Crypto Travel Rule
The Travel Rule is a global anti-money-laundering regulation (FATF Recommendation 16) that requires Virtual Asset Service Providers — VASPs, such as crypto exchanges and custodial wallet providers — to exchange originator and beneficiary information when transferring crypto assets between institutions. Caliza is a registered VASP and complies with the Travel Rule on both crypto payouts and crypto deposits.
This page explains how Travel Rule compliance surfaces in the API and what your integration needs to do. Every behavior described here can be exercised in the sandbox environment — see Testing Travel Rule in Sandbox.
What it means for your integration
- Crypto recipients declare where the destination wallet is hosted — at a VASP (
vaspIdfrom the directory) or as a self-hosted wallet (isNonCustodialWallet: true). See Create Recipients. - Payouts to self-hosted wallets require a wallet ownership proof before a simulation or transaction can be created. See Self-Hosted Wallets.
- Crypto payouts clear the Travel Rule before leaving custody — see below.
- Third-party crypto deposits may be held until the sender's VASP transmits the Travel Rule message — see below.
VASP directory
When creating a crypto recipient whose wallet is hosted at an exchange or custodial provider, look the provider up in the VASP directory and pass its id as the recipient's details.vaspId:
curl 'https://api.sandbox.caliza.com/core-api/v1/recipients/vasps/search?searchQuery=kraken&page=0&size=20' \
--header 'Authorization: Bearer {{ACCESS_TOKEN}}'The response is a paginated list of { "id", "name" } entries.
The
vaspIdis what allows the Travel Rule message to be addressed to the counterparty VASP, so it is required for every VASP-hosted crypto recipient — a free-textvaspNamealone is not accepted (though it may accompany avaspIdas display information). If the provider is not listed in the directory, contact Caliza support.
Payouts: Travel Rule clearance
When you create a crypto payout, Caliza originates the Travel Rule message to the counterparty VASP (or records the self-hosted wallet attestation). The withdrawal only leaves custody once the Travel Rule requirements are cleared:
- For most transfers this is immediate and invisible — the payout proceeds as usual.
- When the counterparty VASP has to authorize the transfer, the payout pauses until that authorization arrives. The transaction keeps its current status (for example
PROCESSING) while it waits; no webhook is emitted for the pause itself, and no action is required from you. - If the counterparty rejects the Travel Rule message, the payout is placed under manual compliance review.
If a crypto payout stays in
PROCESSINGlonger than usual, Travel Rule clearance with the counterparty VASP is the most common reason. It resolves automatically once the counterparty responds.
Payouts to self-hosted wallet recipients additionally require a valid wallet ownership proof at creation time. Without one, POST /v1/simulations, POST /v2/simulations, and POST /v1/transactions fail with HTTP 422 and error code travel-rule.ownership_proof_required. See Self-Hosted Wallets for how to collect a proof.
Deposits: inbound Travel Rule messages
Crypto deposits at or above the applicable per-currency threshold are held — the funds arrive on-chain but are not credited to the beneficiary's balance — until the deposit's Travel Rule requirements are resolved:
- Deposit sent from a VASP (an exchange or custodial provider): the sender's VASP must transmit a Travel Rule message identifying the originator. The deposit is credited once that message is received and accepted.
- Deposit sent from a self-hosted wallet (including the beneficiary's own wallet): no VASP will send a Travel Rule message. After a waiting period, the origin address goes through automated compliance screening; the deposit is credited if the screening is clean, and goes to manual compliance review otherwise.
Once cleared, the deposit is credited and the usual PAYMENT_IN_COMPLETED webhook fires. Deposits below the threshold are credited immediately, without a hold.
To make sure the sender's VASP can address the Travel Rule message correctly, give the depositor the beneficiary's Travel Rule deposit information along with the wallet address:
curl 'https://api.sandbox.caliza.com/core-api/v1/beneficiaries/{{beneficiaryId}}/travel-rule/deposit-info' \
--header 'Authorization: Bearer {{ACCESS_TOKEN}}'{
"vaspName": "Caliza",
"vaspDid": "did:ethr:0x...",
"beneficiaryName": "Acme Corp LLC"
}The sender provides these values to their exchange when originating the transfer, so the exchange can send the Travel Rule message to Caliza (the beneficiary VASP). The endpoint returns 204 No Content when Travel Rule deposit info is not available for the account.
Related Articles
Updated about 1 month ago
