The API for your account
The Internet banking API is in beta, available only to users invited by the bank. Contracts, scopes and behaviour may still change without the deprecation cycle of the production BaaS API. If unsure, talk to the bank or CorpX support before going to production.
The bank where you hold an account offers internet banking. From there, the account holder can issue a credential so your system — ERP, site, billing app — can talk to the account without using the UI.
This documentation is for whoever received that credential. You are not becoming a bank and you do not operate other people’s accounts: the credential reaches one account, the one the holder authorised.
Who is who
Credential, IP, public-key and outgoing-lock problems are solved in the bank’s internet banking. The API only accepts or refuses what is already configured.
What is different from a BaaS integrator
CorpX integrators use https://tenant.api.corpx.com and a token. Your
credential is different: the token alone is not enough. Every /v1/** call
goes to https://client.api.corpx.com and carries a JWS made with the
private key that stayed on your server.
The reason is simple. The OAuth token is a bearer — whoever copies it from a log or a proxy can use it until it expires. The private key never leaves your server, so a leaked token without it cannot move money.
What you received
At issuance the internet banking shows (once) and you store:
The credential only accepts calls after 18 hours (activeFrom). Until
then the response is 403 credential_not_yet_active. Revoking in the bank
UI takes effect immediately. The grace period exists so a human can see an
alert if someone issued a credential the holder did not want.
Short glossary
Next step
Follow the Quick start: token, signature self-test
and the first balance. If an agent or LLM will integrate for you, ask it to
read For agents and
openapi.yaml filtered by
x-audience containing ib.