> ## Documentation Index
> Fetch the complete documentation index at: https://docs.slash.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create book transfer

> Initiate a *book transfer* — an instant, intra‐Slash money movement
between two accounts the caller has access to.

`from` and `to` accept any Slash account id the caller can address:
  - `sa_group_*` — a Slash account group's primary cash account
  - `sub_*`      — a virtual account inside a Slash account group

The legal entity owning `from` must equal the request's `x-legal-entity`
header (the source-scope guard for user-scoped API keys), and the caller
must be a member of both `from` and `to`'s legal entities. Cross-legal-
entity transfers between entities you own are supported; sending to a
third party is not (see closed-loop-payment, coming soon).

Payment is settled instantly on Slash's ledger — no banking-network rail
is touched. For ACH/wire/RTP, use the rail-specific endpoint.




## OpenAPI

````yaml post /transfers/book-transfer
openapi: 3.1.0
info:
  title: Slash Public API
  description: API description
  version: 0.0.1
  contact: {}
servers:
  - url: https://api.slash.com
    description: production
security:
  - api_key: []
  - partner_api_key: []
  - bearer: []
  - developer_application: []
paths:
  /transfers/book-transfer:
    post:
      description: |
        Initiate a *book transfer* — an instant, intra‐Slash money movement
        between two accounts the caller has access to.

        `from` and `to` accept any Slash account id the caller can address:
          - `sa_group_*` — a Slash account group's primary cash account
          - `sub_*`      — a virtual account inside a Slash account group

        The legal entity owning `from` must equal the request's `x-legal-entity`
        header (the source-scope guard for user-scoped API keys), and the caller
        must be a member of both `from` and `to`'s legal entities. Cross-legal-
        entity transfers between entities you own are supported; sending to a
        third party is not (see closed-loop-payment, coming soon).

        Payment is settled instantly on Slash's ledger — no banking-network rail
        is touched. For ACH/wire/RTP, use the rail-specific endpoint.
      parameters:
        - name: X-Idempotency-Key
          in: header
          required: true
          schema:
            type: string
          description: Unique key to ensure idempotency of the transfer.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                from:
                  type: string
                  description: The Slash account id to debit.
                to:
                  type: string
                  description: The Slash account id to credit.
                amountCents:
                  type: number
                  description: The amount of money to send in cents.
                memo:
                  type: string
                  description: >-
                    Optional memo/description for the transfer to help
                    differentiate transactions.
                  maxLength: 255
              required:
                - from
                - to
                - amountCents
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  transferId:
                    type: string
                    description: The ID of the transfer that was created.
                required:
                  - transferId
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: |
            The provided `X-Idempotency-Key` was already used for a different
            request body. Idempotency keys must be unique per request body —
            replaying a previous key with mismatched parameters is rejected.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
                x-entrypoint:
                  origin: ./src/publicApi
                  sourcePath: src/publicApi/paths/transfers/book-transfer/route.yaml
                  title: Error
                  virtualPath: components/Error
                  globalImport: true
        '429':
          description: TooManyRequests
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Internal Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - api_key: []
        - bearer: []
components:
  schemas:
    Error:
      type: object
      properties:
        message:
          type: string
        name:
          type: string
        identifier:
          type: string
        rawStatus:
          type: number
        meta:
          type: object
          additionalProperties: true
      required:
        - message
        - name
        - identifier
        - rawStatus
      x-entrypoint:
        origin: ./src/publicApi
        sourcePath: ./src/publicApi/main.yaml
        title: Error
        virtualPath: components/Error
      title: Error
  securitySchemes:
    api_key:
      type: apiKey
      description: |
        API key authentication for public API requests.

        Keys come in two flavors:

        - *Legal-entity-scoped keys* are pinned to a single legal entity.
          Minted via the dashboard under a specific entity; every request
          acts on that entity.
        - *User-scoped keys* are pinned to a user and span every legal
          entity that user has access to. Every request made with a
          user-scoped key (except `GET /legal-entity`, which lists the
          legal entities the user can access) must include an
          `x-legal-entity` header naming the legal entity the request is
          operating on. Requests without the header are rejected with
          `400`. The authenticated user must have an active permission
          role on the supplied legal entity, otherwise the request is
          rejected with `403`.
      name: X-API-Key
      in: header
    partner_api_key:
      type: apiKey
      description: |
        Partner-program API key authentication.

        Keys are minted in the partner dashboard (Developers → API Keys),
        are scoped to a single partner program, and are prefixed with
        `sk_partner_`. Partner keys are only accepted by routes that
        declare this scheme; they are rejected by `api_key` routes and
        vice versa.
      name: X-API-Key
      in: header
    bearer:
      type: http
      scheme: bearer
    developer_application:
      type: http
      scheme: basic

````