Quickstart

Base URL https://api.bank-core.org. TLS only; there is no listener on port 80. There is no sandbox: the first integration runs in production with a small real balance.

1. Get access

Access is set up by the Bank Core team: your tenant, the networks and the products you use, and the setup below.

2. Send the setup details

ItemWhy
Egress IP addressesThe API answers only listed addresses, whatever key is presented. Tell us before they change
HTTPS webhook URLWhere events are delivered. Without one you poll GET /v1/events
P-256 public key, DER, base64For signed requests on payouts. The public key only
Addresses to watch, or an xpub and an index rangeFor deposit detection
Addresses you will top up your payout wallet fromVerified before your first transfer, including a test one. See Payouts
VolumesDeposits and new addresses a day, largest single payout, daily payout total. Your limits are set from these

We never ask for a private key, a seed phrase or an xpub's private counterpart.

3. Receive your keys

Each key is shown once and cannot be retrieved again; we keep only its hash. A key carries exactly the scopes it needs, and money-moving jobs get their own key. See Authentication.

4. First calls

GET /v1/whoami
Authorization: Bearer <your key>

Answers your tenant, the key's scopes, and payout_wallets: a map of network to the address of your payout wallet. Call it once per key per process and check the tenant before you send anything with that key.

Then, depending on what you use:

CallConfirms
GET /v1/limitsThe rate limits and money limits applied to this key
GET /v1/feesYour fee schedule
POST /v1/deposit-addressesAddress registration works
GET /v1/deposits?after=0Arrivals are visible
GET /v1/events?after=0The event cursor works
GET /v1/floatYour balance
GET /v1/chain-payouts/estimateA payout can be priced before it is sent
POST /v1/chain-payoutsThe full payout path. This moves real money

Conventions