> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapyd.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Add Bank Account

> Adds a bank account to a verified customer, as the payin source or the payout destination. The fields depend on the customer's country.

<Prompt description="Add Bank Account" actions={["cursor"]}>
  Add the Zapyd "Add Bank Account" call (`POST /cms/api/v1/bank/create`) to my backend. Adds a bank account to a verified customer, as the payin source or the payout destination. The fields depend on the customer's country.

  * Sandbox: `POST https://sandbox.zapyd.com/cms/api/v1/bank/create`
  * Production: `POST https://api.zapyd.com/cms/api/v1/bank/create`

  JSON body:

  * `customer_id` (string, uuid, required): Customer's unique identifier. The customer must be VERIFIED.
  * `bank_account_type` (string, required): Payment rail. The rails depend on the customer's country: see Rails by country. For example ACCOUNT\_DETAILS or UPI. Example: `ACCOUNT_DETAILS`.
  * `identifiers` (object, required): The fields for the rail in bank\_account\_type: see Rails by country. For example `{account_number, ifsc}` for ACCOUNT\_DETAILS, or `{vpa}` for UPI.

  Success: HTTP 200, `{status: true, message, data}`. `data`: `id`, `customer_id`, `country`, `bank_account_type`, `identifiers` (Rail-specific identifiers. ACCOUNT\_DETAILS: account\_number and ifsc. UPI: vpa), `bank_account_status`, `beneficiary_name` (Account holder name returned by bank verification), `bank_name`, `failure_reason` (Set when bank\_account\_status is FAILED).
  Errors (`{status: false, message, err_code, errors}`):

  * 400 `Customer not found or access denied`: Customer not found; Customer does not belong to the organization
  * 400 `Customer is unverified`: Customer is not KYC verified
  * 400 `VPA already in use`: UPI ID is already in use
  * 400 `Maximum 3 UPI IDs allowed`: 3 UPI IDs are already added for the customer
  * 400 `Account number already in use`: Account number is already in use
  * 400 `Maximum 3 bank account details allowed`: 3 bank accounts are already added for the customer
  * 400 `KYC already in use`: KYC is being used by another customer
  * 500 `Internal Server Error`
    Every endpoint can also return 401 `AUTH_*` (signature, timestamp or key: fix, don't retry), and 429 or 5xx (retry with backoff).

  Rules:

  * `bank_account_type` and `identifiers` depend on the customer's country. India (`IND`): `ACCOUNT_DETAILS` with `identifiers: {account_number, ifsc}`, or `UPI` with `identifiers: {vpa}`. US customers link their bank with `POST /bank/generate-link`. Payout-only beneficiaries use `POST /bank/payout/create`.
  * The customer must be `VERIFIED`. The account holder's name must match the KYC name. NRE accounts aren't supported. India remittance (RDA) payouts need `ACCOUNT_DETAILS`.
  * At most 3 active accounts per rail per customer. An account linked to another customer is rejected.
  * Save `data.id` as `bank_id`. Verification is asynchronous (penny drop): `bank_account_status` starts as `PROCESSING`, then a `BANK` webhook reports `VERIFIED` or `FAILED` (`INVALID_IFSC`, `INVALID_ACCOUNT_NUMBER`, `NAME_MISMATCH`, `ACCOUNT_TYPE_NRE`, `PENNY_DROP_FAILED`, `BANK_RISK_CHECK_FAILED`). Quote only against a `VERIFIED` account.
  * In payout quotations, `ACCOUNT_DETAILS` pays out over `IMPS` and `UPI` over `UPI`.
  * Sandbox: set the result with `POST /cms/api/v1/bank/mock-bank-verification`. It sends no webhook, so read the account afterwards.

  Signing (every request):

  * Headers: `X-API-KEY`, `X-TIMESTAMP` (Unix seconds, within 300 s of server time; generate per request) and `X-SIGNATURE`.
  * `X-SIGNATURE` = Base64(HMAC-SHA256(key = API secret, message = apiKey + "|" + timestamp + "|" + canonicalBody)). Base64 of the raw digest, not hex.
  * canonicalBody: the JSON body with keys sorted at every nesting level, no whitespace (separators `,` and `:`), and every non-ASCII character escaped as lowercase `\uXXXX` (Python `json.dumps(body, sort_keys=True, separators=(",", ":"))`). Requests with no body (GET, DELETE) sign `{}`. Query parameters are not signed.
  * Send the exact canonicalBody string you signed as the request body, with `Content-Type: application/json`.
  * Test vector: key `3f1b2c4d-5e6f-4a7b-8c9d-0e1f2a3b4c5d`, secret `test-secret-do-not-use`, timestamp `1735689600`. Signing `{}` gives `6sCtVSRQjU9+2/af8gdwUAvY1l6Ii6ENcbRfanPkhY0=`. Body `{"customer_id":"78c99d71-f28f-47a9-8302-93b286efbe0e","amount":100.5,"currency":"INR","meta":{"note":"Café","b":2,"a":1}}` gives `l+DvQrzlKbsOSxSYOdWoWHEehcFRZfDJPKlLDkm2cSI=`.

  Deliver:

  1. A typed `addBankAccount` function in this codebase's language and HTTP client. Reuse an existing Zapyd client and signer, or write one small shared client.
  2. Config from `ZAPYD_API_KEY`, `ZAPYD_API_SECRET` and `ZAPYD_BASE_URL`. The secret stays on the server, never in a browser or app.
  3. Return `data`. When `status` is false, throw an error with the HTTP status, `err_code`, `message` and `errors`. Don't show raw errors to end users.
  4. Retry only 429 and 5xx: exponential backoff from 1 s, capped at 30 s, at most 5 attempts.
  5. Amounts as strings. Types for every field above.
  6. Tests: the signer against the test vector, and this call against sandbox.

  Reference: `https://docs.zapyd.com/api-reference-exchange/endpoint/bank/create.md`
</Prompt>

<Note>
  The customer must be `VERIFIED`, and the account holder's name must match the name on their KYC.
</Note>

## Rails by country

Send the rail in `bank_account_type` and its fields in `identifiers`. Which rails you can send depends on the customer's `alpha_3_country_code`.

| Country | `bank_account_type` | `identifiers` | Payout method |
| - | - | - | - |
| India (`IND`) | `ACCOUNT_DETAILS` | `account_number`, `ifsc` | `IMPS` |
| | `UPI` | `vpa` | `UPI` |

* **United States:** customers link their bank with [Generate Bank Link](/api-reference-exchange/endpoint/bank/generate-link) instead.
* **Payout-only beneficiaries:** use [Add Payout Bank Account](/api-reference-exchange/endpoint/bank/payout-create). Its fields are set per country and payout method.
* **India:** NRE accounts aren't supported. Remittance (RDA) payouts need `ACCOUNT_DETAILS`.

## Verification

1. Save `data.id` as `bank_id`. The account starts as `PROCESSING`.
2. Zapyd verifies it asynchronously, and a `BANK` webhook reports `VERIFIED` or `FAILED`. On `FAILED`, `failure_reason` says why.
3. Quote only against a `VERIFIED` account.

In sandbox, set the result with [Mock Bank Verification](/api-reference-exchange/endpoint/bank/mock-bank-verification). It sends no webhook, so read the account afterwards.

## Limits

* At most 3 active accounts per rail per customer.
* An account already linked to another customer is rejected.

## Error Codes and Messages

| API Status Code | Response | Reason |
| - | - | - |
| 400 | Customer not found or access denied | Customer not found |
| 400 | Customer not found or access denied | Customer does not belong to the organization |
| 400 | Customer is unverified | Customer is not KYC verified |
| 400 | VPA already in use | UPI ID is already in use |
| 400 | Maximum 3 UPI IDs allowed | 3 UPI IDs are already added for the customer |
| 400 | Account number already in use | Account number is already in use |
| 400 | Maximum 3 bank account details allowed | 3 bank accounts are already added for the customer |
| 400 | KYC already in use | KYC is being used by another customer |
| 500 | Internal Server Error | Internal Server Error |


## OpenAPI

````yaml POST /bank/create
openapi: 3.1.0
info:
  title: Zapyd API
  description: API for Zapyd - Customer, Payout, and Webhook services
  license:
    name: MIT
  version: 1.0.0
servers:
  - url: https://sandbox.zapyd.com/pos/api/v1
    description: Payout API Base URL
    variables:
      base_url:
        default: https://sandbox.zapyd.com
  - url: https://sandbox.zapyd.com/cms/api/v1
    description: Customer API Base URL
    variables:
      base_url:
        default: https://sandbox.zapyd.com
security:
  - ApiKeyAuth: []
    TimestampAuth: []
    SignatureAuth: []
tags:
  - name: Customer
    description: Customer related operations
    x-displayName: Customer
    x-traitTag: true
  - name: Payout
    description: Payout related operations
  - name: Webhooks
    description: Webhook related operations
  - name: Widget
    description: Hosted buy/sell widget session initialization
paths:
  /bank/create:
    post:
      tags:
        - Bank
      description: >-
        Add a bank account for a VERIFIED customer. Send the rail in
        `bank_account_type` and its fields in `identifiers`. At most 3 active
        accounts per rail per customer; an account already linked to another
        customer is rejected.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - customer_id
                - bank_account_type
                - identifiers
              properties:
                customer_id:
                  type: string
                  description: Customer's unique identifier. The customer must be VERIFIED.
                  example: c2cf861b-342b-4318-a90e-85cd0312e82f
                  format: uuid
                bank_account_type:
                  type: string
                  description: >-
                    Payment rail. The rails depend on the customer's country:
                    see Rails by country. For example ACCOUNT_DETAILS or UPI.
                  example: ACCOUNT_DETAILS
                identifiers:
                  type: object
                  description: >-
                    The fields for the rail in bank_account_type: see Rails by
                    country. For example {account_number, ifsc} for
                    ACCOUNT_DETAILS, or {vpa} for UPI.
                  example:
                    account_number: '7627389201'
                    ifsc: SBIN0001829
            examples:
              india_account:
                summary: India, account + IFSC
                value:
                  customer_id: c2cf861b-342b-4318-a90e-85cd0312e82f
                  bank_account_type: ACCOUNT_DETAILS
                  identifiers:
                    account_number: '7627389201'
                    ifsc: SBIN0001829
              india_upi:
                summary: India, UPI
                value:
                  customer_id: c2cf861b-342b-4318-a90e-85cd0312e82f
                  bank_account_type: UPI
                  identifiers:
                    vpa: johndoe@oksbi
      responses:
        '200':
          description: Bank account added successfully
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: boolean
                    example: true
                  message:
                    type: string
                    example: Success
                  data:
                    type: object
                    properties:
                      id:
                        type: string
                        description: Bank account ID
                        example: 4e6f1b20-a73c-11ec-b909-0242ac120002
                        format: uuid
                      customer_id:
                        type: string
                        description: Customer ID
                        example: 550e8400-e29b-41d4-a716-446655440000
                        format: uuid
                      country:
                        type: string
                        description: Customer country (alpha-3)
                        example: IND
                      bank_account_type:
                        type: string
                        description: Payment rail
                        example: ACCOUNT_DETAILS
                        enum:
                          - ACCOUNT_DETAILS
                          - UPI
                      identifiers:
                        type: object
                        description: >-
                          Rail-specific identifiers. ACCOUNT_DETAILS:
                          account_number and ifsc. UPI: vpa.
                        example:
                          account_number: '7627389201'
                          ifsc: SBIN0001829
                      bank_account_status:
                        type: string
                        description: Verification status
                        example: VERIFIED
                        enum:
                          - PROCESSING
                          - VERIFIED
                          - FAILED
                          - MANUAL_REVIEW
                      beneficiary_name:
                        type: string
                        description: Account holder name returned by bank verification
                        example: JOHN DOE
                      bank_name:
                        type: string
                        description: Bank name
                        example: State Bank of India
                      failure_reason:
                        type:
                          - string
                          - 'null'
                        description: Set when bank_account_status is FAILED
                        example: null
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: boolean
                    example: false
                  message:
                    type: string
                    example: Bad Request
                  err_code:
                    type: string
                    example: REQ_FIELD_MISSING
                  errors:
                    type: object
                    properties:
                      identifiers:
                        type: array
                        items:
                          type: string
                        example:
                          - This field is required.
                  data:
                    type: 'null'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: boolean
                    example: false
                  message:
                    type: string
                    example: Internal Server Error
                  data:
                    type: 'null'
                  err_code:
                    type: string
                    example: SYS_INTERNAL_ERROR
                  errors:
                    type: string
                    example: Unexpected error occurred. Please try again later.
      servers:
        - url: https://sandbox.zapyd.com/cms/api/v1
          description: Bank API Base URL
components:
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-API-KEY
      description: API Key for authentication
    TimestampAuth:
      type: apiKey
      in: header
      name: X-TIMESTAMP
      description: Current timestamp in seconds since epoch
    SignatureAuth:
      type: apiKey
      in: header
      name: X-SIGNATURE
      description: HMAC SHA256 signature of the request encoded in Base64

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.