Skip to main content

WorldFirst

Use this source to synchronize the StatementList stream from WorldFirst.

Connection methods​

  • Use your own application: configure the WorldFirst application authorized to read your account. Its credentials are specific to your source.
  • Authorize through Daspire: planned, not yet available. This option remains disabled until Daspire's partner application and the customer authorization flow are verified. An existing customer's application is not automatically a shared Daspire application.

Set up your own application​

  1. Select WorldFirst and enter the source name.

  2. Select Account region using the region assigned to your WorldFirst application, not your current location. Daspire maps the selection to an API address; do not enter an API path.

    Account regionAPI address
    Singapore (SG)https://open-sea.worldfirst.com
    Europe (EU)https://open-eu.worldfirst.com
    United States (US)https://open-na.worldfirst.com
  3. Enter the Application Client ID from your WorldFirst application. This is an application identifier, not the customer account ID.

  4. Enter the application's RSA private key in the secure field. Do not send private keys in chat or support tickets.

  5. Choose Verification mode. The default verifies response signatures and requires the WorldFirst platform public key from Integration Setting or WorldFirst support, not the application public key you uploaded to WorldFirst. Alternatively, explicitly select Private key only — read-only compatibility mode to query statements without a platform key. HTTPS certificate verification stays enabled, but response digital signatures are not verified in this mode. Sandbox and production keys are different.

  6. Choose the acquisition method. For periodic acquisition, enter a number of days between 1 and 100; for manual acquisition, provide the start and end times.

  7. Save and test the source, then select the stream and destination in the connection workflow.

Existing saved API addresses retain their region. Creating a source does not default to an arbitrary region.

Compatibility mode is available only in the own-application workflow and only reads statements; it does not enable payments or transfers. Existing sources are not automatically switched. A source with a configured platform public key continues verifying responses and cannot downgrade or remove that key through credential repair. Adding a platform key upgrades a compatibility source to response verification. Invalid signatures never trigger fallback to compatibility mode.

If your own application requires an existing access token or a connected account ID, expand Application settings (optional) → Additional account authorization. These fields do not create Daspire-managed authorization or automatically renew your application's tokens.

Form fields and defaults​

Enter one Name for the source. For new WorldFirst sources, Daspire also uses it as the source_name label in synchronized records. Editing or copying an existing source preserves its saved record label, even when the display name differs. Other source connectors are unchanged.

Most applications do not need any optional settings. Expand Application settings (optional) only to change the key version (normally 1) or configure Additional account authorization. Supply an access token or connected account ID only when your application requires them; a supplied token also requires its connected account ID.

Expand Filter synchronized data (optional) only when you want to limit statements by currencies, transaction types, balance types or budget account IDs. Otherwise, leave the filters blank. Existing non-default settings open their corresponding sections for review. Collapsing a section preserves its saved and newly entered values.

Retry, timeout, request pacing, response verification tolerance, execution budget, query window and incremental overlap settings are managed by the platform and are hidden from the customer form. The connector uses its defaults for new sources; saving an existing source preserves any stored overrides. Hiding these controls does not disable response signature verification or change existing synchronization settings.

Troubleshooting​

Repair an existing Native source​

Save credentials separately from source name, account, region or replication changes. The credential-repair path accepts the application private key, WorldFirst public key, verification mode, key version and optional access token. Omitted or masked secret fields retain that source's existing encrypted values. Connect a different application or account as a new source.

All supplied keys must be RSA keys of at least 2048 bits; PEM and Base64 DER are accepted. The platform public key is optional only in explicitly selected compatibility mode. A successful save proves configuration persistence, not WorldFirst authorization. Run the source check and a controlled StatementList sync before treating the connection as usable. Check success in compatibility mode explicitly reports that response signatures were not verified.

If saving reports SOURCE_REAUTH_RECONCILE_REQUIRED or SOURCE_REAUTH_INTERRUPTED, contact support before retrying: scheduling may require reconciliation. Do not reset the connection or replace its checkpoint.

  • WorldFirst platform public key missing: supply the key for verified-response mode, or explicitly choose private-key-only read-only mode after reviewing its limitation. Absence of a key alone never enables compatibility mode.
  • Signature or authorization failure: verify the application Client ID, private key, key version, selected region, WorldFirst public key and account permissions.
  • Saved credentials: private keys are not returned in plaintext. Do not replace a saved key with a displayed masking value.
  • No public key field in an older UI: the deployed connector spec and form may be out of sync. Contact your Daspire administrator to update the connector metadata and web application.

Provider references: API overview, signing and verification, OAuth.