CorebanqCorebanq Developer Docs
FXv2

List FX spread rules

Lists spread rules in the shared list envelope. NO RECORD-LEVEL FILTER APPLIES. GetAllRules takes a userID parameter and never puts it in GetAllTotalInput, and sets no RbacRecordType, so every rule is returned to any authenticated caller. GetAllTotalInput.Validate does not catch this because it only rejects a missing record type when the user id is non-nil — here it is the zero value. Contrast /v2/fx/tariffs and /v2/fx/tariffs/fees, which are scoped. SEARCH FILTERS. Every search.* parameter below is one filter on one column, and the list is the whole set the route accepts. Append an operator to compare instead of match — search.{field}.{op}, op one of eq, ne, gt, gte, lt, lte, in, nin, like, start_with, end_with; with no suffix the operator is eq. in and nin take a comma-separated list. like, start_with and end_with are case-insensitive ILIKE. search.{field}.eq=null and search.{field}.ne=null test for NULL; any other operator with an empty value is 400 query.operator_requires_value. A STRING VALUE IS SILENTLY REWRITTEN BEFORE IT REACHES THE QUERY. sanitizeStringValue drops every character that is not a letter, a digit, or one of . / @ - _ and space, and it never reports an error — so search.provider=A*B filters on AB and answers 200, not 400. A value that parses as a timestamp is passed through instead of stripped. Which rejections are 400 and which are 500 is set out under the 400 and 500 responses; the split is not the one a caller would expect. A DATE-TYPED FILTER IS TRUNCATED TO THE DAY. Where the route's field map types a column as date, normalizeSearchValueByFieldType rewrites the value as YYYY-MM-DD at midnight UTC before it reaches SQL, so a time component on such a filter is discarded without a word. Those parameters carry format: date below; the format: date-time ones are compared as sent.

GET
/v2/fx/spreads

Authorization

bearerAuth
AuthorizationBearer <token>

In: header

Query Parameters

limit?integer
offset?integer
sort?string

Comma-separated sort expression over the searchable fields listed below, each optionally prefixed with - for descending. A name outside that set is 400 query_m.invalid_sort_field.

filter?string

JSON-encoded filter criteria; invalid JSON is rejected with 400.

search_text?string

Free-text search. Also accepted as search.

stack?string

Group by this field; data becomes an object keyed by its value. Accepts only the searchable names listed below, optionally with a leading - and a [format] suffix; anything else is 400 query_m.invalid_field.

distinct?string
search.fx_tariff_id?string

Filters the tariff_id column; the table names it tariff_id, the API fx_tariff_id.

search.provider?string
search.base_currency?string

The currency ID, NOT the ISO code the response carries — mapSpreadRuleToResponse resolves the stored id to a code on the way out, and the column is uuid.

search.target_currency?string

The currency ID, not the ISO code the response carries — see search.base_currency.

search.rate_type?string

BUY, SELL or BOTH.

search.bid_spread_bps?number
search.ask_spread_bps?number
search.effective_from?string
search.effective_to?string
search.reason?string
search.id?string
search.created_at?string
search.created_by?string
search.modified_at?string
search.modified_by?string
search.active?boolean

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X GET "https://example.com/v2/fx/spreads"
{
  "total": 0,
  "total_unfiltered": 0,
  "metadata": {},
  "keys": [
    "string"
  ],
  "has_more": true,
  "data": [
    {
      "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
      "fx_tariff_id": "f12d958c-c80c-4752-862c-9e0c09506488",
      "provider": "string",
      "base_currency": "string",
      "target_currency": "string",
      "rate_type": "BUY",
      "bid_spread_bps": 0,
      "ask_spread_bps": 0,
      "effective_from": "2019-08-24T14:15:22Z",
      "effective_to": "2019-08-24T14:15:22Z",
      "reason": "string",
      "active": true,
      "created_at": "2019-08-24T14:15:22Z",
      "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
      "modified_at": "2019-08-24T14:15:22Z",
      "modified_by": "e8d4374d-93a1-4e98-a6c6-fdcf00c5059f"
    }
  ]
}
{
  "status": 409,
  "message": "Spread rule overlaps an existing rule",
  "code": "fx_m.spread_overlap",
  "class": "business",
  "retryable": false,
  "details": [
    {
      "field": "percent_fee",
      "rule": "lte",
      "param": "1",
      "message": "string"
    }
  ]
}
{
  "status": 409,
  "message": "Spread rule overlaps an existing rule",
  "code": "fx_m.spread_overlap",
  "class": "business",
  "retryable": false,
  "details": [
    {
      "field": "percent_fee",
      "rule": "lte",
      "param": "1",
      "message": "string"
    }
  ]
}
{
  "status": 409,
  "message": "Spread rule overlaps an existing rule",
  "code": "fx_m.spread_overlap",
  "class": "business",
  "retryable": false,
  "details": [
    {
      "field": "percent_fee",
      "rule": "lte",
      "param": "1",
      "message": "string"
    }
  ]
}
{
  "status": 429,
  "message": "Rate limit for 203.0.113.7 to GET:/v1/fx/rates exceeded.",
  "code": "rate_limits_m.exceeded",
  "class": "temporary",
  "retryable": true
}
{
  "status": 409,
  "message": "Spread rule overlaps an existing rule",
  "code": "fx_m.spread_overlap",
  "class": "business",
  "retryable": false,
  "details": [
    {
      "field": "percent_fee",
      "rule": "lte",
      "param": "1",
      "message": "string"
    }
  ]
}

{
  "overall_status": "unhealthy",
  "message": "Service is shutting down",
  "timestamp": "2026-08-27T15:04:05Z"
}

GETConvert currency amount (v2)

Convert an amount between currencies. Only `amount` is strictly required — all other parameters fall back to operator-configured AppConfig defaults when omitted. Tariff is resolved via a four-step chain: fx_tariff_id query param → customer's assigned tariff (when customer_id provided) → convert.default_tariff_id AppConfig → the active tariff marked is_default = TRUE. THE APPCONFIG STEP CANNOT SUCCEED: getAppConfigFxTariff reads convert.default_tariff_id, unmarshals it into cfgID, and then queries Where("name = default AND active = true") — a literal with default unquoted, which PostgreSQL reads as the reserved word, so the statement is a syntax error rather than a lookup. The error is not ErrRecordNotFound, so the branch answers 500 common.database_error instead of falling through to the is_default row. The sample bundle ships the key set, so a convert that reaches this step on a default deployment fails; where the key is absent or inactive the step returns early and the is_default lookup is reached. FX date resolution is owned by the FX module business-date lookup policy, so omitted dates anchor to the current business date and optional lookback may resolve the most recent stored rate within the configured prior calendar-day window. Units: this surface carries the STORED fee range, so fee_range money fields are INTEGER MINOR units — unlike /v1/fx/rates/convert, which reports them in major units. amount_unit defaults to minor.

GETGet FX spread rule

Next Page