Simulation
Drive application review states on demand in the sandbox — including lifecycle webhooks, sanctions screening, and risk assessment.
Simulation
Simulation endpoints are sandbox-only tools that let you drive application review states on demand — no need to wait for a real FV Bank reviewer. Most of them also fire the matching lifecycle webhook so you can test handlers end-to-end. /simulate/sanction-status and /simulate/risk-status set a verdict only and fire no webhook. /simulate/create-account is different: it performs the real account-opening request (no supervisor right required) and a real account follows.
All simulate endpoints return 400 in production — they are disabled outside the sandbox.
Key concepts
- Status codes — 2 = Missing, 3 = Approved, 4 = Rejected. All status endpoints use the same values.
- IDs — Each endpoint needs the ID of the item being simulated. Retrieve them from
GET /application/detail/{id}. - Remark field — The comment endpoint sends its text in
Remark. Optional on the status endpoints. - No webhook — sanction and risk simulations do not emit events. Confirm the result with
GET /application/detail/{id}. - Sticky override — sanction and risk statuses are stamped with a broker-override marker (
statusUpdatedByprefixedb_) and are not recomputed afterward. A re-submit can create a new screening record, which is not covered by the previous override. - Create account —
/simulate/create-accountis a one-way door: the application locks at Account Requested and further broker submits are rejected. A200means the request was accepted, not that the account exists. PollAccountOpeningStatuson application detail, or wait foraccount.created.
Common workflows
Test approval
POST /simulate/form-statuswith Status 3 — firesform.approved.- Verify your webhook handler receives and processes the event.
Test document rejection and re-upload
POST /simulate/document-statuswith Status 4 — firesdocument.rejected.- Re-upload the corrected file.
POST /simulate/document-statuswith Status 3 — firesdocument.approved.
Test the ask flow
POST /simulate/ask-created— firesask.created(typically followed byform.missing) and adds an open ask to the application.GET /application/detail/{id}— find the new ask in the Asks list.POST /application/ask/answer— submit the answer.
Test KYC approval
- The applicant completes KYC first (dummy values are fine) until the system concludes approved or rejected.
GET /application/detail/{id}— find the individual/UBO ID inKyc[].IndividualId.POST /simulate/kyc-statuswithIndividualIdandStatus: 3— fireskyc.approved(sandbox only).
Test a reviewer comment
POST /simulate/comment-added with Id (ApplicationId) and a Remark — fires comment.created to your webhook.
Test a sanctions verdict
- Complete KYC first so screening has run (the simulator returns 400 otherwise).
POST /simulate/sanction-statuswith Status 3 — sets the business-name screening. PassIndividualIdto target that individual's screening instead.- No webhook is sent. Confirm the result with
GET /application/detail/{id}.
Test a risk verdict
POST /simulate/risk-statuswith Status 3 — sets the risk assessment. No webhook is sent.- Confirm with
GET /application/detail/{id}. Without this call, risk can pass on its own once every other step is past draft.
Test account opening
- Approve every step first — form, documents, KYC, sanctions, and risk. A business application also needs a Certificate of Incorporation with a usable attachment.
POST /simulate/create-accountwith the applicationId. The application moves to Account Requested and locks.- A
200means the request was accepted, not that the account exists. PollAccountOpeningStatusonGET /application/detail/{id}, or wait for theaccount.createdwebhook. A failed creation staysrequestedand is picked up by an FV Bank agent; nothing is signalled to the broker.