Skip to main content
POST
Simulate a transfer into a sandbox virtual account
Sandbox only. Returns 403 in production.
Credits a bank transfer into one of your sandbox virtual accounts, exactly as the underlying provider’s deposit notification would in production. Balances and the TRANSACTION.UPDATED webhook behave the same. Sandbox virtual accounts receive no money on their own, so use this endpoint whenever you want to test what happens after a customer funds one.

Choosing the account

  • Reusable virtual account (created without amount): pass the accountNumber and amount to credit.
  • One-time virtual account (created with amount): pass the same reference the account was issued with, in addition to accountNumber and amount.

Controlling the outcome

outcome defaults to success. Pass "outcome": "failed" to simulate a failed inflow. The deposit lands as a transaction and is reported by webhook. See the Sandbox testing guide for how virtual accounts fit into the broader sandbox model.

Authorizations

x-api-key
string
header
required

Static business API key issued from the dashboard. A business can provision multiple API keys, each scoped to a configurable set of permissions (e.g. read transactions, create deposits, etc). Permissions are chosen per key at creation time in the dashboard and may be revoked by deleting the key. Requests made with a key that does not include the permission required by the target endpoint is rejected with a 401 Unauthorized response, the same response an unrecognised, malformed, revoked or disabled key returns. The API does not distinguish the two cases on the wire. Manage your keys and their permissions under Developer → API keys in the dashboard.

The permission each endpoint requires is below. Where several are listed, any one of them is enough. Keys created before permissions existed carry none and keep access to every endpoint.

Headers

x-api-version
string

API version in ISO 8601 format. The only supported version is 2026-05-18, which is also the default when the header is omitted. Any other value is rejected with a 400 Bad Request.

Body

application/json
accountNumber
string
required

The virtual account number to pay into.

amount
number
required

The amount transferred.

currency
string
required

The account's currency.

reference
string

The reference a one-time (amount-bound) account was issued with. Not needed for a reusable account.

outcome
enum<string>

Defaults to success.

Available options:
success,
failed

Response

Accepted. The reference of the new deposit.

data
object