Postman collection

The Cybrid-compatible Bank and Organization APIs — every endpoint, grouped by resource, ready to run against sandbox.

Generated from the API spec

This collection is built from the same OpenAPI document the API reference and the code samples come from, and a test fails the build if it drifts. It cannot describe an endpoint that does not exist, or miss one that does.

Getting set up

  1. Import both files: Import → drop them in. The environment is separate so your key never lives in the shared collection file.
  2. Select the DattaRemit — local sandbox environment. It sets base_url to http://localhost:4000 — change it if your API runs elsewhere. Then set two keys, both from API keys in your dashboard: secret_key to a sk_test_ key with bank scope, and organization_secret_key to one with organization scope. Both ship empty — nothing here can hold your key — so the environment carries the page that mints them as api_keys_url (http://localhost:3000/api-keys), and a request sent before secret_key is set stops with that reminder instead of an unhelpful 401.
  3. Open 1 · Smoke test and hit Send on Get Identity. A 200 means you are ready — the response echoes the scope of the key you used.

What is in it

1 · Bank API
Every Bank operation — accounts, customers, transfers, trades, plans and the rest — grouped by resource as the API reference groups them. Requests use {{bank_url}} and your bank-scoped key.
2 · Organization API
Organizations plus webhook subscriptions, events and deliveries. Requests use {{organization_url}} and authenticate with your organization-scoped key.

Running the whole lifecycle

Open the 2 · Full lifecycle folder, choose Run folder, and leave the order untouched — later steps read ids that earlier ones captured. The cleanup deletes sit at the end so a second run starts from a clean slate.

# Or from CI, with Newman:
newman run dattaremit.postman_collection.json \
  --folder "2 · Full lifecycle" \
  --env-var secret_key=$DATTAREMIT_SECRET_KEY \
  --env-var organization_secret_key=$DATTAREMIT_ORG_SECRET_KEY

Some steps will not pass on a fresh sandbox

Money movement depends on state that takes time or on a corridor your bank may not have enabled: a customer must pass identity verification before a transfer can be created, a trade needs settled USD, and the India payout leg is gated separately.

Those steps deliberately assert only that the request was understood — not a 5xx, not an auth or routing error — and log the problem response to the Postman console so you can see exactly what is being waited on. Asserting success there would give you a collection that fails for reasons you cannot fix, which is a fast way to learn to ignore a red run.

Sandbox keys only

Nothing here is safe to point at production. The lifecycle folder creates customers and moves money, and it ends by deleting what it made.