openapi: 3.0.3 info: title: Alloy Bank Accounts OAuth API description: 'The Alloy API is the programmatic surface for Alloy''s identity decisioning platform. It exposes the resources behind Alloy''s KYC, KYB, AML, fraud, credit, and ongoing-monitoring workflows used by banks, credit unions, and fintechs. The API is organized around evaluations, journey applications, entities (persons and businesses), bank accounts, documents, events, cases, investigations, custom lists, published attributes, and webhooks. Sandbox and production environments are exposed as two distinct base URLs. ' version: '1.0' contact: name: Alloy Developer Support url: https://help.alloy.com license: name: Proprietary url: https://www.alloy.com/tos servers: - url: https://sandbox.alloy.co/v1 description: Sandbox environment - url: https://api.alloy.co/v1 description: Production environment security: - basicAuth: [] - bearerAuth: [] tags: - name: OAuth description: OAuth 2.0 bearer token issuance and validation. paths: /oauth/bearer: post: tags: - OAuth summary: Issue a Bearer Token operationId: postOAuthBearer requestBody: required: true content: application/json: schema: type: object responses: '200': description: Token issued content: application/json: schema: $ref: '#/components/schemas/OAuthToken' /oauth/validate: post: tags: - OAuth summary: Validate a Bearer Token operationId: postOAuthValidate requestBody: required: true content: application/json: schema: type: object responses: '200': description: Validation result components: schemas: OAuthToken: type: object properties: access_token: type: string token_type: type: string expires_in: type: integer securitySchemes: basicAuth: type: http scheme: basic description: HTTP Basic Authentication with workflow or account-level API key as username and secret as password. bearerAuth: type: http scheme: bearer description: OAuth 2.0 bearer token obtained via the OAuth endpoints.