Creates a new Account under the given parent. Provisions the container that holds a customer's money, KYB, and tax artifacts before any other resource is attached. Principal / authorized-representative data is added separately through Stakeholder records (isPrincipal=true). For a root Account, the gateway assigns the authenticated Person as the bootstrap Account principal, which carries implicit Admin authority and selects that Person's onboarding lane. Clients cannot choose or read this compatibility pointer; replace it through POST /platform/accounts/{accountId}/transfer-principal. Child Account principals remain explicit. ServiceAccount API keys and Account sessions minted by ServiceAccounts can create children only: parentAccountId is required and must match the effective Account, with live Write authority and users.account:write permission. API keys must select that parent with X-Wingspan-Account. Account sessions must include descendants; their header is optional and defaults to the bound Account, or may select a descendant. These sessions inherit the minting key's scopes; the mint request cannot narrow them. To mint embedded sessions without child-create permission, use a key without users.account:write. Person callers MUST NOT send X-Wingspan-Account. Account-bound Person sessions, leaf Account sessions, and impersonation-issued sessions cannot create new Accounts. Idempotency-Key replay is partitioned by the effective Account whenever one exists, and by the authenticated Person only for unbound, headerless Person callers. The shared response cache may replay a stored response without executing a new create.
If externalId is supplied and already used by another resource of this type for the owning Account, the request returns 409 ResourceConflict; create is not an upsert. Use filter[externalId][eq] on the list endpoint to retrieve the existing resource.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||