Skip to content

API Overview

You can test the API endpoints in this document on our Swagger API page.

To begin using the Compliance AML API, you will need a valid API Key.
If you already have a Compliance AML platform account, you can view and manage your API Key directly within the platform.
If you do not have an account, please contact bd@certik.com to request access.
Once issued, your API Key must be kept secure and never shared in public channels or with unauthorized parties.

https://api.compliance.certik.com/v4

To authenticate a request, include the following two headers with valid credentials:

Header FieldDescriptionExample Value
X-API-KeyUnique identifier for the customer’s API accesshubbuxihpvznyrdfpsosmkghgegvdavn
X-API-SecretSecret key paired with the API Key for secure authenticationTTYAVYAZJYABBTLDHHPEBVDPRFRRCDMY
  • Missing, invalid, or expired X-API-Key or X-API-Secret will result in a 401 Unauthorized error (see Errors for details).
  • Credentials that have been revoked by CertiK (e.g., due to non-compliance with terms of service) will also trigger a 401 Unauthorized error.

All API endpoints follow this top-level response structure. Only the data field varies by endpoint:

Top-Level FieldTypeDescription
codeNumberStatus code: - 200: Success - 400: Bad Request - 401: Unauthorized - 404: Not Found - 429: Too Many Requests - 500: Internal Server Error
messageStringHuman-readable outcome (e.g., “success”, “invalid chain”)
dataNull/Object/ArrayBusiness-specific response content (only returned on success; structure varies by endpoint)
{
"code": 200,
"message": "success",
"data": {
// Endpoint-specific content
}
}
{
"code": 400,
"message": "invalid chain",
"data": null
}