# payment.save

Replace your own payment details. Saved numbers are never shown again in full. Change bank details in your contractor portal. Agents and API tokens can't replace payment details.

`POST /api/v1/contractor/payment.save`

Permissions: `contractor:read`, `contractor:write` · Roles: contractor · Idempotency key required · Send `expectedRevision`

**INTERACTIVE_PORTAL_REQUIRED.** Only the contractor does this, in their own portal. API and MCP calls are refused with a portalUrl to the exact step.

MCP tool: `contractor_payment_save`

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `expectedRevision` | integer or null |  | The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |
| `method` | enum | Yes | One of: `wise_email`, `bank_transfer`, `interac`, `other`. |
| `currency` | string | Yes | Three-letter currency code, such as CAD or USD. |
| `details` | object | Yes | No other fields. |
| `details.wiseEmail` | string (email) or null |  |  |
| `details.wiseLink` | string or null |  |  |
| `details.accountHolderName` | string or null |  |  |
| `details.bankName` | string or null |  |  |
| `details.bankAddress` | string or null |  |  |
| `details.accountNumber` | string or null |  |  |
| `details.swiftBic` | string or null |  |  |
| `details.iban` | string or null |  |  |
| `details.institutionNumber` | string or null |  |  |
| `details.transitNumber` | string or null |  |  |
| `details.routingNumber` | string or null |  |  |
| `details.accountType` | enum or null |  | One of: `checking`, `savings`. |
| `details.country` | string or null |  |  |
| `details.interacEmail` | string (email) or null |  |  |
| `details.otherInstructions` | string or null |  |  |
| `replaceUnreadable` | boolean |  |  |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/contractor/payment.save \
  -H "Authorization: Bearer $OATMILK_OAUTH_TOKEN" \
  -H "X-Accounting-Organization: $OATMILK_ORGANIZATION_ID" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "method": "wise_email",
  "currency": "CAD",
  "details": {}
}'
```

Reference page: https://app.getoatmilk.com/docs/api/contractor/payment.save
