Sandbox environment — test data only. Nothing here moves real money.

Loam Customer API · Preview

Developer Hub

Start here to build on the Loam Customer API.

Both paths need credentials. Start by creating an API client.

A payment, as the API writes it

Send money with amount and currency to an approved destination. The write returns 202 with { id, state } and a Location. It needs the money.write scope and an owner grant under step-up authentication.

POST /api/v1/payments
curl -X POST "$LOAM_API_BASE/payments" \  -H "Authorization: Bearer $LOAM_TOKEN" \  -H "Content-Type: application/json" \  -H "Idempotency-Key: $(uuidgen)" \  -d '{    "destination_id": "2f4cbb59-3ab1-4b6d-8d10-9cd2236cf94e",    "amount": 2500000,    "currency": "USD"  }'// Response
HTTP/1.1 202 Accepted
Location: /api/v1/payments/<payment-id>

{
  "ok": true,
  "data": {
    "id": "<payment-id>",
    "state": "processing"
  }
}

What the API covers today

Open now means callable with the read or write scope. Needs owner grant means the money.write scope, granted by an organisation owner under step-up authentication. Not yet available means the operation is closed until the precondition listed with it is met.

Open now Scopes read and write

  • Settled balances GET /api/v1/balances
  • Payments, listed GET /api/v1/payments
  • Treasury vault terms GET /api/v1/vaults
  • Foreign-exchange quotes POST /api/v1/fx/quotes

Needs owner grant

  • Payments to an approved destination POST /api/v1/payments
  • Funds in from a bank account POST /api/v1/onramp
  • Vault deposits and withdrawals POST /api/v1/vaults/…

Money movement needs an organisation owner to grant the scope under step-up authentication and set a per-transaction limit in Settings → API clients. Payments also need a destination approved there by the owner. Onramp uses an operator-supplied source_id. Vault deposits and withdrawals need neither an approved destination nor a source_id.

Not yet available

  • Funds out to a bank account POST /api/v1/offramp

The offramp stays closed until destination screening and travel-rule certification are complete.

How the API behaves

  • OAuth 2.0

    Client credentials grant

    Exchange a client id and secret for a short-lived bearer token with one form-encoded request. Scopes are read from the client per request, so narrowing one applies at once.

  • Envelope

    One shape for every route

    Success is ok then data; failure is ok: false with a machine-readable error code.

  • Idempotency

    Retries cost nothing

    Every write requires an Idempotency-Key. The same key with the same body replays the first outcome instead of writing twice.

  • Pagination

    Cursors, not offsets

    List routes return page.next_cursor. Pass it back as cursor until it comes back null.

Pick a path from here: the quickstart if you want a working request in front of you first, the reference if you already know the call you need.