providers
Operator banking-partner configuration: provider connections (write-only credentials), routing rules, KYC connections, inbound provider webhooks and the provider event log.
List provider connections
GET /v1/provider-connections
- listProviderConnections
- API key scope integration:read
- Tenant operator
API key scope: integration:read (operator-level keys only, X-Tenant-Id = the operator id).
Parameters
| Name | In | Type | Description |
|---|---|---|---|
X-Tenant-Idrequired | header | Uuid | Tenant context: the operator tenant id (staff operations) or customer tenant id (customer operations). Validated against the caller's memberships; mismatch → |
X-Request-Id | header | string | Client-supplied correlation id. Generated by the server when absent; always echoed in the response and in problem details. |
cursor | query | string | Opaque cursor from |
limit | query | integer | Page size (max 100). |
sort | query | string | Sort order; prefix |
filter | query | object | Filters as |
Responses
200 OK
application/jsonCursor-paginated list of ProviderConnection.
dataarray of ProviderConnectionrequiredpagePageInforequired
400 Malformed request: unparseable JSON, or an invalid header, path or query parameter (`errors[].field` is `header.X`, `path.x` or `query.x`). Body validation failures are 422 `validation-error`.
application/problem+json401 Missing, expired or invalid credentials (`unauthenticated`, `session-expired` with `reason` `idle` / `revoked` / `expired`, `invalid-api-key`, `mfa-required`).
application/problem+json403 Authenticated but not allowed: missing capability or scope, tenant not in memberships, `step-up-required`, IP not allow-listed, impersonation restriction.
application/problem+json429 Rate limit exceeded.
application/problem+jsondefault Unexpected error (`500 internal-error`, `501 not-implemented`, `502 provider-error`, `503 service-unavailable`, `504 provider-timeout`). Money operations that time out at the provider are never retried blindly; their state becomes `exception`/unknown and is reconciled.
application/problem+json
Code samples
curl -X GET "https://bank.wirebloom.com/v1/provider-connections" \
-H "Authorization: Bearer $WIREBLOOM_API_KEY" \
-H "X-Tenant-Id: $WIREBLOOM_CUSTOMER_ID"const response = await fetch("https://bank.wirebloom.com/v1/provider-connections", {
method: "GET",
headers: {
"Authorization": `Bearer ${process.env.WIREBLOOM_API_KEY}`,
"X-Tenant-Id": process.env.WIREBLOOM_CUSTOMER_ID!,
},
});
if (!response.ok) throw new Error(`${response.status} ${await response.text()}`);
const result = await response.json();import os
import requests
response = requests.request(
"GET",
"https://bank.wirebloom.com/v1/provider-connections",
headers={
"Authorization": f"Bearer {os.environ['WIREBLOOM_API_KEY']}",
"X-Tenant-Id": os.environ["WIREBLOOM_CUSTOMER_ID"],
},
timeout=30,
)
response.raise_for_status()Get provider connection (no secrets)
GET /v1/provider-connections/{connectionId}
- getProviderConnection
- API key scope integration:read
- Tenant operator
API key scope: integration:read (operator-level keys only, X-Tenant-Id = the operator id).
Parameters
| Name | In | Type | Description |
|---|---|---|---|
connectionIdrequired | path | Uuid | Identifier (connectionId). |
X-Tenant-Idrequired | header | Uuid | Tenant context: the operator tenant id (staff operations) or customer tenant id (customer operations). Validated against the caller's memberships; mismatch → |
X-Request-Id | header | string | Client-supplied correlation id. Generated by the server when absent; always echoed in the response and in problem details. |
If-None-Match | header | string | Conditional GET; |
Responses
200 OK
application/jsonPer-tenant provider connection (ARCHITECTURE §6). Secrets are write-only. One
activebanking connection per operator and environment (D-32).idUuidrequiredread-onlyFields of id
operatorIdUuidrequiredread-onlyFields of operatorId
customerIdUuid | nullproviderProviderIdrequiredenvironmentProviderEnvironmentrequirednamestringrequiredconfigProviderConnectionConfigrequiredcredentialsSetbooleanrequiredread-onlyWhether credentials are stored. Credentials are never returned.
credentialsKidstring | nullread-onlycredentialsUpdatedAtTimestamp | nullcredentialsFingerprintstring | nullread-onlySalted HMAC fingerprint (
fp_+ 12 hex) so staff can tell credential sets apart without seeing them.webhookSecretSetbooleanread-onlywebhookUrlstring (uri)requiredread-onlyRegister this URL with the provider.
statusConnectionLifecyclerequiredread-onlyFields of status
roleConnectionRolerequiredread-onlyFields of role
fallbackCurrenciesarray of CurrencyCoderequiredread-onlyCurrencies a
fallbackconnection carries; empty for primaries.contractModelContractModel | nullrequiredwebhookRegistrationStateWebhookRegistrationStaterequiredread-onlyFields of webhookRegistrationState
healthyboolean | nullread-onlyHealth flag from the last health check (
erroris not a lifecycle state, D-32).verifiedAtTimestamp | nullactivatedAtTimestamp | nulldrainingAtTimestamp | nullretiredAtTimestamp | nullcapabilitiesobjectread-onlyFields of capabilities
virtualAccountsbooleanrealAccountsbooleansepabooleansepaInstantbooleanswiftbooleanfasterPaymentsbooleanchapsbooleanbacsbooleanreturnsbooleanstatementsCamt053booleancurrenciesarray of CurrencyCodefxbooleanforwardsbooleanheldRatesbooleancardsbooleanwebhooksbooleancopbooleanvopbooleandirectDebitbooleanbulkbooleanrecallsboolean
lastHealthAtTimestamp | nulllastHealthobject | nullread-onlyFields of lastHealth
okbooleanlatencyMsintegermessagestring | null
createdAtTimestamprequiredread-onlyFields of createdAt
updatedAtTimestampread-onlyFields of updatedAt
304 Not modified (`If-None-Match` matched).
401 Missing, expired or invalid credentials (`unauthenticated`, `session-expired` with `reason` `idle` / `revoked` / `expired`, `invalid-api-key`, `mfa-required`).
application/problem+json403 Authenticated but not allowed: missing capability or scope, tenant not in memberships, `step-up-required`, IP not allow-listed, impersonation restriction.
application/problem+json404 Resource does not exist in this tenant (cross-tenant ids also return 404), or feature disabled (`feature-disabled`).
application/problem+json429 Rate limit exceeded.
application/problem+jsondefault Unexpected error (`500 internal-error`, `501 not-implemented`, `502 provider-error`, `503 service-unavailable`, `504 provider-timeout`). Money operations that time out at the provider are never retried blindly; their state becomes `exception`/unknown and is reconciled.
application/problem+json
Code samples
curl -X GET "https://bank.wirebloom.com/v1/provider-connections/{connectionId}" \
-H "Authorization: Bearer $WIREBLOOM_API_KEY" \
-H "X-Tenant-Id: $WIREBLOOM_CUSTOMER_ID"const response = await fetch("https://bank.wirebloom.com/v1/provider-connections/{connectionId}", {
method: "GET",
headers: {
"Authorization": `Bearer ${process.env.WIREBLOOM_API_KEY}`,
"X-Tenant-Id": process.env.WIREBLOOM_CUSTOMER_ID!,
},
});
if (!response.ok) throw new Error(`${response.status} ${await response.text()}`);
const result = await response.json();import os
import requests
response = requests.request(
"GET",
"https://bank.wirebloom.com/v1/provider-connections/{connectionId}",
headers={
"Authorization": f"Bearer {os.environ['WIREBLOOM_API_KEY']}",
"X-Tenant-Id": os.environ["WIREBLOOM_CUSTOMER_ID"],
},
timeout=30,
)
response.raise_for_status()