Payout Banklink API
PSD2 API aggregator and more.
Authentication
This API can be accessed on behalf of a user with an OAuth2 access token issued by
Payout ID. Supported grant flows are authorization_code and client_credentials.
Send the token in the Authorization: Bearer <access_token> header.
| Environment | Authorization endpoint | Token endpoint |
|---|---|---|
| Sandbox | https:// |
https:// |
| Production | https:// |
https:// |
Integrator can use these scopes:
| scope | description | endpoints |
|---|---|---|
| BLAISP | scope for reading details of user bank account | List accounts, Account Details, Account Information, Retrieve account balance, Consent Accounts, / |
| BLIBAN | to verify that currently authorized user has access to bank account | Verify IBAN |
| BLPISP | to create payment on behalf of current user | Payment initialisation, Payment status |
| VERIFY | to verify user identity, retrieved using the client_credentials flow |
Create Verification, Get Verification Status |
List Integrations requires a valid access token but no specific scope.
A missing, invalid or expired token, or a token without the required scope, is rejected
with 403 and error code UNAUTHORIZED.
Authorizing access to the bank account
When the requested account is not connected yet, or its authorization at the bank has
expired, account endpoints respond with 403 and a body containing consent_id and
redirect_url. Redirect the user to redirect_url and add the query parameters
redirect_uri (one of the redirect URIs registered for your application) and optionally
state. The same applies to _links.sca.href returned by Payment initialisation and to
redirect_url returned by Create Verification. After the user authorized access at the
bank, he is redirected back to redirect_uri together with state.
Errors
API uses HTTP response codes.
| Code | Description |
|---|---|
| 400 | Bad request |
| 401 | Unauthorized |
| 403 | Forbidden |
| 404 | Not Found |
| 500 | Internal Server Error |
Errors are returned in a tppMessages array:
{
"tppMessages": [
{
"category": "ERROR",
"code": "INVALID_INPUT",
"text": "Unsupported IBAN country",
"xpath": "/debtorAccount/iban"
}
]
}
xpath is present only for validation errors (INVALID_INPUT).
| HTTP | code | meaning |
|---|---|---|
| 400 | INVALID_REQUEST | Missing or invalid header or body |
| 400 | INVALID_INPUT | A request body field failed validation, see xpath |
| 400 | UNSUPPORTED_BANK | Bank could not be recognised from iban and bank |
| 400 | INVALID_PAYMENT_PRODUCT | Unknown payment_product path parameter |
| 401 | INVALID_TOKEN | Token does not identify the application (aud, auu claims) |
| 403 | UNAUTHORIZED | Missing, invalid or expired token, or missing scope |
| 500 | INTERNAL_SERVER_ERROR | Unexpected bank response or internal error |
A 403 returned by an account endpoint can instead contain consent_id and
redirect_url: the user has to authorize access to the account first, see
Authentication. Unknown payment in Payment status returns 404 with body
{"errors": {"detail": "Not Found"}}.
Retrieve current user connected accounts. Data are returned from Banklink, the bank is not called.
Responses
200 Success
| name | example | description |
|---|---|---|
| accounts[]/ |
SK3112000000198742637541 | IBAN of retrieved account |
| accounts[]/ |
common | Name of account |
| accounts[]/ |
EUR | - |
| accounts[]/ |
tatrabanka | Name of bank servicing the account |
Response 200
SK3112000000198742637541commonEURtatrabankaOther responses
UNAUTHORIZED)curl -X POST 'https://wap-sa.payout.one/api/v1/accounts' \
-H "Authorization: Bearer $TOKEN"const res = await fetch("https://wap-sa.payout.one/api/v1/accounts", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.PAYOUT_TOKEN}`,
},
});
const data = await res.json();import os, requests
res = requests.post(
"https://wap-sa.payout.one/api/v1/accounts",
headers={"Authorization": f"Bearer {os.environ['PAYOUT_TOKEN']}"},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://wap-sa.payout.one/api/v1/accounts");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "POST");
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Authorization: Bearer " . getenv("PAYOUT_TOKEN")]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"accounts": [
{
"identification": {
"iban": "SK3112000000198742637541"
},
"name": "common",
"baseCurrency": "EUR",
"providerName": "tatrabanka"
}
]
}Retrieve current user account balance directly from bank.
Response in case of unexpired connected account
Body parameters
| name | description |
|---|---|
| balances[]/ |
Balance of account |
| balances[]/ |
Currency of this balance from ISO 4217 |
| balances[]/ |
Balance type in ISO 20022 |
| balances[]/ |
CRDT if it is credit, else DBIT |
| balances[]/ |
Date and time of account balance check in RFC3339 |
Response in case of expired/unknown account
Status 403.
| name | description |
|---|---|
| consent_id | Consent id, can be used with Consent Accounts after user authorization |
| redirect_url | Redirect url to use to redirect user to authorize access to account |
Parameters
true or false (default)Request body
SK3112000000198742637541name from List Integrations, for IBANs whose bank cannot be recognised from IBAN alone · e.g. tatrabankaResponse 200
1520.35EURITAVCRDT, DBIT · e.g. CRDT2026-10-06T08:00:00+00:00Other responses
INVALID_REQUEST), or bank could not be recognised (UNSUPPORTED_BANK)redirect_url to authorize access to account. Also returned with UNAUTHORIZED error for a missing, invalid or expired access token, or missing scope.INTERNAL_SERVER_ERROR)curl -X POST 'https://wap-sa.payout.one/api/v1/accounts/balance' \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"iban": "SK3112000000198742637541"
}'const res = await fetch("https://wap-sa.payout.one/api/v1/accounts/balance", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.PAYOUT_TOKEN}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
"iban": "SK3112000000198742637541"
}),
});
const data = await res.json();import os, requests
res = requests.post(
"https://wap-sa.payout.one/api/v1/accounts/balance",
headers={"Authorization": f"Bearer {os.environ['PAYOUT_TOKEN']}"},
json={
"iban": "SK3112000000198742637541",
},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://wap-sa.payout.one/api/v1/accounts/balance");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "POST");
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode([
"iban" => "SK3112000000198742637541"
]));
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Authorization: Bearer " . getenv("PAYOUT_TOKEN"), "Content-Type: application/json"]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"balances": [
{
"amount": {
"value": 1520.35,
"currency": "EUR"
},
"type": "ITAV",
"creditDebitIndicator": "CRDT",
"dateTime": "2026-10-06T08:00:00+00:00"
}
]
}Verify that current user has access to account with specified IBAN.
Response in case of unexpired connected account
Body parameters
| name | description |
|---|---|
| iban | IBAN for which was verification requested |
| verified | Constant true |
Response in case of expired/unknown account
Status 403.
Body parameters
| name | description |
|---|---|
| consent_id | Consent id |
| redirect_url | Url to redirect user to authorize access to account |
Parameters
true or false (default)Request body
SK3112000000198742637541name from List Integrations, for IBANs whose bank cannot be recognised from IBAN alone · e.g. tatrabankaResponse 200
SK3112000000198742637541trueOther responses
INVALID_REQUEST), or bank could not be recognised (UNSUPPORTED_BANK)redirect_url to authorize access to account. Also returned with UNAUTHORIZED error for a missing, invalid or expired access token, or missing scope.INTERNAL_SERVER_ERROR)curl -X POST 'https://wap-sa.payout.one/api/v1/accounts/verify-iban' \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"iban": "SK3112000000198742637541"
}'const res = await fetch("https://wap-sa.payout.one/api/v1/accounts/verify-iban", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.PAYOUT_TOKEN}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
"iban": "SK3112000000198742637541"
}),
});
const data = await res.json();import os, requests
res = requests.post(
"https://wap-sa.payout.one/api/v1/accounts/verify-iban",
headers={"Authorization": f"Bearer {os.environ['PAYOUT_TOKEN']}"},
json={
"iban": "SK3112000000198742637541",
},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://wap-sa.payout.one/api/v1/accounts/verify-iban");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "POST");
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode([
"iban" => "SK3112000000198742637541"
]));
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Authorization: Bearer " . getenv("PAYOUT_TOKEN"), "Content-Type: application/json"]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"iban": "SK3112000000198742637541",
"verified": true
}Retrieve details of user account identified by IBAN
For expired/unknown account the response is 403 with consent_id and redirect_url.
Parameters
true or false (default)Request body
SK3112000000198742637541name from List Integrations, for IBANs whose bank cannot be recognised from IBAN alone · e.g. tatrabankaResponse 200
SK3112000000198742637541commonsuperaccountCACCEUR2026-12-31T08:37:51+00:00Other responses
INVALID_REQUEST), or bank could not be recognised (UNSUPPORTED_BANK)redirect_url to authorize access to account. Also returned with UNAUTHORIZED error for a missing, invalid or expired access token, or missing scope.INTERNAL_SERVER_ERROR)curl -X POST 'https://wap-sa.payout.one/api/v1/accounts/details' \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"iban": "SK3112000000198742637541"
}'const res = await fetch("https://wap-sa.payout.one/api/v1/accounts/details", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.PAYOUT_TOKEN}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
"iban": "SK3112000000198742637541"
}),
});
const data = await res.json();import os, requests
res = requests.post(
"https://wap-sa.payout.one/api/v1/accounts/details",
headers={"Authorization": f"Bearer {os.environ['PAYOUT_TOKEN']}"},
json={
"iban": "SK3112000000198742637541",
},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://wap-sa.payout.one/api/v1/accounts/details");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "POST");
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode([
"iban" => "SK3112000000198742637541"
]));
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Authorization: Bearer " . getenv("PAYOUT_TOKEN"), "Content-Type: application/json"]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"identification": {
"iban": "SK3112000000198742637541"
},
"name": "common",
"productName": "superaccount",
"type": "CACC",
"baseCurrency": "EUR",
"authorizationExpiration": "2026-12-31T08:37:51+00:00"
}Retrieve list of accounts by consent id, which is returned during user authorization
Each item of accounts has the same fields as the Account Details response.
Parameters
true or false (default)Request body
consent_id when user authorization was requested · e.g. 123Response 200
SK3112000000198742637541commonsuperaccountCACCEUR2026-12-31T08:37:51+00:00Other responses
consent_id or unknown consent (INVALID_REQUEST)redirect_url to authorize access to account. Also returned with UNAUTHORIZED error for a missing, invalid or expired access token, or missing scope.INTERNAL_SERVER_ERROR)curl -X POST 'https://wap-sa.payout.one/api/v1/provider/accounts' \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"consent_id": 123
}'const res = await fetch("https://wap-sa.payout.one/api/v1/provider/accounts", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.PAYOUT_TOKEN}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
"consent_id": 123
}),
});
const data = await res.json();import os, requests
res = requests.post(
"https://wap-sa.payout.one/api/v1/provider/accounts",
headers={"Authorization": f"Bearer {os.environ['PAYOUT_TOKEN']}"},
json={
"consent_id": 123,
},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://wap-sa.payout.one/api/v1/provider/accounts");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "POST");
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode([
"consent_id" => 123
]));
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Authorization: Bearer " . getenv("PAYOUT_TOKEN"), "Content-Type: application/json"]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"accounts": [
{
"identification": {
"iban": "SK3112000000198742637541"
},
"name": "common",
"productName": "superaccount",
"type": "CACC",
"baseCurrency": "EUR",
"authorizationExpiration": "2026-12-31T08:37:51+00:00"
}
]
}Retrieve current user account information and balances
account has the same fields as the Account Details response. Each item of balances has
amount/value, amount/currency, creditDebitIndicator and dateTime as described in
Retrieve account balance.
For expired/unknown account the response is 403 with consent_id and redirect_url.
Parameters
true or false (default)Request body
SK3112000000198742637541name from List Integrations, for IBANs whose bank cannot be recognised from IBAN alone · e.g. tatrabankaResponse 200
SK3112000000198742637541commonsuperaccountCACCEUR2026-12-31T08:37:51+00:001520.35EURCRDT, DBIT · e.g. CRDT2026-10-06T08:00:00+00:00Other responses
INVALID_REQUEST), or bank could not be recognised (UNSUPPORTED_BANK)redirect_url to authorize access to account. Also returned with UNAUTHORIZED error for a missing, invalid or expired access token, or missing scope.INTERNAL_SERVER_ERROR)curl -X POST 'https://wap-sa.payout.one/api/v1/accounts/information' \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"iban": "SK3112000000198742637541"
}'const res = await fetch("https://wap-sa.payout.one/api/v1/accounts/information", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.PAYOUT_TOKEN}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
"iban": "SK3112000000198742637541"
}),
});
const data = await res.json();import os, requests
res = requests.post(
"https://wap-sa.payout.one/api/v1/accounts/information",
headers={"Authorization": f"Bearer {os.environ['PAYOUT_TOKEN']}"},
json={
"iban": "SK3112000000198742637541",
},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://wap-sa.payout.one/api/v1/accounts/information");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "POST");
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode([
"iban" => "SK3112000000198742637541"
]));
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Authorization: Bearer " . getenv("PAYOUT_TOKEN"), "Content-Type: application/json"]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"account": {
"identification": {
"iban": "SK3112000000198742637541"
},
"name": "common",
"productName": "superaccount",
"type": "CACC",
"baseCurrency": "EUR",
"authorizationExpiration": "2026-12-31T08:37:51+00:00"
},
"balances": [
{
"amount": {
"value": 1520.35,
"currency": "EUR"
},
"creditDebitIndicator": "CRDT",
"dateTime": "2026-10-06T08:00:00+00:00"
}
]
}Payment initialisation request. Access token for this request requires BLPISP OAuth scope.
Redirect the user to _links.sca.href to authorize the payment, see Authentication.
Responses
201 Created
| name | example | description |
|---|---|---|
| paymentId | 123 | Id of created payment |
| _links/ |
https:// |
HATEOAS link containing redirect to authorize user |
400 Invalid input parameter
| name | example | description |
|---|---|---|
| tppMessages[]/ |
ERROR | Message category, only error is supported for now |
| tppMessages[]/ |
INVALID_INPUT | Kind of error that happened |
| tppMessages[]/ |
Unsupported IBAN country | |
| tppMessages[]/ |
/ |
XPath to field where error happened (optional) |
Parameters
name of an integration from List Integrations, for example tatrabanka, vub, slsp, unicredit, csob, csas, fio, komercni-banka, csob-cz.sepa-credit-transfers (sepa in supported_payment_methods of List Integrations) or instant-sepa-credit-transfers (sepa_ipay). one of sepa-credit-transfers, instant-sepa-credit-transfersRequest body
/VS…/SS…/KS… it is split to variable, specific and constant symbol · max 35 · e.g. /VS1/SS2/KS3COBADEFFXXXJohn Doepayout integration · max 254 · e.g. john.doe@example.comTest TestovicTestingcsob-cz for business customersSK3112000000198742637541DE893704004405320130001.00EUR, CZK · e.g. EURResponse 201
123https://wap-sa.payout.one/providers/forward/Xk7pQ2Other responses
INVALID_INPUT with xpath, or INVALID_PAYMENT_PRODUCT)UNAUTHORIZED)curl -X POST 'https://wap-sa.payout.one/api/v1/payments/{integration}/{payment_product}' \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"endToEndIndentification": "/VS1/SS2/KS3",
"creditorAgent": "COBADEFFXXX",
"creditorName": "John Doe",
"debtorName": "Test Testovic",
"remittanceInformationUnstructured": "Testing",
"debtorAccount": {
"iban": "SK3112000000198742637541"
},
"creditorAccount": {
"iban": "DE89370400440532013000"
},
"instructedAmount": {
"amount": "1.00",
"currency": "EUR"
}
}'const res = await fetch("https://wap-sa.payout.one/api/v1/payments/{integration}/{payment_product}", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.PAYOUT_TOKEN}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
"endToEndIndentification": "/VS1/SS2/KS3",
"creditorAgent": "COBADEFFXXX",
"creditorName": "John Doe",
"debtorName": "Test Testovic",
"remittanceInformationUnstructured": "Testing",
"debtorAccount": {
"iban": "SK3112000000198742637541"
},
"creditorAccount": {
"iban": "DE89370400440532013000"
},
"instructedAmount": {
"amount": "1.00",
"currency": "EUR"
}
}),
});
const data = await res.json();import os, requests
res = requests.post(
"https://wap-sa.payout.one/api/v1/payments/{integration}/{payment_product}",
headers={"Authorization": f"Bearer {os.environ['PAYOUT_TOKEN']}"},
json={
"endToEndIndentification": "/VS1/SS2/KS3",
"creditorAgent": "COBADEFFXXX",
"creditorName": "John Doe",
"debtorName": "Test Testovic",
"remittanceInformationUnstructured": "Testing",
"debtorAccount": {
"iban": "SK3112000000198742637541",
},
"creditorAccount": {
"iban": "DE89370400440532013000",
},
"instructedAmount": {
"amount": "1.00",
"currency": "EUR",
},
},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://wap-sa.payout.one/api/v1/payments/{integration}/{payment_product}");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "POST");
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode([
"endToEndIndentification" => "/VS1/SS2/KS3",
"creditorAgent" => "COBADEFFXXX",
"creditorName" => "John Doe",
"debtorName" => "Test Testovic",
"remittanceInformationUnstructured" => "Testing",
"debtorAccount" => [
"iban" => "SK3112000000198742637541"
],
"creditorAccount" => [
"iban" => "DE89370400440532013000"
],
"instructedAmount" => [
"amount" => "1.00",
"currency" => "EUR"
]
]));
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Authorization: Bearer " . getenv("PAYOUT_TOKEN"), "Content-Type: application/json"]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"paymentId": 123,
"_links": {
"sca": {
"href": "https://wap-sa.payout.one/providers/forward/Xk7pQ2"
}
}
}Retrieve actual status of payment.
Responses
200 Success
| name | example | description |
|---|---|---|
| paymentId | 123 | Id of requested payment |
| transactionStatus | pending | Status of the payment, described in following table |
Payment statuses
| value | description |
|---|---|
| pending | payment created in Banklink but not yet posted to bank |
| initialized | payment posted to bank, but not yet validated |
| received | payment was validated as technically correct by bank |
| accepted | bank accepted payment as valid, is signed by user and waiting to be processed |
| unknown | payment was signed, but we were unable to check it's status after that |
| completed | payment was successfully processed |
| rejected | payment is invalid or declined by user |
404 Not Found
Parameters
Response 200
123pending, initialized, received, accepted, unknown, completed, rejected · e.g. pendingOther responses
UNAUTHORIZED)curl -X GET 'https://wap-sa.payout.one/api/v1/payments/{payment_id}/status' \
-H "Authorization: Bearer $TOKEN"const res = await fetch("https://wap-sa.payout.one/api/v1/payments/{payment_id}/status", {
method: "GET",
headers: {
Authorization: `Bearer ${process.env.PAYOUT_TOKEN}`,
},
});
const data = await res.json();import os, requests
res = requests.get(
"https://wap-sa.payout.one/api/v1/payments/{payment_id}/status",
headers={"Authorization": f"Bearer {os.environ['PAYOUT_TOKEN']}"},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://wap-sa.payout.one/api/v1/payments/{payment_id}/status");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "GET");
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Authorization: Bearer " . getenv("PAYOUT_TOKEN")]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"paymentId": 123,
"transactionStatus": "pending"
}List of bank integrations. name is the value to use as bank in account requests and as integration in Payment initialisation.
Response 200 (array)
tatrabankatruetruepisp is true. sepa stands for sepa-credit-transfers, sepa_ipay for instant-sepa-credit-transfersOther responses
UNAUTHORIZED)curl -X GET 'https://wap-sa.payout.one/api/v1/integrations' \
-H "Authorization: Bearer $TOKEN"const res = await fetch("https://wap-sa.payout.one/api/v1/integrations", {
method: "GET",
headers: {
Authorization: `Bearer ${process.env.PAYOUT_TOKEN}`,
},
});
const data = await res.json();import os, requests
res = requests.get(
"https://wap-sa.payout.one/api/v1/integrations",
headers={"Authorization": f"Bearer {os.environ['PAYOUT_TOKEN']}"},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://wap-sa.payout.one/api/v1/integrations");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "GET");
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Authorization: Bearer " . getenv("PAYOUT_TOKEN")]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);[
{
"name": "payout",
"aisp": true,
"pisp": true,
"supported_payment_methods": [
"sepa"
]
},
{
"name": "tatrabanka",
"aisp": true,
"pisp": true,
"supported_payment_methods": [
"sepa",
"sepa_ipay"
]
}
]Verify user identity using PSD2 APIs. Requires VERIFY scope that can be retrieved using client credentials flow from Payout ID.
Redirect the user to the returned redirect_url, see Authentication. The result can then be retrieved with Get Verification Status.
Request body
CZ6508000000192000145399JanNovákname from List Integrations, for IBANs whose bank cannot be recognised from IBAN alone · e.g. csasResponse 200
3f1c9a52-7d4e-4b8a-9c21-5e6f7a8b9c0dhttps://wap-sa.payout.one/providers/forward/Xk7pQ2initialized, verified_access, verified_ownership, unverified_access, unverified_ownership, error · e.g. initializedOther responses
INVALID_INPUT with xpath)UNAUTHORIZED)curl -X POST 'https://wap-sa.payout.one/api/v1/verifications' \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"iban": "CZ6508000000192000145399",
"first_name": "Jan",
"last_name": "Novák"
}'const res = await fetch("https://wap-sa.payout.one/api/v1/verifications", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.PAYOUT_TOKEN}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
"iban": "CZ6508000000192000145399",
"first_name": "Jan",
"last_name": "Novák"
}),
});
const data = await res.json();import os, requests
res = requests.post(
"https://wap-sa.payout.one/api/v1/verifications",
headers={"Authorization": f"Bearer {os.environ['PAYOUT_TOKEN']}"},
json={
"iban": "CZ6508000000192000145399",
"first_name": "Jan",
"last_name": "Novák",
},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://wap-sa.payout.one/api/v1/verifications");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "POST");
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode([
"iban" => "CZ6508000000192000145399",
"first_name" => "Jan",
"last_name" => "Nov\u00e1k"
]));
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Authorization: Bearer " . getenv("PAYOUT_TOKEN"), "Content-Type: application/json"]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"id": "3f1c9a52-7d4e-4b8a-9c21-5e6f7a8b9c0d",
"redirect_url": "https://wap-sa.payout.one/providers/forward/Xk7pQ2",
"status": "initialized"
}Verification status can be one of:
initialized- verification was created but user was not yet redirected for verificationverified_access- user managed to provide credentials for account, but bank servicing that account is not providing ownership informationverified_ownership- user managed to login and account servicer provided ownership information which also matched name of the userunverified_access- user failed to provide credentials to access accountunverified_ownership- user provided credentials to access account but ownership details were different from provided user detailserror- error during communication between us and account servicer
Only verifications created by the same application can be retrieved.
Parameters
Response 200
initialized, verified_access, verified_ownership, unverified_access, unverified_ownership, error · e.g. initializedOther responses
UNSUPPORTED_BANK)UNAUTHORIZED)curl -X GET 'https://wap-sa.payout.one/api/v1/verifications/{verification_id}' \
-H "Authorization: Bearer $TOKEN"const res = await fetch("https://wap-sa.payout.one/api/v1/verifications/{verification_id}", {
method: "GET",
headers: {
Authorization: `Bearer ${process.env.PAYOUT_TOKEN}`,
},
});
const data = await res.json();import os, requests
res = requests.get(
"https://wap-sa.payout.one/api/v1/verifications/{verification_id}",
headers={"Authorization": f"Bearer {os.environ['PAYOUT_TOKEN']}"},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://wap-sa.payout.one/api/v1/verifications/{verification_id}");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "GET");
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Authorization: Bearer " . getenv("PAYOUT_TOKEN")]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"status": "initialized"
}Retrieve current user transactions directly from bank. Up to 100 transactions are returned per page.
Body parameters
| name | required | description |
|---|---|---|
| iban | true | - |
| bank | false | Optional name of bank, integration name from List Integrations |
| page_index | false | Parameter to be used if we want to visit next or previous page, it can be filled from next_page/ |
| date_from | false | Does not return transaction older than this, default is 90 days ago |
| date_to | false | Does not return transactions newer than this, default is end of today |
Response in case of unexpired connected account
Body parameters
| name | description |
|---|---|
| pagination/ |
Next page index |
| pagination/ |
Previous page index |
| transactions[]/ |
Amount in transaction |
| transactions[]/ |
Currency of transactions |
| transactions[]/ |
The Date at which assets become available to the account owner in case of a credit |
| transactions[]/ |
The Date when an entry is posted to an account on the ASPSPs books. |
| transactions[]/ |
Indication of credit or debit, CRDT or DBIT respectiveli |
| transactions[]/ |
ISO20022 bank transaction code |
| transactions[]/ |
Whatever this transaction is reveresal for previous one |
| transactions[]/ |
Unique transaction id generated by ASPSP |
| transactions[]/ |
The unique identifier of the transaction generated by a bank that it should be considered as a bank reference |
| transactions[]/ |
For card transactions, this is the card number in format ** 1111. |
| transactions[]/ |
Numberic value of amount as fractional number |
| transactions[]/ |
Alphabetic code from ISO 4217 |
| transactions[]/ |
Fraction as exchange rate for transaction |
| transactions[]/ |
Debtor account |
| transactions[]/ |
Unique identificator of debtor account, usually IBAN |
| transactions[]/ |
Creditor account |
| transactions[]/ |
Creditor account unique identificator, usualy IBAN |
| transactions[]/ |
Name of third party, in case of card transactions it is merchant |
| transactions[]/ |
Identification of bank managing debtor account, usually BIC |
| transactions[]/ |
Identification of bank managing creditor account, usually BIC |
| transactions[]/ |
The text aimed as the information for a receiver of the transaction. |
Response in case of expired/unknown account
Status 403.
Body parameters
| name | description |
|---|---|
| consent_id | Consent id |
| redirect_url | Url to redirect user to authorize access to account |
Parameters
true or false (default)Request body
SK3112000000198742637541name from List Integrations, for IBANs whose bank cannot be recognised from IBAN alone · e.g. tatrabankaxAffr341542023-01-052023-01-10Response 200
zxQewRtveXyg1123zseaR12.50EUR2026-09-142026-09-14CRDT, DBIT · e.g. CRDTOther responses
INVALID_REQUEST), or bank could not be recognised (UNSUPPORTED_BANK)redirect_url to authorize access to account. Also returned with UNAUTHORIZED error for a missing, invalid or expired access token, or missing scope.INTERNAL_SERVER_ERROR)curl -X POST 'https://wap-sa.payout.one/api/v1/transactions' \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"iban": "SK3112000000198742637541",
"page_index": "xAffr34154",
"date_from": "2023-01-05",
"date_to": "2023-01-10"
}'const res = await fetch("https://wap-sa.payout.one/api/v1/transactions", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.PAYOUT_TOKEN}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
"iban": "SK3112000000198742637541",
"page_index": "xAffr34154",
"date_from": "2023-01-05",
"date_to": "2023-01-10"
}),
});
const data = await res.json();import os, requests
res = requests.post(
"https://wap-sa.payout.one/api/v1/transactions",
headers={"Authorization": f"Bearer {os.environ['PAYOUT_TOKEN']}"},
json={
"iban": "SK3112000000198742637541",
"page_index": "xAffr34154",
"date_from": "2023-01-05",
"date_to": "2023-01-10",
},
)
data = res.json()<?php
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, "https://wap-sa.payout.one/api/v1/transactions");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "POST");
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode([
"iban" => "SK3112000000198742637541",
"page_index" => "xAffr34154",
"date_from" => "2023-01-05",
"date_to" => "2023-01-10"
]));
curl_setopt($ch, CURLOPT_HTTPHEADER, ["Authorization: Bearer " . getenv("PAYOUT_TOKEN"), "Content-Type: application/json"]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);{
"pagination": {
"next_page": "zxQewRtveXy",
"previous_page": "g1123zseaR"
},
"transactions": [
{
"amount": {
"value": "12.50",
"currency": "EUR"
},
"valueDate": "2026-09-14",
"bookingDate": "2026-09-14",
"creditDebitIndicator": "CRDT"
}
]
}- Need help? Contact support.
- Questions? Contact sales.
- Service status? status.payout.one.
- LLM? Read llms.txt.