API structure
API overview
At Cross River, we have a robust set of APIs spanning our suite of products. To access our APIs and try them out in our sandbox, contact Integration Support to get started.
Our APIs follow REST principles and use object-oriented URLs. Requests are form-encoded, responses are JSON-encoded, and we use standard HTTP methods, authentication, and response codes.
When you call an API, you've sent a request. The answer you receive back is the response.
Resource/object
A resource (object) is the category of information that you want to receive information for, via API. For example, in our P2C product, a card and a transaction are resources, and in our lending product, a loan is a resource.
Endpoints and methods
- An endpoint is the URL address of an API that you want to retrieve. You can retrieve an endpoint by using a method.
- The method is the prefix you add to your endpoint to send the relevant API request. They are:
Prefix | Description |
|---|---|
GET | A GET request retrieves resource information. A GET request never has a body. |
POST | A POST request adds or creates a resource. |
PUT | A PUT request updates or fixes resource information. |
DELETE | A DELETE request deletes or cancels a resource. |
PATCH | A PATCH request updates or fixes a smaller scope of resource information. |
Parameters
There are 3 types of parameters:
Path
A path parameter can be added to a URL endpoint to return a specific response. The path parameter is added to the URL in curly brackets ({ }) and follows a backslash (/).
For example, if you want to retrieve specific information on an account, you can add /{accountnumber} to the URL.
When your API includes curly brackets, a path parameter is required.
Body
Body parameters are the data included in the body of an API, and the information they represent can be changed. The body of the request and response messages are called payloads.
Query
A query parameter narrows down and filters the results of your request based on the information you are requesting. The query parameter is added to the URL and follows a question mark (?). Only GET calls use query parameters.
Request headers
A request header is an HTTP header used in a request that provides information about the request context. It let's the server tailor the response.
In our documentation requests are presented in cURL.
Header | Description |
|---|---|
Authorization: {bearer token} | Authorization credentials for HTTP authentication. Include the bearer token in the Authorization header. |
Content-Type | Required for operations with a request body such as POST and PUT requests. The value is application/json indicating that the request body format is JSON.
|
Accept: application/json | Sets the output type to JSON. |
curl --location --request GET 'https://cr-sandbox-domain/{xxx}
--header 'Accept: application/json'
--header 'Authorization: {Bearer token}' 'https://cr-sandbox-domain/'Request ID
For every request, the response header contains a Requst-ID value. This unique identifier is used by the Cross River Support Team for troubleshooting. We strongly recommend you save this identifier.
String validation
Most parameters use the following regex: ^[A-Za-z0-9^ !_\-@'`\t()#""""*\]+{}|~$%&,:.-\\]+$
Next steps
When you're ready to start trying out our APIs, follow these steps:
- Get an access token (a bearer token).
- Start calling our APIs.