openapi: 3.1.0 info: title: BILL v3 Authentication Funding Accounts API description: 'REST API providing access to BILL''s Accounts Payable, Accounts Receivable, and Spend & Expense capabilities — bills, invoices, vendors, customers, payments, funding accounts, organizations, webhooks, and authentication workflows. Best-effort OpenAPI reconstruction from BILL''s public developer portal at https://developer.bill.com/docs/home. Authoritative reference and Postman collection live under https://developer.bill.com/reference and https://developer.bill.com/llms.txt. ' version: 3.0.0 contact: name: BILL Developer Portal url: https://developer.bill.com/docs/home license: name: Proprietary servers: - url: https://gateway.prod.bill.com/connect/v3 description: BILL production gateway (Connect v3) - url: https://gateway.stage.bill.com/connect/v3 description: BILL sandbox gateway (Connect v3) - url: https://api.bill.com/v3 description: BILL production API - url: https://api-sandbox.bill.com/v3 description: BILL sandbox API security: - sessionAuth: [] tags: - name: Funding Accounts paths: /funding-accounts/banks: get: tags: - Funding Accounts summary: List bank funding accounts operationId: listBankFundingAccounts responses: '200': description: Bank funding accounts. post: tags: - Funding Accounts summary: Create a bank funding account (MFA required) operationId: createBankFundingAccount requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/BankAccount' responses: '201': description: Created. /funding-accounts/banks/{bankAccountId}/verify: parameters: - name: bankAccountId in: path required: true schema: type: string post: tags: - Funding Accounts summary: Verify a bank funding account operationId: verifyBankFundingAccount responses: '200': description: Verification result. components: schemas: BankAccount: type: object required: - routingNumber - accountNumber - accountType properties: routingNumber: type: string accountNumber: type: string accountType: type: string enum: - CHECKING - SAVINGS nameOnAccount: type: string verified: type: boolean securitySchemes: sessionAuth: type: apiKey in: header name: sessionId description: 'Session identifier obtained from `POST /login`. Expires after 35 minutes of inactivity. A `devKey` (developer key) is also required on requests and is sent alongside `sessionId` in the appropriate header per BILL''s official reference. '