Fintech APIs & Platform for KYC, Verification & Transactions in India | Eko Platform Services
Eko Platform Services Logo

POSTAePS Cash Withdrawal

Withdraw cash from any Aadhaar-linked bank account using biometric fingerprint authentication — no card or PIN required.

POST/customer/collection/aeps-fingpay/cash-withdrawl/{customer_id}

Lets a customer withdraw cash from any Aadhaar-linked bank account using a live fingerprint scan — no card or PIN. The agent's biometric device produces a PID XML blob that is forwarded verbatim, and the customer's Aadhaar number is RSA-encrypted before transmission.

Prerequisites

The agent must have completed, in order:

  1. AePS Fingpay activation
  2. One-time eKYC (Send OTP → Verify OTP → Biometric eKYC)
  3. Daily KYC for the current day
Important

Due to NPCI compliance, the agent's Daily KYC must succeed for the current calendar day before any cash-withdrawal is attempted.

Aadhaar encryption

Encrypt the Aadhaar number before sending it (the same scheme used by all AePS transaction APIs):

  1. Base64-decode the public key.
  2. RSA-encrypt the Aadhaar number with the decoded key.
  3. Base64-encode the result and send that as the aadhar parameter.

Production public key:

text
MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCaFyrzeDhMaFLx+LZUNOOO14Pj9aPfr+1WOanDgDHxo9NekENYcWUftM9Y17ul2pXr3bqw0GCh4uxNoTQ5cTH4buI42LI8ibMaf7Kppq9MzdzI9/7pOffgdSn+P8J64CJAk3VrVswVgfy8lABt7fL8R6XReI9x8ewwKHhCRTwBgQIDAQAB

Biometric (PID) capture

Note

New to RDService? The Aadhaar Biometric Authentication guide covers the full capture flow — driver discovery, PidOptions, error codes — for Web and Android, and includes an in-browser device tester.

The PidData XML from the RD-service device must use:

  • Data type="X" (XML), base64-encoded
  • a DeviceInfo mc value carrying the device public-key certificate signed by the Device Provider Key
  • fingerprint quality of at least 35 nmPoints
Warning

Per NPCI's FIR-FMR single-PID-block guidance, capture fingerprints with fType = 2 (not 0). A subset of banks that have not yet completed FMR+FIR compliance still require fType = 0 — check the current bank list before going live.

Tip
This endpoint is one step in a complete workflow:

Request

Path parameters

customer_idstringRequired

Customer's registered mobile number.

example: 9000000000

Body parameters

initiator_idstringRequired

Registered mobile number of the API user (see Platform Credentials).

example: 9962981729

client_ref_idstringoptional

Unique reference ID per API call, generated by your system (max 20 characters).

example: 2026010100123456789

user_codestringRequired

Unique code of your user/agent/retailer the service is run for. Use `Onboard Agent` API to register your users

example: 10000001

bank_codestringRequired

Short bank code identifying the customer's Aadhaar-linked bank (e.g. `HDFC`, `SBIN`). Obtain from the bank list API.

example: HDFC

aadharstringRequired

RSA-encrypted, Base64-encoded Aadhaar number. Encrypt the 12-digit Aadhaar with the Eko RSA public key using PKCS#1 v1.5 padding (Java's default `Cipher.getInstance("RSA")`), then Base64-encode the ciphertext.

example: BASE64_ENCRYPTED_AADHAAR

latlongstringRequired

GPS coordinates of the transaction origin in 'latitude,longitude' format.

example: 28.6139,77.2090

piddatastringRequired

PID data captured from the UIDAI-certified biometric device, as a raw XML string. Must use Data type='X' (XML, not Protobuf). DeviceInfo must include the 'mc' (device certificate) parameter. fType must be 2.

example: <?xml version='1.0'?><PidData><Data type='X'>...</Data><DeviceInfo mc='...' /></PidData>

amountnumberRequired

Withdrawal amount in Indian Rupees (integer). Must be greater than 0 for cash withdrawal.

example: 1000

Response types

response_type_idMeaningNext step
1463Transaction Successful
1464Transaction Fail
1465Transaction Pending — check final status laterTransaction Inquiry

Responses

1463Transaction Successful

  • statusnumber

    Primary success indicator (0 = success).

  • messagestring

    Human-readable response / error message.

  • response_status_idnumber

    Granular status id; see the shared error-codes table.

  • response_type_idnumber

    A unique id for every possible response shape (success or error) — useful for client logic branching and analytics.

  • tx_statusstring

    Transaction state: 0=Success, 1=Fail, 2=Awaited, 3=Refund Pending, 4=Refunded, 5=On Hold.

  • txstatus_descstring

    Human-readable transaction status.

  • dataobject

    API-specific response payload.

    • tidstring

      Eko's internal transaction ID. Use for reconciliation and support queries.

    • amountstring

      Withdrawal amount processed in the transaction (INR).

    • bankstring

      Name of the customer's bank where the debit occurred.

    • bank_ref_numstring

      Bank/NPCI reference number (RRN) for the transaction. Empty on failure.

    • balancestring

      Remaining balance in the customer's bank account after withdrawal, if returned by the bank.

    • customer_balancestring

      Customer's account balance as reported by the bank. Empty when not returned.

    • tdsstring

      Tax deducted at source on the agent's commission (INR).

    • commissionstring

      Commission earned by the agent on this transaction (INR).

    • feestring

      Fee charged for the transaction (INR). May be empty.

    • service_taxstring

      Service tax component on the fee (INR). May be empty.

    • totalfeestring

      Total fee including taxes (INR). May be empty.

    • shopstring

      Agent's shop/merchant name.

    • shop_address_line1string

      Agent's shop address. May be empty.

    • sender_namestring

      Name of the agent/sender initiating the transaction.

    • merchantnamestring

      Registered merchant name of the agent.

    • merchant_codestring

      Merchant code of the agent. May be empty.

    • user_codestring

      Echo of the agent's user_code from the request.

    • aadharstring

      Masked Aadhaar number of the customer.

    • auth_codestring

      Bank authorization code. May be empty.

    • stanstring

      System Trace Audit Number assigned by the switch. May be empty.

    • terminal_idstring

      Terminal identifier. May be empty.

    • tx_statusstring

      Transaction state within the data block: 0=Success, 1=Fail, 2=Pending.

    • transaction_datestring

      Transaction date (DD-MM-YY HH:MM:SS).

    • transaction_timestring

      Transaction timestamp (DD-MM-YY HH:MM:SS).

    • reasonstring

      Failure reason, when the transaction did not complete. Empty on success.

    • commentstring

      Human-readable transaction remark from the provider (e.g. 'Request Completed').

Next steps

NextPOSTAePS Balance EnquiryCheck a customer's bank account balance using Aadhaar number and biometric fingerprint — no card or PIN required.

Related