Postman and Bruno collections for the SanctionsKit sanctions screening API, plus the complete OpenAPI 3.1 specification. Try name screening, inspect match evidence, and submit a batch using a free synthetic sandbox.
Create a workspace · Get a sandbox API key · Developer docs · API reference
| Resource | Start here |
|---|---|
| Postman | Import the collection and environment |
| Bruno | Open the collection folder |
| OpenAPI | Download the specification · Import and update notes |
The collections cover the same ten requests: source discovery, a person screening, result retrieval, a JSON evidence download, an organization screening, a vessel screening, batch submission, batch progress, a batch row's result, and usage. The OpenAPI file describes the wider API, including monitoring, review cases, webhooks, and reports.
- Sign up and create a workspace.
- Open API keys, select Sandbox, and create a key with
sources:read,screenings:write,results:read,batches:write, andusage:read. - Follow the setup in the Postman or Bruno folder. Set
apiKeylocally; the checked-in templates are blank. - Send Screen a person, then retrieve its saved result and evidence.
The base URL is https://www.sanctionskit.com/api/v1. Send the key as a Bearer token. The key selects the environment, so no environment header is needed.
{
"subject": {
"name": "Alex Morgan",
"entityType": "person",
"birthDate": "1984"
},
"package": "sandbox@1",
"retention": "standard"
}Alex Morgan is an invented sandbox subject. The examples also include a fictional organization with a no-match result and a vessel with an identifier match. Sandbox data does not represent real sanctions records and does not consume paid production allowance.
Requests that create screenings or batches use separate idempotency keys. Keep the key and body unchanged when retrying. Clear that request's key variable before starting a new operation; each client guide names the variables.
See the quickstart, authentication guide, and idempotency guide for the details.
Send the inline batch, then poll its progress about every five seconds. A 202 response means the batch was accepted. It does not mean every subject has been screened.
When processing ends, inspect every row. A completed batch can contain failed rows. Follow nextOffset until it is null, and use a completed row's screening_id to retrieve its result. A failed or cancelled row is not a no-match result. The included batch fits on one page.
Read the batch screening guide for file uploads, row outcomes, and pagination.
SanctionsKit supports sanctions screening and watchlist screening in AML and KYC workflows, customer onboarding, and vendor checks. A potential_match needs review. A no_match applies only to the selected coverage and screening policy; it is not legal clearance.
These collections are configured for synthetic sandbox use. For production integration, review source availability, choose eligible source IDs or a versioned package, and use a production key in your own integration. Source discovery describes the production catalog; listing a source does not make it available to every workspace or to the sandbox package.
| Learn more | Documentation |
|---|---|
| Request fields and matching | Screening requests · Matching methodology |
| Retained results and exports | Results and evidence · Retention |
| Retries and rate limits | Errors · Usage and limits |
| Production coverage | Source directory · Coverage |
| Plans and data safeguards | Pricing · Security |
Node.js 22 or newer is needed only for repository checks and OpenAPI updates. You do not need Node.js to open either collection.
npm ci
npm testTo refresh the specification from the production site:
npm run sync:openapi
npm testReview contract changes before updating the collections. Checks validate the files and request contracts locally; authenticated sandbox requests require your own key.
For application code, see SanctionsKit API examples.
Small fixes and clearer examples are welcome. See CONTRIBUTING.md. Keep credentials and real customer data out of issues, screenshots, and pull requests. Report sensitive issues through the security contact.
MIT. The license covers these repository files. Use of the hosted service and third-party source data remains subject to their applicable terms.