public-api

Integrator access: API keys with scopes and integrator webhooks (HMAC-signed callbacks). All other resources are shared with the web/mobile API and documented per scope.

Markdown version: public-api.md

Integration home: connections, webhooks, API keys, usage and portal links

GET /v1/integration

  • getIntegrationHome
  • API key scope integration:read
  • Tenant operator

Operator console "Integration" page (P9-T11, FR-PLAT-06): every non-retired banking connection with lifecycle, health, breaker, webhook registration and last event, event backlog, last reconciliation run and open exceptions, activation checklist progress; API key counts; 7-day usage; integrator webhook health; developer-portal links.

API key scope: integration:read (operator-level keys only, X-Tenant-Id = the operator id).

Parameters

NameInTypeDescription
X-Tenant-IdrequiredheaderUuid

Tenant context: the operator tenant id (staff operations) or customer tenant id (customer operations). Validated against the caller's memberships; mismatch → 403. For API keys it must equal the key's customer id (customer-level keys are bound to one customer) or, for operator-level keys (P9-T08b), the operator id.

X-Request-Idheaderstring

Client-supplied correlation id. Generated by the server when absent; always echoed in the response and in problem details.

Responses

  • 200 OK application/json

    Schema IntegrationHome

    Integration home of an operator (FR-PLAT-06): connections, webhook registration, API keys, usage, integrator webhooks and portal links.

    • operatorId Uuidrequired

    • generatedAt Timestamprequired

    • activeConnectionId string | null (uuid)required

      Active primary connection (production first).

    • connections array of IntegrationConnectionrequired

      Connections not retired, active first.

    • apiKeys objectrequired

      Unrevoked, unexpired keys of the operator (all customers and operator-level).

      Fields of apiKeys
      • active integerrequired

        min 0

      • live integerrequired

        min 0

      • test integerrequired

        min 0

      • operatorLevel integerrequired

        min 0

      • usedLast24h integerrequired

        min 0

    • usageLast7Days ApiUsageTotalsrequired

    • integratorWebhooks objectrequired

      Fields of integratorWebhooks
      • endpoints integerrequired

        min 0

      • active integerrequired

        min 0

      • paused integerrequired

        min 0

      • failed integerrequired

        min 0

      • deliveriesPending integerrequired

        min 0

      • deliveriesFailed24h integerrequired

        min 0

      • lastDeliveryAt Timestamp | nullrequired

    • links objectrequired

      Developer portal (DEVELOPER_PORTAL_URL, D-35, D-42).

      Fields of links
      • portal string (uri)required

      • reference string (uri)required

      • gettingStarted string (uri)required

      • sandbox string (uri)required

      • changelog string (uri)required

      • openapi string (uri)required

  • 401 Missing, expired or invalid credentials (`unauthenticated`, `session-expired` with `reason` `idle` / `revoked` / `expired`, `invalid-api-key`, `mfa-required`). application/problem+json

    Body Problem; see the error catalogue.

  • 403 Authenticated but not allowed: missing capability or scope, tenant not in memberships, `step-up-required`, IP not allow-listed, impersonation restriction. application/problem+json

    Body Problem; see the error catalogue.

  • 429 Rate limit exceeded. application/problem+json

    Body Problem; see the error catalogue.

  • default Unexpected error (`500 internal-error`, `501 not-implemented`, `502 provider-error`, `503 service-unavailable`, `504 provider-timeout`). Money operations that time out at the provider are never retried blindly; their state becomes `exception`/unknown and is reconciled. application/problem+json

    Body Problem; see the error catalogue.

Code samples

Against the sandbox (https://bank.wirebloom.com/v1).

curl -X GET "https://bank.wirebloom.com/v1/integration" \
  -H "Authorization: Bearer $WIREBLOOM_API_KEY" \
  -H "X-Tenant-Id: $WIREBLOOM_CUSTOMER_ID"

Recent requests of an API key (7 days, no bodies)

GET /v1/integration/api-keys/{apiKeyId}/requests

  • listOperatorApiKeyRequests
  • API key scope integration:read
  • Tenant operator

The last requests of any key of the operator (newest first) and the status breakdown over 7 days. Method, route template, status, duration and request id only.

API key scope: integration:read (operator-level keys only, X-Tenant-Id = the operator id).

Parameters

NameInTypeDescription
apiKeyIdrequiredpathUuid

Identifier (apiKeyId).

X-Tenant-IdrequiredheaderUuid

Tenant context: the operator tenant id (staff operations) or customer tenant id (customer operations). Validated against the caller's memberships; mismatch → 403. For API keys it must equal the key's customer id (customer-level keys are bound to one customer) or, for operator-level keys (P9-T08b), the operator id.

X-Request-Idheaderstring

Client-supplied correlation id. Generated by the server when absent; always echoed in the response and in problem details.

limitqueryinteger

Entries (default and max 100).

outcomequerystring

errors: status 400 and above only.

Responses

  • 200 OK application/json

    Schema ApiKeyRequestLog

    • apiKeyId Uuidrequired

    • retentionDays integerrequired

      Days the request log keeps (7).

      min 1

    • statusCounts objectrequired

      Responses per HTTP status over the retention window (error breakdown).

    • data array of ApiRequestLogEntryrequired

      Newest first.

  • 400 Malformed request: unparseable JSON, or an invalid header, path or query parameter (`errors[].field` is `header.X`, `path.x` or `query.x`). Body validation failures are 422 `validation-error`. application/problem+json

    Body Problem; see the error catalogue.

  • 401 Missing, expired or invalid credentials (`unauthenticated`, `session-expired` with `reason` `idle` / `revoked` / `expired`, `invalid-api-key`, `mfa-required`). application/problem+json

    Body Problem; see the error catalogue.

  • 403 Authenticated but not allowed: missing capability or scope, tenant not in memberships, `step-up-required`, IP not allow-listed, impersonation restriction. application/problem+json

    Body Problem; see the error catalogue.

  • 404 Resource does not exist in this tenant (cross-tenant ids also return 404), or feature disabled (`feature-disabled`). application/problem+json

    Body Problem; see the error catalogue.

  • 429 Rate limit exceeded. application/problem+json

    Body Problem; see the error catalogue.

  • default Unexpected error (`500 internal-error`, `501 not-implemented`, `502 provider-error`, `503 service-unavailable`, `504 provider-timeout`). Money operations that time out at the provider are never retried blindly; their state becomes `exception`/unknown and is reconciled. application/problem+json

    Body Problem; see the error catalogue.

Code samples

Against the sandbox (https://bank.wirebloom.com/v1).

curl -X GET "https://bank.wirebloom.com/v1/integration/api-keys/{apiKeyId}/requests" \
  -H "Authorization: Bearer $WIREBLOOM_API_KEY" \
  -H "X-Tenant-Id: $WIREBLOOM_CUSTOMER_ID"

API usage per key across the operator (daily)

GET /v1/integration/api-usage

  • getOperatorApiUsage
  • API key scope integration:read
  • Tenant operator

Per-key totals and daily series (P9-T11). Days before yesterday come from the daily rollup; yesterday and today are live from the request log (a call appears within API_REQUEST_LOG_FLUSH_MS, 5 s by default). Covers every key of the operator: customer keys and operator-level keys.

API key scope: integration:read (operator-level keys only, X-Tenant-Id = the operator id).

Parameters

NameInTypeDescription
X-Tenant-IdrequiredheaderUuid

Tenant context: the operator tenant id (staff operations) or customer tenant id (customer operations). Validated against the caller's memberships; mismatch → 403. For API keys it must equal the key's customer id (customer-level keys are bound to one customer) or, for operator-level keys (P9-T08b), the operator id.

X-Request-Idheaderstring

Client-supplied correlation id. Generated by the server when absent; always echoed in the response and in problem details.

fromqueryDate

First UTC day (default: to minus 6 days).

toqueryDate

Last UTC day, inclusive (default: today). At most 90 days after from.

apiKeyIdqueryUuid

One key only.

environmentquerystring

live or test keys only.

customerIdqueryUuid

One customer's keys only.

Responses

  • 200 OK application/json

    Schema ApiUsageReport

    • from Daterequired

    • to Daterequired

    • generatedAt Timestamprequired

    • totals ApiUsageTotalsrequired

    • keys array of ApiKeyUsagerequired

      Keys in scope (at most 200, newest first): active keys and keys revoked during the window, with or without requests.

  • 400 Malformed request: unparseable JSON, or an invalid header, path or query parameter (`errors[].field` is `header.X`, `path.x` or `query.x`). Body validation failures are 422 `validation-error`. application/problem+json

    Body Problem; see the error catalogue.

  • 401 Missing, expired or invalid credentials (`unauthenticated`, `session-expired` with `reason` `idle` / `revoked` / `expired`, `invalid-api-key`, `mfa-required`). application/problem+json

    Body Problem; see the error catalogue.

  • 403 Authenticated but not allowed: missing capability or scope, tenant not in memberships, `step-up-required`, IP not allow-listed, impersonation restriction. application/problem+json

    Body Problem; see the error catalogue.

  • 429 Rate limit exceeded. application/problem+json

    Body Problem; see the error catalogue.

  • default Unexpected error (`500 internal-error`, `501 not-implemented`, `502 provider-error`, `503 service-unavailable`, `504 provider-timeout`). Money operations that time out at the provider are never retried blindly; their state becomes `exception`/unknown and is reconciled. application/problem+json

    Body Problem; see the error catalogue.

Code samples

Against the sandbox (https://bank.wirebloom.com/v1).

curl -X GET "https://bank.wirebloom.com/v1/integration/api-usage" \
  -H "Authorization: Bearer $WIREBLOOM_API_KEY" \
  -H "X-Tenant-Id: $WIREBLOOM_CUSTOMER_ID"

List integrator webhook endpoints

GET /v1/integrator-webhooks

  • listIntegratorWebhooks
  • API key scope webhooks:manage
  • Tenant any

API key scope: webhooks:manage.

Level (P9-T08b): X-Tenant-Id = a customer → that customer's endpoints; X-Tenant-Id = the operator → the operator-level endpoints (sessions of operator owners with webhooks.manage, operator-level keys with webhooks:manage).

Parameters

NameInTypeDescription
X-Tenant-IdrequiredheaderUuid

Tenant context: the operator tenant id (staff operations) or customer tenant id (customer operations). Validated against the caller's memberships; mismatch → 403. For API keys it must equal the key's customer id (customer-level keys are bound to one customer) or, for operator-level keys (P9-T08b), the operator id.

X-Request-Idheaderstring

Client-supplied correlation id. Generated by the server when absent; always echoed in the response and in problem details.

cursorquerystring

Opaque cursor from page.nextCursor or page.prevCursor. Must be used with the same sort and filter as the request that produced it (400 invalid-cursor otherwise).

limitqueryinteger

Page size (max 100).

sortquerystring

Sort order; prefix - for descending. Cursor stability is guaranteed only for the default sort.

Responses

  • 200 OK application/json

    Schema IntegratorWebhookPage

    Cursor-paginated list of IntegratorWebhook.

  • 400 Malformed request: unparseable JSON, or an invalid header, path or query parameter (`errors[].field` is `header.X`, `path.x` or `query.x`). Body validation failures are 422 `validation-error`. application/problem+json

    Body Problem; see the error catalogue.

  • 401 Missing, expired or invalid credentials (`unauthenticated`, `session-expired` with `reason` `idle` / `revoked` / `expired`, `invalid-api-key`, `mfa-required`). application/problem+json

    Body Problem; see the error catalogue.

  • 403 Authenticated but not allowed: missing capability or scope, tenant not in memberships, `step-up-required`, IP not allow-listed, impersonation restriction. application/problem+json

    Body Problem; see the error catalogue.

  • 429 Rate limit exceeded. application/problem+json

    Body Problem; see the error catalogue.

  • default Unexpected error (`500 internal-error`, `501 not-implemented`, `502 provider-error`, `503 service-unavailable`, `504 provider-timeout`). Money operations that time out at the provider are never retried blindly; their state becomes `exception`/unknown and is reconciled. application/problem+json

    Body Problem; see the error catalogue.

Code samples

Against the sandbox (https://bank.wirebloom.com/v1).

curl -X GET "https://bank.wirebloom.com/v1/integrator-webhooks" \
  -H "Authorization: Bearer $WIREBLOOM_API_KEY" \
  -H "X-Tenant-Id: $WIREBLOOM_CUSTOMER_ID"

Register webhook endpoint

POST /v1/integrator-webhooks

  • createIntegratorWebhook
  • API key scope webhooks:manage
  • Tenant any

Not idempotent: the response carries the signing secret shown once. SSRF guard on the URL (422); at most 10 endpoints per customer (409).

API key scope: webhooks:manage.

Level (P9-T08b): X-Tenant-Id = a customer → that customer's endpoints; X-Tenant-Id = the operator → the operator-level endpoints (sessions of operator owners with webhooks.manage, operator-level keys with webhooks:manage).

Step-up: requires a verified step-up challenge for action integrator_webhook.change within the last 5 minutes (session/bearer only). Otherwise 403 with problem type step-up-required; the step-up check runs before body validation. API keys holding webhooks:manage may call it without a step-up; every create, update, secret rotation and deletion notifies the endpoint owners (webhook_endpoint_changed, staff or customer members with webhooks.manage), whoever made it (review W3-03, P4 S-14).

Parameters

NameInTypeDescription
X-Tenant-IdrequiredheaderUuid

Tenant context: the operator tenant id (staff operations) or customer tenant id (customer operations). Validated against the caller's memberships; mismatch → 403. For API keys it must equal the key's customer id (customer-level keys are bound to one customer) or, for operator-level keys (P9-T08b), the operator id.

X-Request-Idheaderstring

Client-supplied correlation id. Generated by the server when absent; always echoed in the response and in problem details.

Request body

Required. application/json

Schema IntegratorWebhookWrite

  • url string (uri)required

    pattern ^https://

  • events array of IntegratorEventTyperequired

  • description string | null

    max length 200

  • enabled boolean

    default true

Responses

  • 201 Created application/json

    Schema IntegratorWebhookCreated

    • id Uuidrequiredread-only

      Fields of id
    • url string (uri)required

    • events array of IntegratorEventTyperequired

    • description string | null

      max length 200

    • enabled booleanrequired

    • secretPrefix stringrequiredread-only

    • createdAt Timestamprequiredread-only

      Fields of createdAt
    • updatedAt Timestamprequiredread-only

      Row version: the ETag is W/"<updatedAt epoch ms>" (If-Match on PATCH).

      Fields of updatedAt
    • lastDeliveryAt Timestamp | null

    • failureCount integerrequiredread-only

      min 0

    • status stringread-only

      paused after 20 consecutive failed attempts or enabled: false; failed when a delivery exhausts 72 h without success. Re-enable with PATCH enabled: true.

      One of: "active", "paused", "failed"

    • pauseReason string | nullread-only

    • secret stringrequired

      Signing secret whsec_..., shown once.

  • 400 Malformed request: unparseable JSON, or an invalid header, path or query parameter (`errors[].field` is `header.X`, `path.x` or `query.x`). Body validation failures are 422 `validation-error`. application/problem+json

    Body Problem; see the error catalogue.

  • 401 Missing, expired or invalid credentials (`unauthenticated`, `session-expired` with `reason` `idle` / `revoked` / `expired`, `invalid-api-key`, `mfa-required`). application/problem+json

    Body Problem; see the error catalogue.

  • 403 Authenticated but not allowed: missing capability or scope, tenant not in memberships, `step-up-required`, IP not allow-listed, impersonation restriction. application/problem+json

    Body Problem; see the error catalogue.

  • 409 State conflict: `invalid-transition`, `duplicate-recipient`, `quote-expired`, `insufficient-funds`, `idempotency-key-in-use` (with Retry-After), `not-cancellable`. application/problem+json

    Body Problem; see the error catalogue.

  • 422 Semantically invalid request; `errors[]` lists field-level problems. Also `idempotency-key-reused` when the key was used with a different payload, `limit-exceeded`, `recipient-not-approved`. application/problem+json

    Body Problem; see the error catalogue.

  • 429 Rate limit exceeded. application/problem+json

    Body Problem; see the error catalogue.

  • default Unexpected error (`500 internal-error`, `501 not-implemented`, `502 provider-error`, `503 service-unavailable`, `504 provider-timeout`). Money operations that time out at the provider are never retried blindly; their state becomes `exception`/unknown and is reconciled. application/problem+json

    Body Problem; see the error catalogue.

Code samples

Against the sandbox (https://bank.wirebloom.com/v1).

curl -X POST "https://bank.wirebloom.com/v1/integrator-webhooks" \
  -H "Authorization: Bearer $WIREBLOOM_API_KEY" \
  -H "X-Tenant-Id: $WIREBLOOM_CUSTOMER_ID" \
  -H "Content-Type: application/json" \
  --data '{
  "url": "https://example.com",
  "events": [
    "webhook.test"
  ]
}'

Get webhook endpoint

GET /v1/integrator-webhooks/{webhookId}

  • getIntegratorWebhook
  • API key scope webhooks:manage
  • Tenant any

API key scope: webhooks:manage.

Level (P9-T08b): X-Tenant-Id = a customer → that customer's endpoints; X-Tenant-Id = the operator → the operator-level endpoints (sessions of operator owners with webhooks.manage, operator-level keys with webhooks:manage).

Parameters

NameInTypeDescription
webhookIdrequiredpathUuid

Identifier (webhookId).

X-Tenant-IdrequiredheaderUuid

Tenant context: the operator tenant id (staff operations) or customer tenant id (customer operations). Validated against the caller's memberships; mismatch → 403. For API keys it must equal the key's customer id (customer-level keys are bound to one customer) or, for operator-level keys (P9-T08b), the operator id.

X-Request-Idheaderstring

Client-supplied correlation id. Generated by the server when absent; always echoed in the response and in problem details.

If-None-Matchheaderstring

Conditional GET; 304 when unchanged.

Responses

  • 200 OK application/json

    Schema IntegratorWebhook

    Integrator webhook endpoint (tenant.integrator_webhooks). Customer-level endpoints receive the customer's events; operator-level endpoints (created with X-Tenant-Id = the operator, P9-T08b) receive the events of every customer of the operator, including the operator-only types.

    • id Uuidrequiredread-only

      Fields of id
    • url string (uri)required

    • events array of IntegratorEventTyperequired

    • description string | null

      max length 200

    • enabled booleanrequired

    • secretPrefix stringrequiredread-only

    • createdAt Timestamprequiredread-only

      Fields of createdAt
    • updatedAt Timestamprequiredread-only

      Row version: the ETag is W/"<updatedAt epoch ms>" (If-Match on PATCH).

      Fields of updatedAt
    • lastDeliveryAt Timestamp | null

    • failureCount integerrequiredread-only

      min 0

    • status stringread-only

      paused after 20 consecutive failed attempts or enabled: false; failed when a delivery exhausts 72 h without success. Re-enable with PATCH enabled: true.

      One of: "active", "paused", "failed"

    • pauseReason string | nullread-only

  • 304 Not modified (`If-None-Match` matched).
  • 401 Missing, expired or invalid credentials (`unauthenticated`, `session-expired` with `reason` `idle` / `revoked` / `expired`, `invalid-api-key`, `mfa-required`). application/problem+json

    Body Problem; see the error catalogue.

  • 403 Authenticated but not allowed: missing capability or scope, tenant not in memberships, `step-up-required`, IP not allow-listed, impersonation restriction. application/problem+json

    Body Problem; see the error catalogue.

  • 404 Resource does not exist in this tenant (cross-tenant ids also return 404), or feature disabled (`feature-disabled`). application/problem+json

    Body Problem; see the error catalogue.

  • 429 Rate limit exceeded. application/problem+json

    Body Problem; see the error catalogue.

  • default Unexpected error (`500 internal-error`, `501 not-implemented`, `502 provider-error`, `503 service-unavailable`, `504 provider-timeout`). Money operations that time out at the provider are never retried blindly; their state becomes `exception`/unknown and is reconciled. application/problem+json

    Body Problem; see the error catalogue.

Code samples

Against the sandbox (https://bank.wirebloom.com/v1).

curl -X GET "https://bank.wirebloom.com/v1/integrator-webhooks/{webhookId}" \
  -H "Authorization: Bearer $WIREBLOOM_API_KEY" \
  -H "X-Tenant-Id: $WIREBLOOM_CUSTOMER_ID"

Update webhook endpoint

PATCH /v1/integrator-webhooks/{webhookId}

  • updateIntegratorWebhook
  • API key scope webhooks:manage
  • Tenant any

Concurrency: If-Match with the current ETag is required (428 if absent, 412 if stale).

API key scope: webhooks:manage.

Level (P9-T08b): X-Tenant-Id = a customer → that customer's endpoints; X-Tenant-Id = the operator → the operator-level endpoints (sessions of operator owners with webhooks.manage, operator-level keys with webhooks:manage).

Step-up: requires a verified step-up challenge for action integrator_webhook.change within the last 5 minutes (session/bearer only). Otherwise 403 with problem type step-up-required; the step-up check runs before body validation. API keys holding webhooks:manage may call it without a step-up; every create, update, secret rotation and deletion notifies the endpoint owners (webhook_endpoint_changed, staff or customer members with webhooks.manage), whoever made it (review W3-03, P4 S-14).

Parameters

NameInTypeDescription
webhookIdrequiredpathUuid

Identifier (webhookId).

X-Tenant-IdrequiredheaderUuid

Tenant context: the operator tenant id (staff operations) or customer tenant id (customer operations). Validated against the caller's memberships; mismatch → 403. For API keys it must equal the key's customer id (customer-level keys are bound to one customer) or, for operator-level keys (P9-T08b), the operator id.

X-Request-Idheaderstring

Client-supplied correlation id. Generated by the server when absent; always echoed in the response and in problem details.

If-Matchrequiredheaderstring

ETag of the representation being modified (from a prior GET/PATCH).

Request body

Required. application/json

Schema IntegratorWebhookWrite

  • url string (uri)required

    pattern ^https://

  • events array of IntegratorEventTyperequired

  • description string | null

    max length 200

  • enabled boolean

    default true

Responses

  • 200 OK application/json

    Schema IntegratorWebhook

    Integrator webhook endpoint (tenant.integrator_webhooks). Customer-level endpoints receive the customer's events; operator-level endpoints (created with X-Tenant-Id = the operator, P9-T08b) receive the events of every customer of the operator, including the operator-only types.

    • id Uuidrequiredread-only

      Fields of id
    • url string (uri)required

    • events array of IntegratorEventTyperequired

    • description string | null

      max length 200

    • enabled booleanrequired

    • secretPrefix stringrequiredread-only

    • createdAt Timestamprequiredread-only

      Fields of createdAt
    • updatedAt Timestamprequiredread-only

      Row version: the ETag is W/"<updatedAt epoch ms>" (If-Match on PATCH).

      Fields of updatedAt
    • lastDeliveryAt Timestamp | null

    • failureCount integerrequiredread-only

      min 0

    • status stringread-only

      paused after 20 consecutive failed attempts or enabled: false; failed when a delivery exhausts 72 h without success. Re-enable with PATCH enabled: true.

      One of: "active", "paused", "failed"

    • pauseReason string | nullread-only

  • 400 Malformed request: unparseable JSON, or an invalid header, path or query parameter (`errors[].field` is `header.X`, `path.x` or `query.x`). Body validation failures are 422 `validation-error`. application/problem+json

    Body Problem; see the error catalogue.

  • 401 Missing, expired or invalid credentials (`unauthenticated`, `session-expired` with `reason` `idle` / `revoked` / `expired`, `invalid-api-key`, `mfa-required`). application/problem+json

    Body Problem; see the error catalogue.

  • 403 Authenticated but not allowed: missing capability or scope, tenant not in memberships, `step-up-required`, IP not allow-listed, impersonation restriction. application/problem+json

    Body Problem; see the error catalogue.

  • 404 Resource does not exist in this tenant (cross-tenant ids also return 404), or feature disabled (`feature-disabled`). application/problem+json

    Body Problem; see the error catalogue.

  • 409 State conflict: `invalid-transition`, `duplicate-recipient`, `quote-expired`, `insufficient-funds`, `idempotency-key-in-use` (with Retry-After), `not-cancellable`. application/problem+json

    Body Problem; see the error catalogue.

  • 412 `If-Match` does not match the current ETag (resource changed). application/problem+json

    Body Problem; see the error catalogue.

  • 422 Semantically invalid request; `errors[]` lists field-level problems. Also `idempotency-key-reused` when the key was used with a different payload, `limit-exceeded`, `recipient-not-approved`. application/problem+json

    Body Problem; see the error catalogue.

  • 428 `If-Match` header is required for this operation. application/problem+json

    Body Problem; see the error catalogue.

  • 429 Rate limit exceeded. application/problem+json

    Body Problem; see the error catalogue.

  • default Unexpected error (`500 internal-error`, `501 not-implemented`, `502 provider-error`, `503 service-unavailable`, `504 provider-timeout`). Money operations that time out at the provider are never retried blindly; their state becomes `exception`/unknown and is reconciled. application/problem+json

    Body Problem; see the error catalogue.

Code samples

Against the sandbox (https://bank.wirebloom.com/v1).

curl -X PATCH "https://bank.wirebloom.com/v1/integrator-webhooks/{webhookId}" \
  -H "Authorization: Bearer $WIREBLOOM_API_KEY" \
  -H "X-Tenant-Id: $WIREBLOOM_CUSTOMER_ID" \
  -H "If-Match: \"<etag>\"" \
  -H "Content-Type: application/json" \
  --data '{
  "url": "https://example.com",
  "events": [
    "webhook.test"
  ]
}'

Delete webhook endpoint

DELETE /v1/integrator-webhooks/{webhookId}

  • deleteIntegratorWebhook
  • API key scope webhooks:manage
  • Tenant any

API key scope: webhooks:manage.

Level (P9-T08b): X-Tenant-Id = a customer → that customer's endpoints; X-Tenant-Id = the operator → the operator-level endpoints (sessions of operator owners with webhooks.manage, operator-level keys with webhooks:manage).

Step-up: requires a verified step-up challenge for action integrator_webhook.change within the last 5 minutes (session/bearer only). Otherwise 403 with problem type step-up-required; the step-up check runs before body validation. API keys holding webhooks:manage may call it without a step-up; every create, update, secret rotation and deletion notifies the endpoint owners (webhook_endpoint_changed, staff or customer members with webhooks.manage), whoever made it (review W3-03, P4 S-14).

Parameters

NameInTypeDescription
webhookIdrequiredpathUuid

Identifier (webhookId).

X-Tenant-IdrequiredheaderUuid

Tenant context: the operator tenant id (staff operations) or customer tenant id (customer operations). Validated against the caller's memberships; mismatch → 403. For API keys it must equal the key's customer id (customer-level keys are bound to one customer) or, for operator-level keys (P9-T08b), the operator id.

X-Request-Idheaderstring

Client-supplied correlation id. Generated by the server when absent; always echoed in the response and in problem details.

Responses

  • 204 No Content
  • 401 Missing, expired or invalid credentials (`unauthenticated`, `session-expired` with `reason` `idle` / `revoked` / `expired`, `invalid-api-key`, `mfa-required`). application/problem+json

    Body Problem; see the error catalogue.

  • 403 Authenticated but not allowed: missing capability or scope, tenant not in memberships, `step-up-required`, IP not allow-listed, impersonation restriction. application/problem+json

    Body Problem; see the error catalogue.

  • 404 Resource does not exist in this tenant (cross-tenant ids also return 404), or feature disabled (`feature-disabled`). application/problem+json

    Body Problem; see the error catalogue.

  • 409 State conflict: `invalid-transition`, `duplicate-recipient`, `quote-expired`, `insufficient-funds`, `idempotency-key-in-use` (with Retry-After), `not-cancellable`. application/problem+json

    Body Problem; see the error catalogue.

  • 429 Rate limit exceeded. application/problem+json

    Body Problem; see the error catalogue.

  • default Unexpected error (`500 internal-error`, `501 not-implemented`, `502 provider-error`, `503 service-unavailable`, `504 provider-timeout`). Money operations that time out at the provider are never retried blindly; their state becomes `exception`/unknown and is reconciled. application/problem+json

    Body Problem; see the error catalogue.

Code samples

Against the sandbox (https://bank.wirebloom.com/v1).

curl -X DELETE "https://bank.wirebloom.com/v1/integrator-webhooks/{webhookId}" \
  -H "Authorization: Bearer $WIREBLOOM_API_KEY" \
  -H "X-Tenant-Id: $WIREBLOOM_CUSTOMER_ID"

Delivery attempts

GET /v1/integrator-webhooks/{webhookId}/deliveries

  • listWebhookDeliveries
  • API key scope webhooks:manage
  • Tenant any

API key scope: webhooks:manage.

Level (P9-T08b): X-Tenant-Id = a customer → that customer's endpoints; X-Tenant-Id = the operator → the operator-level endpoints (sessions of operator owners with webhooks.manage, operator-level keys with webhooks:manage).

Parameters

NameInTypeDescription
webhookIdrequiredpathUuid

Identifier (webhookId).

X-Tenant-IdrequiredheaderUuid

Tenant context: the operator tenant id (staff operations) or customer tenant id (customer operations). Validated against the caller's memberships; mismatch → 403. For API keys it must equal the key's customer id (customer-level keys are bound to one customer) or, for operator-level keys (P9-T08b), the operator id.

X-Request-Idheaderstring

Client-supplied correlation id. Generated by the server when absent; always echoed in the response and in problem details.

cursorquerystring

Opaque cursor from page.nextCursor or page.prevCursor. Must be used with the same sort and filter as the request that produced it (400 invalid-cursor otherwise).

limitqueryinteger

Page size (max 100).

sortquerystring

Sort order; prefix - for descending. Cursor stability is guaranteed only for the default sort.

filterqueryobject

Filters as filter[field]=value. Multiple values for one field are comma-separated (OR); different fields combine with AND. Date ranges use filter[createdFrom]/filter[createdTo] (inclusive, RFC 3339 or date).

Responses

  • 200 OK application/json

    Schema WebhookDeliveryPage

    Cursor-paginated list of WebhookDelivery.

  • 400 Malformed request: unparseable JSON, or an invalid header, path or query parameter (`errors[].field` is `header.X`, `path.x` or `query.x`). Body validation failures are 422 `validation-error`. application/problem+json

    Body Problem; see the error catalogue.

  • 401 Missing, expired or invalid credentials (`unauthenticated`, `session-expired` with `reason` `idle` / `revoked` / `expired`, `invalid-api-key`, `mfa-required`). application/problem+json

    Body Problem; see the error catalogue.

  • 403 Authenticated but not allowed: missing capability or scope, tenant not in memberships, `step-up-required`, IP not allow-listed, impersonation restriction. application/problem+json

    Body Problem; see the error catalogue.

  • 404 Resource does not exist in this tenant (cross-tenant ids also return 404), or feature disabled (`feature-disabled`). application/problem+json

    Body Problem; see the error catalogue.

  • 429 Rate limit exceeded. application/problem+json

    Body Problem; see the error catalogue.

  • default Unexpected error (`500 internal-error`, `501 not-implemented`, `502 provider-error`, `503 service-unavailable`, `504 provider-timeout`). Money operations that time out at the provider are never retried blindly; their state becomes `exception`/unknown and is reconciled. application/problem+json

    Body Problem; see the error catalogue.

Code samples

Against the sandbox (https://bank.wirebloom.com/v1).

curl -X GET "https://bank.wirebloom.com/v1/integrator-webhooks/{webhookId}/deliveries" \
  -H "Authorization: Bearer $WIREBLOOM_API_KEY" \
  -H "X-Tenant-Id: $WIREBLOOM_CUSTOMER_ID"

Redeliver an event

POST /v1/integrator-webhooks/{webhookId}/deliveries/{deliveryId}/redeliver

  • redeliverWebhook
  • API key scope webhooks:manage
  • Tenant any

API key scope: webhooks:manage.

Level (P9-T08b): X-Tenant-Id = a customer → that customer's endpoints; X-Tenant-Id = the operator → the operator-level endpoints (sessions of operator owners with webhooks.manage, operator-level keys with webhooks:manage).

Parameters

NameInTypeDescription
webhookIdrequiredpathUuid

Identifier (webhookId).

deliveryIdrequiredpathUuid

Identifier (deliveryId).

X-Tenant-IdrequiredheaderUuid

Tenant context: the operator tenant id (staff operations) or customer tenant id (customer operations). Validated against the caller's memberships; mismatch → 403. For API keys it must equal the key's customer id (customer-level keys are bound to one customer) or, for operator-level keys (P9-T08b), the operator id.

X-Request-Idheaderstring

Client-supplied correlation id. Generated by the server when absent; always echoed in the response and in problem details.

Responses

  • 202 Accepted application/json

    Schema WebhookDelivery

    • id Uuidrequiredread-only

      Fields of id
    • eventId Uuidrequired

    • eventType IntegratorEventTyperequired

    • attempt integerrequired

      min 1

    • statusCode integer | null

    • durationMs integer | null

    • succeeded booleanrequired

    • nextRetryAt Timestamp | null

    • createdAt Timestamprequiredread-only

      Fields of createdAt
  • 401 Missing, expired or invalid credentials (`unauthenticated`, `session-expired` with `reason` `idle` / `revoked` / `expired`, `invalid-api-key`, `mfa-required`). application/problem+json

    Body Problem; see the error catalogue.

  • 403 Authenticated but not allowed: missing capability or scope, tenant not in memberships, `step-up-required`, IP not allow-listed, impersonation restriction. application/problem+json

    Body Problem; see the error catalogue.

  • 404 Resource does not exist in this tenant (cross-tenant ids also return 404), or feature disabled (`feature-disabled`). application/problem+json

    Body Problem; see the error catalogue.

  • 409 State conflict: `invalid-transition`, `duplicate-recipient`, `quote-expired`, `insufficient-funds`, `idempotency-key-in-use` (with Retry-After), `not-cancellable`. application/problem+json

    Body Problem; see the error catalogue.

  • 429 Rate limit exceeded. application/problem+json

    Body Problem; see the error catalogue.

  • default Unexpected error (`500 internal-error`, `501 not-implemented`, `502 provider-error`, `503 service-unavailable`, `504 provider-timeout`). Money operations that time out at the provider are never retried blindly; their state becomes `exception`/unknown and is reconciled. application/problem+json

    Body Problem; see the error catalogue.

Code samples

Against the sandbox (https://bank.wirebloom.com/v1).

curl -X POST "https://bank.wirebloom.com/v1/integrator-webhooks/{webhookId}/deliveries/{deliveryId}/redeliver" \
  -H "Authorization: Bearer $WIREBLOOM_API_KEY" \
  -H "X-Tenant-Id: $WIREBLOOM_CUSTOMER_ID"

Rotate signing secret (old valid 24 h)

POST /v1/integrator-webhooks/{webhookId}/rotate-secret

  • rotateIntegratorWebhookSecret
  • API key scope webhooks:manage
  • Tenant any

API key scope: webhooks:manage.

Level (P9-T08b): X-Tenant-Id = a customer → that customer's endpoints; X-Tenant-Id = the operator → the operator-level endpoints (sessions of operator owners with webhooks.manage, operator-level keys with webhooks:manage).

Step-up: requires a verified step-up challenge for action integrator_webhook.change within the last 5 minutes (session/bearer only). Otherwise 403 with problem type step-up-required; the step-up check runs before body validation. API keys holding webhooks:manage may call it without a step-up; every create, update, secret rotation and deletion notifies the endpoint owners (webhook_endpoint_changed, staff or customer members with webhooks.manage), whoever made it (review W3-03, P4 S-14).

Parameters

NameInTypeDescription
webhookIdrequiredpathUuid

Identifier (webhookId).

X-Tenant-IdrequiredheaderUuid

Tenant context: the operator tenant id (staff operations) or customer tenant id (customer operations). Validated against the caller's memberships; mismatch → 403. For API keys it must equal the key's customer id (customer-level keys are bound to one customer) or, for operator-level keys (P9-T08b), the operator id.

X-Request-Idheaderstring

Client-supplied correlation id. Generated by the server when absent; always echoed in the response and in problem details.

Responses

  • 200 OK application/json

    Schema IntegratorWebhookCreated

    • id Uuidrequiredread-only

      Fields of id
    • url string (uri)required

    • events array of IntegratorEventTyperequired

    • description string | null

      max length 200

    • enabled booleanrequired

    • secretPrefix stringrequiredread-only

    • createdAt Timestamprequiredread-only

      Fields of createdAt
    • updatedAt Timestamprequiredread-only

      Row version: the ETag is W/"<updatedAt epoch ms>" (If-Match on PATCH).

      Fields of updatedAt
    • lastDeliveryAt Timestamp | null

    • failureCount integerrequiredread-only

      min 0

    • status stringread-only

      paused after 20 consecutive failed attempts or enabled: false; failed when a delivery exhausts 72 h without success. Re-enable with PATCH enabled: true.

      One of: "active", "paused", "failed"

    • pauseReason string | nullread-only

    • secret stringrequired

      Signing secret whsec_..., shown once.

  • 401 Missing, expired or invalid credentials (`unauthenticated`, `session-expired` with `reason` `idle` / `revoked` / `expired`, `invalid-api-key`, `mfa-required`). application/problem+json

    Body Problem; see the error catalogue.

  • 403 Authenticated but not allowed: missing capability or scope, tenant not in memberships, `step-up-required`, IP not allow-listed, impersonation restriction. application/problem+json

    Body Problem; see the error catalogue.

  • 404 Resource does not exist in this tenant (cross-tenant ids also return 404), or feature disabled (`feature-disabled`). application/problem+json

    Body Problem; see the error catalogue.

  • 409 State conflict: `invalid-transition`, `duplicate-recipient`, `quote-expired`, `insufficient-funds`, `idempotency-key-in-use` (with Retry-After), `not-cancellable`. application/problem+json

    Body Problem; see the error catalogue.

  • 429 Rate limit exceeded. application/problem+json

    Body Problem; see the error catalogue.

  • default Unexpected error (`500 internal-error`, `501 not-implemented`, `502 provider-error`, `503 service-unavailable`, `504 provider-timeout`). Money operations that time out at the provider are never retried blindly; their state becomes `exception`/unknown and is reconciled. application/problem+json

    Body Problem; see the error catalogue.

Code samples

Against the sandbox (https://bank.wirebloom.com/v1).

curl -X POST "https://bank.wirebloom.com/v1/integrator-webhooks/{webhookId}/rotate-secret" \
  -H "Authorization: Bearer $WIREBLOOM_API_KEY" \
  -H "X-Tenant-Id: $WIREBLOOM_CUSTOMER_ID"

Send a test event

POST /v1/integrator-webhooks/{webhookId}/test

  • testIntegratorWebhook
  • API key scope webhooks:manage
  • Tenant any

API key scope: webhooks:manage.

Level (P9-T08b): X-Tenant-Id = a customer → that customer's endpoints; X-Tenant-Id = the operator → the operator-level endpoints (sessions of operator owners with webhooks.manage, operator-level keys with webhooks:manage).

Parameters

NameInTypeDescription
webhookIdrequiredpathUuid

Identifier (webhookId).

X-Tenant-IdrequiredheaderUuid

Tenant context: the operator tenant id (staff operations) or customer tenant id (customer operations). Validated against the caller's memberships; mismatch → 403. For API keys it must equal the key's customer id (customer-level keys are bound to one customer) or, for operator-level keys (P9-T08b), the operator id.

X-Request-Idheaderstring

Client-supplied correlation id. Generated by the server when absent; always echoed in the response and in problem details.

Responses

  • 200 OK application/json

    Schema WebhookDelivery

    • id Uuidrequiredread-only

      Fields of id
    • eventId Uuidrequired

    • eventType IntegratorEventTyperequired

    • attempt integerrequired

      min 1

    • statusCode integer | null

    • durationMs integer | null

    • succeeded booleanrequired

    • nextRetryAt Timestamp | null

    • createdAt Timestamprequiredread-only

      Fields of createdAt
  • 401 Missing, expired or invalid credentials (`unauthenticated`, `session-expired` with `reason` `idle` / `revoked` / `expired`, `invalid-api-key`, `mfa-required`). application/problem+json

    Body Problem; see the error catalogue.

  • 403 Authenticated but not allowed: missing capability or scope, tenant not in memberships, `step-up-required`, IP not allow-listed, impersonation restriction. application/problem+json

    Body Problem; see the error catalogue.

  • 404 Resource does not exist in this tenant (cross-tenant ids also return 404), or feature disabled (`feature-disabled`). application/problem+json

    Body Problem; see the error catalogue.

  • 409 State conflict: `invalid-transition`, `duplicate-recipient`, `quote-expired`, `insufficient-funds`, `idempotency-key-in-use` (with Retry-After), `not-cancellable`. application/problem+json

    Body Problem; see the error catalogue.

  • 429 Rate limit exceeded. application/problem+json

    Body Problem; see the error catalogue.

  • default Unexpected error (`500 internal-error`, `501 not-implemented`, `502 provider-error`, `503 service-unavailable`, `504 provider-timeout`). Money operations that time out at the provider are never retried blindly; their state becomes `exception`/unknown and is reconciled. application/problem+json

    Body Problem; see the error catalogue.

Code samples

Against the sandbox (https://bank.wirebloom.com/v1).

curl -X POST "https://bank.wirebloom.com/v1/integrator-webhooks/{webhookId}/test" \
  -H "Authorization: Bearer $WIREBLOOM_API_KEY" \
  -H "X-Tenant-Id: $WIREBLOOM_CUSTOMER_ID"

Simulate an incoming payment

POST /v1/sandbox/incoming-payments

  • simulateSandboxIncomingPayment
  • API key scope payments:write
  • Tenant customer

Sandbox only (wb_test_ keys and sandbox environments); 404 feature-disabled elsewhere.

API key scope: payments:write.

Parameters

NameInTypeDescription
X-Tenant-IdrequiredheaderUuid

Tenant context: the operator tenant id (staff operations) or customer tenant id (customer operations). Validated against the caller's memberships; mismatch → 403. For API keys it must equal the key's customer id (customer-level keys are bound to one customer) or, for operator-level keys (P9-T08b), the operator id.

X-Request-Idheaderstring

Client-supplied correlation id. Generated by the server when absent; always echoed in the response and in problem details.

Idempotency-Keyheaderstring

Optional idempotency key; same semantics as on money operations.

Request body

Required. application/json

Schema SandboxIncomingPayment

  • balanceId Uuidrequired

  • amount Moneyrequired

  • senderName string

    min length 1 · max length 140

  • reference string

    min length 1 · max length 140

Responses

  • 202 Accepted application/json

    Schema SandboxSimulation

    • simulationId Uuidrequired

    • status stringrequired

      One of: "queued"

    • endpoints integer

      min 0

    • objectId Uuid

  • 400 Malformed request: unparseable JSON, or an invalid header, path or query parameter (`errors[].field` is `header.X`, `path.x` or `query.x`). Body validation failures are 422 `validation-error`. application/problem+json

    Body Problem; see the error catalogue.

  • 401 Missing, expired or invalid credentials (`unauthenticated`, `session-expired` with `reason` `idle` / `revoked` / `expired`, `invalid-api-key`, `mfa-required`). application/problem+json

    Body Problem; see the error catalogue.

  • 403 Authenticated but not allowed: missing capability or scope, tenant not in memberships, `step-up-required`, IP not allow-listed, impersonation restriction. application/problem+json

    Body Problem; see the error catalogue.

  • 409 State conflict: `invalid-transition`, `duplicate-recipient`, `quote-expired`, `insufficient-funds`, `idempotency-key-in-use` (with Retry-After), `not-cancellable`. application/problem+json

    Body Problem; see the error catalogue.

  • 422 Semantically invalid request; `errors[]` lists field-level problems. Also `idempotency-key-reused` when the key was used with a different payload, `limit-exceeded`, `recipient-not-approved`. application/problem+json

    Body Problem; see the error catalogue.

  • 429 Rate limit exceeded. application/problem+json

    Body Problem; see the error catalogue.

  • default Unexpected error (`500 internal-error`, `501 not-implemented`, `502 provider-error`, `503 service-unavailable`, `504 provider-timeout`). Money operations that time out at the provider are never retried blindly; their state becomes `exception`/unknown and is reconciled. application/problem+json

    Body Problem; see the error catalogue.

Code samples

Against the sandbox (https://bank.wirebloom.com/v1).

curl -X POST "https://bank.wirebloom.com/v1/sandbox/incoming-payments" \
  -H "Authorization: Bearer $WIREBLOOM_API_KEY" \
  -H "X-Tenant-Id: $WIREBLOOM_CUSTOMER_ID" \
  -H "Content-Type: application/json" \
  --data '{
  "balanceId": "0192a6f0-7c1e-7b3a-9d2e-5f4c3b2a1908",
  "amount": {
    "amountMinor": "125050",
    "currency": "GBP"
  }
}'

Simulate a provider status for a payment

POST /v1/sandbox/payments/{paymentId}/status

  • simulateSandboxPaymentStatus
  • API key scope payments:write
  • Tenant customer

Sandbox only (wb_test_ keys and sandbox environments); 404 feature-disabled elsewhere.

API key scope: payments:write.

Parameters

NameInTypeDescription
paymentIdrequiredpathUuid

Identifier (paymentId).

X-Tenant-IdrequiredheaderUuid

Tenant context: the operator tenant id (staff operations) or customer tenant id (customer operations). Validated against the caller's memberships; mismatch → 403. For API keys it must equal the key's customer id (customer-level keys are bound to one customer) or, for operator-level keys (P9-T08b), the operator id.

X-Request-Idheaderstring

Client-supplied correlation id. Generated by the server when absent; always echoed in the response and in problem details.

Idempotency-Keyheaderstring

Optional idempotency key; same semantics as on money operations.

Request body

Required. application/json

Schema SandboxPaymentStatus

  • status stringrequired

    One of: "processing", "completed", "rejected", "cancelled", "returned"

Responses

  • 202 Accepted application/json

    Schema SandboxSimulation

    • simulationId Uuidrequired

    • status stringrequired

      One of: "queued"

    • endpoints integer

      min 0

    • objectId Uuid

  • 400 Malformed request: unparseable JSON, or an invalid header, path or query parameter (`errors[].field` is `header.X`, `path.x` or `query.x`). Body validation failures are 422 `validation-error`. application/problem+json

    Body Problem; see the error catalogue.

  • 401 Missing, expired or invalid credentials (`unauthenticated`, `session-expired` with `reason` `idle` / `revoked` / `expired`, `invalid-api-key`, `mfa-required`). application/problem+json

    Body Problem; see the error catalogue.

  • 403 Authenticated but not allowed: missing capability or scope, tenant not in memberships, `step-up-required`, IP not allow-listed, impersonation restriction. application/problem+json

    Body Problem; see the error catalogue.

  • 404 Resource does not exist in this tenant (cross-tenant ids also return 404), or feature disabled (`feature-disabled`). application/problem+json

    Body Problem; see the error catalogue.

  • 409 State conflict: `invalid-transition`, `duplicate-recipient`, `quote-expired`, `insufficient-funds`, `idempotency-key-in-use` (with Retry-After), `not-cancellable`. application/problem+json

    Body Problem; see the error catalogue.

  • 422 Semantically invalid request; `errors[]` lists field-level problems. Also `idempotency-key-reused` when the key was used with a different payload, `limit-exceeded`, `recipient-not-approved`. application/problem+json

    Body Problem; see the error catalogue.

  • 429 Rate limit exceeded. application/problem+json

    Body Problem; see the error catalogue.

  • default Unexpected error (`500 internal-error`, `501 not-implemented`, `502 provider-error`, `503 service-unavailable`, `504 provider-timeout`). Money operations that time out at the provider are never retried blindly; their state becomes `exception`/unknown and is reconciled. application/problem+json

    Body Problem; see the error catalogue.

Code samples

Against the sandbox (https://bank.wirebloom.com/v1).

curl -X POST "https://bank.wirebloom.com/v1/sandbox/payments/{paymentId}/status" \
  -H "Authorization: Bearer $WIREBLOOM_API_KEY" \
  -H "X-Tenant-Id: $WIREBLOOM_CUSTOMER_ID" \
  -H "Content-Type: application/json" \
  --data '{
  "status": "processing"
}'

Reset sandbox deliveries and paused endpoints

POST /v1/sandbox/reset

  • resetSandbox
  • API key scope webhooks:manage
  • Tenant customer

Sandbox only (wb_test_ keys and sandbox environments); 404 feature-disabled elsewhere.

API key scope: webhooks:manage.

Parameters

NameInTypeDescription
X-Tenant-IdrequiredheaderUuid

Tenant context: the operator tenant id (staff operations) or customer tenant id (customer operations). Validated against the caller's memberships; mismatch → 403. For API keys it must equal the key's customer id (customer-level keys are bound to one customer) or, for operator-level keys (P9-T08b), the operator id.

X-Request-Idheaderstring

Client-supplied correlation id. Generated by the server when absent; always echoed in the response and in problem details.

Responses

  • 200 OK application/json

    Schema SandboxReset

    • deliveriesDeleted integerrequired

      min 0

    • endpointsReactivated integerrequired

      min 0

  • 401 Missing, expired or invalid credentials (`unauthenticated`, `session-expired` with `reason` `idle` / `revoked` / `expired`, `invalid-api-key`, `mfa-required`). application/problem+json

    Body Problem; see the error catalogue.

  • 403 Authenticated but not allowed: missing capability or scope, tenant not in memberships, `step-up-required`, IP not allow-listed, impersonation restriction. application/problem+json

    Body Problem; see the error catalogue.

  • 409 State conflict: `invalid-transition`, `duplicate-recipient`, `quote-expired`, `insufficient-funds`, `idempotency-key-in-use` (with Retry-After), `not-cancellable`. application/problem+json

    Body Problem; see the error catalogue.

  • 429 Rate limit exceeded. application/problem+json

    Body Problem; see the error catalogue.

  • default Unexpected error (`500 internal-error`, `501 not-implemented`, `502 provider-error`, `503 service-unavailable`, `504 provider-timeout`). Money operations that time out at the provider are never retried blindly; their state becomes `exception`/unknown and is reconciled. application/problem+json

    Body Problem; see the error catalogue.

Code samples

Against the sandbox (https://bank.wirebloom.com/v1).

curl -X POST "https://bank.wirebloom.com/v1/sandbox/reset" \
  -H "Authorization: Bearer $WIREBLOOM_API_KEY" \
  -H "X-Tenant-Id: $WIREBLOOM_CUSTOMER_ID"

Emit an integrator event

POST /v1/sandbox/webhook-events

  • simulateSandboxWebhookEvent
  • API key scope webhooks:manage
  • Tenant customer

Sandbox only (wb_test_ keys and sandbox environments); 404 feature-disabled elsewhere. Events carry data.sandbox: true.

API key scope: webhooks:manage.

Parameters

NameInTypeDescription
X-Tenant-IdrequiredheaderUuid

Tenant context: the operator tenant id (staff operations) or customer tenant id (customer operations). Validated against the caller's memberships; mismatch → 403. For API keys it must equal the key's customer id (customer-level keys are bound to one customer) or, for operator-level keys (P9-T08b), the operator id.

X-Request-Idheaderstring

Client-supplied correlation id. Generated by the server when absent; always echoed in the response and in problem details.

Idempotency-Keyheaderstring

Optional idempotency key; same semantics as on money operations.

Request body

Required. application/json

Schema SandboxWebhookEvent

Responses

  • 202 Accepted application/json

    Schema SandboxSimulation

    • simulationId Uuidrequired

    • status stringrequired

      One of: "queued"

    • endpoints integer

      min 0

    • objectId Uuid

  • 400 Malformed request: unparseable JSON, or an invalid header, path or query parameter (`errors[].field` is `header.X`, `path.x` or `query.x`). Body validation failures are 422 `validation-error`. application/problem+json

    Body Problem; see the error catalogue.

  • 401 Missing, expired or invalid credentials (`unauthenticated`, `session-expired` with `reason` `idle` / `revoked` / `expired`, `invalid-api-key`, `mfa-required`). application/problem+json

    Body Problem; see the error catalogue.

  • 403 Authenticated but not allowed: missing capability or scope, tenant not in memberships, `step-up-required`, IP not allow-listed, impersonation restriction. application/problem+json

    Body Problem; see the error catalogue.

  • 409 State conflict: `invalid-transition`, `duplicate-recipient`, `quote-expired`, `insufficient-funds`, `idempotency-key-in-use` (with Retry-After), `not-cancellable`. application/problem+json

    Body Problem; see the error catalogue.

  • 422 Semantically invalid request; `errors[]` lists field-level problems. Also `idempotency-key-reused` when the key was used with a different payload, `limit-exceeded`, `recipient-not-approved`. application/problem+json

    Body Problem; see the error catalogue.

  • 429 Rate limit exceeded. application/problem+json

    Body Problem; see the error catalogue.

  • default Unexpected error (`500 internal-error`, `501 not-implemented`, `502 provider-error`, `503 service-unavailable`, `504 provider-timeout`). Money operations that time out at the provider are never retried blindly; their state becomes `exception`/unknown and is reconciled. application/problem+json

    Body Problem; see the error catalogue.

Code samples

Against the sandbox (https://bank.wirebloom.com/v1).

curl -X POST "https://bank.wirebloom.com/v1/sandbox/webhook-events" \
  -H "Authorization: Bearer $WIREBLOOM_API_KEY" \
  -H "X-Tenant-Id: $WIREBLOOM_CUSTOMER_ID" \
  -H "Content-Type: application/json" \
  --data '{
  "type": "webhook.test"
}'