Quick start
Amounts at or above the $10,000 AML threshold are held for review, even with KYC:
Capability discovery
For UCP’s Dynamic Discovery, declare your capability:
Add to .well-known/ucp.json
get_ucp_json_entry() returns a capabilities block. Publish it without the verify_loan_terms operation (see the warning below):
In v3.0.1, get_ucp_json_entry() and get_capability_definition() also list a verify_loan_terms operation, but UCPIntegration has no such method. Remove it from the entry you publish, as shown above.
Middleware pattern
Drop into your UCP flow:
ISO 20022 payments
For bank transfers using ISO 20022:
Verification flow
For ISO 20022 messages, the business limits (max_transaction_amount, positive amount, allowed_currencies) apply to the amounts and currencies read from the parsed XML (since v3.0.0; hardened in v3.0.1, GHSA-mrrj-6m2q-jch9). An empty or missing sanctions_list fails closed as unscreened instead of passing.
Receipt IDs
Every verify_payment_token and verify_iso20022_payment result carries receipts for audit: