Skip to content

Conventions

DirectionAddressBody
Trading system → CDD CorePOST {core_base_url}/functions/v1/trading-link/{route}The envelope itself
CDD Core → trading systemPOST {trading_base_url}/rest/v1/rpc/{function}{"p": { …envelope… }}
HeaderValue
x-link-keyThe secret for that direction, at least 40 random characters
apikeyCDD Core → trading system only: the gateway’s publishable key, which grants nothing by itself
content-typeapplication/json

A missing or wrong key gets HTTP 401 {"error":"LINK_KEY"}. The call is logged and not processed.

Every message, in both directions:

{
"message_id": "b1f0c9e2-6f0a-4c43-9d1e-2b7f6f1d8a10",
"message_type": "RESTRICTION_COMMAND",
"sent_at": "2026-09-20T08:15:30.123Z",
"institution": "INST",
"body": { }
}
FieldRule
message_idUUID made by the sender, unique per message
message_typeOne of the types on the following pages
sent_atUTC, ISO 8601, milliseconds
institutionThe institution code agreed for the link
bodyThe message itself
  • Times are UTC in every message. Screens convert to Bangkok time. A business day is the Bangkok date.
  • Money is text: "125400.50", "0.04500000", never a JSON number.
  • Customers are identified by core_customer_id (UUID, never changes) and link_ref (a reference the platform issues when the customer is bound to the link). The identity number crosses the link once, at binding, and never again.
HTTP 200
{ "message_id": "b1f0c9e2-…", "received_at": "2026-09-20T08:15:30.456Z", "status": "RECEIVED" }

When the same business reference arrives again under a new message_id, the receipt adds a repeat field, for example "repeat": "COMMAND_REF_SEEN" or "repeat": "EVENT_REF_SEEN".

HTTP 422
{ "message_id": "…", "status": "REFUSED", "error": "BAD_SHAPE", "detail": "occurred_at is required" }
CodeHTTPMeaning
LINK_KEY401The key is missing or not the active key
BAD_SHAPE422A required field is missing or has the wrong type; detail names it
UNKNOWN_CUSTOMER422core_customer_id is not a customer of this institution
UNKNOWN_CODE422A leg, action, event type or limit code that is not on the agreed list
ROUTE404Not a route of this endpoint
METHOD405Anything other than POST
CORE_UNAVAILABLE · CORE_ERROR503 · 500CDD Core failed; retry
  • No receipt within 10 seconds counts as no receipt. Retry after 5 s, 30 s, 2 min and 10 min, then every 30 min. After 24 hours, raise an incident.
  • A 4xx is a defect to fix and is never retried. A 5xx is retried; repeat-safety makes that harmless.
  • Where order matters, the receiver orders by the business time inside the body (issued_at, state_version), not by arrival.