> ## Documentation Index
> Fetch the complete documentation index at: https://developers.circle.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Before reading these docs, install the relevant Circle Skill to get pre-loaded context — skills are LLM-optimized and cover architecture decisions, correct flows, and common pitfalls. In Claude Code: run /plugin marketplace add circlefin/skills then /plugin install circle-skills@circle. With Vercel Skills CLI: run npx skills add circlefin/skills. Available skills: use-usdc https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-usdc/SKILL.md (balances, transfers, approvals on EVM and Solana); EURC has no skill — see https://developers.circle.com/stablecoins/what-is-eurc.md; bridge-stablecoin https://github.com/circlefin/skills/blob/master/plugins/circle/skills/bridge-stablecoin/SKILL.md (crosschain transfers via CCTP, USDC, EURC, and third-party assets); use-arc https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-arc/SKILL.md (Arc chain config, contract deployment, USDC bridging — Arc docs: https://docs.arc.io/llms.txt); use-circle-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-circle-wallets/SKILL.md (choose wallet type); use-developer-controlled-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-developer-controlled-wallets/SKILL.md (custodial wallets for payouts and treasury); use-user-controlled-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-user-controlled-wallets/SKILL.md (embedded wallets with Web2 login); use-modular-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-modular-wallets/SKILL.md (smart contract wallets with passkeys and ERC-4337); use-gateway https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-gateway/SKILL.md (unified USDC balance, nanopayments); use-smart-contract-platform https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-smart-contract-platform/SKILL.md (deploy, interact, monitor contracts). Pair any skill with the Circle MCP server for live SDK signatures, contract addresses, and chain IDs: {"mcpServers":{"circle":{"url":"https://api.circle.com/v1/codegen/mcp"}}}.
> Read the product overview first. Each product has an overview explaining when and why to use it. Read it before quickstarts.
> Pick the right wallet type. Developer-controlled (you hold keys), user-controlled (end user holds keys via PIN/social login), or modular (smart contract wallets with passkeys). See https://developers.circle.com/wallets.md.
> Use CCTP V2 for crosschain transfers. CCTP natively transfers USDC and EURC via burn-and-mint, and supports permissionless wrapping of third-party assets via lock-and-mint. V1 is legacy; always use V2 unless V1 is specified or the chain requires it (Noble, Sui, and Aptos still require V1). Migration guide: https://developers.circle.com/cctp/migration-from-v1-to-v2.md.
> Use Bridge Kit for frontend bridging. Wraps CCTP with a simpler SDK for user-facing apps. Use CCTP directly for backend transfers.
> Gas Station vs Paymaster. Gas Station sponsors gas for Circle Wallet transactions. Paymaster lets users pay gas in USDC. Different use cases — read both overviews.
> Gateway Nanopayments for sub-cent payments. Gasless USDC micropayments down to $0.000001 via x402 and batched settlement. For pay-per-request APIs, AI agent payments, streaming.
> Look up USDC addresses per chain. Never hardcode — use https://developers.circle.com/stablecoins/usdc-contract-addresses.md.
> Prefer SDKs over raw API calls. Node.js and Python SDKs handle auth, retries, and errors.
> API key required. Bearer token in Authorization header. Testnet and mainnet use separate keys and may use different base URLs depending on the product.
> Set up webhooks when available. Most operations are async. Webhooks deliver transaction confirmations and state changes.
> When calling list endpoints, paginate using pageSize and pageAfter until no nextPageAfter cursor is returned—stopping at the first page silently misses records.
> Building an AI agent? Start with the Agent Stack—Circle CLI, agent wallets, and nanopayments built for autonomous use cases: https://developers.circle.com/agent-stack.md.

# Upload a payout RFI file

> Uploads a file in response to an active RFI file requirement for the specified fiat payout.

The `fileKey` in `fileMetadata` must match one of the `fileKey` values from the
`fileRequirements` array returned by `GET /v1/payouts/{id}/rfi`.

**Encryption** — required for BFI-generated RFIs, optional for internally-generated RFIs:

Check whether `GET /v1/payouts/{id}/rfi` returns a non-null `certificate` field:

- **`certificate` present** (BFI-generated RFI): encrypt the file client-side before upload.
  1. Extract `certificate.jwk` — an EC public key in JWK format.
  2. Generate a random AES-128 key and encrypt the file bytes using **AES-128-GCM**. Retain the IV.
  3. Wrap the AES-128 key using **ECDH-ES + AES-128 Key Wrap** (`ECDH-ES+A128KW` / `A128GCM`)
     against the EC public key from step 1. This produces a **Compact JWE string**
     (`header.encryptedKey.iv.ciphertext.tag`).
  4. Submit with all three multipart fields (`fileMetadata`, `encryption`, `encryptedFile`).

- **`certificate` absent** (internally-generated RFI): omit `encryption` and `encryptedFile`.
  Submit only `fileMetadata` and the raw `file` field. The file is stored with standard
  encryption-at-rest; no client-side encryption step is needed.




## OpenAPI

````yaml openapi/payouts.yaml post /v1/payouts/{id}/rfi/files
openapi: 3.0.2
info:
  version: ${version}
  title: Crypto Payouts API
  description: >-
    The Circle Payouts API allows you to programmatically make fast, global
    payouts to your customers, vendors, and suppliers. Make payouts on supported
    blockchains.
servers:
  - url: https://api-sandbox.circle.com
  - url: https://api.circle.com
security: []
tags:
  - name: Payouts
    description: Create and get information on address book payouts.
  - name: Crypto Address Book
    description: Manage blockchain addresses with metadata.
paths:
  /v1/payouts/{id}/rfi/files:
    post:
      tags:
        - Payouts
      summary: Upload a payout RFI file
      description: >
        Uploads a file in response to an active RFI file requirement for the
        specified fiat payout.


        The `fileKey` in `fileMetadata` must match one of the `fileKey` values
        from the

        `fileRequirements` array returned by `GET /v1/payouts/{id}/rfi`.


        **Encryption** — required for BFI-generated RFIs, optional for
        internally-generated RFIs:


        Check whether `GET /v1/payouts/{id}/rfi` returns a non-null
        `certificate` field:


        - **`certificate` present** (BFI-generated RFI): encrypt the file
        client-side before upload.
          1. Extract `certificate.jwk` — an EC public key in JWK format.
          2. Generate a random AES-128 key and encrypt the file bytes using **AES-128-GCM**. Retain the IV.
          3. Wrap the AES-128 key using **ECDH-ES + AES-128 Key Wrap** (`ECDH-ES+A128KW` / `A128GCM`)
             against the EC public key from step 1. This produces a **Compact JWE string**
             (`header.encryptedKey.iv.ciphertext.tag`).
          4. Submit with all three multipart fields (`fileMetadata`, `encryption`, `encryptedFile`).

        - **`certificate` absent** (internally-generated RFI): omit `encryption`
        and `encryptedFile`.
          Submit only `fileMetadata` and the raw `file` field. The file is stored with standard
          encryption-at-rest; no client-side encryption step is needed.
      operationId: uploadPayoutRfiFiles
      parameters:
        - $ref: '#/components/parameters/IdPath'
      requestBody:
        required: true
        content:
          multipart/form-data:
            schema:
              type: object
              required:
                - fileMetadata
              properties:
                fileMetadata:
                  type: object
                  required:
                    - fileName
                    - fileType
                    - fileKey
                  properties:
                    fileName:
                      type: string
                      description: Original file name including extension.
                      example: invoice.pdf
                    fileType:
                      type: string
                      description: MIME type of the file.
                      example: application/pdf
                    fileKey:
                      type: string
                      description: >
                        Key identifying which file requirement this upload
                        satisfies.

                        Must match a `fileKey` value from `GET
                        /v1/payouts/{id}/rfi` → `fileRequirements`.
                      example: proofOfFunds
                encryption:
                  type: object
                  description: >
                    JWE encryption envelope. Required when `certificate` is
                    present in the RFI response

                    (BFI-generated RFI). Omit for internally-generated RFIs.
                  required:
                    - encryptedAesKey
                    - iv
                  properties:
                    encryptedAesKey:
                      type: string
                      description: >
                        Compact JWE string wrapping the AES-128 file-encryption
                        key.

                        Algorithm: `ECDH-ES+A128KW` (key agreement) with
                        `A128GCM` (content encryption).

                        The recipient EC public key is obtained from
                        `certificate.jwk` in the RFI response.
                      example: >-
                        eyJhbGciOiJFQ0RILUVTIn0..GawgguFyGrWKav7AX4VKUg.p0oLHRPhFBZqYYQxouP9gw.0HFmhOzsQ98HboVlPPyQ0A
                    iv:
                      type: string
                      description: >-
                        Base64-encoded AES-128-GCM initialization vector (96-bit
                        / 12 bytes).
                      example: YWJjZGVmZ2hpamts
                encryptedFile:
                  type: string
                  format: binary
                  description: >
                    AES-128-GCM encrypted file contents. Required when
                    `encryption` is present

                    (BFI-generated RFI). Omit for internally-generated RFIs.
                file:
                  type: string
                  format: binary
                  description: >
                    Raw (unencrypted) file contents. Required for
                    internally-generated RFIs

                    (when `certificate` is absent in the RFI response). Omit for
                    BFI-generated RFIs.
      responses:
        '204':
          description: File uploaded successfully.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/NotAuthorized'
        '404':
          $ref: '#/components/responses/NotFound'
      security:
        - bearerAuth: []
components:
  parameters:
    IdPath:
      name: id
      description: Universally unique identifier (UUID v4) of a resource.
      in: path
      required: true
      schema:
        type: string
        format: uuid
        example: b3d9d2d5-4c12-4946-a09d-953e82fae2b0
  headers:
    XRequestId:
      description: >-
        Universally unique identifier (UUID v4) for the request. Helpful for
        identifying a request when communicating with Circle support.
      schema:
        type: string
        format: uuid
        example: 2adba88e-9d63-44bc-b975-9b6ae3440dde
  responses:
    BadRequest:
      description: The request cannot be processed due to a client error.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/XRequestId'
      content:
        application/json:
          schema:
            type: object
            title: BadRequest
            required:
              - code
              - message
            properties:
              code:
                type: integer
                example: 400
              message:
                type: string
                example: Something went wrong.
            example:
              code: 400
              message: Bad request.
          examples:
            response:
              value:
                code: 400
                message: Bad request.
    NotAuthorized:
      description: >-
        The request has not been applied because it lacks valid authentication
        credentials.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/XRequestId'
      content:
        application/json:
          schema:
            type: object
            title: NotAuthorized
            required:
              - code
              - message
            properties:
              code:
                type: integer
                example: 400
              message:
                type: string
                example: Something went wrong.
            example:
              code: 401
              message: Malformed authorization.
          examples:
            response:
              value:
                code: 401
                message: Malformed authorization.
    NotFound:
      description: The specified resource was not found.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/XRequestId'
      content:
        application/json:
          schema:
            type: object
            title: NotFound
            required:
              - code
              - message
            properties:
              code:
                type: integer
                example: 400
              message:
                type: string
                example: Something went wrong.
            example:
              code: 404
              message: Not found.
          examples:
            response:
              value:
                code: 404
                message: Not found.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer

````