Getting started

Environments, your first API key and your first request.

The WireBloom Banking Platform API connects an ERP, accounting or treasury system to a WireBloom customer account. One versioned API (/v1) serves the web app, the mobile app and integrators, so everything the web app shows is available to your system within the scopes of your key.

Environments

EnvironmentBase URLKeysMoney
Productionhttps://api.banking.wirebloom.com/v1wb_live_…real (banking partners)
Staginghttps://api.staging.banking.wirebloom.com/v1wb_test_…simulated (sandbox)
Localhttp://localhost:3001/v1wb_test_…simulated

JSON over HTTPS (UTF-8). Money is { "amountMinor": "125000", "currency": "EUR" }: integer minor units as a string, never floats. Timestamps are RFC 3339 UTC (…Z). Clients must ignore unknown fields and tolerate new enum values.

Your first request

  1. Ask a customer Owner or Admin to create a wb_test_ key on the sandbox customer (Settings → API keys, see Authentication and API keys).
  2. Store the key in your secrets manager: it is shown once.
  3. List the balances of the customer:
curl https://api.staging.banking.wirebloom.com/v1/balances \
  -H "Authorization: Bearer $WIREBLOOM_API_KEY" \
  -H "X-Tenant-Id: $WIREBLOOM_CUSTOMER_ID"

X-Tenant-Id is the id of the customer the key belongs to (Tenancy). The response is a paginated list (Pagination); the operation is listBalances.

Next steps

Sample integration

platform/examples/integration-client (TypeScript, Node 22) uses the typed client generated from the contract and includes a webhook receiver that verifies signatures. It lists balances, registers itself as an endpoint, sends a test event, simulates an incoming payment and prints the events it receives, then removes the endpoint.

pnpm --filter @wirebloom/example-client build
WIREBLOOM_API_URL=http://localhost:3001/v1 WIREBLOOM_API_KEY=wb_test_… \
WIREBLOOM_TENANT_ID=<customer id> pnpm --filter @wirebloom/example-client start

Security checklist

  • Keep keys and webhook secrets in a secrets manager; never in code, logs or URLs.
  • One key per system, least scopes, IP allow-list and expiry where possible; rotate regularly.
  • Verify every webhook signature and timestamp; de-duplicate on the event id.
  • Treat webhook payloads as hints: confirm state with the API before acting on money.
  • Report suspected key exposure to your WireBloom administrator and revoke the key at once.

Markdown version: getting-started.md