Quickstart
Base URL https://api.bank-core.org. TLS only; there is no listener on port 80. There is no sandbox: the first integration runs in production with a small real balance.
1. Get access
Access is set up by the Bank Core team: your tenant, the networks and the products you use, and the setup below.
2. Send the setup details
| Item | Why |
|---|---|
| Egress IP addresses | The API answers only listed addresses, whatever key is presented. Tell us before they change |
| HTTPS webhook URL | Where events are delivered. Without one you poll GET /v1/events |
| P-256 public key, DER, base64 | For signed requests on payouts. The public key only |
| Addresses to watch, or an xpub and an index range | For deposit detection |
| Addresses you will top up your payout wallet from | Verified before your first transfer, including a test one. See Payouts |
| Volumes | Deposits and new addresses a day, largest single payout, daily payout total. Your limits are set from these |
We never ask for a private key, a seed phrase or an xpub's private counterpart.
3. Receive your keys
Each key is shown once and cannot be retrieved again; we keep only its hash. A key carries exactly the scopes it needs, and money-moving jobs get their own key. See Authentication.
4. First calls
GET /v1/whoami
Authorization: Bearer <your key>
Answers your tenant, the key's scopes, and payout_wallets: a map of network to the address of your payout wallet. Call it once per key per process and check the tenant before you send anything with that key.
Then, depending on what you use:
| Call | Confirms |
|---|---|
GET /v1/limits | The rate limits and money limits applied to this key |
GET /v1/fees | Your fee schedule |
POST /v1/deposit-addresses | Address registration works |
GET /v1/deposits?after=0 | Arrivals are visible |
GET /v1/events?after=0 | The event cursor works |
GET /v1/float | Your balance |
GET /v1/chain-payouts/estimate | A payout can be priced before it is sent |
POST /v1/chain-payouts | The full payout path. This moves real money |
Conventions
- Amounts are canonical decimal strings with no trailing zeros:
"1000","12.5". Parse them as decimals; never compare the strings. Most amounts are an object,{"amount": "...", "currency": "..."}. - Currency codes name the chain.
USDT_TRC20andUSDT_ERC20are different balances. - Timestamps are RFC 3339 in UTC.
nullis not zero. A value we could not read or were not told isnull, usually with a reason next to it.X-Request-Idis returned on every response. Send your own and it is kept; quote it when you report a problem.- Errors share one envelope. Branch on
error.code, never on the HTTP status. See Errors.