Bank Onboarding
The bank's onboarding administrator completes the bank's onboarding case with these
operations. At most one case exists per bank. A case is editable in the states
AWAITING_BANK_ADMIN, BANK_CONFIGURING and NEEDS_CHANGES; the first edit moves
AWAITING_BANK_ADMIN to BANK_CONFIGURING.
GET /v1/onboarding-casesto find thecase_id, thenGET /v1/onboarding-cases/{case_id}/key-requirementsto see which keys are needed.- Provide the three signing keys (
BANK_ADMIN,CREATE_INTERBANK_TRANSFER_MAKER,APPROVE_INTERBANK_TRANSFER_CHECKER) and the key-encryption key (ENCRYPT_TRANSFER_SOURCE_MESSAGE). Either register keys you hold (POST .../signing-targetsandPOST .../encryption-targets, thenPOST .../{target_id}/verifyto prove the platform can use each key), or let the platform generate them (POST .../key-generation-jobs, then poll the job until every item isREADY). Every key must endVERIFIED. - Add staff members (
POST .../staff-members); at least one needs thebank-adminlabel. - Configure webhooks (
PUT .../webhook-setup): enabled, subscribed tobeneficiary.screening.requested, with a signing secret. - Optionally declare machine-to-machine workloads (
PUT .../m2m-clients). POST .../submit-configurationmoves the case toREADY_FOR_REVIEW. The case is then no longer editable.readiness.ready_for_reviewon the case tells you in advance whether submission will succeed.
The platform operator then accepts the case, which creates an activation operation
(activation_operation_id, state AWAITING_APPROVALS). After approval the case moves to
PROVISIONING, and to ACTIVE once staff and workloads are provisioned in the platform
IAM. REJECTED and FAILED are end states.
List the calling bank's onboarding cases
Returns the onboarding case of the calling bank. An *onboarding case* is the record the
Get one of the calling bank's onboarding cases
Returns the onboarding case, its saved configuration and its `readiness` checklist.
Replace the M2M workloads of an onboarding case
Declares the bank's machine-to-machine (M2M) workloads: back-end systems that call
Configure webhook delivery for an onboarding case
Saves the webhook subscription the platform creates for your bank when onboarding is
Get the mandatory onboarding key requirements
Returns the catalogue of keys the bank must provide before it can submit its
List key-generation jobs for an onboarding case
Lists the most recent key-generation jobs for the case, newest first, with the
Generate missing onboarding keys
Asks the platform to create the requested keys in the AWS KMS account configured for
Get the progress of a key-generation job
Returns the job with the current state of each key allocation. Poll this endpoint
List the bank's signing targets for an onboarding case
Lists the signing targets registered for the case, oldest first (by `created_at`, then
Register a bank signing key for an onboarding case
Registers a reference to a signing key the bank holds, for one purpose. The key
Get a bank signing target
Returns one signing target with its key reference and verification status. After a
Verify a bank signing target
Proves that the registered reference points at the key you described. The platform
List the bank's encryption targets for an onboarding case
Lists the encryption targets registered for the case, oldest first (by `created_at`,
Register the bank's key-encryption key for an onboarding case
Registers the bank-held key-encryption key. The key stays in the bank's AWS account;
Get a bank encryption target
Returns one encryption target with its key ARN and verification status. After a
Verify a bank encryption target
Proves that the platform can use the registered key-encryption key. The platform
Submit the bank's onboarding configuration for operator review
Declares the bank's part of onboarding complete and moves the case to