List FX spread rules
Lists spread rules in the shared list envelope. NO RECORD-LEVEL FILTER APPLIES. GetAllRules takes a userID parameter and never puts it in GetAllTotalInput, and sets no RbacRecordType, so every rule is returned to any authenticated caller. GetAllTotalInput.Validate does not catch this because it only rejects a missing record type when the user id is non-nil — here it is the zero value. Contrast /v2/fx/tariffs and /v2/fx/tariffs/fees, which are scoped. SEARCH FILTERS. Every search.* parameter below is one filter on one column, and the list is the whole set the route accepts. Append an operator to compare instead of match — search.{field}.{op}, op one of eq, ne, gt, gte, lt, lte, in, nin, like, start_with, end_with; with no suffix the operator is eq. in and nin take a comma-separated list. like, start_with and end_with are case-insensitive ILIKE. search.{field}.eq=null and search.{field}.ne=null test for NULL; any other operator with an empty value is 400 query.operator_requires_value. A STRING VALUE IS SILENTLY REWRITTEN BEFORE IT REACHES THE QUERY. sanitizeStringValue drops every character that is not a letter, a digit, or one of . / @ - _ and space, and it never reports an error — so search.provider=A*B filters on AB and answers 200, not 400. A value that parses as a timestamp is passed through instead of stripped. Which rejections are 400 and which are 500 is set out under the 400 and 500 responses; the split is not the one a caller would expect. A DATE-TYPED FILTER IS TRUNCATED TO THE DAY. Where the route's field map types a column as date, normalizeSearchValueByFieldType rewrites the value as YYYY-MM-DD at midnight UTC before it reaches SQL, so a time component on such a filter is discarded without a word. Those parameters carry format: date below; the format: date-time ones are compared as sent.
Authorization
bearerAuth In: header
Query Parameters
Comma-separated sort expression over the searchable fields listed below, each optionally prefixed with - for descending. A name outside that set is 400 query_m.invalid_sort_field.
JSON-encoded filter criteria; invalid JSON is rejected with 400.
Free-text search. Also accepted as search.
Group by this field; data becomes an object keyed by its value. Accepts only the searchable names listed below, optionally with a leading - and a [format] suffix; anything else is 400 query_m.invalid_field.
Filters the tariff_id column; the table names it tariff_id, the API fx_tariff_id.
The currency ID, NOT the ISO code the response carries — mapSpreadRuleToResponse resolves the stored id to a code on the way out, and the column is uuid.
The currency ID, not the ISO code the response carries — see search.base_currency.
BUY, SELL or BOTH.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/v2/fx/spreads"{
"total": 0,
"total_unfiltered": 0,
"metadata": {},
"keys": [
"string"
],
"has_more": true,
"data": [
{
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"fx_tariff_id": "f12d958c-c80c-4752-862c-9e0c09506488",
"provider": "string",
"base_currency": "string",
"target_currency": "string",
"rate_type": "BUY",
"bid_spread_bps": 0,
"ask_spread_bps": 0,
"effective_from": "2019-08-24T14:15:22Z",
"effective_to": "2019-08-24T14:15:22Z",
"reason": "string",
"active": true,
"created_at": "2019-08-24T14:15:22Z",
"created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
"modified_at": "2019-08-24T14:15:22Z",
"modified_by": "e8d4374d-93a1-4e98-a6c6-fdcf00c5059f"
}
]
}{
"status": 409,
"message": "Spread rule overlaps an existing rule",
"code": "fx_m.spread_overlap",
"class": "business",
"retryable": false,
"details": [
{
"field": "percent_fee",
"rule": "lte",
"param": "1",
"message": "string"
}
]
}{
"status": 409,
"message": "Spread rule overlaps an existing rule",
"code": "fx_m.spread_overlap",
"class": "business",
"retryable": false,
"details": [
{
"field": "percent_fee",
"rule": "lte",
"param": "1",
"message": "string"
}
]
}{
"status": 409,
"message": "Spread rule overlaps an existing rule",
"code": "fx_m.spread_overlap",
"class": "business",
"retryable": false,
"details": [
{
"field": "percent_fee",
"rule": "lte",
"param": "1",
"message": "string"
}
]
}{
"status": 429,
"message": "Rate limit for 203.0.113.7 to GET:/v1/fx/rates exceeded.",
"code": "rate_limits_m.exceeded",
"class": "temporary",
"retryable": true
}{
"status": 409,
"message": "Spread rule overlaps an existing rule",
"code": "fx_m.spread_overlap",
"class": "business",
"retryable": false,
"details": [
{
"field": "percent_fee",
"rule": "lte",
"param": "1",
"message": "string"
}
]
}{
"overall_status": "unhealthy",
"message": "Service is shutting down",
"timestamp": "2026-08-27T15:04:05Z"
}Convert an amount between currencies. Only `amount` is strictly required — all other parameters fall back to operator-configured AppConfig defaults when omitted. Tariff is resolved via a four-step chain: fx_tariff_id query param → customer's assigned tariff (when customer_id provided) → convert.default_tariff_id AppConfig → the active tariff marked is_default = TRUE. THE APPCONFIG STEP CANNOT SUCCEED: getAppConfigFxTariff reads convert.default_tariff_id, unmarshals it into cfgID, and then queries Where("name = default AND active = true") — a literal with default unquoted, which PostgreSQL reads as the reserved word, so the statement is a syntax error rather than a lookup. The error is not ErrRecordNotFound, so the branch answers 500 common.database_error instead of falling through to the is_default row. The sample bundle ships the key set, so a convert that reaches this step on a default deployment fails; where the key is absent or inactive the step returns early and the is_default lookup is reached. FX date resolution is owned by the FX module business-date lookup policy, so omitted dates anchor to the current business date and optional lookback may resolve the most recent stored rate within the configured prior calendar-day window. Units: this surface carries the STORED fee range, so fee_range money fields are INTEGER MINOR units — unlike /v1/fx/rates/convert, which reports them in major units. amount_unit defaults to minor.
Next Page