> ## Documentation Index
> Fetch the complete documentation index at: https://docs.slash.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a destination

> Save bank instructions on a contact. Use the returned destination id in the matching per-rail transfer create endpoint.



## OpenAPI

````yaml /openapi-v2.json post /v2/destinations
openapi: 3.1.0
info:
  title: Slash Public API V2
  description: >-
    Send money for a Slash legal entity. Every request uses an API key. Transfer
    creation returns a Transfer that links its resulting transactions.
  version: 0.0.1
servers:
  - url: https://api.slash.com
    description: production
security:
  - api_key: []
paths:
  /v2/destinations:
    parameters:
      - name: x-legal-entity
        in: header
        required: true
        description: >-
          The legal entity to act on. Required on every request; a user API key
          can act on any legal entity its user has access to.
        schema:
          type: string
          pattern: ^le_[a-zA-Z0-9]+$
    post:
      summary: Create a destination
      description: >-
        Save bank instructions on a contact. Use the returned destination id in
        the matching per-rail transfer create endpoint.
      parameters:
        - name: X-Idempotency-Key
          in: header
          required: true
          description: >-
            Unique caller-generated key for one create request. Once an
            authenticated, schema-valid request reaches the operation, the key
            is permanently consumed for that operation and legal entity whether
            the operation succeeds or fails. Reusing it in that scope returns
            `409` and never replays a response, unlike API v1, which replays the
            original response for a matching key.
          schema:
            type: string
            minLength: 1
            maxLength: 255
          example: invoice-1042-attempt-1
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/destination-create'
      responses:
        '200':
          description: The created destination.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/destination'
        '400':
          $ref: >-
            #/components/responses/PublicApiV2Error400InvalidRequestInvalidRequestShapeDestinationsCreate
        '401':
          $ref: '#/components/responses/PublicApiV2Error401Unauthorized'
        '403':
          $ref: >-
            #/components/responses/PublicApiV2Error403ForbiddenForbiddenLegalEntityUserApiKeyRequired
        '404':
          $ref: '#/components/responses/PublicApiV2Error404NotFoundNotFoundNotEnabled'
        '409':
          $ref: >-
            #/components/responses/PublicApiV2Error409ConflictIdempotencyKeyReused
        '429':
          $ref: '#/components/responses/PublicApiV2RateLimited'
        '500':
          $ref: '#/components/responses/PublicApiV2Error500Internal'
components:
  schemas:
    destination-create:
      title: DestinationCreate
      description: Bank instructions to save on a contact.
      oneOf:
        - title: US bank account
          description: >-
            Save US routing and account details for ACH, wire, or realtime
            payments.
          type: object
          properties:
            contactId:
              type: string
              description: Contact id with the `le_c_` prefix.
            type:
              type: string
              enum:
                - bank_account
            name:
              type: string
              minLength: 1
              maxLength: 255
            accountNumber:
              type: string
              minLength: 1
              maxLength: 34
            routingNumber:
              type: string
              pattern: ^[0-9]{9}$
            accountType:
              type: string
              enum:
                - checking
                - savings
            beneficiary:
              type: object
              properties:
                name:
                  type: string
                address:
                  $ref: '#/components/schemas/address'
                email:
                  type: string
                  format: email
                phone:
                  type: string
              required:
                - name
                - address
              additionalProperties: false
          required:
            - contactId
            - type
            - name
            - accountNumber
            - routingNumber
            - accountType
            - beneficiary
          additionalProperties: false
        - title: International bank account
          description: Save SWIFT and beneficiary details for international wires.
          type: object
          properties:
            contactId:
              type: string
              description: Contact id with the `le_c_` prefix.
            type:
              type: string
              enum:
                - international_wire
            name:
              type: string
              minLength: 1
              maxLength: 255
            accountNumber:
              type: string
              minLength: 1
              maxLength: 34
            swiftBic:
              type: string
              minLength: 8
              maxLength: 11
            accountType:
              type: string
              enum:
                - checking
                - savings
            beneficiary:
              type: object
              properties:
                name:
                  type: string
                address:
                  type: object
                  description: >-
                    Beneficiary address; `countryCode` is required for
                    international wires.
                  properties:
                    line1:
                      type: string
                      minLength: 1
                    line2:
                      type: string
                    city:
                      type: string
                      minLength: 1
                    state:
                      type: string
                    postalCode:
                      type: string
                    countryCode:
                      type: string
                      minLength: 2
                      maxLength: 2
                      description: ISO 3166-1 alpha-2 country code.
                  required:
                    - line1
                    - city
                    - countryCode
                  additionalProperties: false
                email:
                  type: string
                  format: email
                phone:
                  type: string
                legalId:
                  type: string
                legalType:
                  type: string
                  enum:
                    - individual
                    - business
                    - non_profit
                    - sole_proprietor
              required:
                - name
                - address
              additionalProperties: false
            bankCountryCode:
              type: string
              minLength: 2
              maxLength: 2
            localBankCode:
              type: string
            localAccountNumber:
              type: string
          required:
            - contactId
            - type
            - name
            - accountNumber
            - swiftBic
            - accountType
            - beneficiary
          additionalProperties: false
      discriminator:
        propertyName: type
    destination:
      title: Destination
      description: Saved payment instructions belonging to a contact.
      oneOf:
        - $ref: '#/components/schemas/destination-bank-account'
        - $ref: '#/components/schemas/destination-international-wire'
      discriminator:
        propertyName: type
        mapping:
          bank_account:
            $ref: '#/components/schemas/destination-bank-account'
          international_wire:
            $ref: '#/components/schemas/destination-international-wire'
    address:
      title: Address
      type: object
      properties:
        line1:
          type: string
          minLength: 1
        line2:
          type: string
        city:
          type: string
          minLength: 1
        state:
          type: string
        postalCode:
          type: string
        countryCode:
          type: string
          minLength: 2
          maxLength: 2
          description: ISO 3166-1 alpha-2 country code.
      required:
        - line1
        - city
      additionalProperties: false
    destination-bank-account:
      title: DestinationBankAccount
      description: >-
        US routing and account details usable for ACH, wire, or realtime
        payments.
      allOf:
        - $ref: '#/components/schemas/destination-base'
        - type: object
          properties:
            type:
              type: string
              enum:
                - bank_account
            bankAccount:
              type: object
              properties:
                bankName:
                  type: string
                accountType:
                  type: string
                  enum:
                    - checking
                    - savings
                accountNumberLastFour:
                  type: string
                routingNumber:
                  type: string
              required:
                - bankName
                - accountType
                - accountNumberLastFour
                - routingNumber
              additionalProperties: false
          required:
            - type
            - bankAccount
    destination-international-wire:
      title: DestinationInternationalWire
      description: SWIFT beneficiary details usable for international wire payments.
      allOf:
        - $ref: '#/components/schemas/destination-base'
        - type: object
          properties:
            type:
              type: string
              enum:
                - international_wire
            internationalWire:
              type: object
              properties:
                beneficiaryName:
                  type: string
                accountType:
                  type: string
                  enum:
                    - checking
                    - savings
                accountNumberLastFour:
                  type: string
                swiftBic:
                  type: string
                bankCountryCode:
                  type: string
                localBankCode:
                  type: string
                localAccountNumberLastFour:
                  type: string
              required:
                - beneficiaryName
                - accountType
                - accountNumberLastFour
                - swiftBic
              additionalProperties: false
          required:
            - type
            - internationalWire
    PublicApiV2ErrorInvalidRequest:
      title: PublicApiV2ErrorInvalidRequest
      description: >-
        The input is well-formed but cannot be acted on; `message` says which
        field or combination is the problem, and `details.field` names the field
        when one is at fault.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - invalid_request
            details:
              type: object
              properties:
                field:
                  type: string
                  description: Dot path of the request field at fault.
                  example: internationalWire.fxQuoteId
                id:
                  type: string
                  description: The identifier that field carried, when it is one.
                  example: fx_quote_2rj4l7hmrrrcv
              additionalProperties: false
          required:
            - code
            - details
    PublicApiV2ErrorInvalidRequestShape:
      title: PublicApiV2ErrorInvalidRequestShape
      description: >-
        The body, query, or headers failed validation, or a required header is
        missing. `details` has one entry per failing location, keyed by JSON
        pointer or header name.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - invalid_request
            details:
              type: object
              properties: {}
              additionalProperties:
                type: string
          required:
            - code
            - details
    PublicApiV2ErrorUnauthorized:
      title: PublicApiV2ErrorUnauthorized
      description: API key authentication is missing or invalid.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - unauthorized
            details:
              type: object
              properties: {}
              additionalProperties: false
          required:
            - code
            - details
    PublicApiV2ErrorForbidden:
      title: PublicApiV2ErrorForbidden
      description: >-
        The credential can see the resource but is not permitted to perform this
        action on it; the missing permission is not disclosed. When the resource
        is a field of the request, `details` names that `field` and the `id` it
        received.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - forbidden
            details:
              type: object
              properties:
                field:
                  type: string
                  description: Dot path of the request field at fault.
                  example: fromAccount
                id:
                  type: string
                  description: The identifier that field carried, when it is one.
                  example: subaccount_source123
              additionalProperties: false
          required:
            - code
            - details
    PublicApiV2ErrorForbiddenLegalEntity:
      title: PublicApiV2ErrorForbiddenLegalEntity
      description: The credential is not permitted to act for the selected legal entity.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - forbidden
            details:
              type: object
              properties: {}
              additionalProperties: false
          required:
            - code
            - details
    PublicApiV2ErrorUserApiKeyRequired:
      title: PublicApiV2ErrorUserApiKeyRequired
      description: >-
        The API key is scoped to a legal entity rather than a user. Every v2
        request needs a user API key, created under Settings → API keys in the
        Slash dashboard, together with the `x-legal-entity` header.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - user_api_key_required
            details:
              type: object
              properties: {}
              additionalProperties: false
          required:
            - code
            - details
    PublicApiV2ErrorNotFound:
      title: PublicApiV2ErrorNotFound
      description: >-
        No resource matches the identifier, it belongs to another legal entity,
        or the credential cannot view it. When the identifier is a field of the
        request, `details` names that `field` and the `id` it received.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - not_found
            details:
              type: object
              properties:
                field:
                  type: string
                  description: Dot path of the request field at fault.
                  example: destinationId
                id:
                  type: string
                  description: The identifier that field carried, when it is one.
                  example: le_contact_destination_bank123
              additionalProperties: false
          required:
            - code
            - details
    PublicApiV2ErrorNotFoundNotEnabled:
      title: PublicApiV2ErrorNotFoundNotEnabled
      description: Public API v2 is not enabled for the selected legal entity.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - not_found
            details:
              type: object
              properties: {}
              additionalProperties: false
          required:
            - code
            - details
    PublicApiV2ErrorConflictIdempotencyKeyReused:
      title: PublicApiV2ErrorConflictIdempotencyKeyReused
      description: >-
        A consumed `X-Idempotency-Key` was reused; the original response is not
        replayed.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - conflict
            details:
              type: object
              properties: {}
              additionalProperties: false
          required:
            - code
            - details
    PublicApiV2ErrorInternal:
      title: PublicApiV2ErrorInternal
      description: >-
        Slash could not complete the request. Quote `referenceId` when
        contacting Slash support.
      allOf:
        - $ref: '#/components/schemas/Error'
        - type: object
          properties:
            code:
              type: string
              enum:
                - internal
            details:
              type: object
              properties: {}
              additionalProperties: false
          required:
            - code
            - details
    destination-base:
      title: DestinationBase
      type: object
      properties:
        id:
          type: string
          description: Destination id with the `le_contact_destination_` prefix.
        contactId:
          type: string
          description: Contact that owns this destination.
        name:
          type: string
          description: Display name visible to your organization.
        status:
          type: string
          enum:
            - active
            - pending
            - disabled
            - archived
        disabledReason:
          type: string
        supportedTransferTypes:
          type: array
          items:
            type: string
            enum:
              - ach
              - wire
              - realtime
              - international_wire
        createdAt:
          type: string
          format: date-time
        updatedAt:
          type: string
          format: date-time
        archivedAt:
          type: string
          format: date-time
      required:
        - id
        - contactId
        - name
        - status
        - supportedTransferTypes
        - createdAt
        - updatedAt
    Error:
      type: object
      properties:
        code:
          type: string
          description: >-
            Machine-readable reason; branch on this, not on `message`. Every
            code an endpoint can return is listed on its reference page; the
            ones shared by all endpoints are explained in the Errors guide.
          example: invalid_request
        message:
          type: string
          description: >-
            Human-readable explanation, safe to show to an operator. Wording may
            change; use `code` and `details` programmatically.
        details:
          type: object
          description: >-
            The values behind `message`, keyed per `code`. For example
            `insufficient_funds` carries `available` and `requested`;
            `invalid_request` from contract validation carries one entry per
            failing field, keyed by JSON pointer. Empty when the code has no
            variable data.
          additionalProperties:
            type: string
          example:
            available: $120.00
            requested: $500.00
        referenceId:
          type: string
          description: Unique id of this failure. Quote it when contacting Slash support.
          example: 4001-2alj5if
      required:
        - code
        - message
        - details
        - referenceId
      additionalProperties: false
      title: Error
  responses:
    PublicApiV2Error400InvalidRequestInvalidRequestShapeDestinationsCreate:
      description: >-
        - `invalid_request` — The input is well-formed but cannot be acted on;
        `message` says which field or combination is the problem, and
        `details.field` names the field when one is at fault.

        - `invalid_request (request shape)` — The body, query, or headers failed
        validation, or a required header is missing. `details` has one entry per
        failing location, keyed by JSON pointer or header name.
      content:
        application/json:
          schema:
            anyOf:
              - title: invalid_request
                allOf:
                  - $ref: '#/components/schemas/PublicApiV2ErrorInvalidRequest'
              - title: invalid_request (request shape)
                allOf:
                  - $ref: '#/components/schemas/PublicApiV2ErrorInvalidRequestShape'
          examples:
            invalid_request:
              summary: invalid_request
              value:
                code: invalid_request
                message: This routing number cannot be used as a destination.
                details:
                  field: routingNumber
                referenceId: 4001-2alj5if
            invalid_request_request_shape:
              summary: invalid_request (request shape)
              value:
                code: invalid_request
                message: 'Invalid `X-Idempotency-Key`: This header is required.'
                details:
                  X-Idempotency-Key: This header is required.
                referenceId: 4001-2alj5if
    PublicApiV2Error401Unauthorized:
      description: '- `unauthorized` — API key authentication is missing or invalid.'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/PublicApiV2ErrorUnauthorized'
          examples:
            unauthorized:
              summary: unauthorized
              value:
                code: unauthorized
                message: API key authentication is missing or invalid.
                details: {}
                referenceId: 4011-2alj5if
    PublicApiV2Error403ForbiddenForbiddenLegalEntityUserApiKeyRequired:
      description: >-
        - `forbidden` — The credential can see the resource but is not permitted
        to perform this action on it; the missing permission is not disclosed.
        When the resource is a field of the request, `details` names that
        `field` and the `id` it received.

        - `forbidden (legal entity)` — The credential is not permitted to act
        for the selected legal entity.

        - `user_api_key_required` — The API key is scoped to a legal entity
        rather than a user. Every v2 request needs a user API key, created under
        Settings → API keys in the Slash dashboard, together with the
        `x-legal-entity` header.
      content:
        application/json:
          schema:
            anyOf:
              - title: forbidden
                allOf:
                  - $ref: '#/components/schemas/PublicApiV2ErrorForbidden'
              - title: forbidden (legal entity)
                allOf:
                  - $ref: '#/components/schemas/PublicApiV2ErrorForbiddenLegalEntity'
              - title: user_api_key_required
                allOf:
                  - $ref: '#/components/schemas/PublicApiV2ErrorUserApiKeyRequired'
          examples:
            forbidden:
              summary: forbidden
              value:
                code: forbidden
                message: >-
                  This credential is not permitted to do that on `fromAccount`
                  subaccount_source123.
                details:
                  field: fromAccount
                  id: subaccount_source123
                referenceId: 4031-2alj5if
            forbidden_legal_entity:
              summary: forbidden (legal entity)
              value:
                code: forbidden
                message: This credential is not permitted to do that.
                details: {}
                referenceId: 4031-2alj5if
            user_api_key_required:
              summary: user_api_key_required
              value:
                code: user_api_key_required
                message: >-
                  Public API v2 requires a user API key. Create one under
                  Settings → API keys in the Slash dashboard.
                details: {}
                referenceId: 4031-2alj5if
    PublicApiV2Error404NotFoundNotFoundNotEnabled:
      description: >-
        - `not_found` — No resource matches the identifier, it belongs to
        another legal entity, or the credential cannot view it. When the
        identifier is a field of the request, `details` names that `field` and
        the `id` it received.

        - `not_found (API not enabled)` — Public API v2 is not enabled for the
        selected legal entity.
      content:
        application/json:
          schema:
            anyOf:
              - title: not_found
                allOf:
                  - $ref: '#/components/schemas/PublicApiV2ErrorNotFound'
              - title: not_found (API not enabled)
                allOf:
                  - $ref: '#/components/schemas/PublicApiV2ErrorNotFoundNotEnabled'
          examples:
            not_found:
              summary: not_found
              value:
                code: not_found
                message: '`destinationId` le_contact_destination_bank123 was not found.'
                details:
                  field: destinationId
                  id: le_contact_destination_bank123
                referenceId: 4041-2alj5if
            not_found_not_enabled:
              summary: not_found (API not enabled)
              value:
                code: not_found
                message: The requested resource was not found.
                details: {}
                referenceId: 4041-2alj5if
    PublicApiV2Error409ConflictIdempotencyKeyReused:
      description: >-
        - `conflict (idempotency key reused)` — A consumed `X-Idempotency-Key`
        was reused; the original response is not replayed.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/PublicApiV2ErrorConflictIdempotencyKeyReused'
          examples:
            conflict_idempotency_key_reused:
              summary: conflict (idempotency key reused)
              value:
                code: conflict
                message: >-
                  This request has already been submitted (duplicate idempotency
                  key).
                details: {}
                referenceId: 4091-2alj5if
    PublicApiV2RateLimited:
      description: >-
        The request exceeded the applicable rate limit. The response body is
        plain text; clients must not depend on a response-body schema for this
        status.
    PublicApiV2Error500Internal:
      description: >-
        - `internal` — Slash could not complete the request. Quote `referenceId`
        when contacting Slash support.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/PublicApiV2ErrorInternal'
          examples:
            internal:
              summary: internal
              value:
                code: internal
                message: >-
                  An unexpected error occurred. If this keeps happening, contact
                  Slash support with the reference id below.
                details: {}
                referenceId: 5001-2alj5if
  securitySchemes:
    api_key:
      type: apiKey
      name: X-API-Key
      in: header
      description: >-
        User API key authentication. Create a key under Settings → API keys in
        the Slash dashboard (https://app.slash.com/global-settings/api-keys) and
        send the `x-legal-entity` header naming the legal entity to act on with
        every request. Keys scoped to a legal entity are rejected with `403
        user_api_key_required`.

````