Strong customer authentication
Strong Customer Authentication (SCA) applies to all sensitive actions in an EEA integration. The authentication method depends on whether the action is taken through the UI or through the API. For more information, see How SCA works and Implement Strong Customer Authentication.UI actions
UI-based sensitive actions require two authentication factors:- Possession factor: Okta Verify
- Knowledge factor: a 4-digit PIN
- First login (includes PIN setup)
- Withdraw (crypto and fiat)
- Create API keys
- Delayed withdrawal settings
- IP allowlist settings
- Change password
- Freeze or unfreeze a subaccount
- Bulk freeze
Programmatic money movement
API calls that initiate money movement require mutual TLS (mTLS) authenticated with a Qualified Website Authentication Certificate (QWAC). A QWAC is a regulated digital certificate that authenticates the API client as a known legal entity. A bearer token alone is insufficient for EEA money movement. Requests that initiate outbound transfers or withdrawals without a valid QWAC-bound mTLS session are rejected. QWACs are issued by accredited trust service providers on the EU Trusted List under eIDAS. Circle coordinates QWAC provisioning as part of the EEA wholesale onboarding process; contact your Circle representative to initiate.Platform address book
EEA outbound crypto transfers are subject to Travel Rule obligations and strict beneficiary controls. All external beneficiary addresses must be pre-registered in the Platform Address Book before a transfer can be initiated.Address statuses
Transfers to addresses that are not in the Platform Address Book, or that have
not reached
VERIFIED status, are rejected at the API level. This is
fail-closed behavior: there is no silent degradation or fallback.
Deposit addresses are not part of the Platform Address Book; the address book
governs outbound transfers only.
Fail-closed asset scope
Digital Asset Accounts in the EEA is limited to operations in the scope of MiCA Article 60(4). API requests for out-of-scope operations return an error. The following operations are blocked in the EEA:No burn fees
Digital Asset Accounts does not charge burn fees and does not participate in redeemer of last resort (ROLR) programs for EEA accounts.MiCA balance reporting
EEA distributors’ subaccount balances are included in Circle’s ACPR regulatory reporting through the Reserve Management API.Circle files the MiCA balance report with the ACPR on behalf of your program.
You do not submit this report directly.
Endpoint
Submit balance data using the following endpoint:Required fields
SetreportType to eea. The following top-level field is also required:
The following fields are required in
additionalFields:
Reporting rules
- FX conversion: Euro-equivalent values use the ECB rate for the reporting date.
- Frequency: One submission per day, per currency. USDC and EURC are submitted as separate reports.
- Currency scope: Only USDC and EURC are in scope for reporting.