Get API credentials
API access setup
Your first step to working with Cross River APIs is to request API credentials. With these credentials you can request and receive an access token to use for sending APIs in our sandbox environment.
Sandbox is a non-production environment and behaves differently from production systems in terms of data handling, stability, and security controls.
Sandbox is intended to simulate behavior, not replicate production data scenarios using real data.
Always use test data in sandbox environments.
⚠️ Important: Do not use real customer data
Do not use real customer data in sandbox under any circumstances.
This includes:
- Personally Identifiable Information (PII)
- Names, email addresses, phone numbers
- Account numbers or financial identifiers
- Any data that belongs to a real individual or business
- Any data that could be traced back to a real customer
Why this matters
Sandbox is designed for testing, not data protection or storage of sensitive information. Using real data in Sandbox may result in:
- Data exposure in logs or debugging tools
- Unintended visibility to support or engineering teams
- Mixing of test and production data patterns
- Compliance and regulatory risk for your organization
IMPORTANT Your IP address, which must be public and static, has to be on our allowlist. Your internal IT department should be able to provide you with this IP. Learn more about static IPs.
Sandbox access
To get API credentials, submit a request. You will complete a form that includes providing a static IP.
Once your static IP is added to our allowlist, we send you 2 encrypted emails with your credentials:
- One email contains your client_id, partner_id and other information you'll need depending on what you have requested.
- The second email, which is encrypted, contains your client_secret and webhook_secret. You'll need these for authentication and for working in the sandbox.