Sail

Reveal Full Account Number

POST/users/{user_id}/accounts/{account_id}/numbers/reveal

Returns the unmasked account and routing numbers. Every reveal is audit-logged (partner, key prefix, user, timestamp) and rate-limited per user. Treat the response as a one-time read for immediate use (e.g. initiating a deposit). Do not persist it unencrypted. Nacha’s data security rule requires stored DFI account numbers to be rendered unreadable.

Path Parameters

user_idstringrequired

The Sail user id.

account_idstringrequired

The Sail account id.

Response

Full deposit numbers (audit-logged).

account_idstring

The Sail account id.

account_numberstring

The full, unmasked account number.

routing_numberstring

The routing number for this account.

reveal_idstring

Audit-log reference for this reveal.

revealed_atstring<date-time>

When this reveal occurred.

user_token_required / invalid_user_token.

insufficient_key_scope, insufficient_token_scope (token minted without numbers:reveal), or product_not_enabled.

rate_limited: reveal velocity exceeded for this user.

Standard error envelope covering 400, 401, 403, 404, 429, and 500.

errorobject

The error detail.

Show error properties
codestring

Machine-readable code, e.g. not_found, token_scope_mismatch, product_not_enabled, insufficient_key_scope, insufficient_token_scope, user_token_required, user_token_expired, invalid_user_token, invalid_key_configuration, connection_not_reconnectable, rate_limited.

messagestring

Human-readable error message. May change, so match on error.code instead.

paramstring

The request field that caused the error, when applicable. Null otherwise.

Request
curl -X POST "https://live.savewithsail.com/api/v1/users/<user_id>/accounts/<account_id>/numbers/reveal" \
  -H "Authorization: Bearer <token>" \
  -H "x-sail-user-token: <x-sail-user-token>"
Response
{
  "account_id": "string",
  "account_number": "string",
  "routing_number": "string",
  "reveal_id": "rvl_5d81xk",
  "revealed_at": "1970-01-01T00:00:00.000Z"
}