VerificationRequests
POST
https://test.api.neotek.sa/iban-verification-neotek/v1/verification-requestsSandbox URL · in Production call https://api.neotek.sa
Submits the check rather than querying it: the receiving institution gets the outcome and acts on it. You get back a RequestId to reference the inquiry, plus a PASPRedirectionUrl where one applies.
It takes the same identity trio as the synchronous call, plus a Source and optional routing context.
Body — everything sits under a top-level Data object:
Source(required) – which provider performs the check. The specification listsSaudi-Payment;ARBalso worksIBAN(required) – the IBAN being verifiedPOIType(required) – the proof-of-identity type:NATfor a national ID,IQAfor an iqamaPOINumber(required) – the ID numberMeta(optional) – routing and context for the receiving institution.Metaitself is optional, so the minimal body is the four fields above:FinancialInstitutionId(optional) – the target institution:RJHISARI,ALBISARI,INMASARI,BSFRSARIorSIBCSARIPSUId(optional) – the Payment Service User identifierUserLoginId(optional) – user login hint, for the decoupled authorisation profilePurpose(optional) – array of stringsEchoList(optional) – name/value pairs returned back with the response, such as achannelRedirectionUrl
Headers:
| Parameter | Required | Description |
|---|---|---|
authorization | Required | Bearer <ACCESS_TOKEN>, with scope iban_verification |
content-type | Required | application/json |
x-request-id | Optional | an RFC 4122 UUID you generate; quote it when raising a support ticket |
accept-language | Optional | en or ar, where the backend supports it |
sub-client | Optional | identifies the downstream consumer when one client fronts several |
cURL
curl -X POST 'https://test.api.neotek.sa/iban-verification-neotek/v1/verification-requests' \ -H 'Authorization: Bearer <ACCESS_TOKEN>' \ -H 'Content-Type: application/json' \ -d '{ "Data": { "Source": "ARB", "IBAN": "SA1080000012345678901001", "POIType": "IQA", "POINumber": "2345678901", "Meta": { "EchoList": [ { "Name": "channelRedirectionUrl", "Value": "https://www.example.com" } ] } }}'Response
JSON
{ "Data": { "RequestId": "8424" }}Errors
| Code | Status | Cause and Action |
|---|---|---|
400 | Bad Request | Missing required field, or a value that fails validation — check Code and Path in the body |
401 | Unauthorized | Token missing, expired, or invalid |
403 | Forbidden | Token doesn't carry the iban_verification scope |
404 | Not Found | No resource matches the identifier provided |
405 | Method Not Allowed | HTTP verb not supported on that path |
406 | Not Acceptable | Accept header doesn't match a supported representation — use application/json |
415 | Unsupported Media Type | Content-Type missing or wrong — use application/json |
429 | Too Many Requests | Rate limit exceeded |
500 | Internal Server Error | Server error — retry with backoff, quote your x-request-id |