> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapyd.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Mock Bank Verification

> Sandbox only. Sets a bank account to VERIFIED, FAILED or MANUAL_REVIEW.

<Prompt description="Mock Bank Verification" actions={["cursor"]}>
  Add the Zapyd "Mock Bank Verification" call (`POST /cms/api/v1/bank/mock-bank-verification`) to my backend. Sandbox only. Sets a bank account to VERIFIED, FAILED or MANUAL\_REVIEW.

  * Sandbox: `POST https://sandbox.zapyd.com/cms/api/v1/bank/mock-bank-verification`
  * Production: none, sandbox only

  JSON body:

  * `customer_id` (string, uuid, required): Zapyd customer ID (UUID) returned by Create Customer.
  * `bank_id` (string, uuid, optional): Required except for US customers. Bank account ID returned by Add Bank Account. For a US customer, leave it out to create a linked sandbox account, which then appears in Fetch Bank Accounts.
  * `bank_status` (string, required): Result to set. One of: `VERIFIED`, `FAILED`, `MANUAL_REVIEW`.
  * `failure_reason` (string, conditional): Required when bank\_status is FAILED. Use a real reason so your error handling gets tested. One of: `INVALID_IFSC`, `INVALID_ACCOUNT_NUMBER`, `ACCOUNT_TYPE_NRE`, `PENNY_DROP_FAILED`, `NAME_MISMATCH`, `BANK_RISK_CHECK_FAILED`.

  Success: HTTP 200, `{status: true, message, data}`. `data`: `id`, `customer_id`, `country`, `bank_account_type`, `identifiers` (Rail-specific identifiers. ACCOUNT\_DETAILS: account\_number and ifsc. UPI: vpa), `bank_account_status`, `beneficiary_name` (Account holder name returned by bank verification), `bank_name`, `failure_reason` (Set when bank\_account\_status is FAILED).
  Errors (`{status: false, message, err_code, errors}`):

  * 400 `Customer not found or access denied`: Customer not found, or not in your organization
  * 400 `Bank account not found or access denied`: Bank account not found, or not linked to this customer
  * 400 `Failure reason is required when bank status is FAILED`: `bank_status` is `FAILED` without `failure_reason`
  * 400 `Mock bank verification is only allowed in non-production environment`: Called in production
  * 500 `Internal Server Error`
    Every endpoint can also return 401 `AUTH_*` (signature, timestamp or key: fix, don't retry), and 429 or 5xx (retry with backoff).

  Rules:

  * Sandbox only: it doesn't exist in production. Keep it behind a sandbox-only flag or in test code.
  * Send `failure_reason` when `bank_status` is `FAILED`. It sends no `BANK` webhook: read the account with `GET /cms/api/v1/bank/{customer_id}/{bank_id}` afterwards.
  * For a US customer, leave out `bank_id`: it creates a linked test account for `ACH_PULL` payins, returned by `GET /cms/api/v1/bank/list/{customer_id}`.

  Signing (every request):

  * Headers: `X-API-KEY`, `X-TIMESTAMP` (Unix seconds, within 300 s of server time; generate per request) and `X-SIGNATURE`.
  * `X-SIGNATURE` = Base64(HMAC-SHA256(key = API secret, message = apiKey + "|" + timestamp + "|" + canonicalBody)). Base64 of the raw digest, not hex.
  * canonicalBody: the JSON body with keys sorted at every nesting level, no whitespace (separators `,` and `:`), and every non-ASCII character escaped as lowercase `\uXXXX` (Python `json.dumps(body, sort_keys=True, separators=(",", ":"))`). Requests with no body (GET, DELETE) sign `{}`. Query parameters are not signed.
  * Send the exact canonicalBody string you signed as the request body, with `Content-Type: application/json`.
  * Test vector: key `3f1b2c4d-5e6f-4a7b-8c9d-0e1f2a3b4c5d`, secret `test-secret-do-not-use`, timestamp `1735689600`. Signing `{}` gives `6sCtVSRQjU9+2/af8gdwUAvY1l6Ii6ENcbRfanPkhY0=`. Body `{"customer_id":"78c99d71-f28f-47a9-8302-93b286efbe0e","amount":100.5,"currency":"INR","meta":{"note":"Café","b":2,"a":1}}` gives `l+DvQrzlKbsOSxSYOdWoWHEehcFRZfDJPKlLDkm2cSI=`.

  Deliver:

  1. A typed `mockBankVerification` function in this codebase's language and HTTP client. Reuse an existing Zapyd client and signer, or write one small shared client.
  2. Config from `ZAPYD_API_KEY`, `ZAPYD_API_SECRET` and `ZAPYD_BASE_URL`. The secret stays on the server, never in a browser or app.
  3. Return `data`. When `status` is false, throw an error with the HTTP status, `err_code`, `message` and `errors`. Don't show raw errors to end users.
  4. Retry only 429 and 5xx: exponential backoff from 1 s, capped at 30 s, at most 5 attempts.
  5. Amounts as strings. Types for every field above.
  6. Tests: the signer against the test vector, and this call against sandbox.

  Reference: `https://docs.zapyd.com/api-reference-exchange/endpoint/bank/mock-bank-verification.md`
</Prompt>

<Note>
  This endpoint doesn't send a `BANK` webhook. Read the account with [Get Bank Account](/api-reference-exchange/endpoint/bank/\{customer_id}-\{bank_id}) to see the new status.
</Note>

## Error Codes and Messages

| API Status Code | Response | Reason |
| - | - | - |
| 400 | Customer not found or access denied | Customer not found, or not in your organization |
| 400 | Bank account not found or access denied | Bank account not found, or not linked to this customer |
| 400 | Failure reason is required when bank status is FAILED | `bank_status` is `FAILED` without `failure_reason` |
| 400 | Mock bank verification is only allowed in non-production environment. | Called in production |
| 500 | Internal Server Error | Internal Server Error |


## OpenAPI

````yaml POST /bank/mock-bank-verification
openapi: 3.1.0
info:
  title: Zapyd API
  description: API for Zapyd - Customer, Payout, and Webhook services
  license:
    name: MIT
  version: 1.0.0
servers:
  - url: https://sandbox.zapyd.com/pos/api/v1
    description: Payout API Base URL
    variables:
      base_url:
        default: https://sandbox.zapyd.com
  - url: https://sandbox.zapyd.com/cms/api/v1
    description: Customer API Base URL
    variables:
      base_url:
        default: https://sandbox.zapyd.com
security:
  - ApiKeyAuth: []
    TimestampAuth: []
    SignatureAuth: []
tags:
  - name: Customer
    description: Customer related operations
    x-displayName: Customer
    x-traitTag: true
  - name: Payout
    description: Payout related operations
  - name: Webhooks
    description: Webhook related operations
  - name: Widget
    description: Hosted buy/sell widget session initialization
paths:
  /bank/mock-bank-verification:
    post:
      tags:
        - Bank
      description: >-
        Sandbox only. Sets the verification result of a customer's bank account,
        so you can test both outcomes. It doesn't send a BANK webhook; read the
        account with Get Bank Account to see the new status. For a US customer,
        leave out bank_id to create a linked account for ACH_PULL payins.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - customer_id
                - bank_status
              properties:
                customer_id:
                  type: string
                  format: uuid
                  description: Zapyd customer ID (UUID) returned by Create Customer.
                  example: c2cf861b-342b-4318-a90e-85cd0312e82f
                bank_id:
                  type: string
                  format: uuid
                  description: >-
                    Required except for US customers. Bank account ID returned
                    by Add Bank Account. For a US customer, leave it out to
                    create a linked sandbox account, which then appears in Fetch
                    Bank Accounts.
                  example: cab47575-bbcb-4294-81a3-30774104f3b6
                bank_status:
                  type: string
                  enum:
                    - VERIFIED
                    - FAILED
                    - MANUAL_REVIEW
                  description: Result to set
                  example: VERIFIED
                failure_reason:
                  type: string
                  description: >-
                    Required when bank_status is FAILED. Use a real reason so
                    your error handling gets tested.
                  enum:
                    - INVALID_IFSC
                    - INVALID_ACCOUNT_NUMBER
                    - ACCOUNT_TYPE_NRE
                    - PENNY_DROP_FAILED
                    - NAME_MISMATCH
                    - BANK_RISK_CHECK_FAILED
                  example: NAME_MISMATCH
            examples:
              verified:
                summary: Verify the account
                value:
                  customer_id: c2cf861b-342b-4318-a90e-85cd0312e82f
                  bank_id: cab47575-bbcb-4294-81a3-30774104f3b6
                  bank_status: VERIFIED
              failed:
                summary: Fail with a reason
                value:
                  customer_id: c2cf861b-342b-4318-a90e-85cd0312e82f
                  bank_id: cab47575-bbcb-4294-81a3-30774104f3b6
                  bank_status: FAILED
                  failure_reason: NAME_MISMATCH
      responses:
        '200':
          description: Bank account status updated
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: boolean
                    example: true
                  message:
                    type: string
                    example: Success
                  data:
                    type: object
                    properties:
                      id:
                        type: string
                        description: Bank account ID
                        example: 4e6f1b20-a73c-11ec-b909-0242ac120002
                        format: uuid
                      customer_id:
                        type: string
                        description: Customer ID
                        example: 550e8400-e29b-41d4-a716-446655440000
                        format: uuid
                      country:
                        type: string
                        description: Customer country (alpha-3)
                        example: IND
                      bank_account_type:
                        type: string
                        description: Payment rail
                        example: ACCOUNT_DETAILS
                        enum:
                          - ACCOUNT_DETAILS
                          - UPI
                      identifiers:
                        type: object
                        description: >-
                          Rail-specific identifiers. ACCOUNT_DETAILS:
                          account_number and ifsc. UPI: vpa.
                        example:
                          account_number: '7627389201'
                          ifsc: SBIN0001829
                      bank_account_status:
                        type: string
                        description: Verification status
                        example: VERIFIED
                        enum:
                          - PROCESSING
                          - VERIFIED
                          - FAILED
                          - MANUAL_REVIEW
                      beneficiary_name:
                        type: string
                        description: Account holder name returned by bank verification
                        example: JOHN DOE
                      bank_name:
                        type: string
                        description: Bank name
                        example: State Bank of India
                      failure_reason:
                        type:
                          - string
                          - 'null'
                        description: Set when bank_account_status is FAILED
                        example: null
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: boolean
                    example: false
                  message:
                    type: string
                    example: Bad Request
                  err_code:
                    type: string
                    example: REQ_FIELD_MISSING
                  errors:
                    type: object
                    properties:
                      account_number:
                        type: array
                        items:
                          type: string
                        example:
                          - account_number is required
                  data:
                    type: 'null'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: boolean
                    example: false
                  message:
                    type: string
                    example: Internal Server Error
                  data:
                    type: 'null'
                  err_code:
                    type: string
                    example: SYS_INTERNAL_ERROR
                  errors:
                    type: string
                    example: Unexpected error occurred. Please try again later.
      servers:
        - url: https://sandbox.zapyd.com/cms/api/v1
          description: Customer API Base URL
components:
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-API-KEY
      description: API Key for authentication
    TimestampAuth:
      type: apiKey
      in: header
      name: X-TIMESTAMP
      description: Current timestamp in seconds since epoch
    SignatureAuth:
      type: apiKey
      in: header
      name: X-SIGNATURE
      description: HMAC SHA256 signature of the request encoded in Base64

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.