curl --request POST \
--url https://api.next.orenda.finance/v1/customers/{customerId}/accounts/{accountId}/block \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"reason": "Suspected fraudulent activity reported by the customer."
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({reason: 'Suspected fraudulent activity reported by the customer.'})
};
fetch('https://api.next.orenda.finance/v1/customers/{customerId}/accounts/{accountId}/block', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.next.orenda.finance/v1/customers/{customerId}/accounts/{accountId}/block"
payload = { "reason": "Suspected fraudulent activity reported by the customer." }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"success": true,
"data": {
"status": "blocked"
}
}Block an account
Blocks the account from the back office: payments stop and linked cards are blocked too. The supplied reason is stored on the account’s status history for audit. Reversible with Unblock an account.
The account must belong to the customerId in the path; any other account returns 404. The new status is saved before the provider, fee and card steps run and stays saved if one of them fails (500). Some accounts outside the UK region have no account block at their provider, so blocking one returns 500 with the account already BLOCKED; accounts[].operations.block in GET /v1/capabilities does not flag that case.
curl --request POST \
--url https://api.next.orenda.finance/v1/customers/{customerId}/accounts/{accountId}/block \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"reason": "Suspected fraudulent activity reported by the customer."
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({reason: 'Suspected fraudulent activity reported by the customer.'})
};
fetch('https://api.next.orenda.finance/v1/customers/{customerId}/accounts/{accountId}/block', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.next.orenda.finance/v1/customers/{customerId}/accounts/{accountId}/block"
payload = { "reason": "Suspected fraudulent activity reported by the customer." }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"success": true,
"data": {
"status": "blocked"
}
}Authorizations
The back-office user's id_token — the ID token, not the access_token. The API rejects access tokens.
Path Parameters
The customer's ID.
The account's ID.
Query Parameters
The program the customer/account belongs to. Required on every request.
Body
Why the status is changing — stored on the account's status history for audit. Trimmed, and must not be blank after trimming; no other keys are accepted.
1