---
title: "Store banking details for an external party"
method: POST
path: "/external-party-accounts"
tags: ["External Party Accounts"]
---

# Store banking details for an external party

`POST /external-party-accounts`

Store banking details for an external party

## Headers

- `Idempotency-Key` string, required
- `X-Agent-ID` string, nullable
- `X-Instance-ID` string, nullable

## Request body

- object
  - `data` object, required
    - `attributes` object, required
      - `externalPartyId` string, required — External party ID (epty_*).
      - `accountDetails` object, required — Type-specific account details. Today the only type is a US bank account (`us_bank_account`).
        - `type` 'us_bank_account', required — Account details type.
        - `accountType` 'checking' | 'savings', required — Bank account type.
        - `accountNumber` string, required — ACH account number, raw or as an Evervault ciphertext.
        - `routingNumber` string, required — 9-digit ABA routing number, raw or as an Evervault ciphertext.
      - `institutionName` string, nullable — Institution display name.

## Response `201`

Successful Response

- object
  - `data` object, required
    - `id` string, required
    - `type` 'external_party_account', required — Resource type.
    - `attributes` object, required
      - `accountDetails` object, required — Type-specific account details. Today the only type is a US bank account (`us_bank_account`).
        - `type` 'us_bank_account', required — Account details type.
        - `accountType` 'checking' | 'savings', required — Bank account type.
        - `last4` string, required — Last four account number digits.
        - `mask` string, required — Masked account number.
      - `validationState` 'pending' | 'validated' | 'failed', required — Account validation state. `pending` when the validation provider could not answer at creation; it resolves asynchronously to `validated` or `failed`.
      - `validationMethod` 'plaid_database_auth', required — Validation method for the account details type. `plaid_database_auth` is the `us_bank_account` validation method.
      - `createdAt` string, required — ISO creation timestamp.
      - `updatedAt` string, required — ISO update timestamp.
    - `relationships` object, required
      - `externalParty` object, required — External party that owns the account.
        - `data` object, required — Related resource identifier.
          - `type` 'external_party', required
          - `id` string, required

## Other responses

- `400` — Validation Error
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found. Returned when the resource does not exist, or when it exists but is not accessible to your account. The two cases are intentionally indistinguishable, so that resource IDs cannot be enumerated by probing.
- `409` — Conflict
- `422` — Validation Error
- `428` — Precondition Required
- `429` — Too Many Requests
- `500` — Internal Server Error
- `501` — Not Implemented
- `502` — Bad Gateway
- `503` — Service Unavailable

---

[API](https://skmtc.net/natural/apis/natural-api.md) · [All operations](https://skmtc.net/natural/apis/natural-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/natural/natural-api/revisions/c2c65e052711/schema)
