Skip to content

Covalent Documentation

Covalent is compliance infrastructure for Travel Rule transfers. Its REST API, authenticated with API keys, covers customers and their wallets, outgoing transfers and the actions on them, counterparty and asset lookups, compliance cases, regulatory reports, rules and thresholds, provider and integration settings, webhooks, and the activity feed and audit log.

These pages describe what the API does today.

Area What You Can Do
Authentication API keys in the x-api-key header, each bound to the test or live environment
Customers Create, list, deactivate, reactivate and erase; set a customer's attested Travel Rule identity
Wallets Register, list, read, relabel, remove and verify
Transfers Create outgoing transfers; list and read transfers; accept, reject and retry; exchange information requests
VASP Search Search the counterparty VASPs of your transfers and wallet discovery
Assets Read the asset catalog, and which assets your environment accepts
Cases List, open, change, assign, annotate and resolve compliance cases
Reports Read report types; list, read and download regulatory reports as PDF
Rules and Thresholds Manage compliance rules and regulatory thresholds
Providers Settings for Notabene, CodeVASP, Veriscope, Global Travel Rule and Sygna Bridge
Integrations Settings for Elliptic, TRM Labs, ComplyAdvantage and Crystal Intelligence
Webhooks Manage subscriptions, and receive signed events for transfers and cases
Activity and Audit Read the activity feed and the audit log
  1. Create a test API key in the dashboard, under Developers, API keys.
  2. Create a customer, and set its Travel Rule identity.
  3. Register the customer's wallet.
  4. Create an outgoing transfer.
  5. Follow it with GET /api/v2/transfers/:id, or with webhooks.
  6. Act on held or failed transfers.
Terminal window
curl "$COVALENT_URL/api/v2/customers" \
-H "x-api-key: $COVALENT_API_KEY"

$COVALENT_URL is your company's host; see Base URL.

  • Every answer is JSON in one envelope: { "data", "meta" } on success, { "error", "code", "details", "meta" } on failure. A downloaded report file is the one exception.
  • Every answer carries api-version: 2 and cache-control: no-store, file downloads included.
  • Lists page by cursor: send meta.cursor back as ?cursor=.
  • A failure that a retry may fix carries Retry-After; the body has no retry flag.
  • The API key decides the environment. No request chooses it.

Creating and revoking API keys, managing team members, promoting test rules to live, drafting and filing reports, cancelling a queued transfer, and managing wallet ownership proofs are done in the dashboard, not through the API.