Base URL:
https://{your-domain}.fincode.software/api/v6/services/Replace {your-domain} with the subdomain assigned to your organisation.Step 1 - Customer Registration
Create a customer record. This is always the first call. The response returns auserId that all subsequent calls depend on.
Subscribe to our webhook notifications to receive real-time customer status updates.
Step 2 - Authentication
Obtain a session token. The token is valid for 50 minutes and is shared across all calls within the session.Step 3 - KYC & Compliance
When a customer is registered, the platform automatically assigns KYC rules based on their risk profile. Call the checklist endpoint to find out what actions are outstanding before a transaction can be booked.
From here, the flow depends on whether you are using the platform’s built-in KYC or your own external KYC provider.
- Using built-in KYC
- Using your own KYC provider
Initiate each requirement
For each item returned by the compliance checklist, call the initiate endpoint. This triggers the action on the platform side and returns what you need to proceed.Replace
{customer-kyc-record-id} with the ID from the checklist.Fulfil each requirement
How each action is fulfilled depends on its type.Email verification
Email verification
Handled automatically. When you call initiate, the platform sends a branded verification email to the customer. No further API call is needed from your side.
Phone OTP
Phone OTP
The platform sends an OTP to the customer via SMS when you call initiate. Your application collects the code from the customer and submits it.
Document upload (Proof of Address, ID, Source of Funds)
Document upload (Proof of Address, ID, Source of Funds)
Your application collects the document from the customer and submits it.
Pass the
associatedRuleId from the checklist item in the request body to link the document to the correct rule.eKYC (electronic identity verification)
eKYC (electronic identity verification)
The initiation call automatically creates the eKYC session. Follow the flow returned in the initiate response to complete electronic identity verification.
Step 4 - Transaction Quote
Get a live exchange rate and fee breakdown before booking.Step 5 - Beneficiary Management
Add and retrieve beneficiaries linked to a sender.Step 6 - Book a Transfer
Both endpoints require anX-Idempotency-Key header to prevent duplicate bookings.
Step 7 - Pay for a Booked Transfer
Retrieve the available payment methods for a booked transfer and implement the chosen payment flow in your application. Card and Open Banking are both supported.The
X-Idempotency-Key must be a unique identifier per request. The pcn must match the one used in the booking call.Step 8 - Check Transfer Status
Check the current status of a booked transfer by its reference number.Subscribe to webhook notifications to receive automatic status updates without polling.
AML Compliance
AML checks run at the point of transaction. Any outstanding requirements must be resolved before the transaction can complete. Submit AML-required documents using the same endpoint as KYC documents. Pass theassociatedRuleId from the outstanding requirement in the request body.
Supported KYC Providers
Applies to integrations using your own KYC provider. The following providers are currently supported. Your chosen provider must be configured in your agent plugin settings before use.Technical requirements
Your provider must meet all of the following before we can accept their results:- ID document verification: must be capable of verifying government-issued identity documents (passport, national ID, driving licence).
- Liveness check (face match): must perform a biometric face match between the document photo and a live selfie or video capture.
- Webhook callback support: must be able to send a webhook to our system when verification is complete.
- Correlation ID embedding: must accept and return a reference ID in the webhook payload so the platform can tie the result back to the correct customer record.
- Structured result payload: the webhook payload must include verification outcome, document details, and any AML/sanctions/PEP screening results in a structured, parseable format.
Summary
1
Register the sender
POST usermanagement/register-customer2
Authenticate
PUT securitymanagement/login3
Complete KYC & compliance
Built-in KYC: initiate each requirement then fulfil it. Your own KYC provider: register the session, configure the webhook, initiate with your provider, and listen for
COMPLIANCE_RISK_PROFILE_UPDATED.4
Get a quote
GET services/quote/callQuote5
Add a beneficiary
POST usermanagement/new-beneficiary6
Book the transfer
POST transactionmanagement/create-transaction7
Process payment
POST paymentmanagement/supported-payment-methods8
Resolve any AML requirements
POST documentmanagement/attach-documents9
Track status
Poll
checktransactionstatus or subscribe to webhooks