Skip to content
Agency One

For your team

One API, standard identity, nothing moves money twice.

The five questions a technology team asks before it signs off a counter network, each answered plainly, with the platform page behind it for the depth.

Question 1

Where does it run?

On a shared platform where each operator's data is isolated at the database itself, or on a dedicated instance in-country where regulation asks for it, with your own release cadence. One codebase, the same controls, either way.

Deployment
Shared platformIsolated per operator
Dedicated instanceYour environment, your cadence
Data residencyIn-country where required
Sandbox, apart from liveIncluded

Question 2

How do we integrate?

Through one versioned API, described before it is built, so the frontends' clients are generated from the same contract your systems read. Every write carries a key, so a retried request finds the first and money moves once. Errors come in one standard shape that names the field.

The API
One versioned API/v1
Every write safe to retryIdempotency key
Errors in one shapeproblem+json
Change within a versionAdditive only

Question 3

How do staff sign in?

Through a dedicated identity provider on OpenID Connect, with sessions and token lifetimes managed centrally. Access is deny by default: a login does what its roles permit and nothing else, checked on the server for every request.

Identity and access
Sign-onOpenID Connect
Sessions and tokensManaged centrally
AccessDeny by default
RolesFive
Two people on risky movesEnforced

Question 4

How do providers connect?

On their own terms: by API where an institution has one, by file and batch for settlement files and lists, or through an assisted connector where there is neither. Each connection is proven in the sandbox and certified before it goes live, and connectors never retry on their own.

Connectors
Partner Bank, by APILive
Partner insurer, nightly fileLive
Government registry, assistedCertifying

Question 5

What do we get to run it?

A record of every change with who, when and why; structured logs and traces for every request; a health board for every provider so a failing connection is seen before a customer meets it; and a sandbox with a stand-in provider for testing a service before it is published.

Running it
Audit trailEvery change
Logs and tracesEvery request
Provider health boardLive
Sandbox with a stand-in providerIncluded
The platform, in depth

Bring your IT team to a demo.

We will walk the API, the identity model and a provider connection, with your architects in the room.