Get Disclosures
Returns the investment disclosures to render, in order.
Called without a user, the response carries the primary disclosure alone, worded for the financial institution's type. This is the correct set for any surface rendered before a user is known, and needs no scope: the text is public legal copy that names no user.
Naming a user narrows the response to that user's disclosures, adding a footnote for each product they have funded. This reveals which products the user holds, so it requires the read:user scope.
- user_account_id
- Partner-supplied user identifier (e.g. CIF, member number) to return disclosures for, or None for the general set.
- user_account_id_type
- Identifier system the user_account_id is expressed in.
The applicable disclosure lines in render order.
- HTTPException
- 400 Bad Request when only one of the user_account_id pair is supplied, or when the financial institution has no vendor configured for the requested user_account_id_type; 403 Forbidden when a user is named without the read:user scope; 404 Not Found when no user exists for the given account ID within the partner's financial institution.
Authorization
APIKeyHeader Partner API key, required on every endpoint except "GET /health". Your financial institution issues and revokes these keys from the InvestiFi Ops Center. Each key carries an environment-identifying prefix such as "ifi_prod_" plus a fixed set of scopes, so a valid key still returns 403 Forbidden on an endpoint whose scope it was not granted; the response "detail" names the check that failed.
In: header
Query Parameters
Return the disclosures for this user rather than the financial institution's general set. Requires the read:user scope.
How to interpret user_account_id. Required when, and only when, user_account_id is set: "investifi" (InvestiFi user account id), "core" (banking-core member number / CIF), or "dbp" (digital-banking-provider user id). A core or dbp id is resolved to the InvestiFi user account before lookup.
Response Body
application/json
application/json
curl -X GET "https://partner-api.investifi.com/v1/disclosures/"{
"disclosures": [
"NOT INSURED. MAY LOSE VALUE. NO GUARANTEE. ...",
"*Product footnote naming the offering entity"
]
}{
"detail": [
{
"loc": [
"string"
],
"msg": "string",
"type": "string",
"input": null,
"ctx": {}
}
]
}Get Health
Public health check endpoint for partner connectivity validation. No authentication required.
Revoke Member Sessions
Requires the `manage:sessions` scope. End every InvestiFi session of one member. A Partner calls this route from their sign-out flow, to end a member's live sessions. This call must come from the Partner's Backend.

