Skip to main content
A capability is one regulated service for one account, in one country, currency and rail. Identity verification proves who the customer is; activation gets the customer approved for the service by the banking partner behind it.
Use the service only when ready is true.

The three capabilities

The capabilities of one account rest on one banking relationship per banking program. Activate each one you use anyway: each records the customer’s consent to that service, and your app must be granted each one. Each activation also names a country (ISO 3166-1 alpha-2), a currency (ISO 4217) and a rail, such as ach. Send amountAtomic only when eligibility depends on an amount tier.

What activation needs first

Activation is idempotent

Idempotency-Key is required, 8 to 256 printable characters. Replaying the identical body with the same key returns the current state of the original action. A changed body with the same key is refused with 409 idempotency_conflict. A new key starts a new action. Use one when the customer lost the hosted page: the new link replaces the old one, which stops working.

The hosted form

For an individual, complete_compliance carries a one-time link to a Stableyard-hosted page. On it the customer:
  1. Confirms a code Stableyard emails to the account’s verified address.
  2. Supplies only the details their identity verification did not already provide.
  3. Reviews and consents to the service.
nextAction.url is a credential. Send it only to the account holder, open it before expiresAt, and never log it, cache it or put it in browser storage.

Statuses

Next actions

Read every capability

An empty capabilities array means nothing has been activated on this account. Read ready and nextAction; never keep an old hosted URL.

Business accounts

A business passes one hosted business verification, and every capability for it rests on that one approval.
1

Start it

Activate any capability with business.legalName. The status starts at submission_pending and nextAction.type is continue_business_verification while the hosted link is prepared.
2

Get the link

Send the identical request again, with the same key. Once the link is ready, nextAction.type is complete_compliance with a provider-hosted url and expiresAt. The list endpoint never returns it.
3

Send it to the representative

Only the company’s authorized representative. If the link expires after the application exists, nextAction.type becomes contact_support: Stableyard support restarts it, not a new activation.
4

Add more capabilities

After approval, activate bank_onramp or another capability without business. It uses the same approval.
Business verification opens US bank rails only. See Business KYB.

Errors

Webhooks

Next: Payments

The Payment object: intent, destinations, frozen snapshots and states.