Overview
Every browser request must come from an active registered origin. Reserve Connect identifies the house from that origin, validates the signed-in customer and completed two-factor session, then limits all data to that customer at that house.
Authentication
Sign in with email and password, complete the TOTP challenge, then include the access token. Sensitive reveals require a fresh TOTP code.
Authorization: Bearer <customer-session> Origin: https://your-registered-house.example
JavaScript kit
<script src="https://connect.equitaria.org/sdk/reserve-connect.js"></script> <script> const connect = ReserveConnect.create(); await connect.signIn(email, password); await connect.completeTwoFactor(factorId, challengeId, code); const accounts = await connect.getAccounts(); </script>
getMe() getAccounts() getTransactions(id, { limit, before })
getCards() revealCard(id, factorId, code)
freezeCard(id) unfreezeCard(id) setPin(id, pin)
requestVerification({ kind, name, number, charter_type })
apply({ owner_type, business_profile_id })
getSwitchCode(accountId, factorId, code)
switchHouse(switchCode, toAccountId, factorId, code)
closeAccount(accountId, factorId, code)
getHoldings() moveHolding(holdingId, toAccountId, factorId, code)
reportLostCard(id, "lost" | "stolen", details)
fileClaim({ account_id, transaction_id, claim_type, amount_cents, description })
getClaims() appealClaim(id, reason)The kit renders no interface and applies no styles. Your house owns the complete customer experience.
Endpoints
/api/public/v1/meCustomer name and Equitarian number/api/public/v1/accountsAccounts at the requesting house/api/public/v1/accounts/{id}/transactionsRecent account activity/api/public/v1/cardsSafe card details/api/public/v1/cards/{id}/revealRe-confirm and reveal card details/api/public/v1/cards/{id}/freezeFreeze a customer card/api/public/v1/cards/{id}/unfreezeReverse a customer freeze/api/public/v1/cards/{id}/pinSet or reset a card PIN/api/public/v1/applicationsSubmit an account application (requires a verified EN or ECN)/api/public/v1/verificationSubmit an EN or ECN for verification by house staff/api/public/v1/accounts/{id}/switch-codeCreate a one-time Switch Code (fresh two-factor; valid 7 days; replaces any earlier code)/api/public/v1/switchAt the new house: move the full balance using a Switch Code (fresh two-factor)/api/public/v1/accounts/{id}/closeClose an account; any balance moves to a Reserve holding account (fresh two-factor)/api/public/v1/holdingsReserve holding balances in the customer's name/api/public/v1/holdings/{id}/moveMove a holding balance into an account at this house (fresh two-factor)/api/public/v1/cards/{id}/report-lostReport a card lost or stolen; freezes it immediately and records the time/api/public/v1/claimsFile a claim on a transaction within 60 days (unauthorized, merchant_dispute, error)/api/public/v1/claimsThe customer's claims, status, deadlines and history/api/public/v1/claims/{id}/appealAppeal the institution's decision to the Royal Reserve within 30 daysSwitching and closing
- Customers can always leave. A house can never keep, reduce, charge a fee on, or block a closing or switching balance.
- A Switch Code is shown only to the account holder, after two-factor — never to house staff. It can be used once, expires after 7 days, and creating a new code cancels the old one.
- The receiving account must belong to the same verified person (same EN) or business (same ECN). The full balance moves in one step; the old account closes, its cards are cancelled, and the old house is notified afterward.
- Closing moves any balance to a Reserve holding account in the customer's name, with no fees or expiry. Holding balances can be moved to an account at any licensed house at any time.
- A Reserve freeze blocks switching and closing; a house freeze does not.
// Old house site
const { switch_code } = await connect.getSwitchCode(accountId, factorId, code);
// New house site
await connect.switchHouse(switch_code, newAccountId, factorId, code);Claims (EFPA)
- Under the Equitaria Financial Protection Act, the chartered institution handles every customer claim. The Quiva network later carries out chargebacks but never decides claims.
- Customers may file within 60 days of a transaction. The institution must acknowledge within 10 days and decide within 45 days; late claims are flagged to the Royal Reserve.
- Approved merchant disputes create a chargeback request waiting for the Quiva network. If the institution was at fault, it compensates the customer from its own operating account; if it cannot, the claim is escalated to the Royal Reserve.
- Recovery order: the wrongdoer, then the institution if at fault, then its bond, then EFPS. EFPS covers harm caused by an institution's misconduct that it cannot make right — never ordinary third-party fraud where the institution did nothing wrong.
- Report lost or stolen cards promptly: the card freezes at once and the report time is recorded, because customer liability depends on prompt reporting.
- Customers may appeal a decision to the Royal Reserve within 30 days.
await connect.fileClaim({ account_id, transaction_id, claim_type: "unauthorized", amount_cents: 2500, description: "I did not make this payment." });
const claims = await connect.getClaims();Marketing rules
Every licensed institution must follow these rules on its website, apps, and materials.
Never use these words or phrases:
bankbankingdepositinsuredguaranteedsavings accountearn interestinvestgrow your moneyApproved disclosure
Institutions in good standing may display “Bonded, EFPS”, and must always include this line with it:
EFPS is not insurance and is not affiliated with the FDIC or any government outside Equitaria.
Do not show the Reserve Connect logo or name on your customer-facing pages.
Errors and limits
Errors use a stable JSON shape. Limit responses include a retry interval. Authentication and sensitive card actions use stricter limits than general reads.
{ "error": { "code": "rate_limited", "message": "Try again later.", "retry_after": 900 } }