List ACH debit returns
Returns ACH debit returns scoped to the authenticated integrator.
Authorizations
HMAC signature authentication for backend integrators.
Required Headers:
- X-Integrator-Key: Integrator API key (format: int_...)
- X-Signature: HMAC signature (format: sha256={hex})
- X-Timestamp: Unix timestamp in milliseconds
- Authorization: Bearer {user-api-key}
Signature Algorithm: HMAC-SHA256
Signature Format: {timestamp}.{METHOD}.{path}.{bodyHash}
- timestamp: Unix timestamp in milliseconds
- METHOD: HTTP method in UPPERCASE (GET, POST, etc.)
- path: Request path (e.g., /v1/transactions)
- bodyHash: SHA256 hex digest of request body (empty string if no body)
Timestamp Tolerance: ±5 minutes (300 seconds)
Example: For POST /v1/transactions with body {"amount":100} and timestamp 1234567890000: Payload: 1234567890000.POST./v1/transactions.{sha256(body)} Signature: sha256=abc123...
Integrator API key (format: int_...) used with HMAC authentication
Unix timestamp in milliseconds for replay attack prevention. Must be within 5 minutes of server time.
Query Parameters
Maximum number of results to return
1 <= x <= 100Opaque cursor from the previous response's nextCursor value
Filter to one Spritz user ID
"6a749a054c3b8fc5da595d1b"
Comma-separated Spritz user IDs to include
Search by user ID, deposit ID, on-ramp ID, return ID, or return code
ACH return code
"R10"
unauthorized, administrative, other not_released, in_flight, partially_confirmed, fully_confirmed true, false none, review_required, restricted, disabled