> ## Documentation Index
> Fetch the complete documentation index at: https://docs.spritz.finance/llms.txt
> Use this file to discover all available pages before exploring further.

# Prepare a direct deposit authorization

> Creates the canonical ACH authorization message for a deposit targeting a raw wallet address. Authorization is derived from the verified ACH funding source; no wallet signature is required.



## OpenAPI

````yaml https://platform.spritz.finance/openapi.json post /v1/deposits/direct/prepare
openapi: 3.0.3
info:
  title: Spritz Finance API
  version: 1.0.0
  description: API for the Spritz Finance platform with RFC 9457 error handling
servers:
  - url: https://platform.spritz.finance
    description: Production
  - url: https://sandbox.spritz.finance
    description: Sandbox
security: []
tags:
  - name: Users
    description: User management endpoints
  - name: Bank Accounts
    description: Manage bank accounts for off-ramp destinations
  - name: Bills
    description: Manage bill pay accounts
  - name: Cards
    description: Spritz-issued debit cards
  - name: Auto-Ramp Accounts
    description: Virtual bank accounts that automatically convert fiat deposits to crypto
  - name: Spritz App
    description: >-
      Endpoints used by the Spritz app and internal SDKs. Excluded from the
      public partner spec.
paths:
  /v1/deposits/direct/prepare:
    post:
      tags:
        - Deposits
      summary: Prepare a direct deposit authorization
      description: >-
        Creates the canonical ACH authorization message for a deposit targeting
        a raw wallet address. Authorization is derived from the verified ACH
        funding source; no wallet signature is required.
      operationId: postV1DepositsDirectPrepare
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                sourceId:
                  description: Opaque public funding source identifier
                  type: string
                  example: fs_01JV7Q8M4Y8K6N2Z5P3R1T9W0X
                address:
                  description: >-
                    Destination wallet address to deposit into. Validated but
                    not proven via wallet signature; authorization is derived
                    from the verified ACH funding source.
                  type: string
                  example: 9n4nbM75f5Ui33ZbPYXn59EwSb9Y1zdyu3x2b1f8jQRY
                network:
                  type: string
                  enum:
                    - solana
                    - ethereum
                    - polygon
                    - base
                    - avalanche
                    - arbitrum
                asset:
                  description: Asset sent to the deposit destination
                  type: string
                  example: USDC
                  enum:
                    - USDC
                quoteType:
                  type: string
                  enum:
                    - exact_input
                    - exact_output
                amountUsd:
                  description: Requested USD amount as a decimal string
                  type: string
                  example: '100.00'
                priority:
                  type: string
                  enum:
                    - normal
                    - high
                feeSubsidy:
                  type: object
                  properties:
                    percentage:
                      minimum: 0
                      maximum: 100
                      type: number
                    maxAmountUsd:
                      minLength: 1
                      type: string
                  required:
                    - percentage
                clientContext:
                  type: object
                  properties:
                    clientIp:
                      type: string
                    userAgent:
                      type: string
                    sessionId:
                      type: string
                    deviceId:
                      type: string
                    platform:
                      type: string
                    appVersion:
                      type: string
              required:
                - sourceId
                - address
                - network
                - asset
                - quoteType
                - amountUsd
                - priority
          application/x-www-form-urlencoded:
            schema:
              type: object
              properties:
                sourceId:
                  description: Opaque public funding source identifier
                  type: string
                  example: fs_01JV7Q8M4Y8K6N2Z5P3R1T9W0X
                address:
                  description: >-
                    Destination wallet address to deposit into. Validated but
                    not proven via wallet signature; authorization is derived
                    from the verified ACH funding source.
                  type: string
                  example: 9n4nbM75f5Ui33ZbPYXn59EwSb9Y1zdyu3x2b1f8jQRY
                network:
                  type: string
                  enum:
                    - solana
                    - ethereum
                    - polygon
                    - base
                    - avalanche
                    - arbitrum
                asset:
                  description: Asset sent to the deposit destination
                  type: string
                  example: USDC
                  enum:
                    - USDC
                quoteType:
                  type: string
                  enum:
                    - exact_input
                    - exact_output
                amountUsd:
                  description: Requested USD amount as a decimal string
                  type: string
                  example: '100.00'
                priority:
                  type: string
                  enum:
                    - normal
                    - high
                feeSubsidy:
                  type: object
                  properties:
                    percentage:
                      minimum: 0
                      maximum: 100
                      type: number
                    maxAmountUsd:
                      minLength: 1
                      type: string
                  required:
                    - percentage
                clientContext:
                  type: object
                  properties:
                    clientIp:
                      type: string
                    userAgent:
                      type: string
                    sessionId:
                      type: string
                    deviceId:
                      type: string
                    platform:
                      type: string
                    appVersion:
                      type: string
              required:
                - sourceId
                - address
                - network
                - asset
                - quoteType
                - amountUsd
                - priority
          multipart/form-data:
            schema:
              type: object
              properties:
                sourceId:
                  description: Opaque public funding source identifier
                  type: string
                  example: fs_01JV7Q8M4Y8K6N2Z5P3R1T9W0X
                address:
                  description: >-
                    Destination wallet address to deposit into. Validated but
                    not proven via wallet signature; authorization is derived
                    from the verified ACH funding source.
                  type: string
                  example: 9n4nbM75f5Ui33ZbPYXn59EwSb9Y1zdyu3x2b1f8jQRY
                network:
                  type: string
                  enum:
                    - solana
                    - ethereum
                    - polygon
                    - base
                    - avalanche
                    - arbitrum
                asset:
                  description: Asset sent to the deposit destination
                  type: string
                  example: USDC
                  enum:
                    - USDC
                quoteType:
                  type: string
                  enum:
                    - exact_input
                    - exact_output
                amountUsd:
                  description: Requested USD amount as a decimal string
                  type: string
                  example: '100.00'
                priority:
                  type: string
                  enum:
                    - normal
                    - high
                feeSubsidy:
                  type: object
                  properties:
                    percentage:
                      minimum: 0
                      maximum: 100
                      type: number
                    maxAmountUsd:
                      minLength: 1
                      type: string
                  required:
                    - percentage
                clientContext:
                  type: object
                  properties:
                    clientIp:
                      type: string
                    userAgent:
                      type: string
                    sessionId:
                      type: string
                    deviceId:
                      type: string
                    platform:
                      type: string
                    appVersion:
                      type: string
              required:
                - sourceId
                - address
                - network
                - asset
                - quoteType
                - amountUsd
                - priority
      responses:
        '200':
          description: Response for status 200
          content:
            application/json:
              schema:
                type: object
                properties:
                  preparationId:
                    description: Opaque public preparation identifier
                    type: string
                    example: prep_01JV7Q8M4Y8K6N2Z5P3R1T9W0X
                  kind:
                    type: string
                    enum:
                      - deposit_authorization
                  expiresAt:
                    format: date-time
                    type: string
                  messageVersion:
                    type: string
                    enum:
                      - v1
                  message:
                    description: Display-ready ACH authorization message
                    type: string
                  summary:
                    type: object
                    properties:
                      quoteType:
                        type: string
                        enum:
                          - exact_input
                          - exact_output
                      requestedAmountUsd:
                        type: string
                      priority:
                        type: string
                        enum:
                          - normal
                          - high
                      feeRateBps:
                        type: number
                      planAdjustmentBps:
                        type: number
                      principalAmountUsd:
                        type: string
                      expectedAssetAmount:
                        type: string
                      grossFeeUsd:
                        type: string
                      publishedFeeUsd:
                        type: string
                      planAdjustmentFeeUsd:
                        type: string
                      feeSubsidyUsd:
                        type: string
                      userFeeUsd:
                        type: string
                      totalDebitAmountUsd:
                        type: string
                      feeSubsidy:
                        type: object
                        properties:
                          percentage:
                            type: number
                          percentageBps:
                            type: number
                          maxAmountUsd:
                            type: string
                            nullable: true
                          appliedAmountUsd:
                            type: string
                        required:
                          - percentage
                          - percentageBps
                          - maxAmountUsd
                          - appliedAmountUsd
                        nullable: true
                      network:
                        type: string
                        enum:
                          - solana
                          - ethereum
                          - polygon
                          - base
                          - avalanche
                          - arbitrum
                      asset:
                        description: Asset sent to the deposit destination
                        type: string
                        example: USDC
                        enum:
                          - USDC
                      assetAddress:
                        type: string
                      destinationAddress:
                        type: string
                    required:
                      - quoteType
                      - requestedAmountUsd
                      - priority
                      - feeRateBps
                      - planAdjustmentBps
                      - principalAmountUsd
                      - expectedAssetAmount
                      - grossFeeUsd
                      - publishedFeeUsd
                      - planAdjustmentFeeUsd
                      - feeSubsidyUsd
                      - userFeeUsd
                      - totalDebitAmountUsd
                      - feeSubsidy
                      - network
                      - asset
                      - assetAddress
                      - destinationAddress
                required:
                  - preparationId
                  - kind
                  - expiresAt
                  - messageVersion
                  - message
                  - summary
        '400':
          description: Response for status 400
          content:
            application/json:
              schema:
                type: object
                allOf:
                  - type: object
                    properties:
                      type:
                        default: about:blank
                        description: A URI reference that identifies the problem type
                        type: string
                        example: urn:problem-type:auth:unauthorized
                      title:
                        description: A short, human-readable summary of the problem type
                        type: string
                        example: Unauthorized
                      status:
                        description: The HTTP status code
                        type: number
                        example: 400
                      detail:
                        description: >-
                          A human-readable explanation specific to this
                          occurrence
                        type: string
                      instance:
                        description: >-
                          A URI reference that identifies the specific
                          occurrence
                        type: string
                        example: /errors/1234567890
                      code:
                        description: >-
                          Machine-readable cause, present when exactly one thing
                          failed. Branch on this, never on `detail`, which is
                          human-facing copy and may change. For deposit limits
                          the vocabulary matches the `reason` values the limits
                          API returns pre-flight.
                        type: string
                        example: transaction_limit
                      field:
                        description: The offending request field, present alongside `code`.
                        type: string
                        example: amountUsd
                      retryable:
                        description: >-
                          Whether retrying the same request later may succeed
                          without changing its inputs.
                        type: boolean
                        example: true
                    required:
                      - title
                      - status
                    additionalProperties: false
                  - type: object
                    properties:
                      errors:
                        description: >-
                          Every cause. A single-cause failure also reports it
                          via top-level `code`/`field`/`detail`; a multi-field
                          failure is described only here.
                        type: array
                        items:
                          type: object
                          properties:
                            field:
                              type: string
                            message:
                              type: string
                            code:
                              type: string
                          required:
                            - field
                            - message
        '401':
          description: Response for status 401
          content:
            application/json:
              schema:
                type: object
                properties:
                  type:
                    default: about:blank
                    description: A URI reference that identifies the problem type
                    type: string
                    example: urn:problem-type:auth:unauthorized
                  title:
                    description: A short, human-readable summary of the problem type
                    type: string
                    example: Unauthorized
                  status:
                    description: The HTTP status code
                    type: number
                    example: 401
                  detail:
                    description: A human-readable explanation specific to this occurrence
                    type: string
                    example: Bearer token required
                  instance:
                    description: A URI reference that identifies the specific occurrence
                    type: string
                  realm:
                    description: The authentication realm
                    type: string
                    example: API
                  scope:
                    description: The required scope for this resource
                    type: string
                    example: read:users
                required:
                  - title
                  - status
                additionalProperties: false
        '403':
          description: Response for status 403
          content:
            application/json:
              schema:
                type: object
                properties:
                  type:
                    default: about:blank
                    description: A URI reference that identifies the problem type
                    type: string
                    example: urn:problem-type:auth:unauthorized
                  title:
                    description: A short, human-readable summary of the problem type
                    type: string
                    example: Unauthorized
                  status:
                    description: The HTTP status code
                    type: number
                    example: 400
                  detail:
                    description: A human-readable explanation specific to this occurrence
                    type: string
                  instance:
                    description: A URI reference that identifies the specific occurrence
                    type: string
                    example: /errors/1234567890
                  code:
                    description: >-
                      Machine-readable cause, present when exactly one thing
                      failed. Branch on this, never on `detail`, which is
                      human-facing copy and may change. For deposit limits the
                      vocabulary matches the `reason` values the limits API
                      returns pre-flight.
                    type: string
                    example: transaction_limit
                  field:
                    description: The offending request field, present alongside `code`.
                    type: string
                    example: amountUsd
                  retryable:
                    description: >-
                      Whether retrying the same request later may succeed
                      without changing its inputs.
                    type: boolean
                    example: true
                required:
                  - title
                  - status
                additionalProperties: false
        '404':
          description: Response for status 404
          content:
            application/json:
              schema:
                type: object
                properties:
                  type:
                    default: about:blank
                    description: A URI reference that identifies the problem type
                    type: string
                  title:
                    description: A short, human-readable summary of the problem type
                    type: string
                  status:
                    description: The HTTP status code
                    type: number
                    example: 404
                  detail:
                    description: A human-readable explanation specific to this occurrence
                    type: string
                  instance:
                    description: A URI reference that identifies the specific occurrence
                    type: string
                  resourceType:
                    description: The type of resource that was not found
                    type: string
                    example: user
                  resourceId:
                    description: The identifier of the resource that was not found
                    type: string
                required:
                  - title
                  - status
                  - resourceType
                  - resourceId
                additionalProperties: false
        '409':
          description: Response for status 409
          content:
            application/json:
              schema:
                type: object
                properties:
                  type:
                    default: about:blank
                    description: A URI reference that identifies the problem type
                    type: string
                    example: urn:problem-type:auth:unauthorized
                  title:
                    description: A short, human-readable summary of the problem type
                    type: string
                    example: Unauthorized
                  status:
                    description: The HTTP status code
                    type: number
                    example: 400
                  detail:
                    description: A human-readable explanation specific to this occurrence
                    type: string
                  instance:
                    description: A URI reference that identifies the specific occurrence
                    type: string
                    example: /errors/1234567890
                  code:
                    description: >-
                      Machine-readable cause, present when exactly one thing
                      failed. Branch on this, never on `detail`, which is
                      human-facing copy and may change. For deposit limits the
                      vocabulary matches the `reason` values the limits API
                      returns pre-flight.
                    type: string
                    example: transaction_limit
                  field:
                    description: The offending request field, present alongside `code`.
                    type: string
                    example: amountUsd
                  retryable:
                    description: >-
                      Whether retrying the same request later may succeed
                      without changing its inputs.
                    type: boolean
                    example: true
                required:
                  - title
                  - status
                additionalProperties: false
        '500':
          description: Response for status 500
          content:
            application/json:
              schema:
                type: object
                properties:
                  type:
                    default: about:blank
                    description: A URI reference that identifies the problem type
                    type: string
                    example: urn:problem-type:auth:unauthorized
                  title:
                    description: A short, human-readable summary of the problem type
                    type: string
                    example: Unauthorized
                  status:
                    description: The HTTP status code
                    type: number
                    example: 400
                  detail:
                    description: A human-readable explanation specific to this occurrence
                    type: string
                  instance:
                    description: A URI reference that identifies the specific occurrence
                    type: string
                    example: /errors/1234567890
                  code:
                    description: >-
                      Machine-readable cause, present when exactly one thing
                      failed. Branch on this, never on `detail`, which is
                      human-facing copy and may change. For deposit limits the
                      vocabulary matches the `reason` values the limits API
                      returns pre-flight.
                    type: string
                    example: transaction_limit
                  field:
                    description: The offending request field, present alongside `code`.
                    type: string
                    example: amountUsd
                  retryable:
                    description: >-
                      Whether retrying the same request later may succeed
                      without changing its inputs.
                    type: boolean
                    example: true
                required:
                  - title
                  - status
                additionalProperties: false
        '503':
          description: Response for status 503
          content:
            application/json:
              schema:
                type: object
                properties:
                  type:
                    default: about:blank
                    description: A URI reference that identifies the problem type
                    type: string
                    example: urn:problem-type:auth:unauthorized
                  title:
                    description: A short, human-readable summary of the problem type
                    type: string
                    example: Unauthorized
                  status:
                    description: The HTTP status code
                    type: number
                    example: 400
                  detail:
                    description: A human-readable explanation specific to this occurrence
                    type: string
                  instance:
                    description: A URI reference that identifies the specific occurrence
                    type: string
                    example: /errors/1234567890
                  code:
                    description: >-
                      Machine-readable cause, present when exactly one thing
                      failed. Branch on this, never on `detail`, which is
                      human-facing copy and may change. For deposit limits the
                      vocabulary matches the `reason` values the limits API
                      returns pre-flight.
                    type: string
                    example: transaction_limit
                  field:
                    description: The offending request field, present alongside `code`.
                    type: string
                    example: amountUsd
                  retryable:
                    description: >-
                      Whether retrying the same request later may succeed
                      without changing its inputs.
                    type: boolean
                    example: true
                required:
                  - title
                  - status
                additionalProperties: false
      security:
        - bearerAuth: []
        - integratorJwt: []
        - hmacAuth: []
          integratorKey: []
          timestamp: []
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: Cognito JWT token for regular user authentication
    integratorJwt:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Integrator JWT token (prefix: spr_) for frontend integrator
        authentication. Obtained via token exchange endpoint.
    hmacAuth:
      type: apiKey
      in: header
      name: X-Signature
      description: >-
        HMAC signature authentication for backend integrators.


        **Required Headers:**

        - X-Integrator-Key: Integrator API key (format: int_...)

        - X-Signature: HMAC signature (format: sha256={hex})

        - X-Timestamp: Unix timestamp in milliseconds

        - Authorization: Bearer {user-api-key}


        **Signature Algorithm:** HMAC-SHA256


        **Signature Format:** {timestamp}.{METHOD}.{path}.{bodyHash}

        - timestamp: Unix timestamp in milliseconds

        - METHOD: HTTP method in UPPERCASE (GET, POST, etc.)

        - path: Request path (e.g., /v1/transactions)

        - bodyHash: SHA256 hex digest of request body (empty string if no body)


        **Timestamp Tolerance:** ±5 minutes (300 seconds)


        **Example:**

        For POST /v1/transactions with body {"amount":100} and timestamp
        1234567890000:

        Payload: 1234567890000.POST./v1/transactions.{sha256(body)}

        Signature: sha256=abc123...
    integratorKey:
      type: apiKey
      in: header
      name: X-Integrator-Key
      description: 'Integrator API key (format: int_...) used with HMAC authentication'
    timestamp:
      type: apiKey
      in: header
      name: X-Timestamp
      description: >-
        Unix timestamp in milliseconds for replay attack prevention. Must be
        within 5 minutes of server time.

````