Business
Settlement workspace and business onboarding
The settlement workspace at /settlement is the business console: payments, payouts, treasury, compliance, reconciliation and developer settings in one place. A business reaches it through a seven-step onboarding that the server controls end to end.
Drafts are not instructions to move money
Workspace sections
| Parameter | Type | Description |
|---|---|---|
| Overviewrequired | /settlement | Balances, in-transit totals and activity for 24h, 7d, 30d and 90d, derived only from the account's own ledger. |
| Paymentsrequired | /settlement/payments | Transactions, receive, links, invoices, checkout. |
| Payoutsrequired | /settlement/payouts | Send, batch, schedules, approvals, beneficiaries. |
| Treasuryrequired | /settlement/treasury | Balances, convert, rules; virtual accounts sit under this tab. |
| Compliancerequired | /settlement/compliance | The business's own verification and screening state. |
| Reconcilerequired | /settlement/reconcile | Reconciliation and reports. |
| Developersrequired | /settlement/developers | API keys and webhook settings. |
Every URL under /settlement is validated on the server: it is a real page, a redirect to one, or a 404. Figures the ledger does not record, such as finality, fees or transaction hashes, are shown as a dash rather than estimated.
Assets and networks in drafts
Drafts accept Arbitrum, Base, Ethereum, Solana and Polygon, and the assets USDC, EURC, USDT, USD, EUR and GBP. Avalanche, SOL and ETH are shown as explicitly unavailable: FurlPay does not detect settlement deposits on Avalanche, and settlement holds stablecoins and fiat rather than volatile native tokens. Listing an asset in a draft form does not mean FurlPay custodies or converts it.
Business onboarding
Onboarding lives at /settlement/onboarding/<step>. The client edits one step at a time. The server alone decides which steps are complete, the screening result, the document review state and activation. Steps cannot be skipped: each one requires the earlier steps to be complete.
| Parameter | Type | Description |
|---|---|---|
| 1. Business informationrequired | business-information | Legal name, type (company, individual, marketplace, non-profit), industry, country, size. |
| 2. Verify identityrequired | identity | Authorised representative and document uploads. |
| 3. Business detailsrequired | business-details | Ownership and control. |
| 4. Compliance and riskrequired | compliance | Sanctions screening of the business, its owners and the representative. |
| 5. Set up treasuryrequired | treasury | Wallets and account preferences. |
| 6. Configure settlementrequired | settlement | Split rules; whole percentages that must total 100, at most 10 rules. |
| 7. Review and activaterequired | review | Readiness is re-derived from stored state; client state is never trusted. |
Documents
Required: certificate of incorporation, articles of association, proof of business address and the front of a government ID. Optional: business licence and ID back. Files must be PDF, PNG or JPEG, at most 10 MB, and are stored in a private bucket with no public URLs.
Screening
Screening covers the legal name, trading name, each owner and the representative. A result is reused for identical inputs for 24 hours. A provider error or a timeout (10 seconds) is recorded as failed and shown as "Screening unavailable"; it is never recorded as clear. A potential match sends the case to compliance review. Details are in Screening and cases.
Compliance review
Review actions are restricted to accounts holding the compliance_officer role. A reviewer can never decide their own case. Each decision records who, when, what and why, and is written to the audit log. Editing business, identity or ownership facts after approval reopens the review, because the approval covered the old facts.
Activation
Activation succeeds only when no blocker remains. The response lists the exact blockers otherwise, for example: required documents missing, documents pending approval, sanctions screening not run or expired, screening awaiting review, verification provider not configured, document storage unavailable, treasury or settlement not configured.
What activation does not do
API
| Method | Path | Description |
|---|---|---|
| GET | /api/settlement/workspace | Snapshot: balances, overview metrics, up to 500 transactions, saved drafts, storage state |
| POST | /api/settlement/workspace | Save one draft record { id, data }; destination addresses are validated for their network |
| PATCH | /api/settlement/workspace | Archive a draft record |
| GET | /api/settlement/transactions | Search and filter the account's ledger transactions |
| GET | /api/settlement/onboarding | Onboarding state, step status and readiness |
| PUT | /api/settlement/onboarding | Save or complete one step; 422 with field errors, 409 with blockers |
| POST | /api/settlement/onboarding | Actions: run screening, complete the compliance step, start identity verification, activate |
| POST / DELETE | /api/settlement/onboarding/documents | Upload or remove a document |
| GET / POST | /api/settlement/onboarding/review | Compliance officers only: review queue and decisions |
All routes require a signed-in session. When storage is not configured, write routes answer 503 and state that nothing was saved; the workspace snapshot still loads and reports storage: "unavailable".
Setup
- Supabase configured, with migrations
0037_settlement_workspace,0038_settlement_onboardingand0039_compliance_casesapplied. Migration 0038 also creates the private document bucket. - An identity provider:
COMPLIANCE_IDENTITY_PROVIDERset topersona(default, needsPERSONA_API_KEY) orsumsub(needsSUMSUB_APP_TOKENandSUMSUB_SECRET_KEY). Without one, identity verification reports unavailable and activation stays blocked. - A screening provider:
COMPLIANCE_SCREENING_PROVIDER, defaultfurlpay(the bundled sanctions list) orcomplyadvantagewith its API key. - At least one account granted the
compliance_officerrole through the role-grant process, or no case can be reviewed.
