Skip to content

feat: add Smart Transfers (preauthorizations, payments, balance and data consent) - #113

Merged
cernadasjuan merged 2 commits into
masterfrom
feat/smart-transfers
Oct 8, 2026
Merged

cernadasjuan merged 2 commits into
masterfrom
feat/smart-transfers

Conversation

@cernadasjuan

@cernadasjuan cernadasjuan commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

What

Smart Transfers, the SDK's first payments surface. It covers all 7 /smart-transfers paths of the API spec.

1. Preauthorizations

  • createSmartTransferPreauthorization(CreateSmartTransferPreauthorizationRequest): connectorId, parameters, recipientIds, and the optional callbackUrls, clientPreauthorizationId, configuration and linkedJourney. linkedJourney: true also asks the user, in the same approval, for permission to read the source account balance.
  • getSmartTransferPreauthorizations(...), paginated, and getSmartTransferPreauthorization(id).
  • SmartTransferPreauthorization.dataConsent: status (AWAITING_AUTHORISATION, AUTHORISED, REJECTED), rejectionReason and updatedAt. It is null when the permission was not requested.

2. Source account balance and data consent

  • getSmartTransferPreauthorizationBalance(id) → GET /smart-transfers/preauthorizations/{id}/balance. Returns balance and overdraft (contracted, used, available), in BRL. overdraft is null when the institution does not share it.
  • cancelSmartTransferPreauthorizationDataConsent(id) → DELETE /smart-transfers/preauthorizations/{id}/data-consent. Cancels only the permission and returns the preauthorization, which stays active.

3. Payments

  • createSmartTransferPayment(CreateSmartTransferPaymentRequest), getSmartTransferPayment(id), and getSmartTransferPreauthorizationPayments(id, ...), paginated with from / to.

Important

EncryptedParametersInterceptor fix. With rsaPublicKey(...) set, the interceptor encrypted the parameters field of any POST/PATCH body. That would have sent the Smart Transfer preauthorization's parameters encrypted, while the API only decrypts them on /items. It also threw a NullPointerException on item requests without parameters, such as MFA. It now encrypts only POST/PATCH /items bodies that carry parameters.

Types follow the rest of the SDK: amounts are Double, dates are Date, and statuses are enums. rejectionReason and errorDetail.code stay String, since new values can appear.

Release

pom.xml goes to 1.16.0, a minor bump for a feat. Merging tags v1.16.0 and cuts the GitHub Release. Publishing to GitHub Packages is still manual: gh workflow run maven-publish.yml -f tag_version=v1.16.0. CLAUDE.md now says the bump belongs in the PR that ships the change.

Tests

  • SmartTransfersTest (20, MockWebServer):
    • method and path of every endpoint;
    • dataConsent present and null;
    • overdraft present and null;
    • linkedJourney serialized only when set.
  • EncryptedParametersInterceptorTest (3): Smart Transfer parameters sent as plain JSON, MFA without parameters, items still encrypted. They fail against the old condition.
  • mvn -B package: 62/62.

…ata consent)

Add the /smart-transfers endpoints to PluggyApiService:

- POST /smart-transfers/preauthorizations (with optional linkedJourney)
- GET /smart-transfers/preauthorizations (paginated) and /{id}
- GET /smart-transfers/preauthorizations/{id}/balance (balance and overdraft)
- DELETE /smart-transfers/preauthorizations/{id}/data-consent
- GET /smart-transfers/preauthorizations/{id}/payments (paginated, from/to)
- POST /smart-transfers/payments and GET /smart-transfers/payments/{id}

The preauthorization exposes dataConsent (status, rejectionReason,
updatedAt), null when the balance permission was not requested.

EncryptedParametersInterceptor now encrypts only POST/PATCH /items bodies
that carry parameters. Before, it also encrypted the payer's parameters on
Smart Transfer preauthorizations, which the API expects as plain JSON, and
threw a NullPointerException on item requests without parameters (MFA).
@cernadasjuan
cernadasjuan merged commit e9c269a into master Oct 8, 2026
4 of 5 checks passed
@cernadasjuan
cernadasjuan deleted the feat/smart-transfers branch October 8, 2026 20:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant