Skip to main content
POST
Create an account transfer

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Headers

X-Sca-Challenge-Id
string<uuid>

The challengeId returned by POST /v1/accounts/passkeys/challenges. Required for end users under EEA/FR legal entities (PSD2 SCA). Omit for all other end users.

Example:

"b2c3d4e5-f6a7-8901-bc23-def456789012"

X-Sca-Assertion
string

The signed assertion string returned by the DAA web SDK's sca.approve method. Required for end users under EEA/FR legal entities (PSD2 SCA). Pass the value through unchanged — do not base64-encode or re-serialize it.

Body

application/json
idempotencyKey
string<uuid>
required

Universally unique identifier (UUID v4) idempotency key. This key is utilized to ensure exactly-once execution of mutating requests.

Example:

"ba943ff1-ca16-49b2-ba55-1057e70ca5c7"

destination
object
required

The destination of a transfer. Can be a verified blockchain address or another account.

amount
object
required
riskSignals
object
required

Risk metadata for the end user initiating the request. All three fields must be present.

deviceId must be the identifier returned by checkDevice() in the @circle-fin/device-checks SDK. Circle resolves it against the device check that produced it, so an identifier you generate yourself does not resolve. When it does not resolve, the request is accepted and then declined: the endpoint returns 201, and the transaction later settles as failed with errorCode transfer_denied. See Collect device risk signals.

source
object

The source of the transfer. The type must be account.

Response

Successfully created a transfer.

data
object

A transfer of funds returned by the create transfer endpoint.