# Connectivity

## Production addresses

| Surface | Entry point | Intended caller |
| --- | --- | --- |
| Gateway | `https://api.threasury.org` | operators and documentation |
| Health | `https://api.threasury.org/v1/health` | load balancer and monitoring |
| Internal API | `https://api.threasury.org/internal/v1` | FEI and approved Threasury services |
| External API | `https://api.threasury.org/external/v1` | approved partners and providers |
| Platform | `https://threasury.org/platform` | mobile/web BFF clients |
| Ledger | `https://bank.threasury.org/ledger` | controlled internal services |

## FEI

FEI calls `POST /internal/v1/commands` using canonical command envelopes. Required context: actor, organisation, legal entity, tenant, capability, purpose, correlation ID and timestamp. State-changing commands also require an idempotency key. Gateway-generated canonical events are delivered to FEI's event-ingestion boundary, never its database.

## Ledger

Provider transactions, settlements, statement files, FX confirmations, card events and balance reports are routed as canonical provider events to Payment Orchestration/Reconciliation, then to the Ledger Command Gateway. The Gateway has no Ledger database credential and cannot submit arbitrary accounts or postings.

## Platform and apps

Mobile/Web -> dedicated BFF -> Platform API -> FEI/Ledger. A "Connect bank" journey is initiated through the Platform API, which invokes an internal Gateway capability. No app contains provider logic or Gateway credentials.

Threasury consent and provider permission are deliberately separate. The Consent Manager owns purpose, scope, customer evidence, expiry and revocation. The provider adapter may observe the provider's permission metadata, open update mode for reauthorisation and call the provider's revocation endpoint. Provider webhooks can restrict or end a connection but cannot grant or widen Threasury consent.

## Credential delivery

Production credentials must be minted after deployment, stored in the approved AWS credential backend and delivered out of band. The no-additional-charge profile uses Standard Systems Manager `SecureString` parameters; the separately approved institutional profile uses AWS Secrets Manager. Use OAuth 2.0 client credentials with short-lived tokens and mTLS for institutional connections; HMAC or asymmetric signatures for webhooks; environment-specific keys; narrow scopes; rotation; IP policy where appropriate; audit; and emergency revocation.
