Simulate one signer's cosignature for a non-custodial sandbox payout
Sandbox-only endpoint that stamps a single signer’s vote against a non-custodial payout’s M-of-N signing quorum, bypassing the real passkey-approval flow. Each call advances the quorum by one vote: pass signerId to target a specific ACTIVE wallet signer, or omit it to auto-advance to the next signer with no recorded vote (so repeated calls walk 1 of N → 2 of N → completed). The verification completes ONLY when the M-th approval lands; intermediate approvals leave it PENDING. A single declined stamp terminalizes the whole quorum as declined. Read incremental progress via GET /v2/verifications/{token} (the quorum block). 404 if the payout does not belong to the org or is not a WITHDRAWAL. Replays (the cosign gate already cleared, or the payout never required cosign) return the payout at its current state. Returns the payout at its current state.
Authorizations
Path Parameters
"txn_1A2b3C4d5E6f7G8h9I0jKl"
Body
Response
Client-facing view of an outbound withdrawal (debit out of a customer VA/wallet).
^txn_[0-9A-Za-z]{22}$^cus_[0-9A-Za-z]{22}$pending, processing, completed, failed, cancelled One side (source or destination) of a transaction. Discriminated by type.
- Option 1
- Option 2
- Option 3
- Option 4
- Option 5
- Option 6
- Option 7
- Option 8
One side (source or destination) of a transaction. Discriminated by type.
- Option 1
- Option 2
- Option 3
- Option 4
- Option 5
- Option 6
- Option 7
- Option 8
ISO 8601 timestamp
"2026-01-15T09:30:00.000Z"
True when at least one published (non-draft, non-cancelled) RFI targets this transaction. Always present; derived at read time, no stored column.
withdrawal Display name of the customer that owns the transaction: business legal name or individual full name. Same value on the transactions and payouts reads for the same row. Omitted when the customer's identity record hasn't resolved a name yet; per the public omit-don't-null convention, absence is never surfaced as null.
Client-supplied reference, unique per resource within your organization. 1-255 characters from A-Za-z, 0-9, underscore, hyphen, colon, and period — no spaces.
^[A-Za-z0-9_\-:.]{1,255}$Progress signal for a non-terminal transaction, informational only — it does not replace requiresUserSignature, hasRfi, or failureCode for deciding whether your integration needs to act. awaiting_signature: waiting on the required transaction signature (see requiresUserSignature). awaiting_customer_action: further input is needed before the transaction can go on. Read hasRfi to learn where the ask is: true means a request for information holds the answer — rfiId names it, and GET /v2/rfis/{id} carries what to send; false means the matching event carries the detail (e.g. transaction.awaiting_sender_information). under_review: compliance, document, or verification review of something already submitted is in progress — usually no action needed; check hasRfi if unsure. settling: funds movement or settlement is in progress, no customer action required — covers long-lived fiat rails like SWIFT that legitimately take days as well as any other non-blocked in-flight state. Omitted once status reaches a terminal value (completed / failed / cancelled). The set of values may grow over time — treat unrecognized values the same as processing.
awaiting_signature, awaiting_customer_action, under_review, settling ISO 8601 timestamp
"2026-01-15T09:30:00.000Z"
user_signature_timeout, user_signature_expired, user_signature_declined, user_signature_rejected_by_provider, crypto_wallet_misconfigured, compliance_hold, compliance_review_rejected, compliance_rejected, returned_by_sender, rail_policy_rejected, insufficient_funds, insufficient_funds_at_settle, rail_unavailable, sender_info_timeout, travel_rule_rejected, provider_rejected, chain_broadcast_failed, roster_changed Human-readable description of failureCode. Defaults to the public error catalog text for the code; sandbox-driven failures may carry the operator-supplied reason instead.
ISO-8601 timestamp when the transaction was cancelled. Present only on status: cancelled.
"2026-01-15T09:30:00.000Z"
Machine-readable cancellation reason. client_cancelled when the client called POST /v2/payouts/:id/cancel; expired is reserved. Omitted on non-cancelled rows. Mirrors orders.cancellationReason.
expired, client_cancelled ^ord_[0-9A-Za-z]{22}$The business purpose declared at payout creation. Drives compliance gating: intercompany requires a whitelisted recipient; other values require supporting documentation.
intercompany, treasury_management, payment_for_goods_or_services, payroll, investments, other, prefunding The most recently published such RFI — usually the one stage refers to, but a later unrelated RFI on the same transaction takes this slot instead. Omitted (never null) when hasRfi is false.
^rfi_[0-9A-Za-z]{22}$The free-text reference the payer supplied on the payout, fiat or crypto. On a transfer between two of the customer's own wallets the same value reads on both halves: the withdrawal that sent it and the deposit that credits it.
The UETR of the fiat leg — the ISO 20022 unique end-to-end transaction reference. Present whenever the payment carried one, including on a deposit whose source is still external_unknown because the sender has not resolved. The side that carries wire references repeats it — destination.swiftUetr on a payout, source.swiftUetr on a deposit — but not every side does, which is why it reads here as well. A Fedwire message carries a UETR too, so its presence does not mean the payment travelled on SWIFT. Omitted (never null) when the rail supplied none.
The margin you declared on this payout, echoed back. Present when you declared one that came to at least one minor unit of the payout's asset. bps and flatAmount read back for the life of the payout, whatever becomes of it, so you can always confirm what you sent. What each payout accrued to you is answered by GET /v2/markup/statement-lines, where a reversal reads as a negative amount.
Position in the per-(wallet, chain) signing queue. Only waiting payouts (position ≥ 1) expose this field; the active/head payout omits it. Absent when the payout is not on the user-signature path or has reached a terminal status.
1 <= x <= 9007199254740991The payout this one replaces. Present when an operator re-sent a payout the receiving bank returned; the original transfer reads failed with failure code returned_by_sender.
^txn_[0-9A-Za-z]{22}$