Skip to main content
POST
Create an account bank withdrawal

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Headers

X-Sca-Challenge-Id
string<uuid>

The challengeId returned by POST /v1/accounts/passkeys/challenges. Required for end users under EEA/FR legal entities (PSD2 SCA). Omit for all other end users.

Example:

"b2c3d4e5-f6a7-8901-bc23-def456789012"

X-Sca-Assertion
string

The signed assertion string returned by the DAA web SDK's sca.approve method. Required for end users under EEA/FR legal entities (PSD2 SCA). Pass the value through unchanged — do not base64-encode or re-serialize it.

Body

application/json
idempotencyKey
string<uuid>
required

Universally unique identifier (UUID v4) idempotency key. This key is utilized to ensure exactly-once execution of mutating requests.

Example:

"ba943ff1-ca16-49b2-ba55-1057e70ca5c7"

destination
object
required

The destination bank account.

amount
object
required
riskSignals
object
required

Risk metadata for the end user initiating the request. All three fields must be present.

deviceId must be the identifier returned by checkDevice() in the @circle-fin/device-checks SDK. Circle resolves it against the device check that produced it, so an identifier you generate yourself does not resolve. When it does not resolve, the request is accepted and then declined: the endpoint returns 201, and the transaction later settles as failed with errorCode transfer_denied. See Collect device risk signals.

source
object

The source account for the withdrawal. The type must be account.

toAmount
object

To be used when requesting currency exchange.

burnAll
boolean
default:false

If true, withdraw the full balance of all sub-accounts and the main wallet in a single operation. The source must be the main wallet. When set, amount.amount is ignored and amount.currency must be USD.

Response

Successfully created a withdrawal.

data
object