Skip to content
This repository was archived by the owner on Sep 13, 2026. It is now read-only.
api-evangelistPublic archive

About

Cross River — independent third-party profile of a public API surface, by API Evangelist. Cross River is a regulated bank (FDIC member, Fort Lee, NJ) that delivers embedded finance and Banking-as-a-Service (BaaS) through its Cross River Operating System (COS) - a collection of REST APIs for deposit accounts, ACH, wires, instant payments (RTP, FedNo

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

Cross River (cross-river)

About this repository

This is not our API. This repository is an independent, third-party profile of a company's publicly available API surface, maintained by API Evangelist. API Evangelist does not operate, host, resell, or support this company's APIs, and is not affiliated with or endorsed by the company unless stated on the profile.

Where the information came from. Everything here is assembled from material a member of the public can reach with a browser and no credentials — the company's own website, developer portal and documentation, the specifications it publishes for public use (OpenAPI, AsyncAPI, JSON Schema, apis.json, llms.txt and similar), its public repositories, and its public status, pricing and changelog pages. Nothing here is obtained by breaching a system, defeating an access control, or using credentials of any kind.

The rating is an independent assessment. The Kin Score and Agent Readiness rating are independently calculated scores of a company's public API artifacts, produced by API Evangelist against a published rubric. They are not certifications, endorsements, security assessments, or audits, and they score published artifacts — not the quality, safety, or security of the software.

Corrections, re-scores, and removal are free. No partnership, contract, or purchase is required, and you do not need to justify the request.

  • Something wrong? Open an issue on this repository, or email info@apievangelist.com.
  • Published something new? Ask for a re-score and we will re-run the rating.
  • Want the listing taken down? Say so and we will honor it. The profile is reduced to your company name, a factual description, and a link to your own site, and the company is recorded as unrated — never scored zero for having asked.

Response times. Acknowledgement within one business day; removal or restriction within two business days; corrections and re-scores within five business days.

Not from the company, and here with a question? You are welcome here — we would rather be the front line and point you the right way than have a good report go nowhere. What this repository can answer is narrow, though, so it is worth knowing who you are actually looking for:

  • A question about how the API works, an account, billing, or a bug in the service — that is the company's own support, not us. We profile this API; we do not operate it and cannot see your account.
  • A bug in an open-source project we only catalog — file it on that project's own repository. This has happened with a real and correct bug report that reached us instead of the people who could fix it, which helped nobody.
  • Anything about this listing itself — the description, the tags, the rating, a missing or wrong artifact — is ours. Open an issue here.
  • Not sure, or something general about API Evangelist or APIs.io — open an issue on the APIs.io Inbox and we will route it.

This repository contains no software, and we will never ask you to download anything. There is no build, release, installer, or binary here — only text and machine-readable API descriptions, so there is nothing here that can be "corrupt" or need "repairing". Any issue, comment, or email claiming otherwise and offering a download link is not from us and is hostile. Do not follow the link; it is a lure. Report it to GitHub and, if you like, tell us at info@apievangelist.com so we can take it down.

On a security or compliance team? Email info@apievangelist.com with security in the subject line and you will get a person, not a form. We will tell you exactly which public URLs this profile was built from so your team can see the same surface we did, and we will take the listing down on request while you work through it.

Full detail: Where this data comes from

Cross River is a regulated bank (FDIC member, Fort Lee, NJ) that delivers embedded finance and Banking-as-a-Service (BaaS) through the Cross River Operating System (COS) - a collection of RESTful APIs for deposit accounts, ACH, wires, instant payments (RTP, FedNow, CRNow), card issuing and processing, lending, and customer management (KYC / onboarding).

Access model (read first)

Cross River is a chartered, regulated bank, and COS is partner/enterprise-gated - there is no open, self-service signup:

  • Programs are onboarded through Cross River sales and a relationship manager (start at crossriver.com/contact).
  • During onboarding you are provisioned OAuth 2.0 client credentials (client_id / client_secret) for the sandbox (https://sandbox.crbcos.com), and later for production at go-live.
  • The production base URL is not published in the open documentation - it is issued as part of your program.
  • The public documentation at docs.crossriver.com is openly readable (paths, methods, concepts, per-module base URLs), but the live sandbox and the full OpenAPI / Postman collection are shared only with onboarded partners.

Because of this, the OpenAPI in this repo has confirmed endpoint paths and methods (from the public docs) but modeled request/response body schemas - clearly flagged inline. Verify field-level schemas against the partner-provided collection.

APIs.json: https://raw.githubusercontent.com/api-evangelist/cross-river/refs/heads/main/apis.yml

Authentication

OAuth 2.0 client credentials grant. POST client_id, client_secret, and grant_type=client_credentials (optionally audience and scope) to the COS identity provider:

  • Core modules (sandbox): https://idptest.crbcos.com/connect/token
  • Lending (sandbox): https://oauthtest.crbnj.net/connect/token

The response is a signed JWT that must be sent as Authorization: Bearer <token> on every request.

Tags

  • Embedded Finance
  • Banking as a Service
  • BaaS
  • Payments
  • ACH
  • Wire
  • Push-to-Card
  • Lending
  • Accounts
  • Cards
  • Fintech
  • RTP
  • FedNow

Timestamps

  • Created: 2026-07-12
  • Modified: 2026-07-12

APIs

Cross River Accounts API

Open and manage COS deposit accounts (DDA) and subledgers - create accounts from a product, apply and remove restrictions, retrieve statements and tax documents, and manage time deposits (CDs). Part of the COS Core module.

Tags

  • Accounts
  • Deposits
  • DDA

Properties

Cross River ACH Payments API

Originate and receive ACH payments over the Federal Reserve ACH network - single payments, client batches, same-day ACH, reversals, and returns, with utilization monitoring. Part of the COS Payments module.

Tags

  • ACH
  • Payments
  • Same Day ACH

Properties

Cross River Wires API

Send domestic wire transfer payments, cancel wires, and handle drawdown requests and responses. Part of the COS Payments module.

Tags

  • Wires
  • Fedwire
  • Payments

Properties

Cross River Instant Payments API

Send and receive funds instantly 24/7 across CRNow, RTP (The Clearing House), and FedNow - initiate credit transfers, requests for payment, returns, and query supported financial institutions via the directory. Part of the COS Payments module.

Tags

  • RTP
  • FedNow
  • Instant Payments

Properties

Cross River Cards API

Issue and manage debit cards - create cards, activate, suspend and unsuspend, close, replace lost/stolen/damaged cards, set the PIN, and manage spend controls. Part of the COS Card Management module.

Tags

  • Cards
  • Card Issuing
  • Debit

Properties

Cross River Lending API

Originate and service loans - create and update loan applications, attach documents, request funding payment rails, retrieve loan details, and cancel loans. Uses a separate lending host and OAuth server from the core COS modules.

Tags

  • Lending
  • Loans
  • Loan Origination

Properties

Cross River Customer Management API

Create and manage the customer records (KYC / onboarding) required before opening accounts or issuing cards - personal and business customers, beneficial owners, identifications, addresses, phones, email, due diligence, and profile updates. Part of the COS Core module.

Tags

  • KYC
  • Onboarding
  • Customer Management

Properties

Common Properties

WebSocket review

Does Cross River expose a documented public WebSocket API? No. COS is request/response REST over HTTPS; asynchronous notifications are delivered by COS Webhooks (HTTP callbacks), not a wss:// stream. See review.yml. No AsyncAPI document was authored.

Maintainers

FN: Kin Lane Email: kin@apievangelist.com

About

Cross River — independent third-party profile of a public API surface, by API Evangelist. Cross River is a regulated bank (FDIC member, Fort Lee, NJ) that delivers embedded finance and Banking-as-a-Service (BaaS) through its Cross River Operating System (COS) - a collection of REST APIs for deposit accounts, ACH, wires, instant payments (RTP, FedNo

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors