Send the money

This is the step that moves money. It debits your balance and
returns the payout. There is no separate funding or signing step.

If this times out, the outcome is unknown — the payout may have been
accepted. Retry with the same Idempotency-Key. A replay returns
the original payout; re-quoting sends a second payment.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
string
required
length ≥ 1

The opaque organization id issued to you, normally CUID-shaped (for
example cmsx…). It is not an org_-prefixed alias. Pass it unchanged
in every organization-scoped path.

Body Params
string
required
length ≥ 1

The snapshot's id from the pricing step.

string
length ≥ 1

The snapshot's best_quote_id.

const
enum
required
Allowed:
string
^[A-Za-z0-9 :-]*$

Your payment reference. Echoed back and searchable.

endUser
object

Who you are paying on behalf of. Attribution only — it is not forwarded
to the payment network and does not change the sender of record, which
stays your organization. Echoed on the payout and in every webhook, so a
support question is answerable without your own id map.

files
array of strings

Compliance attachments as data URIs. Each item is
data:<mime>;base64,<contents>; use PDF, JPEG, or PNG, up
to 5 MB each. Some regulated corridors require an invoice.
When both files and attachment are sent, files wins.

files
string
^data:(application/pdf|image/jpeg|image/png);base64,.+$

Single-attachment convenience using the same data-URI format as files.

string
enum

Fixed compliance catalogue used by the two-step quote-accept flow.

string

Free-text note forwarded to compliance.

date-time

When the supporting document was attested as genuine.

string

Name of the person who made the attestation.

Headers
string
required
length between 1 and 255
^[A-Za-z0-9_.:-]+$

A unique value per logical operation, 1-255 chars of A-Z a-z 0-9 _ . : -.

Reuse it to retry. Same key with the same body replays the stored
response; same key with a different body is a 409, because
answering with the first call's result would hand you a receipt for a
payout you did not request. A 4xx releases the key, so you can fix the
body and reuse it.

Reuse it — do not generate one per attempt. A key minted per attempt
defeats replay entirely: every retry looks like a new request, so every
retry pays. We also watch for an identical body arriving under a
different key within 15 minutes and refuse it with
DUPLICATE_REQUEST_DETECTED.

Records are kept for 7 days. That is a retention window, not a
correctness one — there is no path where an expired key is re-executed.

string
enum

Set to true to send a request that is byte-identical to one you sent
seconds ago under a different key. Only set it deliberately: it switches
off the guard that catches a retry arriving under a fresh key.

Allowed:
Responses

Language
Credentials
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json