ZB Developers
Certified partner access to standalone APIs.
Apply as an organisation, get vetted, build against a staging sandbox that holds mock data only, and certify your integration. Each API keeps its own reference documentation; this portal is where access is granted.
How access works
Access is granted to organisations, not to anonymous callers. Every step below happens in this portal, in your own signed-in session.
- 01
Apply
Describe your organisation, the APIs you need and your use case. Sign in with your ZB ID credentials to start.
- 02
Vetting
A certification officer checks the organisation, the contact and that the requested access is the least your use case needs.
- 03
Sandbox credentials
Once approved, issue keys yourself in your partner session. Each key is shown once, scoped to what was approved, and works on staging only.
- 04
Certification
Submit evidence against each certification check. Production access is arranged by operations after certification, outside this portal.
Services
Each service is a standalone API with its own reference documentation. The portal lists what a certified partner can reach and links out to each reference.
- ZB ID
Identity for partner integrations: OAuth 2.0 client-credential tokens, discovery and JWKS.
- Customer 360
Event ingest, with reads confined to the events your own key produced (read:own).
- Notification Hub
Send notifications and read templates with brand-bound keys. Sandbox keys never deliver.
- Banking partner API
Embedded payment intents and partner reads. Credit and insurance are simulated on staging.
Exposure tiers
Every route group is classified into exactly one tier. The catalogue shows the public and partner-gated tiers.
- Public
- Read-only reference: health, discovery and signing keys. Anyone may call these.
- Partner-gated
- Least-privilege keys for certified partners, against staging with mock data. Route paths are listed once you sign in as a partner.
- Everything else
- Internal and administrative routes are not listed here and are never issued to partners. When a route is not classified, it is treated as internal.