Get an External Account
Get an External Account by id.
Authorizations
Token from POST /auth/token
Path Parameters
External Account ID (ext_ prefix).
Response
The request has succeeded.
A saved payment destination registered for a customer or one of their counterparties. Exactly one of the per-type response detail objects is populated, selected by type. Write-only secrets (full account number, full IBAN) are never present on reads - only their last-4 renderings.
External Account ID (ext_ prefix).
^[a-z]+_([0-9a-hjkmnp-tv-z]{26}|[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})$Resource type discriminator. Always "externalAccount".
externalAccount Who owns this account: the customer or one of their counterparties.
- Customer-owned
- Counterparty-owned
Server-rendered display name of the owning Customer — lets a list row render "who owns this account" without a second request. Additive next to the owner reference. Present only when owner.kind is customer; absent for counterparty-owned accounts.
Resolved id + display name of the owning customer. Present only when owner.kind = customer; absent for counterparty-owned accounts.
The instrument type; determines which detail object is populated.
bankUs, bankIban, bankCanada, card, walletExternal High-level grouping: fiatAccount for bank or card accounts, crypto for wallets. The same value as the instrument category when this account is referenced in a transaction.
fiatAccount, crypto Current lifecycle status. A transition to invalid always fires the externalAccount.statusChanged webhook.
active, pending, rejected, invalid, deleted, failed Set when status = failed.
ereborRejected, cardProviderRejected, providerAccountMissing, cardLimitReached, cardInUse, provisioningTimeout, systemError Structured provider rejection detail. Set when status = failed and the failure was a provider terminal rejection; absent for provisioning timeouts and internal failures.
Why registration was rejected. Present when status is rejected; the key is absent otherwise.
countryProhibited, cardVerificationDeclined, bankVerificationDeclined, countryNotSupported Why the account became unusable after activation, derived from a returned payout. Present when status is invalid; the key is absent otherwise.
accountClosed, accountFrozenByBank, routingOrAccountNumberInvalid, accountHolderDeceased, accountDoesNotSupportTransfers, payeeNameMismatch, walletUnreachableOnNetwork, billingAddressMismatch, cardExpired, cardClosedOrLostStolen, pushToCardUnsupported, cardDeclinedByIssuer The provider's own code for the failure behind invalidReason, verbatim — for US bank accounts the NACHA return code from the failed payout, e.g. R15. Absent when the provider gave no code, or when the account was invalidated by something other than a returned payment.
Read invalidReason to decide what to do; read this when you need the precise cause for support or reconciliation. invalidReason is a deliberately small set, so several codes map to one member — treat this field as an open vocabulary and do not switch on it. A return code that maps to no invalidReason leaves the account active and sets neither field; the returned payout still fails the transaction, but the unmapped code is not surfaced on the External Account.
Optional display label.
Free-form key-value pairs supplied at creation or update.
Populated when type = bankUs.
Populated when type = bankIban.
Populated when type = bankCanada.
Populated when type = walletExternal.
Populated when type = card.
Transaction ids that this registration submitted for sender-attribution release. Returned ONLY on the POST create response, and only when registering this walletExternal matched held inbounds. Attribution is async: each entry is submitted to the provider from awaitingAction.awaitingSenderAttribution and moves to processing.fundsPulled once settlement confirms — so an immediate GET of an id may still show awaitingAction. Omitted on GETs (the create path is the only writer).
Public TypeID, e.g. txn_01h455vb4pex5vsknk084sn02q; legacy UUID suffixes are accepted until non-v7 rows are retired.
^[a-z]+_([0-9a-hjkmnp-tv-z]{26}|[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})$When the external account was registered.
When the external account was last updated.