# IBAN ownership verification

The Banklink API can verify that a user has access to a bank account and, when the bank provides the owner's name, that the user owns it. The user logs in to their bank and grants read-only access; Banklink then compares the account owner with the name you sent. Some banks do not provide the owner's name; for them, Banklink only verifies that the user has access to the account.

The endpoints are protected by [PayoutID](https://developers.payout.tech/guides/payout-id.html) and require the scope `VERIFY` (uppercase). Request the token with the client credentials grant. This is a different scope from the lowercase `verify` of PayoutID [identity verification](https://developers.payout.tech/guides/payout-id-identity-verification.html).

![Verify user using Banklink verification API](https://developers.payout.tech/_media/verification.svg)

1. **Create the verification.** Call [Create verification](https://developers.payout.tech/api/banklink.html#create_verification) with the `iban` and the user's `first_name` and `last_name`; without the names, ownership cannot be confirmed. The response contains the verification `id`, a `redirect_url` and the status `initialized`.
2. **Redirect the user.** Append the query parameter `redirect_uri` and, optionally, `state` to `redirect_url`, and send the user's browser there. `redirect_uri` must be one of the redirect URIs registered for your client.
3. **The user grants access.** The user logs in to their bank and gives read-only access to the account. Banklink then redirects the browser to your `redirect_uri` with your `state`. If something went wrong, the redirect also carries `error` and `errorDescription`.
4. **Get the result.** Call [Get verification status](https://developers.payout.tech/api/banklink.html#get_verification_status) with the verification `id` from step 1.

The verification ends in one of these statuses:

| Status | Meaning |
| --- | --- |
| `initialized` | The verification was created, but the user has not completed the bank login. A cancelled or failed login also leaves this status. |
| `verified_access` | The user accessed the account, but the bank does not provide the owner's name. |
| `verified_ownership` | The user accessed the account, and the owner's name provided by the bank matches the name you sent. |
| `unverified_ownership` | The user accessed the account, but the owner's name provided by the bank differs from the name you sent. |
| `unverified_access` | The user could not access the account. Currently not set: a failed login leaves the status `initialized`. |
| `error` | Communication with the bank failed. |
