ6508000000192000145399
creditorobject
Show 1 child attributeHide child attributes
namestring

Name of the party

Example Example Shop, s.r.o.
creditorAccountobject
Show 1 child attributeHide child attributes
identificationstring

Account identifier for the account, IBAN for the counterparty

Example Q7v_K2mNp4Xs
relatedDatesobject
Show 1 child attributeHide child attributes
acceptanceDateTimestring<date>

Same as bookingDate

Example 2026-09-15

Other responses

400

The body is not valid JSON.

Example
{
  "errors": {
    "message": "Bad request"
  }
}
401

Missing or invalid bearer token, or the token lacks the required scope.

Example
{
  "status": 401,
  "reason": "Unauthorized"
}
POST

Create payment order

/api/psd2/v1/payments/standard/sba

Creates a payment order, a standard SBA payment from a Payout account to the creditor's IBAN. The payment order starts in status PDNG and is executed only after you submit it.

Request
curl -X POST 'https://sandbox.payout.one/api/psd2/v1/payments/standard/sba' \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
       "instructionIdentification": "aff52ratg5ageh53",
       "debtor": {
         "identifier": "Q7v_K2mNp4Xs"
       },
       "creditor": {
         "name": "Example Supplier, s.r.o.",
         "iban": "SK3112000000198742637541",
         "email": "[email protected]"
       },
       "instructedAmount": {
         "value": 12.5,
         "currency": "EUR"
       },
       "endToEndIdentification": "/VS20261006/SS/KS",
       "remittanceInformation": "Invoice 2026-104"
     }'
Response 201
{
  "orderId": "3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d",
  "status": "PDNG",
  "statusDatetime": "2026-10-06T08:15:30.123456Z"
}

Parameters

Correlation-IDheader · string

Your ID to match a request to its response. Echoed back in the correlation-id response header.

Example 5f0c7b9e-2a41-4d3b-8e6f-1a2b3c4d5e6f
Process-IDheader · string

Your ID to group several requests into one process. Echoed back in the process-id response header.

Example 7c1d2e3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f

Request body

instructionIdentification requiredstring

Your identification of the instruction

Max length 255 · Example aff52ratg5ageh53
debtor requiredobject
Show 1 child attributeHide child attributes
identifier requiredstring

Account to pay from (identification.identifier from List accounts)

Max length 255 · Example Q7v_K2mNp4Xs
creditor requiredobject
Show 3 child attributesHide child attributes
name requiredstring

Full name or company name of the creditor

Max length 255 · Example Example Supplier, s.r.o.
iban requiredstring

IBAN of the creditor

Max length 255 · Example SK3112000000198742637541
email requiredstring

E-mail address of the creditor

Max length 255 · Example [email protected]
instructedAmount requiredobject
Show 2 child attributesHide child attributes
value requirednumber

Amount with two decimals

Example 12.5
currency requiredstring

ISO 4217 currency code

Max length 255 · Example EUR
endToEndIdentificationstring

Your transaction reference. In the form /VS{variable symbol}/SS{specific symbol}/KS{constant symbol}, the variable symbol becomes the payment reference and must be numeric with at most 10 digits. This value, or instructionIdentification when it is empty, must not repeat across payments from the same account. Otherwise the submission is refused.

Max length 255 · Example /VS20261006/SS/KS
remittanceInformationstring

Description that appears on the creditor's statement, with only letters without accents, digits, spaces and /-?:().,'+. Creating the payment order accepts up to 255 characters, but its submission is refused when the text is longer than 140 characters or has other characters.

Max length 140 · Example Invoice 2026-104

Response 201

Returns a PaymentOrder object.

Show 3 attributesHide attributes
orderIdstring<uuid>

Payment order ID

Example 3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d
statusstring

Status of the payment order

  • PDNGCreated, not submitted yet
  • ACSCSubmitted, payment created
  • RJCTSubmission refused (returned only by Submit payment order)
statusDatetimestring<date-time>

When the status was read

Example 2026-10-06T08:15:30.123456Z

Other responses

400

The body is not valid JSON or a required attribute is missing.

Example
{
  "errors": {
    "message": "Bad request"
  }
}
401

Missing or invalid bearer token, or the token lacks the required scope.

Example
{
  "status": 401,
  "reason": "Unauthorized"
}
404

No account has the identifier given in debtor.identifier.

Example
{
  "errors": {
    "message": "Resource not found"
  }
}
POST

Submit payment order

/api/psd2/v1/payments/submission

Submits a created payment order for execution. On success the payment order moves to status ACSC.

Call it with a PISPSUBMIT token obtained for the payment order (see Payment flow). The token identifies the payment order, so the request has no body.

Request
curl -X POST 'https://sandbox.payout.one/api/psd2/v1/payments/submission' \
  -H "Authorization: Bearer $TOKEN"
Response 201
{
  "orderId": "3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d",
  "status": "ACSC",
  "statusDatetime": "2026-10-06T08:16:02.481530Z"
}

Parameters

Correlation-IDheader · string

Your ID to match a request to its response. Echoed back in the correlation-id response header.

Example 5f0c7b9e-2a41-4d3b-8e6f-1a2b3c4d5e6f
Process-IDheader · string

Your ID to group several requests into one process. Echoed back in the process-id response header.

Example 7c1d2e3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f

Response 201

Returns a PaymentOrder object.

Show 3 attributesHide attributes
orderIdstring<uuid>

Payment order ID

Example 3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d
statusstring

Status of the payment order

  • PDNGCreated, not submitted yet
  • ACSCSubmitted, payment created
  • RJCTSubmission refused (returned only by Submit payment order)
statusDatetimestring<date-time>

When the status was read

Example 2026-10-06T08:15:30.123456Z

Other responses

200

The payment order was already submitted. It is returned unchanged.

Example
{
  "orderId": "3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d",
  "status": "ACSC",
  "statusDatetime": "2026-10-06T08:16:02.481530Z"
}
400

The payment order was refused, for example because the available balance is too low or a field of the payment order breaks a rule given in its description. The body has status RJCT; its orderId is a newly generated UUID, not the ID of the submitted payment order.

Example
{
  "orderId": "9d2c4f1a-6b3e-4c8d-a5f7-0e1b2c3d4e5f",
  "status": "RJCT",
  "statusDatetime": "2026-10-06T08:16:02.481530Z"
}
401

Missing or invalid bearer token, or the token lacks the required scope.

Example
{
  "status": 401,
  "reason": "Unauthorized"
}
GET

Retrieve payment order status

/api/psd2/v1/payments/{order_id}/status

Retrieves the current status of a payment order.

Request
curl -X GET 'https://sandbox.payout.one/api/psd2/v1/payments/3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d/status' \
  -H "Authorization: Bearer $TOKEN"
Response 200
{
  "orderId": "3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d",
  "status": "PDNG",
  "statusDatetime": "2026-10-06T08:15:30.123456Z"
}

Parameters

order_id requiredpath · string<uuid>

Payment order ID, returned as orderId by Create payment order

Example 3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d
Correlation-IDheader · string

Your ID to match a request to its response. Echoed back in the correlation-id response header.

Example 5f0c7b9e-2a41-4d3b-8e6f-1a2b3c4d5e6f
Process-IDheader · string

Your ID to group several requests into one process. Echoed back in the process-id response header.

Example 7c1d2e3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f

Response 200

Returns a PaymentOrder object.

Show 3 attributesHide attributes
orderIdstring<uuid>

Payment order ID

Example 3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d
statusstring

Status of the payment order

  • PDNGCreated, not submitted yet
  • ACSCSubmitted, payment created
  • RJCTSubmission refused (returned only by Submit payment order)
statusDatetimestring<date-time>

When the status was read

Example 2026-10-06T08:15:30.123456Z

Other responses

400

order_id is not a UUID.

Example
{
  "errors": {
    "message": "Bad request"
  }
}
401

Missing or invalid bearer token, or the token lacks the required scope.

Example
{
  "status": 401,
  "reason": "Unauthorized"
}
404

No payment order has this ID.

Example
{
  "errors": {
    "message": "Resource not found"
  }
}
POST

Check balance

/api/psd2/v1/accounts/balanceCheck

Checks whether an account has enough available balance for an amount.

Request
curl -X POST 'https://sandbox.payout.one/api/psd2/v1/accounts/balanceCheck' \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
       "instructionIdentification": "piisp-20261006-0001",
       "identifier": "Q7v_K2mNp4Xs",
       "amount": {
         "amount": 6000,
         "currency": "EUR"
       }
     }'
Response 200
{
  "response": "APPR",
  "dateTime": "2026-10-06T08:15:30.123456+00:00"
}

Parameters

Correlation-IDheader · string

Your ID to match a request to its response. Echoed back in the correlation-id response header.

Example 5f0c7b9e-2a41-4d3b-8e6f-1a2b3c4d5e6f
Process-IDheader · string

Your ID to group several requests into one process. Echoed back in the process-id response header.

Example 7c1d2e3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f

Request body

instructionIdentificationstring

Your technical identification of the request. Accepted but not evaluated.

Example piisp-20261006-0001
creationDateTimestring<date-time>

When the request was created, in RFC 3339 format. Accepted but not evaluated.

Example 2026-10-06T08:15:30.123456+00:00
identifier requiredstring

Account identifier (identification.identifier from List accounts)

Example Q7v_K2mNp4Xs
amount requiredobject
Show 2 child attributesHide child attributes
amount requiredinteger | string

Amount to check, as an integer or a decimal string such as "60.50". Fractional JSON numbers are not accepted.

Example 6000
Show 0 child attributesHide child attributes

One of:

Option 1

integer

Option 2

string

currency requiredstring

ISO 4217 currency code

Example EUR

Response 200

responsestring

Result of the check

  • APPRThe available balance in currency is greater than amount
  • DECLThe available balance is not greater than amount, or the user's account has no balance in currency
Example APPR
dateTimestring<date-time>

When the check was made, in RFC 3339 format

Example 2026-10-06T08:15:30.123456+00:00

Other responses

400

The body is not valid JSON or a required attribute is missing.

Example
{
  "errors": {
    "message": "Bad request"
  }
}
401

Missing or invalid bearer token, or the token lacks the required scope.

Example
{
  "status": 401,
  "reason": "Unauthorized"
}

Was this page helpful?