Authentication
An EEA integration authenticates at two independent layers. Implement both:Platform authentication
Under MiCA, your entity authenticates to Circle with mTLS in addition to your API key. Circle issues your client certificate from its private certificate authority; you don’t purchase a Qualified Website Authentication Certificate (QWAC) or any other third-party certificate. Circle presents a QWAC as its server certificate on the regional EU host,api-eu.circle.com, and your client
validates it. See
How mTLS authentication works.
End-user approval with SCA
Each money movement or trusted-destination change for an end user booked to Circle’s EEA entity requires a passkey approval from that end user. Your platform’s API key and mTLS session don’t satisfy this requirement on their own: a protected endpoint returns HTTP428 until the request carries a valid SCA
assertion. See
How Strong Customer Authentication works
and
Implement Strong Customer Authentication.
Console sign-in for your team
Your own team members who use the Mint Console sign in with Okta Verify (possession factor) and a 4-digit PIN (knowledge factor). This governs your staff’s console access, such as creating API keys or changing IP allowlist settings. It’s separate from end-user SCA and doesn’t apply to API calls.Platform address book
EEA outbound crypto transfers are subject to Travel Rule obligations and strict beneficiary controls. Register every external beneficiary address as a recipient address before you initiate a transfer to it. For end users booked to Circle’s EEA entity, the request must declare walletownership, and adding or deleting an
address requires an SCA approval.
Address statuses
Transfers to an address that isn’t registered, or that isn’t
active, are
rejected at the API level. This is fail-closed behavior: there is no silent
degradation or fallback.
Deposit addresses are not part of the Platform Address Book; the address book
governs outbound transfers only.
Fail-closed asset scope
Digital Asset Accounts in the EEA is limited to operations in the scope of MiCA Article 60(4). API requests for out-of-scope operations return an error. The following operations are blocked in the EEA:No burn fees
Digital Asset Accounts does not charge burn fees and does not participate in redeemer of last resort (ROLR) programs for EEA accounts.MiCA balance reporting
EEA distributors’ subaccount balances are included in Circle’s ACPR regulatory reporting through the Reserve Management API.Circle files the MiCA balance report with the ACPR on behalf of your program.
You do not submit this report directly.
Endpoint
Submit balance data using the following endpoint:Required fields
SetreportType to eea. The following top-level field is also required:
The following fields are required in
additionalFields:
Reporting rules
- FX conversion: Euro-equivalent values use the ECB rate for the reporting date.
- Frequency: One submission per day, per currency. USDC and EURC are submitted as separate reports.
- Currency scope: Only USDC and EURC are in scope for reporting.