# FIS Global > FIS (Fidelity National Information Services) is a financial technology company providing core > banking, payments, wealth management and capital markets infrastructure to financial > institutions. Most of its API surface sits behind the Code Connect marketplace, which requires > a reviewed registration before any catalog entry or specification is visible. One FIS API is > publicly readable end to end: FIS Accounting Data as a Service (formerly Railz), whose > OpenAPI 3.0.0 contract is served openly at https://api.railz.ai/swagger.json with 175 paths > and 233 operations. This file is generated by API Evangelist from a third-party profile of FIS's public API surface. It is not published by FIS. Everything below was fetched from a public URL with no credentials. ## Publicly readable API - [FIS Accounting Data as a Service](https://docs.railz.ai/): Read and write a business's accounting, banking and commerce data through an authorised connection to their own system. Base URL `https://api.railz.ai`. 233 operations across two live generations (an unprefixed v1 surface and a `/v2/` surface that supersedes it). - [OpenAPI 3.0.0 contract](https://api.railz.ai/swagger.json): Served openly, no key required to read it. - [Authentication](https://docs.railz.ai/reference/authentication): HTTP Basic (`client_id` / `secret_key`) to mint a JWT access token valid 60 minutes, then `Authorization: Bearer`. Sandbox keys are prefixed `SB_`, production keys `ID_`. - [Response codes](https://docs.railz.ai/reference/errors): Fifteen documented statuses. The error envelope is `{ error: { statusCode, message[], error }, payload: {} }` — `message` is an **array** of strings, not a string. Not RFC 9457. - [Changelog](https://docs.railz.ai/changelog): Dated quarterly releases, current to 2026-09-02. - [Status page](https://status.railz.ai): Public Atlassian Statuspage with a machine-readable summary at `/api/v2/summary.json`, broken out per upstream accounting connector. - [Pricing](https://www.fisglobal.com/products/accounting-data-as-a-service): Two tiers — a free tier capped at five connected businesses, and contact-sales Enterprise. ## Gated API surface - [FIS Code Connect](https://codeconnect.fisglobal.com/): The marketplace for FIS core banking, payments and wealth APIs. The catalog, the guides and the key-generation flow all render inside an Angular application that serves the same shell to an unauthenticated client. Registration requires review, and FIS-representative approval is required for any API not classified "Public". - [FIS developer index](https://www.fisglobal.com/developer): Names four further product portals — Total Issuing (developers.tsys.com), Total Issuing PRIME (developers.prime.tsys.com), FIS Everlink (developer.everlink.ca) and this Accounting Data service. The first two gate at a login; the Everlink docs project returns "no project found". ## Client libraries Nine first-party npm packages under the `@railzai` scope, all browser-side: `@railzai/railz-connect` (2.23.0, the account-linking widget), `@railzai/railz-uikit` and its React/Angular/Vue wrappers, `@railzai/railz-visualizations` and its React/Angular wrappers, and `@railzai/railz-tokens`. **There is no server-side API client in any language** for the 233 REST operations. ## Agent surfaces - **MCP**: `https://docs.railz.ai/mcp` is a real, reachable MCP endpoint, but it is the ReadMe documentation platform's search server, not tools over the API. `tools/list` returns 401 with `WWW-Authenticate: Bearer realm="mcp"` and no OAuth discovery document is published, so the tool set is not readable. **No MCP server exists over the FIS API surface itself.** - **A2A agent card**: none. `/.well-known/agent-card.json` and `/.well-known/agent.json` were probed on every FIS and Railz host and hit on none. - **Webhooks**: nine events — `login`, `auth`, `connectionStatus`, `customerRequest`, `data`, `dataPerType`, `push`, `batchPush`, `delete` — configured in the Dashboard only, with a sandbox trigger at `POST /v2/sandbox/fireWebhooks`. No AsyncAPI document is published. - **security.txt**: `https://fisglobal.com/.well-known/security.txt` is served (expired `Expires` field), pointing at a Bugcrowd bug bounty at `https://bugcrowd.com/engagements/fis`. ## Things an agent should know before calling - **No idempotency.** None of the 86 mutating operations accepts an `Idempotency-Key`. A retried push writes a second record into a real business's ledger. - **No rate-limit signal.** 429 is documented with no threshold, no `Retry-After` and no `RateLimit-*` header on any response. - **No request-id header**, so a support ticket has no identifier to quote. - **No deprecation signal.** The v1 operations that `/v2/` replaces are not flagged deprecated and no Sunset header exists. - **`accountingMethod` (cash vs accrual)** changes what the figures mean, not which rows return. - **Reversal paths exist but no window is stated** for any of them; a refund cannot be reversed and a queued sync cannot be cancelled. ## Profile - [API Evangelist profile](https://apis.io/provider/fis/) - [apis.yml](https://raw.githubusercontent.com/api-evangelist/fis/refs/heads/main/apis.yml)