v4.0.0
OpenAPI 3.1.1

TrueACH API

Overview

Welcome to the interactive API documentation for TrueACH! Before you begin, please ensure you’ve read through the API Guide.

Portal Access

AFS Support will create your UAT and Production accounts. You can access your TrueACH accounts through these portals:

Base URLs

Use the following base URLs when configuring your application:

Tokens and Authentication

To authenticate API requests, Advanced Fraud Solutions requires an API token to be included in each request. TrueACH supports authentication in one of the following ways:

Long-Lived Token Model

  • The API token is issued via the Client Portal.
  • The token is included in every API request.
  • The token remains valid until it expires or is manually revoked.

Refresh + Access Token Model

  • A long-lived Refresh API token is issued.
  • The refresh token is used to call the token endpoint: Security/GetAccessToken.
  • The endpoint returns a short-lived Access token.
  • The access token is then used to authenticate business API requests.

Important considerations:

  • Refresh tokens are long-lived and must be stored securely.
  • Access tokens are short-lived and expire based on the configurable time to live.
  • When an access token expires, a new one must be obtained using the refresh token.

Authorization Header Format

Include your token in the request header using:

Authorization: Bearer <API_TOKEN>

Token Management

API Rules

TrueACH has an API Rules feature that allows clients to define rules to control which API requests will be processed and which will be ignored. This functionality helps prevent unnecessary queries and fees by validating API requests against configured rules before they are executed. Refer to https://docs.advancedfraudsolutions.com/trueach/api-rules for more details.

Client Libraries

AchClient (Collapsed)

​

AchValidation (Collapsed)

​

Security (Collapsed)

​