Welcome to the GoEscrow Partner API Documentation for E-Commerce Retailers and Marketplace operators.
This documentation aims to provide all the information you need to work with our API.
You may find the partner application, additional support documentation and whitepaper for the GoEscrow Partner API here.
State-changing requests can be safely retried without performing the operation twice by sending an Idempotency-Key header. We strongly recommend using it on every money-movement request, so that a network timeout or a retry never results in a duplicate transaction.
How to use it
Idempotency-Key request header.Idempotent-Replayed: true header.Status codes you may receive
409 Conflict — a request with the same key is still being processed. Wait a moment and retry.422 Unprocessable Entity — the key was already used with a different request body. Use a new key for a different operation.Notes
2xx) responses are remembered. If a request fails, the key is released so you can safely retry it with the same key.Idempotency keys are honoured on: create transaction, settle transaction, request cancellation, PayTo payment, and create dispute.
To authenticate requests, include a X-API-Key header with the value "{YOUR_AUTH_KEY}".
All authenticated endpoints are marked with a requires authentication badge in the documentation below.
To connect via API authentication is required.
Contact your GoEscrow account manager for a one time use URL token to create your X-API-Key. Send that specific X-API-Key in a custom header (replacing '123456789abcdef') as follows:
POST /v1/transactions HTTP/1.1
Host: partners.goescrow.net
X-API-Key: 123456789abcdef
Content-Type: application/json
Accept: application/json
curl --request GET \
--get "https://partners.staging.goescrow.net/api/v1/healthcheck" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" Manage Companies
Looks up an existing company by Australian Business Number. Access is limited to companies represented by a user belonging to the authenticated partner, unless using an internal API key.
The Australian Business Number. Formatting spaces are accepted.
curl --request GET \
--get "https://partners.staging.goescrow.net/api/v1/companies/lookup?abn=40+650+703+736" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" {
"data": {
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"reference": "ABC123",
"name": "Acme Corp Pty Ltd",
"abn": "40650703736",
"acn": "004085616",
"kyb_verified": true,
"aml_verified": true,
"aml_verified_at": "2026-06-25T00:00:00.000000Z",
"bank_verified": true,
"abr_status": "Active",
"representatives": [
{
"id": "9d2e5c8a-1234-5678-9abc-def012345679",
"reference": "ABC123",
"name": "Jane Doe"
}
]
}
}
Creates a new company and attaches one or more existing users as its representatives.
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/companies" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"name\": \"Acme Corp Pty Ltd\",
\"abn\": \"40650703736\",
\"acn\": \"004085616\",
\"email\": \"info@acmecorp.com.au\",
\"phone\": \"+61298765432\",
\"website\": \"https:\\/\\/www.acmecorp.com.au\",
\"type\": \"Proprietary Limited\",
\"majority_owned_by_another_australian_company\": false,
\"majority_owned_by_overseas_person_or_company\": false,
\"majority_owned_by_listed_australian_company\": false,
\"acting_as_trustee_for_a_trust\": false,
\"representatives\": [
\"9d2e5c8a-1234-5678-9abc-def012345678\"
],
\"address\": {
\"unit_number\": \"3\",
\"street_number\": \"20\",
\"street\": \"Company Street\",
\"suburb\": \"Melbourne\",
\"state\": \"VIC\",
\"postcode\": \"3000\",
\"country\": \"Australia\"
}
}"
{
"data": {
"id": "comp_123",
"reference": "ABC123",
"name": "Acme Corp Pty Ltd",
"abn": "40650703736",
"acn": "004085616",
"kyb_verified": true,
"aml_verified": true,
"aml_verified_at": "2026-06-25T00:00:00.000000Z",
"bank_verified": true,
"abr_status": "Active",
"representatives": [
{
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"reference": "ABC123",
"name": "Jane Doe"
}
]
}
}
Updates an existing company. Only provided fields will be updated. ABN must be omitted, even when unchanged; create a new company for a different ABN.
The company UUID (36-character internal identifier)
curl --request PUT \
"https://partners.staging.goescrow.net/api/v1/companies/1" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"name\": \"Acme Corp Pty Ltd\",
\"acn\": \"004085616\",
\"email\": \"info@acmecorp.com.au\",
\"phone\": \"+61298765432\",
\"website\": \"https:\\/\\/www.acmecorp.com.au\",
\"type\": \"Proprietary Limited\",
\"majority_owned_by_another_australian_company\": false,
\"majority_owned_by_overseas_person_or_company\": false,
\"majority_owned_by_listed_australian_company\": false,
\"acting_as_trustee_for_a_trust\": false,
\"add_representatives\": [
\"9d2e5c8a-1234-5678-9abc-def012345678\"
],
\"remove_representatives\": [
\"9d2e5c8a-1234-5678-9abc-def012345679\"
],
\"address\": {
\"unit_number\": \"3\",
\"street_number\": \"20\",
\"street\": \"Company Street\",
\"suburb\": \"Melbourne\",
\"state\": \"VIC\",
\"postcode\": \"3000\",
\"country\": \"Australia\"
}
}"
{
"data": {
"id": "comp_123",
"reference": "ABC123",
"name": "Acme Corp Pty Ltd",
"abn": "40650703736",
"acn": "004085616",
"kyb_verified": true,
"aml_verified": true,
"aml_verified_at": "2026-06-25T00:00:00.000000Z",
"bank_verified": true,
"abr_status": "Active",
"representatives": [
{
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"reference": "ABC123",
"name": "Jane Doe"
}
]
}
}
Uploads one or more files to a company filing cabinet. The authenticated partner must represent the company.
The company UUID (36-character internal identifier)
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/companies/9d2e5c8a-1234-5678-9abc-def012345678/files" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: multipart/form-data" \
--header "Accept: application/json" \
--form "files[]=@/tmp/phpq49sfpgbkkildILogIl" {
"data": [
{
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"file": "a1b2c3d4/document.pdf",
"filename": "document.pdf",
"created_at": "2024-01-15T10:30:00Z"
}
]
}
Manage Users
Creates a new user. Email and phone must be unique. The user will be automatically associated with the authenticated partner. If the authenticated Partner has welcome emails enabled, newly created API users receive a GoEscrow Welcome By Partner email with a 24-hour, single-use password setup link.
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/users" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"first_name\": \"John\",
\"last_name\": \"Doe\",
\"email\": \"john.doe@example.com\",
\"phone\": \"+61412345678\",
\"birth_date\": \"1990-01-15\",
\"initiate_mobile_verification_flow\": \"yes\",
\"address\": {
\"unit_number\": \"10B\",
\"street_number\": \"123\",
\"street\": \"Smith St\",
\"suburb\": \"Sydney\",
\"state\": \"NSW\",
\"postcode\": \"2000\"
}
}"
{
"data": {
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"reference": "ABC123",
"first_name": "John",
"last_name": "Doe",
"email": "john.doe@example.com",
"phone": "+61412345678",
"birth_date": "1990-01-15",
"kyc_verified": false,
"aml_verified": false,
"aml_verified_at": null,
"email_verified": false,
"mobile_verified": false,
"mobilekyc_verified": false,
"bank_verified": false,
"suspended": false,
"address": {
"unit_number": "10B",
"street_number": "123",
"street": "Smith St",
"suburb": "Sydney",
"state": "NSW",
"postcode": "2000",
"country": "Australia"
}
}
}
Updates an existing user for the authenticated partner. Email and phone must remain unique.
The user UUID (36-character internal identifier)
curl --request PUT \
"https://partners.staging.goescrow.net/api/v1/users/1" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"first_name\": \"John\",
\"last_name\": \"Doe\",
\"email\": \"john.doe@example.com\",
\"phone\": \"+61412345678\",
\"birth_date\": \"1990-01-15\",
\"address\": {
\"unit_number\": \"10B\",
\"street_number\": \"123\",
\"street\": \"Smith St\",
\"suburb\": \"Sydney\",
\"state\": \"NSW\",
\"postcode\": \"2000\"
}
}"
{
"data": {
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"reference": "ABC123",
"first_name": "John",
"last_name": "Doe",
"email": "john.doe@example.com",
"phone": "+61412345678",
"birth_date": "1990-01-15",
"kyc_verified": false,
"aml_verified": false,
"aml_verified_at": null,
"email_verified": false,
"mobile_verified": false,
"mobilekyc_verified": false,
"bank_verified": false,
"suspended": false,
"address": {
"unit_number": "10B",
"street_number": "123",
"street": "Smith St",
"suburb": "Sydney",
"state": "NSW",
"postcode": "2000",
"country": "Australia"
}
}
}
Look up an existing user by email, phone, or GoEscrow reference. Company reference matches return only the company name and reference. Exactly one parameter must be provided.
The user's email address. Supply exactly one of email, phone, or reference.
The user's phone number. Supply exactly one of email, phone, or reference. Accepts 0412345678, +61412345678, or 61412345678.
A user or company GoEscrow reference. Supply exactly one of email, phone, or reference.
curl --request GET \
--get "https://partners.staging.goescrow.net/api/v1/users/lookup?email=john.doe%40example.com&phone=%2B61412345678&reference=ABC123" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" {
"data": {
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"reference": "ABC123",
"first_name": "John",
"last_name": "Doe",
"email": "john.doe@example.com",
"phone": "+61412345678",
"birth_date": "1990-01-15",
"kyc_verified": true,
"aml_verified": true,
"aml_verified_at": "2026-06-25T00:00:00.000000Z",
"email_verified": true,
"mobile_verified": true,
"mobilekyc_verified": true,
"bank_verified": true,
"suspended": false,
"address": {
"unit_number": "1",
"street_number": "123",
"street": "Main Street",
"suburb": "Sydney",
"state": "NSW",
"postcode": "2000",
"country": "Australia"
}
}
}
Sends a verification code via SMS to the user's registered phone number. The code will be valid for a limited time.
The user UUID (36-character internal identifier)
curl --request GET \
--get "https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/verify-mobile" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" [Empty response]
Verifies the mobile phone number using the code sent via SMS. Upon successful verification, the user's phone will be marked as verified.
The user UUID (36-character internal identifier)
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/verify-mobile" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"code\": \"123456\"
}"
[Empty response]
Sends a verification code via email to the user's registered email address. The code will be valid for a limited time.
The user UUID (36-character internal identifier)
curl --request GET \
--get "https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/verify-email" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" [Empty response]
Verifies the email address using the code sent via email. Upon successful verification, the user's email will be marked as verified.
The user UUID (36-character internal identifier)
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/verify-email" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"code\": \"123456\"
}"
[Empty response]
Generates and returns a PDF bank statement for the specified user. The statement includes transaction history and account details.
The user UUID (36-character internal identifier)
curl --request GET \
--get "https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/bank-statement" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" []
Uploads one or more files to a user filing cabinet. The authenticated partner must own the user.
The user UUID (36-character internal identifier)
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/files" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: multipart/form-data" \
--header "Accept: application/json" \
--form "files[]=@/tmp/php87mnhuep7j1gaAIfEno" {
"data": [
{
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"file": "a1b2c3d4/document.pdf",
"filename": "document.pdf",
"created_at": "2024-01-15T10:30:00Z"
}
]
}
Generates a short-lived password reset link for the user.
The user UUID (36-character internal identifier)
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/password-reset-link" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"send_email\": true
}"
{
"reset_url": "https://app.goescrow.com.au/auth/forgot-password/abc123",
"expires_in": "60 minutes"
}
Create and manage transaction disputes
Creates a dispute for a transaction. This will mark the transaction as disputed and create a compliance note for the CS team to review.
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/disputes" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Idempotency-Key: 6f3a8e1c-9b2d-4f5a-8c1e-2a7b9d0e1f23" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"requester_id\": \"9d2e5c8a-1234-5678-9abc-def012345678\",
\"requester_role\": \"buyer\",
\"transaction_id\": \"9d2e5c8a-1234-5678-9abc-def012345678\",
\"request_type\": \"pause\",
\"issue_description\": \"The goods were not delivered as described.\"
}"
{
"message": "Dispute created successfully.",
"dispute_reference": "DISP-2024-001234",
"transaction_id": "9d2e5c8a-1234-5678-9abc-def012345678",
"status": "disputed"
}
Manage cancellation requests and approvals for partner transactions.
A transaction with two or more disbursement entries uses per-party cancellation approval. The API derives the parties from the saved payer and disbursement recipients. Do not include a list of other parties or resend the disbursement array in cancellation requests. All calls below use the existing /api/v1/transactions/{transaction_id} endpoints.
/cancellation-request with requester_id, the requesting user or company UUID. For a company with multiple representatives, also send representative_id, the UUID of the linked user acting for that company. Use the same representative for code delivery and verification.requires_2fa is true, codes have been sent but the request has not yet been created. POST /verify-cancellation with the same actor details, email_code and phone_code to create it.cancellation_request_id. Each other party POSTs /cancellation-accept with its own accepter_id, the current cancellation_request_id and, where needed, representative_id.requires_2fa: true, that party POSTs /verify-cancellation-accept with the same actor details and request ID, plus email_code and phone_code./cancellation-deny with denier_id, the current cancellation_request_id and, where needed, representative_id. Denial does not require verification codes.For example, an individual requests cancellation without listing the other parties:
{"requester_id": "9d2e5c8a-1234-5678-9abc-def012345678"}
After the request is created, another party accepts using the returned request ID:
{"accepter_id": "9d2e5c8a-1234-5678-9abc-def012345680", "cancellation_request_id": "2c9bb6a0-b123-4567-89ab-0123456789ab"}
The requester contributes the first approval. With one payer and two distinct payees, all three legal parties must approve; one representative acting for two companies must approve separately for each company. An HTTP 200 can mean only that one approval was recorded. The transaction remains cancellation_requested until all required approvals are complete. Check status for canceled; refund processing may still be pending.
Pending multi-payee transactions also require all parties to approve; they are not cancelled immediately. Partially or fully funded multi-payee transactions require email and phone verification for every approval, based on positive, unreversed payment receipts. If funding arrives after an unverified approval, that party must approve again with verification. Codes expire after five minutes and are bound to the transaction, legal party, representative and cancellation attempt.
A missing or stale cancellation_request_id on acceptance, acceptance verification or denial returns HTTP 422. Refresh the transaction and use the current ID; do not replay an old approval against a new request. The response ID is null before a request is created and after cancellation or denial ends it. Older active requests without a generated ID return legacy; send the returned value unchanged.
Denial normally restores the previous status. For a multi-payee Timed transaction less than 12 hours before a future release, denial instead sets contact_helpdesk, suspends payee settlements and alerts customer service.
Single-payee and marketplace transactions retain their existing cancellation flow. The multi-payee-only fields and approval rules below do not change that flow.
Initiates cancellation. For non-marketplace multi-payee Anytime and Timed transactions, supply only the requesting party ID and, when needed, its representative ID; the API already knows the other parties. Unfunded pending or accepted transactions enter cancellation_requested with the requester approval recorded. If requires_2fa is true, call verify-cancellation to create the request. Single-payee pending transactions retain immediate cancellation; accepted transactions retain the existing counterparty flow.
The transaction UUID (36-character internal identifier)
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/transactions/9d2e5c8a-1234-5678-9abc-def012345678/cancellation-request" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Idempotency-Key: 6f3a8e1c-9b2d-4f5a-8c1e-2a7b9d0e1f23" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"requester_id\": \"9d2e5c8a-1234-5678-9abc-def012345678\",
\"representative_id\": \"9d2e5c8a-1234-5678-9abc-def012345679\"
}"
{
"message": "Cancellation requested. 2FA verification required. Codes sent to requester's email and phone.",
"requires_2fa": true,
"transaction_id": "9d2e5c8a-1234-5678-9abc-def012345678",
"status": "accepted"
}
Verifies requester codes and creates the cancellation request. For multi-payee transactions, this records only the requester approval and returns cancellation_request_id for the remaining parties. Use the same requester_id and representative_id as the code-delivery call. No cancellation_request_id is needed to create the request.
The transaction UUID (36-character internal identifier)
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/transactions/9d2e5c8a-1234-5678-9abc-def012345678/verify-cancellation" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"requester_id\": \"9d2e5c8a-1234-5678-9abc-def012345678\",
\"email_code\": \"123456\",
\"phone_code\": \"654321\",
\"representative_id\": \"9d2e5c8a-1234-5678-9abc-def012345679\"
}"
{
"message": "Cancellation requested. Waiting for counterparty response.",
"requires_2fa": false,
"transaction_id": "9d2e5c8a-1234-5678-9abc-def012345678",
"status": "cancellation_requested"
}
Records approval from one outstanding party. Multi-payee requests require the current cancellation_request_id. If requires_2fa is true, codes were sent but approval is not yet recorded: call verify-cancellation-accept. Otherwise HTTP 200 may still have status cancellation_requested while other approvals are outstanding. Only the final required approval completes cancellation. Single-payee requests retain the existing counterparty flow.
The transaction UUID (36-character internal identifier)
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/transactions/9d2e5c8a-1234-5678-9abc-def012345678/cancellation-accept" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"accepter_id\": \"9d2e5c8a-1234-5678-9abc-def012345678\",
\"representative_id\": \"9d2e5c8a-1234-5678-9abc-def012345679\",
\"cancellation_request_id\": \"2c9bb6a0-b123-4567-89ab-0123456789ab\"
}"
{
"message": "Cancellation acceptance requires 2FA verification. Codes sent to accepter's email and phone.",
"requires_2fa": true,
"transaction_id": "9d2e5c8a-1234-5678-9abc-def012345678",
"status": "cancellation_requested"
}
Verifies one party approval using email_code and phone_code. For multi-payee transactions, include the current cancellation_request_id and use the same accepter_id and representative_id as the code-delivery call. Cancellation remains pending until the payer and every payee have approved with any required verification.
The transaction UUID (36-character internal identifier)
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/transactions/9d2e5c8a-1234-5678-9abc-def012345678/verify-cancellation-accept" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"accepter_id\": \"9d2e5c8a-1234-5678-9abc-def012345678\",
\"email_code\": \"123456\",
\"phone_code\": \"654321\",
\"representative_id\": \"9d2e5c8a-1234-5678-9abc-def012345679\",
\"cancellation_request_id\": \"2c9bb6a0-b123-4567-89ab-0123456789ab\"
}"
{
"message": "Cancellation accepted. Transaction cancelled successfully.",
"requires_2fa": false,
"transaction_id": "9d2e5c8a-1234-5678-9abc-def012345678",
"status": "canceled"
}
Denies an active cancellation request without verification codes. For multi-payee transactions, only a party still requiring approval may deny; supply the current cancellation_request_id. Normally restores the previous status. Within 12 hours before a future Timed release, multi-payee denial instead sets contact_helpdesk, suspends payee settlements and alerts customer service. Single-payee requests retain their existing denial flow.
The transaction UUID (36-character internal identifier)
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/transactions/9d2e5c8a-1234-5678-9abc-def012345678/cancellation-deny" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"denier_id\": \"9d2e5c8a-1234-5678-9abc-def012345678\",
\"representative_id\": \"9d2e5c8a-1234-5678-9abc-def012345679\",
\"cancellation_request_id\": \"2c9bb6a0-b123-4567-89ab-0123456789ab\"
}"
{
"message": "Cancellation denied. Transaction reverted to active status.",
"transaction_id": "9d2e5c8a-1234-5678-9abc-def012345678",
"status": "accepted"
}
Manage Transactions
Creates a new escrow transaction with disbursements. Partner API transactions are auto-accepted (skip pending status).
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/transactions" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Idempotency-Key: 6f3a8e1c-9b2d-4f5a-8c1e-2a7b9d0e1f23" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"action\": \"buy\",
\"type\": \"anytime_escrow\",
\"amount_type\": \"escrow\",
\"other_user\": \"9d2e5c8a-1234-5678-9abc-def012345678\",
\"other_company_id\": \"9d2e5c8a-1234-5678-9abc-def012345678\",
\"sub_type\": \"marketplace\",
\"user_id\": \"9d2e5c8a-1234-5678-9abc-def012345678\",
\"company_id\": \"9d2e5c8a-1234-5678-9abc-def012345678\",
\"marketplace_operator_id\": \"9d2e5c8a-1234-5678-9abc-def012345678\",
\"release_at\": \"2024-12-31T23:59:59Z\",
\"details\": \"Dental Surgery\",
\"amount\": 15000050,
\"disbursements\": [
\"fugit\"
],
\"beneficiaries\": [
{
\"first_name\": \"Greg\",
\"last_name\": \"Recipient\",
\"mobile\": \"+61400000001\",
\"required\": true
}
]
}"
{
"data": {
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"reference": "TXN-2024-001234",
"type": "anytime_escrow",
"sub_type": "marketplace",
"status": "accepted",
"funding_status": "pending",
"amount": 150000.5,
"details": "Property settlement for 123 Main St",
"created_at": "2024-01-15T10:30:00Z",
"beneficiaries": [
{
"id": "9d2e5c8a-1234-5678-9abc-def012345679",
"first_name": "G**g",
"last_name": "R*******t",
"mobile": "+61******001",
"required": true,
"status": "pending"
}
]
}
}
Returns full transaction details including funding information. Provide exactly one of transaction_id or reference_id. Requires party_id to verify access.
The transaction UUID (36-character internal identifier). Required when reference_id is not provided. Must not be provided with reference_id.
The transaction reference number. Required when transaction_id is not provided. Must not be provided with transaction_id.
The ID of the buyer, seller, or disbursement recipient to verify access
curl --request GET \
--get "https://partners.staging.goescrow.net/api/v1/transactions/status?transaction_id=9d2e5c8a-1234-5678-9abc-def012345678&reference_id=TXN-2024-001234&party_id=9d2e5c8a-1234-5678-9abc-def012345678" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"transaction_id\": \"4b3f9a1c-0e69-32e3-90a4-369d7ca4699f\",
\"reference_id\": \"et\",
\"party_id\": \"609298a8-62fe-3779-9328-1ed7e3ca5d01\"
}"
{
"data": {
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"reference": "TXN-2024-001234",
"type": "anytime_escrow",
"sub_type": "marketplace",
"status": "accepted",
"funding_status": "pending",
"amount": 150000.5,
"fee": 1500,
"amount_with_fee": 151500.5,
"details": "Property settlement",
"release_at": null,
"created_at": "2024-01-15T10:30:00Z",
"buyer_id": "9d2e5c8a-1234-5678-9abc-def012345678",
"buyer_reference": "ABC123",
"seller_id": "9d2e5c8a-1234-5678-9abc-def012345679",
"seller_reference": "XYZ789",
"other_party_hint": "J*** D***",
"funding_details": {
"bsb": "123456",
"account_number": "12345678",
"account_name": "GoEscrow Trust",
"pay_id": "pay@goescrow.com.au",
"reference": "TXN-2024-001234",
"rail": "azupay",
"account_scope": "transaction",
"payment_reference": "TXN-2024-001234",
"reference_required": false,
"provisioning_status": "ready",
"amount_received": "0.00",
"amount_outstanding": "151500.50"
}
}
}
Returns full transaction details including funding information. Requires party_id to verify access.
The transaction UUID (36-character internal identifier)
The ID of the buyer or seller to verify access
curl --request GET \
--get "https://partners.staging.goescrow.net/api/v1/transactions/1?party_id=9d2e5c8a-1234-5678-9abc-def012345678" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" {
"data": {
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"reference": "TXN-2024-001234",
"type": "anytime_escrow",
"sub_type": "marketplace",
"status": "accepted",
"funding_status": "pending",
"amount": 150000.5,
"fee": 1500,
"amount_with_fee": 151500.5,
"details": "Property settlement",
"release_at": null,
"created_at": "2024-01-15T10:30:00Z",
"buyer_id": "9d2e5c8a-1234-5678-9abc-def012345678",
"buyer_reference": "ABC123",
"seller_id": "9d2e5c8a-1234-5678-9abc-def012345679",
"seller_reference": "XYZ789",
"other_party_hint": "J*** D***",
"funding_details": {
"bsb": "123456",
"account_number": "12345678",
"account_name": "GoEscrow Trust",
"pay_id": "pay@goescrow.com.au",
"reference": "TXN-2024-001234",
"rail": "azupay",
"account_scope": "transaction",
"payment_reference": "TXN-2024-001234",
"reference_required": false,
"provisioning_status": "ready",
"amount_received": "0.00",
"amount_outstanding": "151500.50"
}
}
}
Creates or rotates a single-use beneficiary confirmation link and sends it by SMS to the beneficiary. The token and confirmation URL are not returned to the partner.
The transaction UUID
The beneficiary UUID
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/transactions/1/beneficiaries/1/confirmation-request" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"heading\": \"Confirm your session\"
}"
{
"data": {
"message": "Confirmation link sent",
"beneficiary_id": "9d2e5c8a-1234-5678-9abc-def012345678",
"sent_to": "+614****5678",
"expires_at": "2026-08-16T12:00:00+00:00",
"heading": "Confirm receipt"
}
}
Calculates fees and provides a quote for a transaction without creating it. Uses the same request structure as transaction creation. This allows partners to show pricing to their customers before committing to a transaction.
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/transactions/quote" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"action\": \"buy\",
\"type\": \"anytime_escrow\",
\"amount_type\": \"escrow\",
\"other_user\": \"9d2e5c8a-1234-5678-9abc-def012345678\",
\"other_company_id\": \"9d2e5c8a-1234-5678-9abc-def012345678\",
\"sub_type\": \"super_disbursement\",
\"user_id\": \"9d2e5c8a-1234-5678-9abc-def012345678\",
\"company_id\": \"9d2e5c8a-1234-5678-9abc-def012345678\",
\"release_at\": \"2024-12-31T23:59:59Z\",
\"details\": \"Dental Surgery\",
\"amount\": 15000050,
\"disbursements\": [
\"adipisci\"
]
}"
{
"data": {
"sub_type": "super_disbursement",
"amount": 150000.5,
"partner_fee": 299.4,
"partner_fee_percentage": 0.2,
"goescrow_fee": 0,
"goescrow_fee_percentage": 0,
"total_fees": 299.4,
"net_amount": 149701.1,
"disbursements_count": 2,
"disbursements": [
{
"user_id": "9d2e5c8a-1234-5678-9abc-def012345679",
"amount": 74850.55
},
{
"company_id": "9d2e5c8a-1234-5678-9abc-def012345680",
"amount": 74850.55
}
]
}
}
Uploads one or more files to a transaction filing cabinet. The authenticated partner must own the transaction or be its marketplace operator.
The transaction UUID (36-character internal identifier)
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/transactions/9d2e5c8a-1234-5678-9abc-def012345678/files" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: multipart/form-data" \
--header "Accept: application/json" \
--form "files[]=@/tmp/php1o66eobt7j4l2IaBanK" {
"data": [
{
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"file": "a1b2c3d4/document.pdf",
"filename": "document.pdf",
"created_at": "2024-01-15T10:30:00Z"
}
]
}
Triggers settlement for a marketplace escrow transaction. Only the marketplace operator can trigger settlement.
The transaction UUID (36-character internal identifier)
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/transactions/9d2e5c8a-1234-5678-9abc-def012345678/settle" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Idempotency-Key: 6f3a8e1c-9b2d-4f5a-8c1e-2a7b9d0e1f23" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"buyer_id\": \"9d2e5c8a-1234-5678-9abc-def012345678\",
\"seller_id\": \"9d2e5c8a-1234-5678-9abc-def012345679\",
\"settlement_amount\": 150000.5
}"
{
"message": "Settlement initiated successfully.",
"transaction_id": "9d2e5c8a-1234-5678-9abc-def012345678",
"status": "settlement_in_progress"
}
Initiate PayTo Payments for Transactions
Initiates a PayTo debit payment from the specified user's bank account to fund the transaction. The user must have an active PayTo agreement. This endpoint dispatches an async job and returns immediately with a tracking ID.
The transaction UUID (36-character internal identifier)
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/transactions/9d2e5c8a-1234-5678-9abc-def012345678/payto-payment" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Idempotency-Key: 6f3a8e1c-9b2d-4f5a-8c1e-2a7b9d0e1f23" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"user_id\": \"9d2e5c8a-1234-5678-9abc-def012345678\"
}"
{
"code": "accepted",
"message": "Payment initiation queued. Use the tracking_id to poll for status.",
"tracking_id": "payto_9d2e5c8a"
}
Checks the status of a PayTo payment using either a tracking_id (from async initiation) or a payment_initiation_id (from Azupay).
The transaction UUID (36-character internal identifier)
Either a tracking_id (e.g., payto_abc123) or an Azupay payment_initiation_id (e.g., PI-123456789)
curl --request GET \
--get "https://partners.staging.goescrow.net/api/v1/transactions/9d2e5c8a-1234-5678-9abc-def012345678/payto-payment/payto_abc123" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" {
"code": "settled",
"message": "Payment settled successfully. Transaction is now funded.",
"status": "settled"
}
Manage User Bank Accounts
Updates the bank account details for a user. This will automatically trigger a verification payout of $0.01 to the new account with a 6-digit verification code in the transaction description.
The user UUID (36-character internal identifier)
curl --request PUT \
"https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/bank-account" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"bsb_number\": \"123456\",
\"account_number\": \"12345678\",
\"account_name\": \"John Doe\"
}"
{
"message": "Bank account updated. Verification code sent via $0.01 payout.",
"is_verified": false
}
Verifies the bank account using the 6-digit code received in the $0.01 verification payout.
The user UUID (36-character internal identifier)
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/bank-account/verify" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"code\": \"123456\"
}"
{
"message": "Bank account verified successfully.",
"is_verified": true
}
Manage User Identification Documents
Creates a new passport record for the user or updates an existing one. Only one passport per user is allowed.
The user UUID (36-character internal identifier)
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/passport" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"document_number\": \"N1234567\",
\"first_name\": \"John\",
\"last_name\": \"Doe\",
\"middle_name\": \"Michael\",
\"issuing_country\": \"United Kingdom\",
\"nationality\": \"British\",
\"date_of_birth\": \"1990-01-15\",
\"date_of_issue\": \"2020-01-15\",
\"date_of_expiration\": \"2030-01-15\",
\"place_of_birth\": \"Sydney, Australia\",
\"gender\": \"M\"
}"
{
"data": {
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"document_number": "N1234567",
"first_name": "John",
"last_name": "Doe",
"middle_name": "Michael",
"nationality": "United Kingdom",
"issuing_country": "United Kingdom",
"date_of_birth": "1990-01-15",
"date_of_issue": "2020-01-15",
"date_of_expiration": "2030-01-15",
"place_of_birth": "Sydney, Australia",
"gender": "M",
"rapidid_verification_requested_at": null,
"rapidid_verified_at": null,
"rapidid_failed_at": null,
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}
}
Retrieves the passport information for the specified user.
The user UUID (36-character internal identifier)
curl --request GET \
--get "https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/passport" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" {
"data": {
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"document_number": "N1234567",
"first_name": "John",
"last_name": "Doe",
"middle_name": "Michael",
"nationality": "United Kingdom",
"issuing_country": "United Kingdom",
"date_of_birth": "1990-01-15",
"date_of_issue": "2020-01-15",
"date_of_expiration": "2030-01-15",
"place_of_birth": "Sydney, Australia",
"gender": "M",
"rapidid_verification_requested_at": null,
"rapidid_verified_at": null,
"rapidid_failed_at": null,
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}
}
Deletes the passport record for the specified user.
The user UUID (36-character internal identifier)
curl --request DELETE \
"https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/passport" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" [Empty response]
Creates a new Medicare card record for the user or updates an existing one. Only one Medicare card per user is allowed.
The user UUID (36-character internal identifier)
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/medicare" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"document_number\": \"1234567890\",
\"name_on_card\": \"John Michael Doe\",
\"card_color\": \"green\",
\"individual_reference_number\": \"1\",
\"expiration_date\": \"2025-12\"
}"
{
"data": {
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"document_number": "1234567890",
"name_on_card": "John Michael Doe",
"card_color": "green",
"individual_reference_number": "1",
"expiration_date": "2025-12",
"rapidid_verification_requested_at": null,
"rapidid_verified_at": null,
"rapidid_failed_at": null,
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}
}
Retrieves the Medicare card information for the specified user.
The user UUID (36-character internal identifier)
curl --request GET \
--get "https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/medicare" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" {
"data": {
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"document_number": "1234567890",
"name_on_card": "John Michael Doe",
"card_color": "green",
"individual_reference_number": "1",
"expiration_date": "2025-12",
"rapidid_verification_requested_at": null,
"rapidid_verified_at": null,
"rapidid_failed_at": null,
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}
}
Deletes the Medicare card record for the specified user.
The user UUID (36-character internal identifier)
curl --request DELETE \
"https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/medicare" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" [Empty response]
Creates a new driver license record for the user or updates an existing one. Only one driver license per user is allowed.
The user UUID (36-character internal identifier)
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/driver-license" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"state_issued\": \"NSW\",
\"license_number\": \"12345678\",
\"card_number\": \"1234567890\",
\"expiration_date\": \"2030-01-15\",
\"first_name\": \"John\",
\"last_name\": \"Doe\",
\"middle_name\": \"Michael\",
\"date_of_birth\": \"1990-01-15\"
}"
{
"data": {
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"state_issued": "NSW",
"license_number": "12345678",
"card_number": "1234567890",
"expiration_date": "2030-01-15",
"first_name": "John",
"last_name": "Doe",
"middle_name": "Michael",
"date_of_birth": "1990-01-15",
"rapidid_verification_requested_at": null,
"rapidid_verified_at": null,
"rapidid_failed_at": null,
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}
}
Retrieves the driver license information for the specified user.
The user UUID (36-character internal identifier)
curl --request GET \
--get "https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/driver-license" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" {
"data": {
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"state_issued": "NSW",
"license_number": "12345678",
"card_number": "1234567890",
"expiration_date": "2030-01-15",
"first_name": "John",
"last_name": "Doe",
"middle_name": "Michael",
"date_of_birth": "1990-01-15",
"rapidid_verification_requested_at": null,
"rapidid_verified_at": null,
"rapidid_failed_at": null,
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}
}
Deletes the driver license record for the specified user.
The user UUID (36-character internal identifier)
curl --request DELETE \
"https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/driver-license" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" [Empty response]
Creates a new immigration card record for the user or updates an existing one. Only one immigration card per user is allowed.
The user UUID (36-character internal identifier)
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/immigration-card" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"given_name\": \"John\",
\"family_name\": \"Doe\",
\"card_number\": \"IMM123456\",
\"expiration_date\": \"2030-01-15\",
\"card_type\": \"ams\",
\"vevo_check_given_name\": \"John\",
\"vevo_check_family_name\": \"Doe\",
\"vevo_check_passport_number\": \"N1234567\",
\"vevo_check_country_of_issue\": \"Australia\"
}"
{
"data": {
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"given_name": "John",
"family_name": "Doe",
"card_number": "IMM123456",
"expiration_date": "2030-01-15",
"card_type": "ams",
"vevo_check_given_name": "John",
"vevo_check_family_name": "Doe",
"vevo_check_passport_number": "N1234567",
"vevo_check_country_of_issue": "Australia",
"rapidid_verification_requested_at": null,
"rapidid_verified_at": null,
"rapidid_failed_at": null,
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}
}
Retrieves the immigration card information for the specified user.
The user UUID (36-character internal identifier)
curl --request GET \
--get "https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/immigration-card" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" {
"data": {
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"given_name": "John",
"family_name": "Doe",
"card_number": "IMM123456",
"expiration_date": "2030-01-15",
"card_type": "ams",
"vevo_check_given_name": "John",
"vevo_check_family_name": "Doe",
"vevo_check_passport_number": "N1234567",
"vevo_check_country_of_issue": "Australia",
"rapidid_verification_requested_at": null,
"rapidid_verified_at": null,
"rapidid_failed_at": null,
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}
}
Deletes the immigration card record for the specified user.
The user UUID (36-character internal identifier)
curl --request DELETE \
"https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/immigration-card" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" [Empty response]
Creates a new Centrelink card record for the user or updates an existing one. Only one Centrelink card per user is allowed.
The user UUID (36-character internal identifier)
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/centrelink-card" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"crn\": \"123456789A\",
\"name_on_card\": \"John Doe\",
\"expiration_date\": \"2030-01-15\",
\"card_type\": \"hcc\"
}"
{
"data": {
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"crn": "123456789A",
"name_on_card": "John Doe",
"expiration_date": "2030-01-15",
"card_type": "hcc",
"rapidid_verification_requested_at": null,
"rapidid_verified_at": null,
"rapidid_failed_at": null,
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}
}
Retrieves the Centrelink card information for the specified user.
The user UUID (36-character internal identifier)
curl --request GET \
--get "https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/centrelink-card" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" {
"data": {
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"crn": "123456789A",
"name_on_card": "John Doe",
"expiration_date": "2030-01-15",
"card_type": "hcc",
"rapidid_verification_requested_at": null,
"rapidid_verified_at": null,
"rapidid_failed_at": null,
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}
}
Deletes the Centrelink card record for the specified user.
The user UUID (36-character internal identifier)
curl --request DELETE \
"https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/centrelink-card" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" [Empty response]
Manage User PayTo Agreements
Returns the current PayTo agreement status and details for a user.
The user UUID (36-character internal identifier)
curl --request GET \
--get "https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/payto-agreement" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" {
"has_agreement": true,
"agreement_id": "PA-123456",
"maximum_amount": 10000,
"status": "ACTIVE"
}
Creates a new PayTo agreement for the user. The user must authorize the agreement in their banking app.
The user UUID (36-character internal identifier)
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/users/9d2e5c8a-1234-5678-9abc-def012345678/payto-agreement" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"maximum_amount\": 5000,
\"pay_id\": \"john@example.com\",
\"pay_id_type\": \"EMAIL\",
\"account_name\": \"John Doe\",
\"account_number\": \"12345678\",
\"bsb\": \"123456\"
}"
{
"agreement_id": "PA-123456",
"status": "CREATED",
"message": "PayTo agreement created. User must authorize in their banking app."
}
Manage webhook subscriptions for transaction events
Returns all registered webhooks for the authenticated partner.
curl --request GET \
--get "https://partners.staging.goescrow.net/api/v1/webhooks" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" {
"data": [
{
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"url": "https://partner.com/webhooks/goescrow",
"events": [
"transaction.created",
"transaction.clearance_pending",
"transaction.funded",
"transaction.status_changed",
"transaction.funding_status_changed"
],
"is_active": true,
"last_triggered_at": "2024-01-15T10:30:00Z",
"failure_count": 0,
"created_at": "2024-01-01T00:00:00Z"
}
]
}
Registers a new webhook URL to receive transaction event notifications. Available events: transaction.created (when a transaction is created), transaction.clearance_pending (when inbound funding is held for clearance), transaction.funded (when a transaction is funded), transaction.status_changed (when transaction status changes), transaction.funding_status_changed (when transaction funding status changes), transaction.completed (when a transaction is completed/settled), beneficiary.confirmation_requested (when beneficiary confirmation is requested), beneficiary.confirmed (when a beneficiary confirms receipt), beneficiary.declined (when a beneficiary reports non-receipt).
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/webhooks" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"url\": \"https:\\/\\/partner.com\\/webhooks\\/goescrow\",
\"events\": [
\"transaction.created\",
\"beneficiary.confirmation_requested\",
\"beneficiary.confirmed\",
\"beneficiary.declined\"
]
}"
{
"message": "Webhook registered successfully.",
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"url": "https://partner.com/webhooks/goescrow",
"secret": "whsec_abc123xyz789...",
"events": [
"transaction.created",
"transaction.clearance_pending"
]
}
Unregisters a webhook.
The webhook ID
curl --request DELETE \
"https://partners.staging.goescrow.net/api/v1/webhooks/1" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" {
"message": "Webhook deleted successfully."
}
Returns the delivery history for a webhook (most recent first), so missed events can be inspected and replayed after an outage. Each delivery records the event, the exact payload that was (or will be) sent, the number of attempts, and the last response status.
The webhook ID
curl --request GET \
--get "https://partners.staging.goescrow.net/api/v1/webhooks/1/deliveries" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" {
"data": [
{
"id": "9f1b2c3d-4567-89ab-cdef-0123456789ab",
"event": "transaction.funded",
"status": "failed",
"attempts": 3,
"response_status": 500,
"last_attempted_at": "2024-01-15T10:32:00Z",
"delivered_at": null,
"created_at": "2024-01-15T10:30:00Z",
"payload": {
"transaction_id": "...",
"status": "pending"
}
}
],
"meta": {
"current_page": 1,
"last_page": 1,
"per_page": 50,
"total": 1
}
}
Queues a fresh delivery attempt for a past event, using the original payload. Use this to backfill events your endpoint missed during an outage. A new delivery record is created (with a new id) so the original attempt history is preserved.
The webhook ID
The delivery ID to redeliver
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/webhooks/1/deliveries/1/redeliver" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" {
"message": "Webhook delivery has been queued for redelivery.",
"id": "a1b2c3d4-5678-90ab-cdef-1234567890ab",
"event": "transaction.funded",
"status": "pending"
}
Manage company bank accounts using Confirmation of Payee
Updates company bank details and runs Confirmation of Payee checks against the company's active known names.
The company UUID (36-character internal identifier)
curl --request PUT \
"https://partners.staging.goescrow.net/api/v1/companies/9d2e5c8a-1234-5678-9abc-def012345678/bank-account" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"bsb_number\": \"123456\",
\"account_number\": \"12345678\",
\"account_name\": \"Acme Corp Pty Ltd\"
}"
{
"message": "Company bank account updated successfully.",
"is_verified": true
}
Re-runs Confirmation of Payee against the company's existing bank details. This is not payout-code verification.
The company UUID (36-character internal identifier)
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/companies/9d2e5c8a-1234-5678-9abc-def012345678/bank-account/verify" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" {
"message": "Company bank account check completed.",
"is_verified": true
}
Create an identity-only hosted login session, send the user to the returned GoEscrow URL, receive a one-time code at the registered redirect URL, then verify the code server-to-server. The redirect URL is configured by GoEscrow and snapshotted when the session is created.
Creates a short-lived hosted login session. Open the returned url in the user's browser. After the user signs in and confirms, GoEscrow redirects to the partner's registered URL with session_id, code, and the optional reference query parameters.
curl -X POST 'https://partner-api.goescrow.com.au/api/v1/login-sessions' \
-H 'X-Api-Key: YOUR_API_KEY' \
-H 'Content-Type: application/json' \
-d '{"email":"jane@example.com","reference":"order-8812"}'
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/login-sessions" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"email\": \"jane@example.com\",
\"reference\": \"order-8812\"
}"
{
"data": {
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"url": "https://app.goescrow.com.au/partner-login/plaintext-session-token",
"expires_at": "2026-08-31T04:15:00.000000Z",
"reference": "order-8812"
}
}
Redeems the one-time code delivered to the registered redirect URL. Verification must use the same partner API key that created the session and must occur before the code expires.
curl -X POST 'https://partner-api.goescrow.com.au/api/v1/login-sessions/9d2e5c8a-1234-5678-9abc-def012345678/verify' \
-H 'X-Api-Key: YOUR_API_KEY' \
-H 'Content-Type: application/json' \
-d '{"code":"CODE_FROM_REDIRECT"}'
The hosted login session UUID returned during creation.
curl --request POST \
"https://partners.staging.goescrow.net/api/v1/login-sessions/9d2e5c8a-1234-5678-9abc-def012345678/verify" \
--header "X-API-Key: {YOUR_AUTH_KEY}" \
--header "Content-Type: application/json" \
--header "Accept: application/json" \
--data "{
\"code\": \"CODE_FROM_REDIRECT\"
}"
{
"data": {
"user": {
"id": "9d2e5c8a-1234-5678-9abc-def012345678",
"reference": "ABC123",
"first_name": "Jane",
"last_name": "Doe",
"email": "jane@example.com",
"phone": "+61412345678",
"birth_date": "1990-01-15",
"kyc_verified": true,
"aml_verified": true,
"aml_verified_at": "2026-08-20T00:00:00.000000Z",
"email_verified": true,
"mobile_verified": true,
"mobilekyc_verified": true,
"bank_verified": true,
"suspended": false,
"address": null
},
"reference": "order-8812",
"authenticated_at": "2026-08-31T04:01:00.000000Z"
}
}