> ## Documentation Index
> Fetch the complete documentation index at: https://docs.conduit.financial/llms.txt
> Use this file to discover all available pages before exploring further.

# Simulate a Conduit compliance RFI on a sandbox customer

> Opens a request for information about one of your customers, as Conduit compliance does. The RFI is `open` with one round that carries your `ask`, every user of your organization is a recipient, and `rfi.published` fires. Read it with `GET /v2/rfis/{id}`, answer it with `POST /v2/rfis/{id}/responses`, and close it with `POST /v2/sandbox/rfis/{id}/simulate/resolve` or ask again with `POST /v2/sandbox/rfis/{id}/simulate/more-info`. `dueAt` is optional and is 48 hours from now when you do not send it. A customer that your organization does not own returns 404 `CUSTOMER_NOT_FOUND`.



## OpenAPI

````yaml https://api.sandbox.conduit.financial/v2/api-docs/openapi.json post /sandbox/rfis/simulate
openapi: 3.0.0
info:
  title: Conduit Sandbox API
  description: >-
    **Sandbox API** — clients integrate against this surface to exercise happy
    and unhappy paths without consuming real KYC/PSP credits or moving real
    money. Customer KYC, banking partners, and crypto custody are stubbed;
    org-level KYB runs against real providers. Simulation endpoints under
    `/v2/sandbox/*` drive specific scenarios.


    Internal and portal endpoints are excluded from this spec.
  version: '2.0'
  contact: {}
servers:
  - url: https://api.sandbox.conduit.financial/v2
    description: Sandbox
  - url: https://api.conduit.financial/v2
    description: Production
security:
  - api-key: []
tags:
  - name: Customers
  - name: Registered Addresses
  - name: Wallets
  - name: Wallet Signers
  - name: Signing Quorum
  - name: Virtual Accounts
  - name: Applications
  - name: RFIs
  - name: Documents
  - name: Verifications
  - name: Signing Requests
  - name: Transactions
  - name: Payouts
  - name: Whitelist Recipients
  - name: Orders
  - name: Asset Chain Pairs
  - name: Quotes
  - name: Webhook Endpoints
  - name: Webhook Deliveries
  - name: Webhook Event Types
  - name: Features
  - name: Customer Onboarding
  - name: Markup
  - name: Sandbox
paths:
  /sandbox/rfis/simulate:
    post:
      tags:
        - Sandbox
      summary: Simulate a Conduit compliance RFI on a sandbox customer
      description: >-
        Opens a request for information about one of your customers, as Conduit
        compliance does. The RFI is `open` with one round that carries your
        `ask`, every user of your organization is a recipient, and
        `rfi.published` fires. Read it with `GET /v2/rfis/{id}`, answer it with
        `POST /v2/rfis/{id}/responses`, and close it with `POST
        /v2/sandbox/rfis/{id}/simulate/resolve` or ask again with `POST
        /v2/sandbox/rfis/{id}/simulate/more-info`. `dueAt` is optional and is 48
        hours from now when you do not send it. A customer that your
        organization does not own returns 404 `CUSTOMER_NOT_FOUND`.
      operationId: RfiSandboxController_simulateOpen_v2
      parameters: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SimulateOpenRfiBodyDto'
      responses:
        '201':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ClientRfiDetailDto'
        '400':
          description: >-
            **INVALID_OID_FORMAT**: A path or query parameter expected a valid
            object identifier but received a value that does not match the
            expected format.


            **VALIDATION_ERROR**: The request body or query parameters failed
            validation. One or more fields have invalid values, missing required
            properties, or incorrect types. A required text field that holds
            only spaces counts as missing. Multipart file uploads that fail at
            the multipart-parser layer (unexpected form-field name, too many
            parts) carry an extra 'field' member naming the offending
            form-field.


            **MALFORMED_JSON**: The request body could not be parsed as JSON.
            Bodies declared as 'application/json' — and bodies with no
            Content-Type header, which are assumed to be JSON — must contain
            syntactically valid JSON.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationErrorDto'
              example:
                type: INVALID_OID_FORMAT
                title: Invalid Object ID Format
                status: 400
                detail: >-
                  A path or query parameter expected a valid object identifier
                  but received a value that does not match the expected format.
                resolution: >-
                  Verify that all IDs in the request URL and query parameters
                  are correctly formatted. IDs are typically prefixed strings
                  like 'cus_...', 'app_...', or 'doc_...'.
                docs: https://conduit-v2.mintlify.app/errors#invalid-oid-format
                instance: /v2/...
                correlationId: 00469ea4-52c1-4ffa-bd05-9f28b236a5fe
                timestamp: '2026-01-15T09:30:00.000Z'
        '401':
          description: >-
            **API_KEY_MISSING**: The request did not include an API key. All API
            requests must be authenticated.


            **API_KEY_INVALID**: The provided API key is not recognized or has
            been revoked.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ProblemDetailDto'
              example:
                type: API_KEY_MISSING
                title: API Key Missing
                status: 401
                detail: >-
                  The request did not include an API key. All API requests must
                  be authenticated.
                resolution: >-
                  Include your API key in the 'x-api-key' header with every
                  request.
                docs: https://conduit-v2.mintlify.app/errors#api-key-missing
                instance: /v2/...
                correlationId: 00469ea4-52c1-4ffa-bd05-9f28b236a5fe
                timestamp: '2026-01-15T09:30:00.000Z'
        '403':
          description: >-
            **ORGANIZATION_ACCESS_SUSPENDED**: Conduit has suspended this
            organization's access. Requests with the organization's API keys and
            from its users are refused until Conduit restores access.


            **API_KEY_READ_ONLY**: This API key has read-only access and cannot
            perform write operations. Read-only keys may make read requests
            (GET, HEAD, OPTIONS) only.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ProblemDetailDto'
              example:
                type: ORGANIZATION_ACCESS_SUSPENDED
                title: Organization Access Suspended
                status: 403
                detail: >-
                  Conduit has suspended this organization's access. Requests
                  with the organization's API keys and from its users are
                  refused until Conduit restores access.
                resolution: Contact Conduit support.
                docs: >-
                  https://conduit-v2.mintlify.app/errors#organization-access-suspended
                instance: /v2/...
                correlationId: 00469ea4-52c1-4ffa-bd05-9f28b236a5fe
                timestamp: '2026-01-15T09:30:00.000Z'
        '404':
          description: >-
            **CUSTOMER_NOT_FOUND**: No customer exists with the specified ID, or
            the customer belongs to a different organization.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ProblemDetailDto'
              example:
                type: CUSTOMER_NOT_FOUND
                title: Customer Not Found
                status: 404
                detail: >-
                  No customer exists with the specified ID, or the customer
                  belongs to a different organization.
                resolution: >-
                  Verify the customer ID is correct. Use the list customers
                  endpoint to find valid customer IDs for your organization.
                docs: https://conduit-v2.mintlify.app/errors#customer-not-found
                instance: /v2/...
                correlationId: 00469ea4-52c1-4ffa-bd05-9f28b236a5fe
                timestamp: '2026-01-15T09:30:00.000Z'
        '415':
          description: >-
            **UNSUPPORTED_MEDIA_TYPE**: The request carries a body with a
            Content-Type this endpoint cannot parse. JSON endpoints accept
            'application/json'; a body with no Content-Type header at all is
            assumed to be JSON. File-upload endpoints accept only
            'multipart/form-data' — JSON or undeclared bodies are rejected
            there.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ProblemDetailDto'
              example:
                type: UNSUPPORTED_MEDIA_TYPE
                title: Unsupported Media Type
                status: 415
                detail: >-
                  The request carries a body with a Content-Type this endpoint
                  cannot parse. JSON endpoints accept 'application/json'; a body
                  with no Content-Type header at all is assumed to be JSON.
                  File-upload endpoints accept only 'multipart/form-data' — JSON
                  or undeclared bodies are rejected there.
                resolution: >-
                  Send the request body with the 'Content-Type:
                  application/json' header. For file uploads, use 'Content-Type:
                  multipart/form-data' — upload endpoints accept no other body
                  type.
                docs: https://conduit-v2.mintlify.app/errors#unsupported-media-type
                instance: /v2/...
                correlationId: 00469ea4-52c1-4ffa-bd05-9f28b236a5fe
                timestamp: '2026-01-15T09:30:00.000Z'
        '429':
          description: >-
            **RATE_LIMITED**: Too many requests. This error is returned by three
            independent checks: the per-organization bucket applied to every
            authenticated API request; the per-IP bucket applied to
            unauthenticated traffic before an API key is validated; and the
            per-IP bucket applied when repeated invalid API keys are submitted
            from the same address. Honor the Retry-After header (also exposed as
            retryAfterSeconds in the body) before retrying. Current limits and
            remaining budget are visible in X-RateLimit-Limit (the bucket size),
            X-RateLimit-Remaining, and X-RateLimit-Reset (seconds until the
            bucket refills) on every response once your API key is accepted.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RateLimitedErrorDto'
              example:
                type: RATE_LIMITED
                title: Rate Limited
                status: 429
                detail: >-
                  Too many requests. This error is returned by three independent
                  checks: the per-organization bucket applied to every
                  authenticated API request; the per-IP bucket applied to
                  unauthenticated traffic before an API key is validated; and
                  the per-IP bucket applied when repeated invalid API keys are
                  submitted from the same address. Honor the Retry-After header
                  (also exposed as retryAfterSeconds in the body) before
                  retrying. Current limits and remaining budget are visible in
                  X-RateLimit-Limit (the bucket size), X-RateLimit-Remaining,
                  and X-RateLimit-Reset (seconds until the bucket refills) on
                  every response once your API key is accepted.
                resolution: >-
                  Sleep until Retry-After seconds have elapsed, then retry. For
                  sustained workloads exceeding the per-organization defaults,
                  request a rate-limit increase through your support contact.
                docs: https://conduit-v2.mintlify.app/errors#rate-limited
                instance: /v2/...
                correlationId: 00469ea4-52c1-4ffa-bd05-9f28b236a5fe
                timestamp: '2026-01-15T09:30:00.000Z'
                retryAfterSeconds: 3
        '500':
          description: >-
            **INTERNAL_ERROR**: An unexpected error occurred while processing
            your request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ProblemDetailDto'
              example:
                type: INTERNAL_ERROR
                title: Internal Error
                status: 500
                detail: An unexpected error occurred while processing your request.
                resolution: >-
                  Retry the request after a brief delay. If the error persists,
                  contact support and include the correlationId from the error
                  response for investigation.
                docs: https://conduit-v2.mintlify.app/errors#internal-error
                instance: /v2/...
                correlationId: 00469ea4-52c1-4ffa-bd05-9f28b236a5fe
                timestamp: '2026-01-15T09:30:00.000Z'
components:
  schemas:
    SimulateOpenRfiBodyDto:
      type: object
      properties:
        customerId:
          type: string
          pattern: ^cus_[0-9A-Za-z]{22}$
          description: The customer the RFI asks about.
        title:
          description: Short title of the RFI. Defaults to "Request for information".
          type: string
          minLength: 1
          maxLength: 255
        ask:
          type: string
          minLength: 1
          maxLength: 10000
          description: The question to ask, in your own words.
        dueAt:
          type: string
          format: date-time
          description: When the answer is due. Defaults to 48 hours from now.
          example: '2026-01-15T09:30:00.000Z'
      required:
        - customerId
        - ask
      additionalProperties: false
    ClientRfiDetailDto:
      type: object
      properties:
        id:
          type: string
          pattern: ^rfi_[0-9A-Za-z]{22}$
          description: Identifier of the request for information.
        subjects:
          type: array
          items:
            type: object
            properties:
              subjectType:
                description: What the request is about.
                type: string
                enum:
                  - customer
                  - transaction
                  - organization
                  - application
              subjectId:
                type: string
                description: >-
                  Identifier of the subject. Its prefix follows `subjectType`:
                  `cus_` for a customer, `txn_` for a transaction, `app_` for an
                  application, `org_` for an organization.
              customerId:
                description: >-
                  The customer the transaction or application belongs to.
                  Present when `subjectType` is `transaction`, or `application`
                  for a customer's application.
                type: string
                pattern: ^cus_[0-9A-Za-z]{22}$
            required:
              - subjectType
              - subjectId
          description: What the request is about — one entry per subject.
        status:
          description: >-
            Where the request stands. It stays open until every round is
            answered and a reviewer closes it.
          type: string
          enum:
            - draft
            - open
            - responded
            - resolved
            - cancelled
        title:
          type: string
          description: Short reviewer-written label summarising what is being asked.
        dueAt:
          description: >-
            When the earliest unanswered round is due, when one carries a due
            date.
          type: string
          format: date-time
          example: '2026-01-15T09:30:00.000Z'
        publishedAt:
          type: string
          format: date-time
          description: When the request was sent to you.
          example: '2026-01-15T09:30:00.000Z'
        createdAt:
          type: string
          format: date-time
          description: When the request record was created.
          example: '2026-01-15T09:30:00.000Z'
        updatedAt:
          type: string
          format: date-time
          description: >-
            When the request last changed — a new round, a new answer, or a
            status change.
          example: '2026-01-15T09:30:00.000Z'
        summary:
          description: Reviewer-written context for the request, when one was given.
          type: string
        rounds:
          type: array
          items:
            type: object
            properties:
              id:
                type: string
                pattern: ^rnd_[0-9A-Za-z]{22}$
                description: Identifier of this round.
              roundNumber:
                type: integer
                minimum: -9007199254740991
                maximum: 9007199254740991
                description: >-
                  Position of this round in the request, starting at 1. A
                  reviewer opens a new round when the previous answer did not
                  settle the question.
              status:
                description: >-
                  Whether this round is still awaiting an answer or has been
                  closed by a reviewer.
                type: string
                enum:
                  - open
                  - responded
                  - closed
              ask:
                type: string
                description: >-
                  The question to answer, in the reviewer's own words. Show it
                  to whoever prepares the reply, and answer it with `POST
                  /v2/rfis/{rfiId}/responses`.
              dueAt:
                type: string
                format: date-time
                description: >-
                  When the answer is due. Passing it does not close the round by
                  itself.
                example: '2026-01-15T09:30:00.000Z'
              openedAt:
                type: string
                format: date-time
                description: When this round started.
                example: '2026-01-15T09:30:00.000Z'
              closedAt:
                description: When a reviewer closed this round. Absent while it is open.
                type: string
                format: date-time
                example: '2026-01-15T09:30:00.000Z'
            required:
              - id
              - roundNumber
              - status
              - ask
              - dueAt
              - openedAt
          description: Every round on this request, oldest first.
        responses:
          type: array
          items:
            type: object
            properties:
              id:
                type: string
                pattern: ^rfr_[0-9A-Za-z]{22}$
                description: Identifier of this answer.
              roundId:
                type: string
                pattern: ^rnd_[0-9A-Za-z]{22}$
                description: The round this answer belongs to.
              message:
                type: string
                description: >-
                  The answer text as it was submitted, with invisible formatting
                  characters removed.
              documentIds:
                type: array
                items:
                  type: string
                description: >-
                  Documents attached to this answer, uploaded with `POST
                  /v2/documents`. Each id has the form `doc_` followed by 22
                  alphanumeric characters.
              channel:
                description: >-
                  How the answer reached Conduit — through the API, or recorded
                  by a reviewer who received it another way.
                type: string
                enum:
                  - portal
                  - api
              submittedByEmail:
                type: string
                format: email
                description: Email address of whoever submitted the answer.
              submittedByName:
                description: Name of whoever submitted the answer, when one was given.
                type: string
              createdAt:
                type: string
                format: date-time
                description: When the answer was submitted.
                example: '2026-01-15T09:30:00.000Z'
            required:
              - id
              - roundId
              - message
              - documentIds
              - channel
              - submittedByEmail
              - createdAt
          description: Every answer submitted so far, across all rounds.
      required:
        - id
        - subjects
        - status
        - title
        - publishedAt
        - createdAt
        - updatedAt
        - rounds
        - responses
    ValidationErrorDto:
      type: object
      properties:
        type:
          type: string
          description: Machine-readable error code
          example: CUSTOMER_NOT_FOUND
        title:
          type: string
          description: Human-readable error type label
          example: Customer Not Found
        status:
          type: number
          description: HTTP status code
          example: 404
        detail:
          type: string
          description: Human-readable explanation of this occurrence
          example: Customer with id cus_034A0gCCVsxdV2PjHLx9k1 not found
        resolution:
          type: string
          description: What the developer should do to resolve this error
          example: >-
            Verify the customer ID. Check you are using the correct API key for
            this organization.
        docs:
          type: string
          description: URL to error documentation
          example: https://conduit-v2.mintlify.app/errors#customer-not-found
        instance:
          type: string
          description: Request path that produced the error
          example: /v2/customers/cus_034A0gCCVsxdV2PjHLx9k1
        correlationId:
          description: Request correlation ID
          example: 00469ea4-52c1-4ffa-bd05-9f28b236a5fe
          type: string
        timestamp:
          type: string
          description: ISO 8601 UTC timestamp
          example: '2026-04-27T20:00:00.000Z'
        details:
          description: >-
            Additional structured data for domain-specific errors (e.g. missing
            field lists, pair info)
        errors:
          type: array
          items:
            type: object
            properties:
              pointer:
                type: string
                description: JSON pointer to the invalid field
                example: /email
              detail:
                type: string
                description: What is wrong with this field
                example: Invalid email format
              allowedValues:
                description: The values this field accepts, when it is a closed set
                example:
                  - ach
                  - fedwire
                  - rtp
                type: array
                items:
                  type: string
              category:
                description: >-
                  Class of blocker (requirements-validator output only). 'field'
                  = form-field gap, 'document' = missing or insufficient
                  document (including per-UBO document slots), 'individual' =
                  required person missing.
                example: field
                type: string
                enum:
                  - field
                  - document
                  - individual
            required:
              - pointer
              - detail
      required:
        - type
        - title
        - status
        - detail
        - resolution
        - docs
        - instance
        - timestamp
    ProblemDetailDto:
      type: object
      properties:
        type:
          type: string
          description: Machine-readable error code
          example: CUSTOMER_NOT_FOUND
        title:
          type: string
          description: Human-readable error type label
          example: Customer Not Found
        status:
          type: number
          description: HTTP status code
          example: 404
        detail:
          type: string
          description: Human-readable explanation of this occurrence
          example: Customer with id cus_034A0gCCVsxdV2PjHLx9k1 not found
        resolution:
          type: string
          description: What the developer should do to resolve this error
          example: >-
            Verify the customer ID. Check you are using the correct API key for
            this organization.
        docs:
          type: string
          description: URL to error documentation
          example: https://conduit-v2.mintlify.app/errors#customer-not-found
        instance:
          type: string
          description: Request path that produced the error
          example: /v2/customers/cus_034A0gCCVsxdV2PjHLx9k1
        correlationId:
          description: Request correlation ID
          example: 00469ea4-52c1-4ffa-bd05-9f28b236a5fe
          type: string
        timestamp:
          type: string
          description: ISO 8601 UTC timestamp
          example: '2026-04-27T20:00:00.000Z'
        details:
          description: >-
            Additional structured data for domain-specific errors (e.g. missing
            field lists, pair info)
      required:
        - type
        - title
        - status
        - detail
        - resolution
        - docs
        - instance
        - timestamp
    RateLimitedErrorDto:
      type: object
      properties:
        type:
          type: string
          description: Machine-readable error code
          example: CUSTOMER_NOT_FOUND
        title:
          type: string
          description: Human-readable error type label
          example: Customer Not Found
        status:
          type: number
          description: HTTP status code
          example: 404
        detail:
          type: string
          description: Human-readable explanation of this occurrence
          example: Customer with id cus_034A0gCCVsxdV2PjHLx9k1 not found
        resolution:
          type: string
          description: What the developer should do to resolve this error
          example: >-
            Verify the customer ID. Check you are using the correct API key for
            this organization.
        docs:
          type: string
          description: URL to error documentation
          example: https://conduit-v2.mintlify.app/errors#customer-not-found
        instance:
          type: string
          description: Request path that produced the error
          example: /v2/customers/cus_034A0gCCVsxdV2PjHLx9k1
        correlationId:
          description: Request correlation ID
          example: 00469ea4-52c1-4ffa-bd05-9f28b236a5fe
          type: string
        timestamp:
          type: string
          description: ISO 8601 UTC timestamp
          example: '2026-04-27T20:00:00.000Z'
        details:
          description: >-
            Additional structured data for domain-specific errors (e.g. missing
            field lists, pair info)
        retryAfterSeconds:
          type: integer
          minimum: 0
          exclusiveMinimum: true
          maximum: 9007199254740991
          description: Seconds to wait before retrying
          example: 3
      required:
        - type
        - title
        - status
        - detail
        - resolution
        - docs
        - instance
        - timestamp
        - retryAfterSeconds
  securitySchemes:
    api-key:
      type: apiKey
      in: header
      name: x-api-key

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.