> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sahlfinancial.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Coverage

> Capability by availability: API key, console, or not available. No roadmap.

Read on 2026-10-07 from the Sahl API code. "API key" means a key with the stated scope calls it. "Console" means a signed-in member does it in the console with a session. "Not available" means no route does it for that audience. This page states what the code does today and nothing about the future.

<Card title="Upgrade for real bank connections" icon="building-columns" href="https://sahlfinancial.com/use-cases" horizontal>
  Real bank connections are not available in production yet: outside the sandbox the console routes answer `409 bank_connect_unavailable`. The sandbox simulates them on every workspace. Talk to Sales about a pilot.
</Card>

There are two API references. The [Partner API](/api-reference/introduction) is what a key can call. The [Console API](/console-api/overview) documents, for information, the routes the console calls with a login session; it is not available with an API key. Where a row says "Console API reference", that capability is documented there.

| Capability | API key | Console |
| - | - | - |
| Document reading | Yes: `POST /v1/kyc/extract`, scope `kyc:extract` | Yes: Upload page |
| Verification of a profile | Yes: `POST /v1/kyc/verify`, scope `kyc:verify` | Per-document checks on staff uploads only |
| Risk assessment | Yes: `POST /v1/kyc/assess`, scope `kyc:verify` | Credit score on a case (a different result) |
| eID | Yes: `POST /v1/kyc/eid`, `GET /v1/kyc/eid/{key}`, `GET /v1/kyc/eid/{key}/report`, scope `kyc:eid` | Not available |
| Bank connections | Not available | Sandbox simulation only; `409 bank_connect_unavailable` otherwise. [Console API reference](/console-api/overview) |
| Cases | Not available (your `reference` groups the calls) | Yes. [Console API reference](/console-api/overview) |
| Policies (scoring) | Not available | Yes, admin. [Console API reference](/console-api/overview) |
| Policies (KYC rules for `/v1/kyc/*`) | Applied to your calls, not editable by key | Yes, admin, versioned |
| Webhooks: receive events | Yes: signed deliveries to your URL | Delivery log |
| Webhooks: manage endpoints | Not available | Yes, admin or API manager. [Console API reference](/console-api/overview) |
| API keys: manage | Not available | Yes, admin or API manager. [Console API reference](/console-api/overview) |
| Call log | Not available | Yes |
| Review queue | Not available | Routes exist, no console page calls them |
| Flows | Not available | Yes. [Console API reference](/console-api/overview) |
| Ask Sahl | Not available | Yes |

## How this was decided

* A route is key-authenticated when it needs an API key with a scope and not a signed-in console session. This is the same rule the console uses to build your OpenAPI.
* Applying it to all 179 operations the API generates found 10 such routes: the 6 documented here and 4 partner-program routes that Sahl does not publish. Every other route needs a session.
* The same 10 appear on every release line that has a partner API, so the count does not depend on which one you read.

Next: [Console features](/console-features).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.