Skip to main content
POST
Authorize a quote's SCA challenge

Authorizations

Authorization
string
header
required

API token authentication using format <api token id>:<api client secret>

Path Parameters

quoteId
string
required

The unique identifier of the quote whose SCA challenge is being authorized.

Body

application/json

Proof that satisfies an ScaChallenge. Provide exactly one of code (for SMS_OTP / TOTP) or passkeyAssertion (for PASSKEY). When supplying a passkeyAssertion, origin is required — the WebAuthn assertion is bound to the origin it was produced against, and a passkey confirmation is rejected without it.

code
string | null

The one-time code the customer received by SMS, or read from their authenticator app. In sandbox, the code is always 123456.

Example:

"123456"

passkeyAssertion
object | null

Opaque WebAuthn assertion produced by the device from the challenge's passkeyAssertionOptions. Required when satisfying a PASSKEY challenge.

origin
string | null

The WebAuthn origin the passkeyAssertion was produced against. Required alongside passkeyAssertion; omit it for the code path. When the challenge lists passkeyAllowedOrigins (enrollment / login challenges), it must be one of those. A per-transaction passkey challenge carries passkeyAssertionOptions but may omit passkeyAllowedOrigins; in that case supply the origin your app invoked the WebAuthn API from, which must match the relying party in passkeyAssertionOptions.

Example:

"https://app.example.com"

Response

Challenge authorized; the updated quote is returned.

id
string
required

Unique identifier for this quote

Example:

"Quote:019542f5-b3e7-1d02-0000-000000000006"

status
enum<string>
required

Current status of the quote. PENDING_AUTHORIZATION occurs only for customers in a region where Strong Customer Authentication is required (e.g. EU): the quote carries an scaChallenge that must be authorized before execution, and for realtime-funding sources paymentInstructions are withheld until it is satisfied.

Available options:
PENDING,
PENDING_AUTHORIZATION,
PROCESSING,
COMPLETED,
FAILED,
EXPIRED
Example:

"PENDING"

createdAt
string<date-time>
required

When this quote was created

Example:

"2025-10-03T12:00:00Z"

expiresAt
string<date-time>
required

Absolute UTC timestamp when the rate locked in this quote becomes invalid and the quote can no longer be executed. The window depends on the rail and corridor: instant rails (Lightning, Spark, USDC on Solana/Base/Polygon, RTP, SEPA Instant) typically expire in 1–5 minutes; corridors with longer settlement guarantees may have longer windows. Always rely on this timestamp rather than assuming a fixed window.

Example:

"2025-10-03T12:05:00Z"

source
Account · object
required

Source account details

destination
Account · object
required

Destination account details

sendingCurrency
object
required

Currency for the sending amount

receivingCurrency
object
required

Currency for the receiving amount

totalSendingAmount
integer<int64>
required

The total amount that will be sent in the smallest unit of the sending currency (eg. cents).

Example:

123010

totalReceivingAmount
integer<int64>
required

The total amount that will be received in the smallest unit of the receiving currency (eg. cents).

Example:

1000

exchangeRate
number
required

Number of sending currency units per receiving currency unit.

feesIncluded
integer<int64>
required

The fees associated with the quote in the smallest unit of the sending currency (eg. cents). Note: this value may fluctuate between quotes — some underlying fee components are defined in the receiving currency, so their equivalent in the sending currency moves with the FX rate. The fees shown here are locked only for the lifetime of this quote.

Required range: x >= 0
Example:

10

transactionId
string
required

The ID of the transaction created from this quote.

Example:

"Transaction:019542f5-b3e7-1d02-0000-000000000005"

paymentInstructions
object[]

Payment instructions for executing the payment. This is not required when using an internal account source.

Example:
remittanceInformation
string

Free-form information about the payment that travels with it to the recipient, as provided on the quote request. The field this populates depends on the payment rail: for ACH it populates the Addenda record, for FedNow and RTP it populates the remittanceInformation field, and for wires it populates the OBI (Originator to Beneficiary Information) / beneficiary information.

Maximum string length: 80
Example:

"12345"

counterpartyInformation
object

Additional information about the counterparty, if available and required by the platform in their configuration.

Example:
rateDetails
object

Details about the rate and fees for the transaction.

scaChallenge
object
read-only

Present only while status is PENDING_AUTHORIZATION: the Strong Customer Authentication challenge to satisfy before this quote can be executed (or, for realtime-funding sources, before paymentInstructions are issued). Omitted for customers outside SCA-regulated regions (non-EU).