# Genome > Genome (legal entity UAB "Maneuver LT", Vilnius, Lithuania) is an Electronic Money Institution > licensed and supervised by the Bank of Lithuania. It runs multi-currency personal and business > accounts, issues Visa cards, and sells a merchant payments stack: a hosted payment page, direct > card processing, card and SEPA payouts, transaction reporting, Verification of Payee, and a PSD2 > dedicated interface for registered AISPs and PISPs. Generated by API Evangelist on 2026-09-12 from Genome's own public documentation. Genome does not publish an llms.txt of its own; this file is an independent index, not a Genome document. ## What an agent needs to know first - Errors do not use HTTP status codes. Every merchant endpoint returns HTTP 200 and puts the outcome in the body as `{"code": n, "message": "...", "status": "..."}`. Code 0 is the only success. Branching on `response.ok` is always wrong here. - Some non-zero codes mean UNKNOWN, not failure: 1, 2, 3, 10, 11, 12, 1003, 3109, 3117, 3118, 3124, 3125, 3133, 6000, 7000, 7101, 7102, 7103. On any of these, send a CHECK request. Retrying the payment instead can charge a cardholder twice. - Credentials travel in the request BODY (`merchant_account`, `merchant_password`), not a header. - `transaction_unique_id` prevents duplicates (code 3001 on reuse) but does NOT replay the original response. It is duplicate prevention, not idempotency. - Test mode is selected by CURRENCY on the production host: send XTS. There is no sandbox hostname and no test key. - A card payout (`initPayout`) and a SEPA payout have NO reversal. Card authorizations can be VOIDed before settlement (the hold lasts about 7 days); settled transactions can be REFUNDed once. - No rate limits are published and no rate-limit headers are returned. ## APIs - [Host-to-Host API](https://developers.genome.eu/merchants/host-to-host-api/): direct card processing at POST https://api.genome.eu/api/pf/host-to-host. One endpoint, eight transaction types selected by `transaction_type`: AUTH, AUTH3D, SALE, SALE3D, SETTLE, REFUND, VOID, CHECK. - [Payout API](https://developers.genome.eu/merchants/payout-api/): send funds to a cardholder at POST https://api.genome.eu/api/pf/payout, by full card data or by token. Irreversible. - [SEPA Payout API](https://developers.genome.eu/sepa-payout-api/): SEPA credit transfer payout at POST https://api.genome.eu/api/mp/payout. Status checks at POST https://api.genome.eu/api/mp/transaction (add /ra for amounts excluding the payout fee). - [Query on Demand API](https://developers.genome.eu/merchants/query-on-demand-api/): historical transaction and chargeback reporting at POST https://api.genome.eu/api/pf/qod. Paged by `page` (1-12) and `limit` (max 1000) over a required `time_from`/`time_to` unix window. - [Verification of Payee API](https://developers.genome.eu/verification-of-payee-api/): check a SEPA beneficiary before paying them, at POST https://api.genome.eu/api/mp/payee/verification. Returns match / close match / no match / no applicable, plus `payee_suggested_name` on a close match. - [Hosted Payment Page](https://developers.genome.eu/merchants/hosted-payment-page/): redirect checkout at https://pay.genome.eu, opened with an HS256 JWT whose signing key is the SHA-256 digest of the payment page secret (not the raw secret). - [Financial Pixel Web SDK](https://developers.genome.eu/merchants/web-sdk-integration/): iframe and popup payment form, loaded as an ES module from https://pay.genome.eu/sdk/iframe.es.js or /sdk/popup.es.js. - [PSD2 API](https://developers.genome.eu/psd2-api/): Berlin Group NextGenPSD2 dedicated interface at https://my.genome.eu/psd2/v1/ with OAuth 2.0 at https://my.genome.eu/oauth2. AIS, PIS (sepa-credit-transfers) and Confirmation of Funds. Registered TPPs only; requires an eIDAS QWAC in the `Tpp-Qwac-Certificate` header. Free of charge. Contact psd2@genome.eu. - [Webhooks](https://developers.genome.eu/webhooks/): incoming payment notifications signed with HmacSHA256 in `X-Signature`, retried on an exponential schedule across up to 12 attempts (~72 hours). At-least-once — deduplicate on `transaction_id`. - [Batch creation](https://developers.genome.eu/specifications-for-batch-creation/): SEPA mass transfers as ISO 20022 `pain.001.001.03` XML or CSV. ## Reference - [Response codes](https://developers.genome.eu/list-of-response-codes/): the full 137-code registry plus Genome's own behaviour table for which codes mean "check the status". - [Live field reference](https://gateway.genome.eu/help/cc): machine-generated per-transaction-type field list, described by Genome as "based on deployed code". - [Ready-to-go libraries](https://developers.genome.eu/merchants/ready-to-go-libraries/): the Java and PHP merchant clients. ## Client libraries - [genome/merchant](https://packagist.org/packages/genome/merchant) — PHP 7.2+, v0.0.4 (2025-11-25), MIT. - [eu.genome:merchantclient](https://central.sonatype.com/artifact/eu.genome/merchantclient) — Java 8+, v0.0.1 (2025-11-25), MIT. - [genome-eu on GitHub](https://github.com/genome-eu) — mobile SDKs and e-commerce plugins for WooCommerce, Magento, PrestaShop, OpenCart, OXID, Ecwid and Drupal. Most were last touched between 2019 and 2022. ## Operations - [Status page](https://status.genome.eu) — 14 components including Gateway API and PSD2 Dedicated interface. No JSON feed; it cannot be polled programmatically. - [Performance metrics](https://apimetrics.genome.eu) — OAuth success rate and latency charts, the PSD2 RTS availability publication. Images only, no data series. - [Pricing, low-risk merchants](https://genome.eu/low-risk-merchant-account-pricing/) and [high-risk merchants](https://genome.eu/high-risk-merchant-account-pricing/). Nothing is metered per API call. - [Security and certifications](https://genome.eu/genome-security/) — ISO/IEC 27001:2022 (TUV NORD CERT, valid to 2027-12-19) and ISO/IEC 27701:2019 (TUV CYPRUS, valid to 2028-02-13), both issued to Maneuver LT, UAB. PCI DSS is described as "aligned", not certified. - [Support](https://support.genome.eu/hc/en-us/) — Monday to Friday 08:00-20:00, support@genome.eu. ## Not published Genome publishes none of the following, and an agent should not look for them: an OpenAPI or other machine-readable contract on any host, an AsyncAPI or event catalog, a GraphQL endpoint, an MCP server, an A2A agent card, any `/.well-known/` document (including security.txt, OAuth authorization server metadata and api-catalog), an llms.txt, a changelog or release-notes page, a Postman collection, a published rate-limit policy, an SLA, a vulnerability disclosure programme or bug bounty, or a scope reference for its PSD2 OAuth surface. ## API Evangelist artifacts - Authentication profile: authentication/genome-authentication.yml - Runtime conventions, idempotency and reversibility: conventions/genome-conventions.yml - Error registry (137 codes): errors/genome-error-codes.yml - Card decline codes (45): errors/genome-decline-codes.yml - Webhook catalog: asyncapi/genome-webhooks.yml - Conformance and certifications: conformance/genome-conformance.yml - Data model: data-model/genome-data-model.yml - Sandbox and test cards: sandbox/genome-sandbox.yml - Packages and SDK currency: packages/genome-packages.yml - Agent skills: skills/_index.yml