Scoped authentication
OAuth access tokens bind an active institution principal to the exact API scopes and roles granted for the request.
Karvo exposes tenant-scoped resources for customers, beneficiaries, payment intents, quotes, transfers, settlement obligations, reconciliation cases, webhooks and institutional credentials.
Payment intent / 01
These illustrative contract examples use UUID resource identifiers, OAuth bearer authorization and integer minor-unit strings. Creating an intent requires an existing beneficiary and immutable FX quote; the example does not execute a real rail.
POST /v1/payment-intents
Authorization: Bearer <OAuth access token>
Idempotency-Key: 2d83d542-cd92-4d3f-9b67-63cd0c4f6ea8
Content-Type: application/json
{
"beneficiary_id": "30000000-0000-0000-0000-000000000001",
"fx_quote_id": "40000000-0000-0000-0000-000000000001",
"source_amount": {
"amount_minor": "2500000",
"currency": "GHS"
},
"reference": "INV-8842"
}201 Created
{
"id": "50000000-0000-0000-0000-000000000001",
"beneficiary_id": "30000000-0000-0000-0000-000000000001",
"fx_quote_id": "40000000-0000-0000-0000-000000000001",
"source_amount": {
"amount_minor": "2500000",
"currency": "GHS"
},
"destination_amount": {
"amount_minor": "292500000",
"currency": "NGN"
},
"reference": "INV-8842",
"state": "CREATED",
"created_at": "2026-08-23T12:00:00Z",
"provider_reference": null
}Live availability / 02
This server-rendered check reads the backend health boundary without placing credentials, tokens or internal service addresses in the browser.
Live sandbox API
Checking availabilityThe server is checking the sandbox health boundary. No financial state is inferred from this check.
State model / 03
Karvo distinguishes customer-visible transfer state from provider attempt certainty, settlement state and reconciliation state.
Integration modes / 04
Participant adapters map modern and legacy interfaces into the same canonical contracts and capability model.
OAuth access tokens bind an active institution principal to the exact API scopes and roles granted for the request.
Identical command replay returns the original economic result; changed semantics are rejected.
Webhook payloads carry event identity and are signed over timestamp, event ID and raw body.
Request, command, event, provider, ledger, settlement and reconciliation identities remain connected.
State conflicts return 409; semantic or idempotency fingerprint mismatch returns 422.
Contracts are additive within v1; breaking semantics require a new API version.
Event reliability / 05
Each service commits its own state and outbox atomically. Consumers record event identity with their effect, making replay safe under at-least-once delivery.
A state change and its publishable event commit in the same owned database transaction.
Kafka partitions by tenant and aggregate identity so lifecycle events remain locally ordered and replayable.
Every consumer deduplicates event IDs in the same transaction as its resulting state change.
Lost callbacks, delayed events and poison messages become observable queues, checkpoints or reconciliation cases.
Work with Karvo
Tell us where your institution sits in the transaction chain and which corridor or capability you are evaluating.
Start a conversationLive sandbox API
Sandbox API operationalAvailability confirms only that the sandbox API answered its health check. It is not evidence that a payment moved, settled or reconciled.
Checked