Western Alliance Bancorporation · Authentication Profile

Western Alliance Bancorporation Authentication

Authentication

Western Alliance Bancorporation secures its APIs with apiKey, http, and mutualTLS across 4 declared security schemes, as derived from its OpenAPI definitions.

BankingFinancial ServicesTreasury ManagementPaymentsAccountTransactionWiresACHDigital AssetsWebhook
Methods: apiKey, http, mutualTLS Schemes: 4 OAuth flows: API key in: header

Security Schemes

bearerToken http
scheme: bearer
appClientId apiKey
· in: header (appClientId)
appClientSecret apiKey
· in: header (appClientSecret)
clientCertificate mutualTLS

Source

Authentication Profile

Raw ↑
generated: '2026-09-17'
method: searched
source: openapi/western-alliance-bancorporation-ach-eapi-beta-openapi.yml, openapi/western-alliance-bancorporation-all-account-balance-api-openapi.yml,
  openapi/western-alliance-bancorporation-all-account-intraday-api-openapi.yml, openapi/western-alliance-bancorporation-all-account-priorday-api-openapi.yml,
  openapi/western-alliance-bancorporation-bank-statement-api-openapi.yml, openapi/western-alliance-bancorporation-book-transfer-api-openapi.yml,
  openapi/western-alliance-bancorporation-check-image-api-openapi.yml, openapi/western-alliance-bancorporation-date-range-transactions-api-openapi.yml,
  openapi/western-alliance-bancorporation-intrabank-transfer-api-openapi.yml, openapi/western-alliance-bancorporation-single-account-balance-api-openapi.yml,
  openapi/western-alliance-bancorporation-single-account-intraday-api-openapi.yml, openapi/western-alliance-bancorporation-single-account-priorday-api-openapi.yml
  ...
summary:
  types:
  - apiKey
  - http
  - mutualTLS
  api_key_in:
  - header
schemes:
- name: bearerToken
  type: http
  scheme: bearer
  description: Bearer token returned by GET /entitlements-get-token-eapi/api/v1/token (Token API) in exchange for
    the appClientId + appClientSecret headers. Tokens are valid for a limited period (API Services Terms 6(c)(iii)).
  sources:
  - openapi/western-alliance-bancorporation-ach-eapi-beta-openapi.yml
  - openapi/western-alliance-bancorporation-all-account-balance-api-openapi.yml
  - openapi/western-alliance-bancorporation-all-account-intraday-api-openapi.yml
  - openapi/western-alliance-bancorporation-all-account-priorday-api-openapi.yml
  - openapi/western-alliance-bancorporation-bank-statement-api-openapi.yml
  - openapi/western-alliance-bancorporation-book-transfer-api-openapi.yml
  - openapi/western-alliance-bancorporation-check-image-api-openapi.yml
  - openapi/western-alliance-bancorporation-date-range-transactions-api-openapi.yml
  - openapi/western-alliance-bancorporation-intrabank-transfer-api-openapi.yml
  - openapi/western-alliance-bancorporation-single-account-balance-api-openapi.yml
  - openapi/western-alliance-bancorporation-single-account-intraday-api-openapi.yml
  - openapi/western-alliance-bancorporation-single-account-priorday-api-openapi.yml
  - openapi/western-alliance-bancorporation-stop-payments-api-openapi.yml
  - openapi/western-alliance-bancorporation-tassatpay-eapi-beta-openapi.yml
  - openapi/western-alliance-bancorporation-token-api-openapi.yml
  - openapi/western-alliance-bancorporation-wires-request-api-openapi.yml
- name: appClientId
  type: apiKey
  in: header
  parameter: appClientId
  description: Client ID assigned by WAB at enrollment (used with appClientSecret on the token endpoint).
  sources:
  - openapi/western-alliance-bancorporation-ach-eapi-beta-openapi.yml
  - openapi/western-alliance-bancorporation-all-account-balance-api-openapi.yml
  - openapi/western-alliance-bancorporation-all-account-intraday-api-openapi.yml
  - openapi/western-alliance-bancorporation-all-account-priorday-api-openapi.yml
  - openapi/western-alliance-bancorporation-bank-statement-api-openapi.yml
  - openapi/western-alliance-bancorporation-book-transfer-api-openapi.yml
  - openapi/western-alliance-bancorporation-check-image-api-openapi.yml
  - openapi/western-alliance-bancorporation-date-range-transactions-api-openapi.yml
  - openapi/western-alliance-bancorporation-single-account-balance-api-openapi.yml
  - openapi/western-alliance-bancorporation-single-account-intraday-api-openapi.yml
  - openapi/western-alliance-bancorporation-single-account-priorday-api-openapi.yml
  - openapi/western-alliance-bancorporation-stop-payments-api-openapi.yml
  - openapi/western-alliance-bancorporation-tassatpay-eapi-beta-openapi.yml
  - openapi/western-alliance-bancorporation-token-api-openapi.yml
  - openapi/western-alliance-bancorporation-wires-request-api-openapi.yml
- name: appClientSecret
  type: apiKey
  in: header
  parameter: appClientSecret
  description: Client Secret known only to the client and the WAB API gateway.
  sources:
  - openapi/western-alliance-bancorporation-ach-eapi-beta-openapi.yml
  - openapi/western-alliance-bancorporation-all-account-balance-api-openapi.yml
  - openapi/western-alliance-bancorporation-all-account-intraday-api-openapi.yml
  - openapi/western-alliance-bancorporation-all-account-priorday-api-openapi.yml
  - openapi/western-alliance-bancorporation-bank-statement-api-openapi.yml
  - openapi/western-alliance-bancorporation-book-transfer-api-openapi.yml
  - openapi/western-alliance-bancorporation-check-image-api-openapi.yml
  - openapi/western-alliance-bancorporation-date-range-transactions-api-openapi.yml
  - openapi/western-alliance-bancorporation-single-account-balance-api-openapi.yml
  - openapi/western-alliance-bancorporation-single-account-intraday-api-openapi.yml
  - openapi/western-alliance-bancorporation-single-account-priorday-api-openapi.yml
  - openapi/western-alliance-bancorporation-stop-payments-api-openapi.yml
  - openapi/western-alliance-bancorporation-tassatpay-eapi-beta-openapi.yml
  - openapi/western-alliance-bancorporation-token-api-openapi.yml
  - openapi/western-alliance-bancorporation-wires-request-api-openapi.yml
- name: clientCertificate
  type: mutualTLS
  description: WAB-issued Client Certificate installed on approved company servers "capable of and/or allowed to
    initiate a funds transfer" (API Services Terms 1(i), 6(c)(ii)). Documented in the Terms, not in any published
    collection.
  sources:
  - https://www.westernalliancebancorporation.com/sites/default/files/2025-05/api-services-terms-conditions.pdf
docs:
- https://www.westernalliancebancorporation.com/sites/default/files/2025-05/api-services-terms-conditions.pdf
- https://developer.westernalliancebank.com/s/get-token-tutorial
- https://developer.westernalliancebank.com/sfsites/c/cms/delivery/media/MCPZ4TMDU3SZEDPHAR5JH5YAK6EY
note: Upgraded from the API Services Terms & Conditions (v6, May 14 2025) and the provider Token API Postman collection.
  Enrollment through Treasury Management issues a Client ID and Client Secret (Terms 1(j)/(k), 6(c)(i)); the client
  sends them as the appClientId / appClientSecret headers to GET /entitlements-get-token-eapi/api/v1/token?Scope=<Informational|...>
  and receives a bearer token "valid for a limited period of time" (Terms 6(c)(iii)); every API call must be signed
  with that token. Funds-transfer clients also install a WAB-issued Client Certificate on approved servers (Terms
  1(i), 6(c)(ii)) - a mutual-TLS control the Postman collections cannot show. The TassatPay beta adds a second credential
  layer (Tassat client_id/client_secret -> access_token, then a user_token per wallet user). Multi-factor procedures
  may be required (Terms 7). The developer.westernalliancebank.com openid-configuration is the Salesforce portal
  login IdP, not the API auth server.
flow:
- step: 1
  action: Enroll in Treasury Management API services; WAB issues Client ID + Client Secret (and a Client Certificate
    for funds-transfer products).
- step: 2
  action: GET https://api-connect.westernalliancebank.com/entitlements-get-token-eapi/api/v1/token?Scope=Informational
    with headers appClientId, appClientSecret, X-Correlation-ID (GUID).
  operationId: getToken
- step: 3
  action: 'Send Authorization: Bearer <token> plus X-Correlation-ID on every product API call; refresh the token
    when it expires (lifetime not published).'
scopes:
  style: query parameter Scope on the token endpoint
  documented_values:
  - Informational
  note: Only "Informational" appears in the published collections; the Transactional and Digital Assets collections
    request the same scope value. No scope reference page is published anonymously.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/western-alliance-bancorporation-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.