Bank

How to Integrate a Bank Account Verification API

🕒 7 Minutes  ·  📅 October 10, 2026

How to Integrate a Bank Account Verification API

In brief: integrating a bank account verification API means sending an account number, IFSC and account holder name from your server, reading back whether the account is valid and how well the name matches, and turning that into a clear decision in your flow. This guide covers the decisions around the call, not just the call itself.

How a bank account verification API integration works

Every bank account verification API integration follows the same basic pattern. Your customer enters their bank details in your app. Your server sends the account number, IFSC and the name you expect to see to the API. The API checks the account against the banking system and returns whether it is valid and active, the name registered on it, and how closely that name matches the one you sent. Your system then approves the account, sends it for review, or asks the customer to correct it.

The call itself is the easy part of a bank account verification API integration. Most of the work in a good bank account verification API integration is deciding when to verify, which method to use, how to read the name match, and what to do when something goes wrong.

Bank account verification API integration: a bank account card verified by a cloud API with a checkmark

Before you start

Test in a sandbox first

Use a sandbox to see real response formats and error cases before you write production code. Veriqos offers a self-serve sandbox at sandbox.veriqos.com, so your team can make test calls before any commercial conversation. Expect to complete business verification before you are given live access.

Call the API from your server only

Never call a verification API directly from a browser or a mobile app. Keep API keys on your server, in environment variables or a secrets manager, and let your app talk to your own backend. A key shipped inside an app can be extracted and misused.

Decide where verification sits in your flow

Ask for bank details only when you actually need them, usually just before the first payout, disbursal or refund. Running the bank check in parallel with identity checks, rather than after them, shortens onboarding.

Choose penny drop or penny-less first

There are two methods, and the choice affects how you handle retries and costs:

  • Penny drop sends a small credit, often one rupee, to the account and reads back the beneficiary name. It proves the account can receive money right now, but it moves real money and takes a few seconds.
  • Penny-less confirms the account and name without moving money. It is faster and cheaper at scale, and coverage can vary by bank.

Many teams use penny-less by default and fall back to penny drop where coverage is incomplete or the payout value justifies extra certainty. See penny drop vs penny-less verification for a full comparison.

Collect and validate inputs before you call

Catching obvious typing mistakes in your own form saves a paid call and gives the customer instant feedback.

  • IFSC: an IFSC is 11 characters: four letters for the bank, then the digit 0, then six letters or digits for the branch, as set by the Reserve Bank of India. Check the format as the customer types.
  • Account number: account numbers vary in length between banks, so check that the value is numeric and within a sensible range rather than enforcing one fixed length. Ask for it twice, or let the customer confirm it, to catch transposed digits.
  • Account holder name: collect the name exactly as the customer says it appears on their bank account, not just their display name in your app.

Read the result

A bank account verification API returns a few key pieces of information. Depending on the method, the response tells you:

  • whether the account is valid and active;
  • the name registered on the account;
  • a name-match result or score comparing that name with the one you sent;
  • bank and branch details, where the method provides them.

In a bank account verification API integration, store the result, the registered name and the time of the check with the customer or payout record, so every decision can be explained later.

Turn the name match into a decision

Confirming that an account exists is rarely the point. The valuable output is whether the account belongs to the person or business you are about to pay. Use three bands rather than a single pass or fail:

  • Approve automatically when the match is strong.
  • Send for review when the match is partial.
  • Ask the customer to correct their details when there is a clear mismatch.

Set the cut-offs from your own sample of real results, not from a number you read in a blog post, including this one. Common causes of harmless mismatches include initials instead of full names, salutations such as Mr or Mrs, name order, and joint accounts. Read more about name matching.

Handle errors, timeouts and retries

Separate the customer’s mistakes from temporary problems

An invalid account or IFSC means the customer needs to correct their details. A timeout or a source that is briefly unavailable means you should try again later. Show different messages for each, so customers are not told their account is wrong when the bank simply did not respond.

Do not blindly retry penny drop

A penny drop moves real money. If a request times out, the credit may still have gone through, so a blind retry can send a second credit. Check the outcome of the first request before trying again, and set a sensible limit on attempts for the same account.

Log what support will need

Keep the request reference returned with each check, the time of the call and the outcome. When something looks wrong, these details let your team and your provider trace the call quickly.

Bank details are personal data. Ask for the customer’s consent before you verify their account, mask account numbers in logs and screens, and keep only what you need for your payouts and audit trail. Read about how the DPDP Act applies to KYC data.

Go-live checklist for your bank account verification API integration

  • Inputs are validated in your form before any call is made.
  • The API is called only from your server, with keys kept out of your code.
  • You have chosen penny-less, penny drop or a fallback between them.
  • Name-match bands are set from your own sample data, with a review queue for partial matches.
  • Penny drop retries check the first outcome before trying again.
  • Customers see different messages for wrong details and temporary failures.
  • Results, registered names and timestamps are stored with each payout record.
  • Account numbers are masked in logs, and consent is recorded.

For the wider picture, see the KYC API integration checklist.

Frequently asked questions

Can I verify a bank account without depositing money?

Yes. Penny-less verification confirms the account and the registered name without moving money. Penny drop sends a small credit and is useful where penny-less coverage is incomplete or you need proof that the account can receive money.

What does a low name-match score mean?

It means the name on the bank account differs from the name you sent. That can be fraud, but it is often a harmless difference such as initials, a salutation or a joint account. Send partial matches for review rather than rejecting them outright.

Can I call a bank account verification API from my mobile app?

No. Call it from your own server and keep your API keys there. Your app should send the customer’s details to your backend, which makes the call.

Start your integration

Veriqos offers a bank account verification API, a penny-less bank account verification API and a penny drop verification API. Try them in the sandbox, or talk to our team about your flow. To see these checks in a real product, read how lending apps use real-time bank account verification.

Amish Tiwari

Amish Tiwari is the Founder of Veriqos Technologies, with 10+ years of experience in BFSI and identity verification.

Get In Touch

Have questions about identity verification, KYC, or fraud prevention for your business? Our team will follow up within 2 hours.

Veriqos support

More From the Blog