> ## Documentation Index
> Fetch the complete documentation index at: https://docs.spritz.finance/llms.txt
> Use this file to discover all available pages before exploring further.

# Get a funding source

> Returns details for a specific funding source for the authenticated user.



## OpenAPI

````yaml https://platform.spritz.finance/openapi.json get /v1/funding-sources/{fundingSourceId}
openapi: 3.0.3
info:
  title: Spritz Finance API
  version: 1.0.0
  description: API for the Spritz Finance platform with RFC 9457 error handling
servers:
  - url: https://platform.spritz.finance
    description: Production
  - url: https://sandbox.spritz.finance
    description: Sandbox
security: []
tags:
  - name: Users
    description: User management endpoints
  - name: Bank Accounts
    description: Manage bank accounts for off-ramp destinations
  - name: Bills
    description: Manage bill pay accounts
  - name: Cards
    description: Spritz-issued debit cards
  - name: Auto-Ramp Accounts
    description: Virtual bank accounts that automatically convert fiat deposits to crypto
  - name: Spritz App
    description: >-
      Endpoints used by the Spritz app and internal SDKs. Excluded from the
      public partner spec.
paths:
  /v1/funding-sources/{fundingSourceId}:
    get:
      tags:
        - Funding Sources
      summary: Get a funding source
      description: >-
        Returns details for a specific funding source for the authenticated
        user.
      operationId: getV1Funding-sourcesByFundingSourceId
      parameters:
        - name: fundingSourceId
          in: path
          required: true
          schema:
            description: Opaque public funding source ID
            type: string
            example: fs_01JV7Q8M4Y8K6N2Z5P3R1T9W0X
      responses:
        '200':
          description: A linked bank account that can be evaluated for inbound funding
          content:
            application/json:
              schema:
                description: >-
                  A linked bank account that can be evaluated for inbound
                  funding
                type: object
                properties:
                  id:
                    description: Opaque public identifier for the funding source
                    type: string
                    example: fs_01JV7Q8M4Y8K6N2Z5P3R1T9W0X
                  bankAccountId:
                    description: Underlying bank account identifier
                    type: string
                    example: ba_abc123
                  institutionName:
                    type: string
                    description: >-
                      Institution name used for funding source display. Prefer
                      `institution.name` when present; this field will be
                      removed in a future release.
                    nullable: true
                    example: Plaid Test Bank
                  institution:
                    description: >-
                      Branding metadata for the institution backing the funding
                      source, or null when no institution data is available.
                    type: object
                    properties:
                      name:
                        description: Display name for the institution
                        type: string
                        example: Chase
                      logoUrl:
                        type: string
                        description: >-
                          Absolute URL to the institution's logo (PNG). Null
                          when the institution has no logo on file.
                        nullable: true
                        example: >-
                          https://assets.platform.spritz.finance/institutions/ins_109508.png
                      primaryColor:
                        type: string
                        description: >-
                          Hex color (e.g. `#1e88e5`) representing the
                          institution's brand. Null when unavailable.
                        nullable: true
                        example: '#1e88e5'
                    required:
                      - name
                      - logoUrl
                      - primaryColor
                    nullable: true
                  accountNumberLast4:
                    type: string
                    description: Last 4 digits of the linked bank account number
                    nullable: true
                    example: '6789'
                  accountType:
                    type: string
                    enum:
                      - checking
                      - savings
                      - business
                      - unknown
                  status:
                    type: string
                    enum:
                      - pending
                      - active
                      - review_required
                      - ineligible
                      - disabled
                      - deleted
                  statusReason:
                    type: string
                    enum:
                      - ownership_mismatch
                      - ownership_review_required
                      - user_not_verified
                      - duplicate_bank_account
                      - returned
                      - risk_blocked
                      - rerouted
                      - manually_disabled
                      - null
                    description: >-
                      Why the funding source is not active, or null when no
                      reason applies.
                    nullable: true
                    example: ownership_mismatch
                  availableAt:
                    format: date-time
                    type: string
                    description: >-
                      For a time-boxed block (`statusReason: rerouted`), when
                      the funding source becomes usable again on its own.
                      Re-linking the same account does not shorten it. Null when
                      the source is usable or the block is not time-bound.
                    nullable: true
                    example: '2026-09-18T15:04:05.000Z'
                  permanent:
                    description: >-
                      True when the funding source is disabled and will not
                      become usable again on its own; the user should link a
                      different bank account.
                    type: boolean
                  deletedAt:
                    format: date-time
                    type: string
                    description: >-
                      When the funding source was removed by the user, or null
                      while it remains linked. Removed funding sources stay
                      retrievable by id for historical reference.
                    nullable: true
                    example: null
                  createdAt:
                    description: When the funding source was created
                    format: date-time
                    type: string
                required:
                  - id
                  - bankAccountId
                  - institutionName
                  - institution
                  - accountNumberLast4
                  - accountType
                  - status
                  - statusReason
                  - availableAt
                  - permanent
                  - deletedAt
                  - createdAt
        '401':
          description: Response for status 401
          content:
            application/problem+json:
              schema:
                type: object
                properties:
                  type:
                    default: about:blank
                    description: A URI reference that identifies the problem type
                    type: string
                    example: urn:problem-type:auth:unauthorized
                  title:
                    description: A short, human-readable summary of the problem type
                    type: string
                    example: Unauthorized
                  status:
                    description: The HTTP status code
                    type: number
                    example: 401
                  detail:
                    description: A human-readable explanation specific to this occurrence
                    type: string
                    example: Bearer token required
                  instance:
                    description: A URI reference that identifies the specific occurrence
                    type: string
                  realm:
                    description: The authentication realm
                    type: string
                    example: API
                  scope:
                    description: The required scope for this resource
                    type: string
                    example: read:users
                required:
                  - title
                  - status
                additionalProperties: false
        '404':
          description: Response for status 404
          content:
            application/problem+json:
              schema:
                type: object
                properties:
                  type:
                    default: about:blank
                    description: A URI reference that identifies the problem type
                    type: string
                  title:
                    description: A short, human-readable summary of the problem type
                    type: string
                  status:
                    description: The HTTP status code
                    type: number
                    example: 404
                  detail:
                    description: A human-readable explanation specific to this occurrence
                    type: string
                  instance:
                    description: A URI reference that identifies the specific occurrence
                    type: string
                  resourceType:
                    description: The type of resource that was not found
                    type: string
                    example: user
                  resourceId:
                    description: The identifier of the resource that was not found
                    type: string
                required:
                  - title
                  - status
                  - resourceType
                  - resourceId
                additionalProperties: false
        '500':
          description: Response for status 500
          content:
            application/problem+json:
              schema:
                additionalProperties: true
                type: object
                properties:
                  type:
                    default: about:blank
                    description: A URI reference that identifies the problem type
                    type: string
                    example: urn:problem-type:auth:unauthorized
                  title:
                    description: A short, human-readable summary of the problem type
                    type: string
                    example: Unauthorized
                  status:
                    description: The HTTP status code
                    type: number
                    example: 400
                  detail:
                    description: A human-readable explanation specific to this occurrence
                    type: string
                  instance:
                    description: A URI reference that identifies the specific occurrence
                    type: string
                    example: /errors/1234567890
                  code:
                    description: >-
                      Machine-readable cause, present when exactly one thing
                      failed. Branch on this, never on `detail`, which is
                      human-facing copy and may change. For deposit limits the
                      vocabulary matches the `reason` values the limits API
                      returns pre-flight.
                    type: string
                    example: transaction_limit
                  field:
                    description: The offending request field, present alongside `code`.
                    type: string
                    example: amountUsd
                  retryable:
                    description: >-
                      Whether retrying the same request later may succeed
                      without changing its inputs.
                    type: boolean
                    example: true
                  retryAfter:
                    description: >-
                      Seconds to wait before retrying, present alongside
                      `retryable: true`. Mirrors the `Retry-After` response
                      header and is meant for short backoffs the server chose
                      (load shedding); for a condition that clears on its own
                      schedule, `clearsAt` carries the absolute time instead.
                    type: number
                    example: 5
                  suggestedAction:
                    type: string
                    enum:
                      - auto_ramp
                      - wait_for_settlement
                  clearsAt:
                    format: date-time
                    type: string
                    description: >-
                      Earliest known time the current temporary condition may
                      clear.
                    nullable: true
                  availableAt:
                    format: date-time
                    type: string
                    description: >-
                      When a temporarily ineligible funding source may become
                      available again.
                    nullable: true
                  permanent:
                    description: >-
                      Whether the current funding-source restriction will not
                      clear automatically.
                    type: boolean
                required:
                  - title
                  - status
      security:
        - bearerAuth: []
        - integratorJwt: []
        - bearerAuth: []
          hmacAuth: []
          integratorKey: []
          timestamp: []
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT or ak_ user API key
      description: >-
        User bearer credential: either a Cognito JWT or an ak_ user API key.
        Backend integrators using HMAC must include the user API key alongside
        the three HMAC headers on user-scoped endpoints.
    integratorJwt:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Integrator JWT token (prefix: spr_) for frontend integrator
        authentication. Obtained via token exchange endpoint.
    hmacAuth:
      type: apiKey
      in: header
      name: X-Signature
      description: >-
        HMAC signature authentication for backend integrators.


        **Required Headers:**

        - X-Integrator-Key: Integrator API key (format: ik_...)

        - X-Signature: HMAC signature (format: sha256={hex})

        - X-Timestamp: Unix timestamp in milliseconds

        - Authorization: Bearer {user-api-key}


        **Signature Algorithm:** HMAC-SHA256


        **Signature Format:** {timestamp}.{METHOD}.{path}.{bodyHash}

        - timestamp: Unix timestamp in milliseconds

        - METHOD: HTTP method in UPPERCASE (GET, POST, etc.)

        - path: Request path (e.g., /v1/transactions)

        - bodyHash: SHA256 hex digest of request body (empty string if no body)


        **Timestamp Tolerance:** ±5 minutes (300 seconds)


        **Example:**

        For POST /v1/transactions with body {"amount":100} and timestamp
        1234567890000:

        Payload: 1234567890000.POST./v1/transactions.{sha256(body)}

        Signature: sha256=abc123...
    integratorKey:
      type: apiKey
      in: header
      name: X-Integrator-Key
      description: 'Integrator API key (format: ik_...) used with HMAC authentication'
    timestamp:
      type: apiKey
      in: header
      name: X-Timestamp
      description: >-
        Unix timestamp in milliseconds for request freshness. Must be within 5
        minutes of server time. The timestamp alone bounds but does not prevent
        an exact replay within that window. Use Idempotency-Key on supported
        mutations.

````