Depa LogoDocsv1
API Reference

API Reference Overview

Environments, authentication, conventions and every endpoint of the Depa API v1.

The Depa API is a JSON REST API over HTTPS. Every page in this reference is generated from Depa's OpenAPI description, so endpoints, fields and examples match what the API accepts and returns.

Environments

EnvironmentBase URLUse it for
Sandboxhttps://sandbox.depasify.com/api/v1Building and testing. No real money moves, and the Sandbox endpoints let you simulate incoming payments.
Productionhttps://backoffice.depasify.com/api/v1Live accounts and payments.

Each environment has its own users and credentials. Code samples in this reference use the sandbox.

Authentication

Sign in with POST /sign_in to get a token, then send it on every request:

Authorization: Bearer <token>

Tokens expire. When a request returns 401, sign in again. The token's payload lists the vaults you can access, which you need for the /vaults/{vault_id}/… endpoints.

Requests and responses

  • Send JSON bodies with Content-Type: application/json. File uploads use multipart/form-data.
  • Responses wrap the result in data. Lists add a pagination object:
{
  "data": [{ "id": "c3e7a1f9-2b8d-4c6e-9f1a-5d0b7e3c8a12", "amount": "1000.0", "currency": "EUR" }],
  "pagination": { "current_page": 1, "per_page": 80, "total_pages": 1, "total_count": 1 }
}
  • Paginate with page (from 1) and, where supported, per_page. Keep requesting pages until current_page equals total_pages.

Errors

Depa uses standard HTTP status codes. Errors come in two shapes:

{ "error": "You are not authenticated." }
{ "errors": [{ "code": "not_found", "message": "Record not found" }] }

The first is used for authentication and some older endpoints; the second lists one entry per problem. Branch on code, not on message.

StatusMeaning
400The request is malformed, for example an invalid date.
401The token is missing, invalid or expired.
403The resource can't be changed in its current state.
404The resource doesn't exist, or your token can't access it.
422The request is valid JSON but can't be processed. Validation errors list every invalid field.
503A rate or liquidity provider is temporarily unavailable. Retry shortly.

Conventions

  • IDs are UUIDs.
  • Amounts in responses are decimal strings, such as "1250.0", so no precision is lost. Check each field's type in the reference.
  • Timestamps are Unix seconds (created_at: 1772813114). Payment link and quote expiry times are ISO 8601.
  • Codes follow ISO standards: ISO 4217 for currencies, ISO 3166-1 alpha-2 for countries.
  • Percentages are decimal fractions: 0.01 is 1%.
  • Your references: set trx_uuid (payment links, card payments, payouts) or client_id (trades) to your own ID. It lets you find the operation later, and trx_uuid must be unique per account, so a retry can't create a duplicate.

Endpoints

Core ledger (The Book)

Identity & onboarding

Money movement (The Journal)

Controls & fees (The Watch)

Support & testing

On this page

🍪 We do not track your behaviour or use any cookie on this site.