Direction Address Body Trading system → CDD Core POST {core_base_url}/functions/v1/trading-link/{route}The envelope itself CDD Core → trading system POST {trading_base_url}/rest/v1/rpc/{function}{"p": { …envelope… }}
Header Value x-link-keyThe secret for that direction, at least 40 random characters apikeyCDD Core → trading system only: the gateway’s publishable key, which grants nothing by itself content-typeapplication/json
A missing or wrong key gets HTTP 401 {"error":"LINK_KEY"}. The call is logged and not processed.
Every message, in both directions:
"message_id" : " b1f0c9e2-6f0a-4c43-9d1e-2b7f6f1d8a10 " ,
"message_type" : " RESTRICTION_COMMAND " ,
"sent_at" : " 2026-09-20T08:15:30.123Z " ,
Field Rule message_idUUID made by the sender, unique per message message_typeOne of the types on the following pages sent_atUTC, ISO 8601, milliseconds institutionThe institution code agreed for the link bodyThe message itself
Times are UTC in every message. Screens convert to Bangkok time. A business day is the Bangkok date.
Money is text : "125400.50", "0.04500000", never a JSON number.
Customers are identified by core_customer_id (UUID, never changes) and link_ref (a reference the platform issues when the customer is bound to the link). The identity number crosses the link once, at binding, and never again.
{ "message_id" : " b1f0c9e2-… " , "received_at" : " 2026-09-20T08:15:30.456Z " , "status" : " RECEIVED " }
When the same business reference arrives again under a new message_id, the receipt adds a repeat field, for example "repeat": "COMMAND_REF_SEEN" or "repeat": "EVENT_REF_SEEN".
{ "message_id" : " … " , "status" : " REFUSED " , "error" : " BAD_SHAPE " , "detail" : " occurred_at is required " }
Code HTTP Meaning LINK_KEY401 The key is missing or not the active key BAD_SHAPE422 A required field is missing or has the wrong type; detail names it UNKNOWN_CUSTOMER422 core_customer_id is not a customer of this institutionUNKNOWN_CODE422 A leg, action, event type or limit code that is not on the agreed list ROUTE404 Not a route of this endpoint METHOD405 Anything other than POST CORE_UNAVAILABLE · CORE_ERROR503 · 500 CDD Core failed; retry
No receipt within 10 seconds counts as no receipt. Retry after 5 s, 30 s, 2 min and 10 min, then every 30 min. After 24 hours, raise an incident.
A 4xx is a defect to fix and is never retried. A 5xx is retried; repeat-safety makes that harmless.
Where order matters, the receiver orders by the business time inside the body (issued_at, state_version), not by arrival.