Create an approval request for a gated transaction
Authorization
apiKey Merchant API key. Publishable keys (pk_test_* / pk_live_) are safe for browser/frontend use and carry a limited scope set (sessions, payment_instruments, customers, orders writes; products, product_prices, payment_links reads). Secret keys (sk_test_ / sk_live_*) grant full admin access and must only be used server-side.
In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://loading/v1/api/treasury/approval-requests" \ -H "Content-Type: application/json" \ -d '{ "transaction_id": "0fec1e58-b197-4052-99cf-2218496c5482", "security_rule_id": "bc6a5d12-7116-49c7-98fb-50c5b1f930e1" }'{
"success": true,
"timestamp": "2019-08-24T14:15:22Z",
"data": null,
"message": "string",
"pagination": {
"total": 0,
"limit": 1,
"offset": 0,
"has_more": true,
"truncated": true,
"cursors": {
"first": "string",
"last": "string"
}
}
}{
"success": false,
"timestamp": "2019-08-24T14:15:22Z",
"error": {
"code": "string",
"message": "string",
"details": null
}
}{
"success": false,
"timestamp": "2019-08-24T14:15:22Z",
"error": {
"code": "string",
"message": "string",
"details": null
}
}{
"success": false,
"timestamp": "2019-08-24T14:15:22Z",
"error": {
"code": "string",
"message": "string",
"details": null
}
}{
"success": false,
"timestamp": "2019-08-24T14:15:22Z",
"error": {
"code": "string",
"message": "string",
"details": null
}
}Accept recipient invitation (public)
Public endpoint. Validates invitation token, accepts banking details submitted by the recipient, tokenizes account number via Basis Theory, and marks invitation as completed.
Link uploaded attachments to a treasury transaction
Persist metadata rows in `transaction_attachments` for files already uploaded via /v1/auth/attachments/upload. Ownership is enforced both per-path (first segment must equal caller's company_id) and per-transaction (transaction must belong to caller's company).