# Kriya > Kriya (Kriya Finance Limited, London) is a UK B2B embedded-finance provider that lets merchants offer trade credit to their business buyers. It publishes two partner-facing REST APIs — Payments (B2B buy-now-pay-later: company search, buyer risk decisioning, order lifecycle, payment deductions) and Onboarding (automated company and KYC checks) — plus hosted Payments Journey and Onboarding Journey web flows, HMAC-signed webhooks, and a test environment with scenario simulators. Kriya was acquired by Allica Bank in October 2025. Generated by the API Evangelist enrichment pipeline on 2026-07-19. Kriya publishes no llms.txt of its own; this file is generated from the catalog entry and the artifacts in this repository. Key facts for agents: - Authentication is a static partner API key in the `X-Kriya-ApiKey` header on every request. Access is restricted to approved partners. Test and Production keys are issued separately and are not interchangeable. - There is no OAuth, no scopes, and no idempotency-key contract. Do not assume requests are safe to replay. - Rate limits: 2000 requests per 5 minutes per API key; company search is limited to 5 requests per second. Breaches return 429. - Errors return a `problemDetails` JSON body (title, message, errors, date, operationId). Despite the name this is NOT RFC 9457 — no type/status/detail/instance, and the media type is application/json. - `TransitionOrderStatus` to `ReadyToAdvance` causes Kriya to advance real funds and cannot be reversed or cancelled. Treat as irreversible. - Operations under `/scenario/` exist only in the Test environment (https://api.kriya.dev/). Never call them against Production. ## APIs - [Kriya Payments API](https://docs.kriya.co/payments): B2B buy-now-pay-later scheme — company search, buyer registration and risk decisioning, pricing schemes, order creation and status transitions, 2FA sessions, delivery confirmation, payment deductions. Base URL https://api.kriya.co/payments/ - [Kriya Onboarding API](https://docs.kriya.co/onboarding): Automates buyer onboarding — Onboarding Journeys for limited companies, government entities and sole traders, company credit checks, and optional identity verification, sanction screening and selfie checks. Base URL https://api.kriya.co/onboarding/ ## Specs - [Kriya Payments OpenAPI 3.0.1](openapi/kriya-payments-openapi.yaml): 17 operations, 42 schemas. Harvested from https://cdn.kriya.co/images/Kriya-Payments-api.yaml - [Kriya Onboarding OpenAPI 3.0.1](openapi/kriya-onboarding-openapi.yaml): 3 operations, 7 schemas. Harvested from https://cdn.kriya.co/images/Kriya-Onboarding-api.yaml - [Payments overlay](overlays/kriya-payments-overlay.yaml): API Evangelist enhancements — declares the undeclared API key scheme, removes the localhost server, adds the documented 429/503 responses. - [Onboarding overlay](overlays/kriya-onboarding-overlay.yaml): API Evangelist enhancements. ## Docs - [Developer portal](https://docs.kriya.co/): Redoc-rendered reference for both APIs. - [Payments documentation](https://docs.kriya.co/payments): Includes definitions, integration scenarios, order statuses, webhooks and API environments. - [Onboarding documentation](https://docs.kriya.co/onboarding): Onboarding Journey initiation and additional checks. - [Website](https://www.kriya.co): Product overview — Embedded PayLater, Invoice Finance, working capital loans, Buyer Authentication, Offline Payments, Kriya on Stripe. - [Blog](https://www.kriya.co/blog) - [Contact and support](https://www.kriya.co/contact-us): API support at apisupport@kriya.co. - [Responsible disclosure policy](https://www.kriya.co/responsible-disclosure): Report vulnerabilities to disclosure@kriya.co. No financial rewards offered. - [Terms and conditions](https://www.kriya.co/terms-and-conditions) - [Privacy policy](https://www.kriya.co/privacy-policy) - [Merchant portal login](https://merchant.kriya.co/) ## Artifacts - [Authentication profile](authentication/kriya-authentication.yml): API key model plus webhook HMAC verification. - [API conventions](conventions/kriya-conventions.yml): Auth style, pagination, rate limiting, error envelope, monetary values, identifiers. - [Error catalog](errors/kriya-problem-types.yml): 400/401/404/409/429/500/503 with remediation. - [Decline codes](errors/kriya-decline-codes.yml): Payments Journey decline reasons and buyer decision statuses. - [Webhook catalog](asyncapi/kriya-payments-webhooks.yml): 4 event types, payloads, HMAC signing, retry policy. - [Sandbox](sandbox/kriya-sandbox.yml): Test environment and the scenario simulators. - [Data model](data-model/kriya-data-model.yml): Entity graph — Merchant, Buyer, Supplier, Order, Payment, PaymentDeduction, OnboardingJourney. - [Embedded components](components/kriya-components.yml): Hosted journeys and the BigCommerce, Magento, nopCommerce, PrestaShop and Salesforce plugins. - [Lifecycle](lifecycle/kriya-lifecycle.yml): Versioning, deprecation and status-page posture. - [Conformance](conformance/kriya-conformance.yml): Standards assessment. - [Domain security](security/kriya-domain-security.yml): TLS, HSTS, DNSSEC, SPF, DMARC probe results. - [Vulnerability disclosure](security/kriya-vulnerability-disclosure.yml) - [MCP candidate](mcp/kriya-mcp.yml): Derived tool list. Kriya publishes no MCP server. - [Agent skills](skills/_index.yml) ## Not published Kriya publishes none of the following; do not look for them: an OpenAPI-declared security scheme, an llms.txt, any /.well-known/ document including security.txt, a status page, a dated changelog, a deprecation or versioning policy, an SLA, an AsyncAPI document, an MCP server, a CLI, a GitHub organisation, or any first-party SDK in npm, PyPI or another package registry. Packages named "kriya" in npm and PyPI belong to unrelated projects.