Skip to main content
This page lists every endpoint your application needs to go live. Work through the sections in order - each section’s output feeds the next.
Base URL: https://{your-domain}.fincode.software/api/v6/services/Replace {your-domain} with the subdomain assigned to your organisation.

Step 1 - Customer Registration

Create a customer record. This is always the first call. The response returns a userId that all subsequent calls depend on.
Subscribe to our webhook notifications to receive real-time customer status updates.

Step 2 - Authentication

Obtain a session token. The token is valid for 50 minutes and is shared across all calls within the session.

Step 3 - KYC & Compliance

When a customer is registered, the platform automatically assigns KYC rules based on their risk profile. Call the checklist endpoint to find out what actions are outstanding before a transaction can be booked. From here, the flow depends on whether you are using the platform’s built-in KYC or your own external KYC provider.

Initiate each requirement

For each item returned by the compliance checklist, call the initiate endpoint. This triggers the action on the platform side and returns what you need to proceed.Replace {customer-kyc-record-id} with the ID from the checklist.

Fulfil each requirement

How each action is fulfilled depends on its type.
Handled automatically. When you call initiate, the platform sends a branded verification email to the customer. No further API call is needed from your side.
The platform sends an OTP to the customer via SMS when you call initiate. Your application collects the code from the customer and submits it.
Your application collects the document from the customer and submits it.Pass the associatedRuleId from the checklist item in the request body to link the document to the correct rule.
The initiation call automatically creates the eKYC session. Follow the flow returned in the initiate response to complete electronic identity verification.

Step 4 - Transaction Quote

Get a live exchange rate and fee breakdown before booking.

Step 5 - Beneficiary Management

Add and retrieve beneficiaries linked to a sender.

Step 6 - Book a Transfer

Both endpoints require an X-Idempotency-Key header to prevent duplicate bookings.
The X-Idempotency-Key must be a unique identifier per request. Subscribe to webhook notifications as an alternative to polling the status endpoint.

Step 7 - Pay for a Booked Transfer

Retrieve the available payment methods for a booked transfer and implement the chosen payment flow in your application. Card and Open Banking are both supported.
The X-Idempotency-Key must be a unique identifier per request. The pcn must match the one used in the booking call.

Step 8 - Check Transfer Status

Check the current status of a booked transfer by its reference number.
Subscribe to webhook notifications to receive automatic status updates without polling.

AML Compliance

AML checks run at the point of transaction. Any outstanding requirements must be resolved before the transaction can complete. Submit AML-required documents using the same endpoint as KYC documents. Pass the associatedRuleId from the outstanding requirement in the request body.

Supported KYC Providers

Applies to integrations using your own KYC provider. The following providers are currently supported. Your chosen provider must be configured in your agent plugin settings before use.

Technical requirements

Your provider must meet all of the following before we can accept their results:
  • ID document verification: must be capable of verifying government-issued identity documents (passport, national ID, driving licence).
  • Liveness check (face match): must perform a biometric face match between the document photo and a live selfie or video capture.
  • Webhook callback support: must be able to send a webhook to our system when verification is complete.
  • Correlation ID embedding: must accept and return a reference ID in the webhook payload so the platform can tie the result back to the correct customer record.
  • Structured result payload: the webhook payload must include verification outcome, document details, and any AML/sanctions/PEP screening results in a structured, parseable format.

Summary

1

Register the sender

POST usermanagement/register-customer
2

Authenticate

PUT securitymanagement/login
3

Complete KYC & compliance

Built-in KYC: initiate each requirement then fulfil it. Your own KYC provider: register the session, configure the webhook, initiate with your provider, and listen for COMPLIANCE_RISK_PROFILE_UPDATED.
4

Get a quote

GET services/quote/callQuote
5

Add a beneficiary

POST usermanagement/new-beneficiary
6

Book the transfer

POST transactionmanagement/create-transaction
7

Process payment

POST paymentmanagement/supported-payment-methods
8

Resolve any AML requirements

POST documentmanagement/attach-documents
9

Track status

Poll checktransactionstatus or subscribe to webhooks