Concepts

The handful of ideas the rest of the API assumes you already know.

Organizations

Everything on the platform belongs to an organization — your company as we know it. API keys, end customers, counterparties, plans and webhook endpoints are all scoped to exactly one organization, and nothing is shared between them.

That scoping is enforced on every request, not just in the dashboard. An API key belongs to one organization, so it can only ever address that organization's resources — there is no cross-organization call to make. Requesting an ID that belongs to someone else returns 404, never 403: a 403 would confirm the ID exists.

Lifecycle

Pending

Created, awaiting our review. You can explore the dashboard; you cannot move money.

Active

Approved. Live keys work, subject to your limits.

Suspended

Access disabled. API calls are rejected until reinstated.

New organizations start in review — we activate them manually, so nobody reaches the payment rails by self-service alone.

Team roles

Teammates are added from Settings → Team in the dashboard and hold one role each.

OWNER

Full access, including billing and transferring ownership. Every organization must keep at least one.

ADMIN

Manage the team, API keys, webhooks and settings.

DEVELOPER

Create API keys and send test remittances. Cannot change the team.

VIEWER

Read-only access to customers and the plan ledger.

Roles gate the dashboard, keys gate the API

A role controls what a teammate can do in the console. It does not restrict an API key — any key can call any endpoint its organization is entitled to. Per-key scopes are on the roadmap.

Sandbox and live

Every organization has two environments, told apart by the key prefix. The API shape is identical in both, so the only change when you go live is the key.

Sandbox
sk_test_… — hits the Cybrid sandbox. No real money moves. KYC auto-passes and funding settles in seconds.
Live
sk_live_… — real money, real KYC, real ACH timing. Requires an active organization.

Sandbox timing is not live timing

Sandbox settles almost instantly. In production, ACH funding takes about one business day, so build your UX around the plan.funding event rather than assuming a fast round trip.

Identifiers

The API is Cybrid-compatible, so every resource carries a guid— a 32-character identifier, the same shape Cybrid uses. An existing Cybrid integration's stored ids keep working unchanged.

guid   "1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d"   customer, transfer, plan, …
bank_guid        the bank the object belongs to
customer_guid    the customer an object belongs to