Payout OpenBanking PSD2 API
PSD2 API for third-party providers (TPPs). Read the accounts and transactions a user granted to you, confirm funds and initiate payments from Payout accounts. The API follows the SBA standard.
The API accepts and returns JSON only. Send request bodies with Content-Type: application/json.
Amounts in responses are decimal strings, such as "3055.8500". In requests,
instructedAmount.value is a JSON number and the balance check amount.amount an integer or a
decimal string.
Timestamps in responses are RFC 3339 in UTC with microseconds. statusDatetime ends in Z,
the others in +00:00.
Every response has these headers:
response-id– a unique UUID of the responsecorrelation-id– yourCorrelation-IDrequest header, or a new UUID when you did not send oneprocess-id– yourProcess-IDrequest header, or a new UUID when you did not send one
Environments
| Environment | Base URL |
|---|---|
| Sandbox, for testing only | https://sandbox.payout.one |
| Production | https://app.payout.one |
Authentication
Every endpoint except Enrol needs an OAuth 2.0 access token (JWT) issued by
PayoutID to your TPP client. Send it in the Authorization header:
Authorization: Bearer <access_token>
Get the tokens from PayoutID in the same environment as the API:
| Environment | Authorization URL | Token URL |
|---|---|---|
| Sandbox | https:// |
https:// |
| Production | https:// |
https:// |
Their parameters are described at Authorize user and Get access token.
The token must be issued to a TPP client registered with Payout and carry the scope the endpoint requires:
| Scope | Grant | Endpoints |
|---|---|---|
AISP |
authorization_code, on behalf of the user |
List accounts, Retrieve account details and balances, List transactions |
PIISP |
authorization_code, on behalf of the user |
Check balance |
PISP |
client_credentials |
Create payment order, Retrieve payment order status |
PISPSUBMIT |
authorization_code for one payment order, see Payment flow |
Submit payment order |
Request AISP, PIISP and PISPSUBMIT as the only scope of an authorization request: PayoutID
refuses to combine them with other scopes.
Account information endpoints return data only for the accounts the user granted to your TPP.
Payment flow
-
Get a
PISPtoken with theclient_credentialsgrant at the token URL. -
Create the payment order with Create payment order. Keep its
orderId. -
Send the user to the authorization URL with
scope=PISPSUBMITand theorderIdasresource, in sandbox:HTTPGET https://id-sa.payout.one/oauth/authorize?response_type=code&client_id=<client_id>&redirect_uri=<redirect_uri>&scope=PISPSUBMIT&resource=<orderId>Exchange the
codePayoutID returns toredirect_urifor aPISPSUBMITtoken at the token URL. -
Submit the payment order with Submit payment order and the
PISPSUBMITtoken.
Errors
Authentication failures return 401:
{
"status": 401,
"reason": "Unauthorized"
}
You get it when the token:
- is missing, invalid or expired
- lacks the required scope or user
- was issued to an unknown client
Other errors use this shape:
{
"errors": {
"message": "Resource not found"
}
}
| Status | Message | When |
|---|---|---|
| 400 | Bad request |
The body is not valid JSON, a required attribute is missing, or the payment order ID is not a UUID |
| 404 | Resource not found |
The account or payment order does not exist, or the account was not granted to your TPP |
| 406 | Request is not acceptable |
The Accept header does not allow JSON |
| 500 | Internal server error |
Unexpected error |
Enrol validation errors and refused payment order submissions also
return 400, with the bodies described at those endpoints.
Registers your TPP as a new client and returns its client credentials. This endpoint does not need an access token.
Payout is notified of the enrolment. The client stays inactive until Payout activates it.
curl -X POST 'https://sandbox.payout.one/api/psd2/v1/enrol' \
-H "Content-Type: application/json" \
-d '{
"licenseNumber": "12345",
"clientName": "Example TPP, s.r.o.",
"logoUri": "https://tpp.example.com/logo.png",
"certificate": "MIIDdzCCAl+gAwIBAgIURXhhbXBsZVBTRDJDZXJ0aWZpY2F0ZQ==",
"scopes": [
"AISP"
],
"contacts": [
"[email protected]"
],
"redirectUris": [
"https://tpp.example.com/oauth/callback"
]
}'const res = await fetch("https://sandbox.payout.one/api/psd2/v1/enrol", {
method: "POST",
headers: {
"Content-Type": "application/json",
},
body: JSON.stringify({
"licenseNumber": "12345",
"clientName": "Example TPP, s.r.o.",
"logoUri": "https://tpp.example.com/logo.png",
"certificate": "MIIDdzCCAl+gAwIBAgIURXhhbXBsZVBTRDJDZXJ0aWZpY2F0ZQ==",
"scopes": [
"AISP"
],
"contacts": [
"[email protected]"
],
"redirectUris": [
"https://tpp.example.com/oauth/callback"
]
}),
});
const data = await res.json();import os, requests
res = requests.post(
"https://sandbox.payout.one/api/psd2/v1/enrol",
json={
"licenseNumber": "12345",
"clientName": "Example TPP, s.r.o.",
"logoUri": "https://tpp.example.com/logo.png",
"certificate": "MIIDdzCCAl+gAwIBAgIURXhhbXBsZVBTRDJDZXJ0aWZpY2F0ZQ==",
"scopes": [
"AISP",
],
"contacts": [
"[email protected]",
],
"redirectUris": [
"https://tpp.example.com/oauth/callback",
],
},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://sandbox.payout.one/api/psd2/v1/enrol");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "POST");
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode([
"licenseNumber" => "12345",
"clientName" => "Example TPP, s.r.o.",
"logoUri" => "https://tpp.example.com/logo.png",
"certificate" => "MIIDdzCCAl+gAwIBAgIURXhhbXBsZVBTRDJDZXJ0aWZpY2F0ZQ==",
"scopes" => [
"AISP"
],
"contacts" => [
"[email protected]"
],
"redirectUris" => [
"https://tpp.example.com/oauth/callback"
]
]));
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Content-Type: application/json"]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"licenseNumber": "12345",
"clientId": "a1b2c3d4e5f60718293a4b5c6d7e8f90a1b2c3d4e5f60718293a4b5c6d7e8f90",
"clientSecret": "0f1e2d3c4b5a69788796a5b4c3d2e1f00f1e2d3c4b5a69788796a5b4c3d2e1f0",
"cleintName": "Example TPP, s.r.o.",
"logoUri": "https://tpp.example.com/logo.png",
"scopes": [
"AISP"
],
"contacts": [
"[email protected]"
],
"redirectsUris": [
"https://tpp.example.com/oauth/callback"
]
}Parameters
Your ID to match a request to its response. Echoed back in the correlation-id response header.
Your ID to group several requests into one process. Echoed back in the process-id response header.
Request body
PSD2 license number of your TPP. Each license number can be enrolled only once.
Client name of your TPP
URL of a publicly accessible logo of your TPP
Scopes your TPP will request. See Authentication for the grant and endpoints of each.
AISPRead granted accounts, their balances and transactionsPISPCreate payment orders and read their statusPISPSUBMITSubmit a payment orderPIISPCheck whether an account has enough balanceprofileDefault OAuth scope, not required by any endpoint of this API
E-mail addresses to contact your TPP. At least one is required.
Redirect URIs your TPP will use. Each must be an absolute HTTPS URL without a fragment.
Base64-encoded PSD2 certificate of your TPP
Response 201
PSD2 license number, as sent
Client ID generated for your TPP, 64 hexadecimal characters
Client secret generated for your TPP. It is returned only in this response and cannot be retrieved again, so store it securely.
Client name of your TPP, as sent in clientName. The key is spelled cleintName.
Logo URL, as sent. null when you sent none
Scopes, as sent
Contact e-mail addresses, as sent
Redirect URIs, as sent in redirectUris. The key is spelled redirectsUris.
Other responses
Validation failed (for example, the license number is already enrolled), or a required attribute is missing.
Example
{
"status": 400,
"errors": {
"license_number": "has already been taken"
}
}Lists the user's accounts that the user granted to your TPP.
curl -X GET 'https://sandbox.payout.one/api/psd2/v1/accounts' \
-H "Authorization: Bearer $TOKEN"const res = await fetch("https://sandbox.payout.one/api/psd2/v1/accounts", {
method: "GET",
headers: {
Authorization: `Bearer ${process.env.PAYOUT_TOKEN}`,
},
});
const data = await res.json();import os, requests
res = requests.get(
"https://sandbox.payout.one/api/psd2/v1/accounts",
headers={"Authorization": f"Bearer {os.environ['PAYOUT_TOKEN']}"},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://sandbox.payout.one/api/psd2/v1/accounts");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "GET");
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Authorization: Bearer " . getenv("PAYOUT_TOKEN")]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"creationDateTime": "2026-10-06T08:15:30.123456+00:00",
"accounts": [
{
"identification": {
"identifier": "Q7v_K2mNp4Xs"
},
"name": "Example Shop, s.r.o.",
"productName": "Payout Account",
"type": "CACC",
"baseCurrency": "EUR",
"servicer": {
"financialInstitutionIdentification": "Payout, s.r.o."
},
"consent": [
"AISP"
]
}
]
}Parameters
Your ID to match a request to its response. Echoed back in the correlation-id response header.
Your ID to group several requests into one process. Echoed back in the process-id response header.
Response 200
When the list was created, in RFC 3339 format
Show 7 child attributesHide child attributes
Show 1 child attributeHide child attributes
Account identifier. Send it as identifier to the other endpoints.
Account name
Product name, always Payout Account
ISO 20022 cash account type code, always CACC
ISO 4217 base currency of the account, always EUR
Institution that services the account
Show 1 child attributeHide child attributes
Name of the institution
Scopes of the access token used for the request
Other responses
Missing or invalid bearer token, or the token lacks the required scope.
Example
{
"status": 401,
"reason": "Unauthorized"
}Retrieves the details of one granted account and its balance in each currency.
curl -X POST 'https://sandbox.payout.one/api/psd2/v1/accounts/information' \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"identifier": "Q7v_K2mNp4Xs"
}'const res = await fetch("https://sandbox.payout.one/api/psd2/v1/accounts/information", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.PAYOUT_TOKEN}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
"identifier": "Q7v_K2mNp4Xs"
}),
});
const data = await res.json();import os, requests
res = requests.post(
"https://sandbox.payout.one/api/psd2/v1/accounts/information",
headers={"Authorization": f"Bearer {os.environ['PAYOUT_TOKEN']}"},
json={
"identifier": "Q7v_K2mNp4Xs",
},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://sandbox.payout.one/api/psd2/v1/accounts/information");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "POST");
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode([
"identifier" => "Q7v_K2mNp4Xs"
]));
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Authorization: Bearer " . getenv("PAYOUT_TOKEN"), "Content-Type: application/json"]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"account": {
"name": "Example Shop, s.r.o.",
"productName": "Payout Account",
"baseCurrency": "EUR",
"type": "CACC"
},
"balances": [
{
"name": "Example Shop, s.r.o.",
"typeCodeOrProprietary": "ITAV",
"amount": {
"value": "3055.8500",
"currency": "EUR"
},
"creditDebitIndicator": "CRDT",
"dateTime": "2026-10-06T08:15:30.123456+00:00"
}
]
}Parameters
Your ID to match a request to its response. Echoed back in the correlation-id response header.
Your ID to group several requests into one process. Echoed back in the process-id response header.
Request body
Account identifier (identification.identifier from List accounts)
Response 200
Show 4 child attributesHide child attributes
Account name
Product name, always Payout Account
ISO 4217 base currency of the account, always EUR
ISO 20022 cash account type code, always CACC
One balance per currency
Show 5 child attributesHide child attributes
Account name
Balance type, always ITAV
Amount of money with its currency
Show 2 child attributesHide child attributes
Decimal amount, serialized as a string
ISO 4217 currency code
Whether incoming or outgoing funds prevail
CRDTIncoming funds exceed outgoing fundsDBITOutgoing funds equal or exceed incoming funds
When the balance was read, in RFC 3339 format
Other responses
The body is not valid JSON or has no identifier.
Example
{
"errors": {
"message": "Bad request"
}
}Missing or invalid bearer token, or the token lacks the required scope.
Example
{
"status": 401,
"reason": "Unauthorized"
}None of the accounts the user granted to your TPP has this identifier.
Example
{
"errors": {
"message": "Resource not found"
}
}Lists the transactions of the accounts the user granted to your TPP, newest first. All filters are optional; without a body you get the first page across all granted accounts.
Warning
In this API, status BOOKED means pending and INFO means executed, the reverse
of their usual ISO 20022 meaning. This applies to the status filter and to the status of
each transaction.
curl -X POST 'https://sandbox.payout.one/api/psd2/v1/accounts/transactions' \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"page": 2,
"identifier": "Q7v_K2mNp4Xs"
}'const res = await fetch("https://sandbox.payout.one/api/psd2/v1/accounts/transactions", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.PAYOUT_TOKEN}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
"page": 2,
"identifier": "Q7v_K2mNp4Xs"
}),
});
const data = await res.json();import os, requests
res = requests.post(
"https://sandbox.payout.one/api/psd2/v1/accounts/transactions",
headers={"Authorization": f"Bearer {os.environ['PAYOUT_TOKEN']}"},
json={
"page": 2,
"identifier": "Q7v_K2mNp4Xs",
},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://sandbox.payout.one/api/psd2/v1/accounts/transactions");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "POST");
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode([
"page" => 2,
"identifier" => "Q7v_K2mNp4Xs"
]));
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Authorization: Bearer " . getenv("PAYOUT_TOKEN"), "Content-Type: application/json"]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"pageCount": 3,
"transactions": [
{
"amount": {
"value": "25.0000",
"currency": "EUR"
},
"creditDebitIndicator": "CRDT",
"reversalIndicator": false,
"status": "INFO",
"bookingDate": "2026-09-15",
"valueDate": "2026-09-15",
"bankTransactionCode": "PM",
"transactionDetails": {
"references": {
"accountServicerReference": "184512",
"endToEndIdentification": "/VS20260915/SS/KS"
},
"relatedParties": {
"debtor": {
"name": "Example Customer"
},
"debtorAccount": {
"identification": "CZ6508000000192000145399"
},
"creditor": {
"name": "Example Shop, s.r.o."
},
"creditorAccount": {
"identification": "Q7v_K2mNp4Xs"
}
},
"relatedDates": {
"acceptanceDateTime": "2026-09-15"
}
}
}
]
}Parameters
Your ID to match a request to its response. Echoed back in the correlation-id response header.
Your ID to group several requests into one process. Echoed back in the process-id response header.
Request body
Return only transactions of this account (identification.identifier from List accounts)
Return transactions created on or after this date, YYYY-MM-DD. Other formats are ignored.
Return transactions created before this date, YYYY-MM-DD. Other formats are ignored.
Return only transactions with this status. Note that BOOKED means pending and INFO means executed, the reverse of their usual ISO 20022 meaning.
BOOKEDOnly pending transactionsINFOOnly executed transactions
Number of transactions per page
Page number, starting at 0
Response 200
Total number of pages for the given filters
Show 8 child attributesHide child attributes
Amount of money with its currency
Show 2 child attributesHide child attributes
Decimal amount, serialized as a string
ISO 4217 currency code
Direction of the transaction
CRDTCredit, money into the accountDBITDebit, money out of the account
Whether the transaction reverses an earlier transaction
Execution state of the transaction. Note that INFO means executed and BOOKED means pending, the reverse of their usual ISO 20022 meaning.
INFOExecutedBOOKEDPending, not executed yet
Date the transaction was created
Same as bookingDate
Transaction type code
PMAny other transactionGHCAccount management, support, monthly minimum or receipts fee
Show 3 child attributesHide child attributes
References that identify the transaction
Show 2 child attributesHide child attributes
Payout's transaction ID
Transaction reference in the form /VS{variable symbol}/SS/KS, or null when the transaction has none
The account is the debtor of a debit and the creditor of a credit. When the transaction has no counterparty, the other party is Payout, s.r.o. with identification PAYOUT.
Show 4 child attributesHide child attributes
Show 1 child attributeHide child attributes
Name of the party
Show 1 child attributeHide child attributes
Account identifier for the account, IBAN for the counterparty
Show 1 child attributeHide child attributes
Name of the party
Show 1 child attributeHide child attributes
Account identifier for the account, IBAN for the counterparty
Show 1 child attributeHide child attributes
Same as bookingDate
Other responses
The body is not valid JSON.
Example
{
"errors": {
"message": "Bad request"
}
}Missing or invalid bearer token, or the token lacks the required scope.
Example
{
"status": 401,
"reason": "Unauthorized"
}Creates a payment order, a standard SBA payment from a Payout account to the creditor's IBAN.
The payment order starts in status PDNG and is executed only after you
submit it.
curl -X POST 'https://sandbox.payout.one/api/psd2/v1/payments/standard/sba' \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"instructionIdentification": "aff52ratg5ageh53",
"debtor": {
"identifier": "Q7v_K2mNp4Xs"
},
"creditor": {
"name": "Example Supplier, s.r.o.",
"iban": "SK3112000000198742637541",
"email": "[email protected]"
},
"instructedAmount": {
"value": 12.5,
"currency": "EUR"
},
"endToEndIdentification": "/VS20261006/SS/KS",
"remittanceInformation": "Invoice 2026-104"
}'const res = await fetch("https://sandbox.payout.one/api/psd2/v1/payments/standard/sba", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.PAYOUT_TOKEN}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
"instructionIdentification": "aff52ratg5ageh53",
"debtor": {
"identifier": "Q7v_K2mNp4Xs"
},
"creditor": {
"name": "Example Supplier, s.r.o.",
"iban": "SK3112000000198742637541",
"email": "[email protected]"
},
"instructedAmount": {
"value": 12.5,
"currency": "EUR"
},
"endToEndIdentification": "/VS20261006/SS/KS",
"remittanceInformation": "Invoice 2026-104"
}),
});
const data = await res.json();import os, requests
res = requests.post(
"https://sandbox.payout.one/api/psd2/v1/payments/standard/sba",
headers={"Authorization": f"Bearer {os.environ['PAYOUT_TOKEN']}"},
json={
"instructionIdentification": "aff52ratg5ageh53",
"debtor": {
"identifier": "Q7v_K2mNp4Xs",
},
"creditor": {
"name": "Example Supplier, s.r.o.",
"iban": "SK3112000000198742637541",
"email": "[email protected]",
},
"instructedAmount": {
"value": 12.5,
"currency": "EUR",
},
"endToEndIdentification": "/VS20261006/SS/KS",
"remittanceInformation": "Invoice 2026-104",
},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://sandbox.payout.one/api/psd2/v1/payments/standard/sba");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "POST");
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode([
"instructionIdentification" => "aff52ratg5ageh53",
"debtor" => [
"identifier" => "Q7v_K2mNp4Xs"
],
"creditor" => [
"name" => "Example Supplier, s.r.o.",
"iban" => "SK3112000000198742637541",
"email" => "[email protected]"
],
"instructedAmount" => [
"value" => 12.5,
"currency" => "EUR"
],
"endToEndIdentification" => "/VS20261006/SS/KS",
"remittanceInformation" => "Invoice 2026-104"
]));
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Authorization: Bearer " . getenv("PAYOUT_TOKEN"), "Content-Type: application/json"]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"orderId": "3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d",
"status": "PDNG",
"statusDatetime": "2026-10-06T08:15:30.123456Z"
}Parameters
Your ID to match a request to its response. Echoed back in the correlation-id response header.
Your ID to group several requests into one process. Echoed back in the process-id response header.
Request body
Your identification of the instruction
Show 1 child attributeHide child attributes
Account to pay from (identification.identifier from List accounts)
Show 3 child attributesHide child attributes
Full name or company name of the creditor
IBAN of the creditor
E-mail address of the creditor
Show 2 child attributesHide child attributes
Amount with two decimals
ISO 4217 currency code
Your transaction reference. In the form /VS{variable symbol}/SS{specific symbol}/KS{constant symbol}, the variable symbol becomes the payment reference and must be numeric with at most 10 digits. This value, or instructionIdentification when it is empty, must not repeat across payments from the same account. Otherwise the submission is refused.
Description that appears on the creditor's statement, with only letters without accents, digits, spaces and /-?:().,'+. Creating the payment order accepts up to 255 characters, but its submission is refused when the text is longer than 140 characters or has other characters.
Response 201
Returns a PaymentOrder object.
Show 3 attributesHide attributes
Payment order ID
Status of the payment order
PDNGCreated, not submitted yetACSCSubmitted, payment createdRJCTSubmission refused (returned only by Submit payment order)
When the status was read
Other responses
The body is not valid JSON or a required attribute is missing.
Example
{
"errors": {
"message": "Bad request"
}
}Missing or invalid bearer token, or the token lacks the required scope.
Example
{
"status": 401,
"reason": "Unauthorized"
}No account has the identifier given in debtor.identifier.
Example
{
"errors": {
"message": "Resource not found"
}
}Submits a created payment order for execution. On success the payment order moves to status
ACSC.
Call it with a PISPSUBMIT token obtained for the payment order (see
Payment flow). The token identifies the payment order, so the request has no
body.
curl -X POST 'https://sandbox.payout.one/api/psd2/v1/payments/submission' \
-H "Authorization: Bearer $TOKEN"const res = await fetch("https://sandbox.payout.one/api/psd2/v1/payments/submission", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.PAYOUT_TOKEN}`,
},
});
const data = await res.json();import os, requests
res = requests.post(
"https://sandbox.payout.one/api/psd2/v1/payments/submission",
headers={"Authorization": f"Bearer {os.environ['PAYOUT_TOKEN']}"},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://sandbox.payout.one/api/psd2/v1/payments/submission");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "POST");
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Authorization: Bearer " . getenv("PAYOUT_TOKEN")]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"orderId": "3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d",
"status": "ACSC",
"statusDatetime": "2026-10-06T08:16:02.481530Z"
}Parameters
Your ID to match a request to its response. Echoed back in the correlation-id response header.
Your ID to group several requests into one process. Echoed back in the process-id response header.
Response 201
Returns a PaymentOrder object.
Show 3 attributesHide attributes
Payment order ID
Status of the payment order
PDNGCreated, not submitted yetACSCSubmitted, payment createdRJCTSubmission refused (returned only by Submit payment order)
When the status was read
Other responses
The payment order was already submitted. It is returned unchanged.
Example
{
"orderId": "3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d",
"status": "ACSC",
"statusDatetime": "2026-10-06T08:16:02.481530Z"
}The payment order was refused, for example because the available balance is too low or a field of the payment order breaks a rule given in its description. The body has status RJCT; its orderId is a newly generated UUID, not the ID of the submitted payment order.
Example
{
"orderId": "9d2c4f1a-6b3e-4c8d-a5f7-0e1b2c3d4e5f",
"status": "RJCT",
"statusDatetime": "2026-10-06T08:16:02.481530Z"
}Missing or invalid bearer token, or the token lacks the required scope.
Example
{
"status": 401,
"reason": "Unauthorized"
}Retrieves the current status of a payment order.
curl -X GET 'https://sandbox.payout.one/api/psd2/v1/payments/3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d/status' \
-H "Authorization: Bearer $TOKEN"const res = await fetch("https://sandbox.payout.one/api/psd2/v1/payments/3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d/status", {
method: "GET",
headers: {
Authorization: `Bearer ${process.env.PAYOUT_TOKEN}`,
},
});
const data = await res.json();import os, requests
res = requests.get(
"https://sandbox.payout.one/api/psd2/v1/payments/3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d/status",
headers={"Authorization": f"Bearer {os.environ['PAYOUT_TOKEN']}"},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://sandbox.payout.one/api/psd2/v1/payments/3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d/status");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "GET");
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Authorization: Bearer " . getenv("PAYOUT_TOKEN")]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"orderId": "3b0f6c2e-8d41-4a7b-9c55-1e2f3a4b5c6d",
"status": "PDNG",
"statusDatetime": "2026-10-06T08:15:30.123456Z"
}Parameters
Payment order ID, returned as orderId by Create payment order
Your ID to match a request to its response. Echoed back in the correlation-id response header.
Your ID to group several requests into one process. Echoed back in the process-id response header.
Response 200
Returns a PaymentOrder object.
Show 3 attributesHide attributes
Payment order ID
Status of the payment order
PDNGCreated, not submitted yetACSCSubmitted, payment createdRJCTSubmission refused (returned only by Submit payment order)
When the status was read
Other responses
order_id is not a UUID.
Example
{
"errors": {
"message": "Bad request"
}
}Missing or invalid bearer token, or the token lacks the required scope.
Example
{
"status": 401,
"reason": "Unauthorized"
}No payment order has this ID.
Example
{
"errors": {
"message": "Resource not found"
}
}Checks whether an account has enough available balance for an amount.
curl -X POST 'https://sandbox.payout.one/api/psd2/v1/accounts/balanceCheck' \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"instructionIdentification": "piisp-20261006-0001",
"identifier": "Q7v_K2mNp4Xs",
"amount": {
"amount": 6000,
"currency": "EUR"
}
}'const res = await fetch("https://sandbox.payout.one/api/psd2/v1/accounts/balanceCheck", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.PAYOUT_TOKEN}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
"instructionIdentification": "piisp-20261006-0001",
"identifier": "Q7v_K2mNp4Xs",
"amount": {
"amount": 6000,
"currency": "EUR"
}
}),
});
const data = await res.json();import os, requests
res = requests.post(
"https://sandbox.payout.one/api/psd2/v1/accounts/balanceCheck",
headers={"Authorization": f"Bearer {os.environ['PAYOUT_TOKEN']}"},
json={
"instructionIdentification": "piisp-20261006-0001",
"identifier": "Q7v_K2mNp4Xs",
"amount": {
"amount": 6000,
"currency": "EUR",
},
},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://sandbox.payout.one/api/psd2/v1/accounts/balanceCheck");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "POST");
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode([
"instructionIdentification" => "piisp-20261006-0001",
"identifier" => "Q7v_K2mNp4Xs",
"amount" => [
"amount" => 6000,
"currency" => "EUR"
]
]));
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Authorization: Bearer " . getenv("PAYOUT_TOKEN"), "Content-Type: application/json"]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"response": "APPR",
"dateTime": "2026-10-06T08:15:30.123456+00:00"
}Parameters
Your ID to match a request to its response. Echoed back in the correlation-id response header.
Your ID to group several requests into one process. Echoed back in the process-id response header.
Request body
Your technical identification of the request. Accepted but not evaluated.
When the request was created, in RFC 3339 format. Accepted but not evaluated.
Account identifier (identification.identifier from List accounts)
Show 2 child attributesHide child attributes
Amount to check, as an integer or a decimal string such as "60.50". Fractional JSON numbers are not accepted.
Show 0 child attributesHide child attributes
One of:
Option 1
integer
Option 2
string
ISO 4217 currency code
Response 200
Result of the check
APPRThe available balance incurrencyis greater thanamountDECLThe available balance is not greater thanamount, or the user's account has no balance incurrency
When the check was made, in RFC 3339 format
Other responses
The body is not valid JSON or a required attribute is missing.
Example
{
"errors": {
"message": "Bad request"
}
}Missing or invalid bearer token, or the token lacks the required scope.
Example
{
"status": 401,
"reason": "Unauthorized"
}- Need help? Contact support.
- Questions? Contact sales.
- Service status? status.payout.one.
- LLM? Read llms.txt.