# Monzo > Monzo is a UK digital challenger bank. Its public REST API (https://api.monzo.com) lets a user build personal applications against their own Monzo account: accounts, balance, savings pots, transactions, feed items, attachments, receipts, and real-time transaction webhooks. Access uses OAuth 2.0 with Strong Customer Authentication approved in the Monzo app. ## APIs - [Monzo API Documentation](https://docs.monzo.com): REST reference for accounts, balance, pots, transactions, feed, attachments, receipts and webhooks. - [Monzo for Developers](https://developers.monzo.com): Developer portal — create OAuth clients and use the API Playground. - [API Playground](https://developers.monzo.com/api/playground): Get a developer-scoped access token to try the API live. ## Authentication - OAuth 2.0 authorization code grant. Authorize at https://auth.monzo.com/, exchange the code at https://api.monzo.com/oauth2/token. - Present the token as `Authorization: Bearer {access_token}`. - Strong Customer Authentication (SCA): the user approves access from a push notification in the Monzo app. - Refresh tokens are issued to confidential clients only. ## Endpoints - GET /accounts — list accounts (filter with account_type=uk_retail). - GET /balance?account_id=... — balance, total balance, spend today. - GET /pots?current_account_id=... — list pots. - PUT /pots/{pot_id}/deposit — deposit (requires dedupe_id). - PUT /pots/{pot_id}/withdraw — withdraw (requires dedupe_id). - GET /transactions — list transactions (limit, since, before; expand[]=merchant). - GET /transactions/{transaction_id} — retrieve a transaction. - PATCH /transactions/{transaction_id} — annotate with metadata. - POST /feed — create a feed item. - POST /attachment/upload | /attachment/register | /attachment/deregister — attachments. - PUT | GET | DELETE /transaction-receipts — receipts. - POST | GET | DELETE /webhooks — manage webhooks (transaction.created events). ## Conventions - Pagination: limit (default 30, max 100), since, before. - Idempotency: dedupe_id on pot deposit/withdraw. - Errors: standard HTTP status codes with JSON bodies; OAuth errors as {error, error_description}. - Rate limiting: HTTP 429 when exceeded. ## Docs - [Developer Community](https://community.monzo.com): Developers category. - [Status](https://status.monzo.com): Monzo service status. - [Security & bug bounty](https://monzo.com/.well-known/security.txt): Intigriti program, security@monzo.com. ## Notes - The API is intended for personal use and small authorized user groups, not large public applications. - Generated by the API Evangelist enrichment pipeline from Monzo's public developer documentation.