Fully managed accounts

Create child accounts that your platform fully owns and operates, with full access to every resource and all notifications routed to you.

Who this section is for

Product, compliance, and engineering teams at businesses building platforms on the Create an account path that own and operate their child accounts end to end, so the child's authorized representative never deals with PayMongo directly.

What it is

A fully managed account is a child account that the parent fully owns and operates. It is an opt-in parent capability: your platform must be enrolled in full-access delegation before it can create one.

For a fully managed child:

  • Full access. The parent gets full access to every current and future resource on the child, bypassing per-module policy contract permissions.
  • Notifications go to the parent. All notifications and contact about the account go to the parent. PayMongo does not email the child's authorized representative about the account or its requests.
  • Dashboard access can be disabled. A fully managed child is eligible for Disable dashboard access, so the recipient never sees PayMongo.

When to use it

The common use case is a fully or partially white-labeled implementation. Your platform designs its own ecosystem and uses PayMongo's products as building blocks, so PayMongo powers each merchant's business or app behind your brand.

How to use it

Set fully_managed: true at the top level of the POST /v2/accounts body. See Create account for the full request schema.

curl --request POST \
     --url https://api.paymongo.com/v2/accounts \
     --header 'Content-Type: application/json' \
     --header 'authorization: Basic <base64-encoded-sk_parent_key>' \
     --data '{
       "type": "merchant",
       "fully_managed": true,
       "person": {
         "email_address": "[email protected]",
         "mobile_number": "+639991234567"
       }
     }'
  • Creation-time only. fully_managed is set when the account is created. Existing accounts are unaffected.
  • Not enrolled → 403. A parent that is not enrolled in full-access delegation receives 403 when it sends fully_managed.

Current state

📘

Available by email request

Email [email protected] from an authorized contact on your platform with your parent account ID (org_…) and a short description of how you operate your child accounts. PayMongo replies with the next steps for enrolling you in full-access delegation.

Related pages


Did this page help you?