curl --request GET \
--url https://api.next.orenda.finance/v1/customers/{customerId}/accounts/{accountId}/payments/requests \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.next.orenda.finance/v1/customers/{customerId}/accounts/{accountId}/payments/requests"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.next.orenda.finance/v1/customers/{customerId}/accounts/{accountId}/payments/requests', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.next.orenda.finance/v1/customers/{customerId}/accounts/{accountId}/payments/requests",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.next.orenda.finance/v1/customers/{customerId}/accounts/{accountId}/payments/requests"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.next.orenda.finance/v1/customers/{customerId}/accounts/{accountId}/payments/requests")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.next.orenda.finance/v1/customers/{customerId}/accounts/{accountId}/payments/requests")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"success": true,
"data": [
{
"id": "3f1c9b7e-1f4a-4d2b-9c11-2f8a6b0e4d31",
"accountId": "7c1d8e4a-9b2f-4a3c-8d5e-6f7a8b9c0d1e",
"customerId": "3f9a2b7e-6c1d-4e8f-a0b1-c2d3e4f5a6b7",
"status": "PENDING",
"type": "CUSTOMER",
"amount": 150,
"currency": "GBP",
"paymentRef": "Invoice 1024",
"isDirectDebit": false,
"createdDateTime": "2026-06-18T10:32:00Z",
"payee": {
"name": "Ada Lovelace",
"accountNumber": "87654321",
"sortCode": "040506",
"beneficiaryId": "8c2f1b3e-4d5a-4f6b-9c7d-0e1f2a3b4c5d"
},
"statusHistory": [
{
"dateTime": "2026-06-18T10:32:00Z",
"status": "PENDING"
}
]
},
{
"id": "d4f5e6a7-b8c9-4d0e-9f1a-2b3c4d5e6f7a",
"accountId": "7c1d8e4a-9b2f-4a3c-8d5e-6f7a8b9c0d1e",
"customerId": "3f9a2b7e-6c1d-4e8f-a0b1-c2d3e4f5a6b7",
"status": "INITIATED",
"type": "CUSTOMER",
"amount": 42.5,
"currency": "EUR",
"paymentRef": "SEPA DD collection",
"isDirectDebit": true,
"createdDateTime": "2026-06-17T09:00:00Z",
"statusHistory": [
{
"dateTime": "2026-06-17T09:00:00Z",
"status": "INITIATED"
}
]
}
],
"total": 4,
"page": 1,
"limit": 10
}{
"success": false,
"code": "VALIDATION_ERROR",
"message": "Authorization Error: Missing programId in query string"
}{
"message": "Unauthorized"
}{
"message": "Forbidden"
}{
"success": false,
"code": "INTERNAL_SERVER_ERROR",
"message": "Internal Server Error"
}List payment requests
Returns the account’s payment requests: the in-flight record of each payment between initiation and settlement. Use it for a pending-payments screen, especially payments held for compliance review.
status | Meaning |
|---|---|
PENDING | Initiated, not yet processed. |
PENDING_TM | Held for transaction-monitoring (compliance) review. |
INITIATED | Direct debit collection announced, not yet funded. |
PENDING_CANCELLATION | Customer asked to cancel; awaiting the bank’s refusal. |
COMPLETED | Cleared. It will appear in transactions. |
FAILED | Rejected or failed. |
Without a status filter you get PENDING, PENDING_TM, INITIATED, and PENDING_CANCELLATION, so in-flight and upcoming direct debits are included. Pass status=COMPLETED,FAILED for history. Filters accept comma-separated values.
Every row carries isDirectDebit (boolean). Use it to tell SEPA direct debit collections from other requests and to decide whether Cancel direct debit collection applies. isDirectDebit=true returns only SEPA DD COLLECT rows; isDirectDebit=false excludes them, including rows that never stamped the flag.
statusHistory is always an array (it used to arrive as an object keyed "0", "1", and so on). On an international payout payee.currency is the target currency the beneficiary is credited in, distinct from the top-level source currency. subType, providerRequestId, batchItemId, and childAccountId are returned and supported as filters.
Breaking change: this endpoint returns a defined field set. It previously returned the stored record as-is, so any key the search index held could appear on a row. It now returns exactly the PaymentRequest fields documented here. Fields that no longer appear (this list is exhaustive against the stored record):
| Removed | What it held |
|---|---|
cardAuth and its cardAuth.* keys | Masked PAN, expiry, auth code, merchant detail |
tmHistory, transactionMonitoring | Transaction-monitoring decisions and reasons |
programId, entity, custodianId | Internal routing and ownership keys |
endToEndReference, originalEndToEndReference | Provider-side reconciliation ids |
providerStatus, unloadId, debtorViban | Provider-side state, unload id, virtual IBAN debited |
batchId, purpose | Parent batch id and internal purpose code |
priorStatusBeforeCancellation, cancellationRequestedAt, cancellationReasonCode, cancellationSource | SEPA direct-debit cancellation context |
updatedAt | Last write time of the stored record |
auditId, cryptoQuoteId, idempotencyRequestHash | Internal record-keeping ids |
sandbox, isScheduled, heldInternally, heldForCustomerId | Internal flags |
refundFromCardProvider, refundPreCalculated | Internal refund routing flags |
cardAuth is why: CARD is in the default type filter, and an app that server-renders this response puts whatever it contains into page source. If you render in-flight direct debits, note that PENDING_CANCELLATION rows are in your default result set and the reason and timestamp behind a cancellation are no longer on them.
curl --request GET \
--url https://api.next.orenda.finance/v1/customers/{customerId}/accounts/{accountId}/payments/requests \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.next.orenda.finance/v1/customers/{customerId}/accounts/{accountId}/payments/requests"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.next.orenda.finance/v1/customers/{customerId}/accounts/{accountId}/payments/requests', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.next.orenda.finance/v1/customers/{customerId}/accounts/{accountId}/payments/requests",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.next.orenda.finance/v1/customers/{customerId}/accounts/{accountId}/payments/requests"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.next.orenda.finance/v1/customers/{customerId}/accounts/{accountId}/payments/requests")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.next.orenda.finance/v1/customers/{customerId}/accounts/{accountId}/payments/requests")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"success": true,
"data": [
{
"id": "3f1c9b7e-1f4a-4d2b-9c11-2f8a6b0e4d31",
"accountId": "7c1d8e4a-9b2f-4a3c-8d5e-6f7a8b9c0d1e",
"customerId": "3f9a2b7e-6c1d-4e8f-a0b1-c2d3e4f5a6b7",
"status": "PENDING",
"type": "CUSTOMER",
"amount": 150,
"currency": "GBP",
"paymentRef": "Invoice 1024",
"isDirectDebit": false,
"createdDateTime": "2026-06-18T10:32:00Z",
"payee": {
"name": "Ada Lovelace",
"accountNumber": "87654321",
"sortCode": "040506",
"beneficiaryId": "8c2f1b3e-4d5a-4f6b-9c7d-0e1f2a3b4c5d"
},
"statusHistory": [
{
"dateTime": "2026-06-18T10:32:00Z",
"status": "PENDING"
}
]
},
{
"id": "d4f5e6a7-b8c9-4d0e-9f1a-2b3c4d5e6f7a",
"accountId": "7c1d8e4a-9b2f-4a3c-8d5e-6f7a8b9c0d1e",
"customerId": "3f9a2b7e-6c1d-4e8f-a0b1-c2d3e4f5a6b7",
"status": "INITIATED",
"type": "CUSTOMER",
"amount": 42.5,
"currency": "EUR",
"paymentRef": "SEPA DD collection",
"isDirectDebit": true,
"createdDateTime": "2026-06-17T09:00:00Z",
"statusHistory": [
{
"dateTime": "2026-06-17T09:00:00Z",
"status": "INITIATED"
}
]
}
],
"total": 4,
"page": 1,
"limit": 10
}{
"success": false,
"code": "VALIDATION_ERROR",
"message": "Authorization Error: Missing programId in query string"
}{
"message": "Unauthorized"
}{
"message": "Forbidden"
}{
"success": false,
"code": "INTERNAL_SERVER_ERROR",
"message": "Internal Server Error"
}Authorizations
The user's access_token from authentication. The program and environment come from the token.
Path Parameters
Customer identifier.
Account identifier. The account determines which optional features and limits apply.
Query Parameters
PENDING, PENDING_TM, INITIATED, PENDING_CANCELLATION, COMPLETED, FAILED (comma-separated). Default: PENDING,PENDING_TM,INITIATED,PENDING_CANCELLATION.
CUSTOMER, BATCH, CARD, SETTLEMENT, FEE (comma-separated). Default: CUSTOMER,BATCH,CARD,SETTLEMENT: SETTLEMENT rows come back unless you pass an explicit type.
Filter to specific payment requests by id (comma-separated). paymentRequestId is accepted as an alias.
REFUND, COLLECT, SEND, SCHEDULED, AUTHORIZATION (comma-separated).
Filter by provider-side request id (comma-separated).
Filter by batch item id (comma-separated).
Filter by child account on prepaid master accounts (comma-separated).
Filter by transaction-monitoring state (comma-separated). A filter only: the state itself is not returned on this surface.
Filter SEPA direct debit COLLECT rows. true = only direct debits; false = exclude direct debits (also matches rows that never stamped the flag).
asc, desc