Xace API
Build with Xace. Ship Finance, Fast.
Embed accounts, payments, FX, and approvals straight into your product—on infrastructure trusted by iGaming leaders and built for regulated scale.
API coverage
Accounts, payments, FX, and events — one surface
Every banking primitive accessible from a single integration point. No separate providers, no undocumented endpoints, no surprises at scale.
Complete REST surface
Accounts, payments, FX, payees, and approval controls across consistent REST endpoints. Versioned contracts, idempotency keys on writes, and predictable error handling at every primitive.
Real-time event streams
Subscribe to granular account and payment events. Automatic retry with exponential backoff and full delivery logs keep your integration in sync without polling.
Full sandbox from day one
Mirrors production exactly — same endpoints, same auth schema, simulated rails. Your integration is proven before it touches live money.
Three layers of the API
Every banking primitive — documented and ready to call
Accounts, payments, FX, Open Banking, and approval controls as clean REST endpoints. Consistent patterns, versioned contracts, idempotency on every write operation.
Accounts, payments, and FX in one surface
One integration delivers programmatic access to multi-currency accounts, payment initiation across SEPA/FPS/SWIFT, FX conversion, and payee management — no separate providers.
Predictable patterns at every endpoint
Consistent JSON structure, explicit error codes, idempotency keys on all write operations, and cursor pagination — so your integration behaves as expected at scale.
OAuth 2.0 with scoped access control
Granular permission scopes let every API client hold exactly the access it needs. Server-to-server and user-delegated flows both supported from the same credential model.
Authentication
Secure by default. Flexible by design.
OAuth 2.0 with granular permission scopes means every API client holds exactly the access it needs — nothing more. Server-to-server flows handle backend integrations; user-delegated flows support multi-tenant architectures where users grant scoped access to their own accounts. JWT Bearer tokens rotate automatically, and every authentication event is logged and auditable from the developer dashboard.
Rate limits
Built for production throughput, not sandboxed demos
Generous per-method rate limits with standard response headers let your integration plan around capacity rather than react to failures. Burst allowances handle high-volume payment windows — bulk payroll runs, affiliate batch payouts, FX conversion cycles — without surprises. Rate limit status surfaces in every response, so your system degrades gracefully when headroom narrows rather than silently failing at the worst moment.
Batch operations
Process thousands of payments without per-request overhead
Batch endpoints across payments, payee creation, and FX conversions handle high-volume flows in single API calls. Idempotency keys are supported on every batch operation — retries are safe by default, with no duplicate payments and no partial-failure risk left unresolved. Batch results return per-item status so your system handles the minority of exceptions without reprocessing the entire set.
Built for evaluators
The API documentation developers actually trust
Most banking APIs are designed for getting-started guides — not the technical questions that matter when a product team commits to an integration. What does the rate limit look like at a hundred thousand payments a month? How does the auth model handle a multi-tenant architecture? What happens to a webhook when it fails three consecutive deliveries?
Xace API documentation covers those questions directly — with accurate reference docs, reproducible sandbox scenarios, and a technical contact who knows the integration from the inside. The goal is that your engineering team has real confidence before the first production call, not after the integration is already serving customers.
The API built for production teams
REST
Versioned API with idempotency keys
Full
Sandbox with simulated rails
Real-time
Webhooks with retry logic
OAuth 2.0
Granular scoped access
Technical questions
FAQs for builders
Answers for product and engineering teams validating API coverage, authentication, rate limits, and sandbox depth.
Where next
Keep building