LH
Lee Hartley
Total AUC (All Clients)
Loading…
 
Active Clients
Loading…
 
Payments MTD
Loading…
Month-to-date
Flags & Alerts
Not yet wired
Review →
Platform Activity
View all →
Loading platform activity…
Client Breakdown
Total clients
With accounts
Onboarding queue
Restricted accounts
(not yet wired)
Total accounts (Griffin)
Griffin API Health
API status
— Loading
Base URL
Org ID
Webhook delivery
(not yet wired)
FPS rail
(not yet wired)
All Credit Unions Limited Cos Onboarding With accounts
Client Type Griffin Account KYC Status Account Status Balance Pmts (MTD) Last Activity
Loading clients from Griffin…
Available Balance
 
Payments MTD
Out
In
Member Accounts
 
Accounts & money
Operating Account
Bank accounts
Select a client to load
Recent Transactions
GET /v0/bank/accounts/ba_.../transactions
DateAccountDescriptionReferenceTypeAmountBalance After
Select a client to load transactions.
Configuration
Portal Features
GET /api/features/{lp_id}
Which pages this client sees in the MemberPay partner portal. Locked items (e.g. Dashboard) are always on. Save writes through to the proxy; the partner portal reads on next page load.
Select a client to load features.
People & access
Governing Body & Senior Managers
People responsible for this society — senior-manager-function-holders and governing-body-members. Each is a Griffin legal-person (individual) linked to this society via role-association claims.
Select a client to load officers.
GET /v0/legal-persons/{lp_id}/claims
Griffin Verify model. OnePay creates a legal person in Griffin and submits onboarding claims. Griffin's automated checks run in real time. A decision-created webhook fires when a decision is made (accepted / declined / requires-attention).
Loading onboarding queue…
All Not submitted Pending Submitted Delivered Failed
TimeClientRecipientReferenceRailStatusAmount
Loading payments from Griffin…
Preview data. OnePay's flagging rules (large-payment thresholds, CoP mismatches, returned FPS, KYC requires-attention) need a rules engine in front of the Griffin webhook stream before this page can show live alerts.
Large single payment — Example Client A
High Priority
£85,000 FPS outbound submitted at 08:55 today. Exceeds this client's typical single-payment pattern (avg £12,400). Griffin payment pending submission.
ClientExample Client A
Amount£85,000
RecipientVarious (batch)
CoP resultMatch
Payment held — not yet submitted to Griffin FPS rail
Payment returned — Example Client B
Medium
FPS payment PAY-EX-0337 (£3,200) was returned by the recipient bank. Reason: account-closed. Funds credited back to the client's account. Client notification not yet confirmed.
event: payment-submission-updated · status: payment-returned · pmt_example
KYC requires-attention — Example Client C
Medium
Griffin returned decision: requires-attention. Manual review needed before the embedded account can be activated. Likely cause: director address history mismatch.
event: decision-created · outcome: requires-attention · lp_example
API Requests Today
2,847
Across all endpoints
Webhook Events (24h)
341
100% delivered
Concurrent Requests
12 / 50
Within Griffin limit
Endpoint Usage (Today)
EndpointCallsErrors
GET /v0/bank/accounts/{id}/transactions1,2040
GET /v0/bank/accounts/{id}8920
POST /v0/bank/accounts/{id}/payments1470
POST /v0/payments/{id}/submission1443
POST /v0/organizations/{id}/cop-request2030
POST /v0/organizations/{id}/legal-persons20
Webhook Events
payment-submission-updated
● Active
transaction-created
● Active
decision-created
● Active
Delivery rate (24h)
100%
Events delivered (24h)
341
API Keys
Live key
live_key_****8f2a
Sandbox key
sandbox_key_****3c1d
Environment
● Live
Default Client Settings
Onepay Griffin Organisation
Organisation ref
(from /health)
Griffin relationship
Controller
Client role
Account owner
Onboarding model
Verify
Max legal persons
Unlimited
FPS capability
● Enabled
GET /v0/organizations/{org-id}
Active Keys
23
2 Griffin · 21 client
0 expiring soon
API Calls Today
4,812
Across all clients
↑ 12% vs yesterday
Webhook Delivery
99.6%
Last 24 hours
3 retries queued
Last Key Rotation
12 days ago
Griffin live key · 16 Mar
View →
Griffin Org Keys
Client API Keys
Webhooks
Access Log
These are OnePay's organisation-level API keys for the Griffin Bank API. They are used server-side only and should never be exposed to clients. Rotate every 90 days minimum.
Live API Key Active
Used for all production Griffin API calls · api.griffin.com/v0/
GK-LIVE-•••••••••••••••••••••••••••••••• Show key Copy
Created
16 Mar 2026
Last Used
2 mins ago
Calls (24h)
4,812
Next rotation due
14 Jun 2026
Scopes
payments:write accounts:write accounts:read legal-persons:read legal-persons:write webhooks:read webhooks:write org:admin
Sandbox API Key Sandbox
Non-production testing · sandbox.griffin.com/v0/ · no real money movement
GK-SAND-•••••••••••••••••••••••••••••••• Show key Copy
Created
01 Jan 2026
Last Used
1 hour ago
Calls (24h)
238
Environment
Sandbox
Live API Key (previous) Revoked
Rotated on 16 Mar 2026 · Retained for 30-day audit period
GK-LIVE-████████████████████████████████ Revoked 16 Mar 2026
21 active keys across 18 clients — issued for direct API integration with MemberPay
CA
Example Client A Active
Production key · Issued 01 Feb 2026 · Expires 01 Feb 2027
MP-••••-••••-••••-••••-ClientA Show key Copy
Last used
5 mins ago
Calls today
1,204
Error rate
0.02%
Expires
01 Feb 2027
Scopes
payments:read payments:write accounts:read transactions:read payees:read payees:write
CB
Example Client B Active
Production key · Issued 14 Feb 2026 · Expires 14 Feb 2027
MP-••••-••••-••••-••••-ClientB Show key Copy
Last used
22 mins ago
Calls today
874
Error rate
1.4%
Expires
14 Feb 2027
payments:read accounts:read transactions:read
CC
Example Client C Expiring soon
Production key · Issued 01 Apr 2025 · Expires 01 Apr 2026 (4 days)
This key expires in 4 days. Renew it now to avoid service disruption for Example Client C. An email reminder has been sent to their account admin.
CD
Example Client D Revoked
Revoked 10 Mar 2026 · Reason: Client offboarded · Retained 90 days
Preview — not wired to live key management
Griffin delivers webhook events to your platform endpoint first. MemberPay then fans them out to each client's configured endpoint. All deliveries are signed with HMAC-SHA256.
OnePay Platform Endpoint (Griffin → OnePay)
Healthy
https://api.onepay.co.uk/webhooks/griffin Copy URL
99.6%
Delivery rate (24h)
1,847
Events received (24h)
3
Retries queued
142ms
Avg response time
Subscribed events
payment-submission-updated transaction-created decision-created verification-updated account-status-updated
Client Webhook Endpoints (OnePay → Clients)
CA
Example Client A
https://api.example-client-a.example/hooks/memberpay
Active
100%
Delivery (24h)
312
Events sent
0
Failures
88ms
Avg response
payment-submission-updated transaction-created decision-created
CB
Example Client B
https://api.example-client-b.example/payments/webhook
Degraded
94.1%
Delivery (24h)
187
Events sent
11
Failures
3,420ms
Avg response
11 failed deliveries in the last 24h. Retrying with exponential backoff (next attempt in 4 min). View retry queue →
CC
Example Client C
No endpoint configured
Not set
Method
Endpoint
Status
Client
Time
POST/v0/bank/accounts/{id}/payments201Example Client A10:47:32
GET/v0/bank/accounts/{id}/transactions200Example Client A10:47:28
POST/v0/payments/{id}/submission200Example Client A10:47:15
GET/v0/bank/accounts/{id}200Example Client B10:46:54
POST/v0/organizations/{id}/cop-request201Example Client B10:46:41
POST/v0/bank/accounts/{id}/payments422Example Client B10:46:38
GET/v0/legal-persons/{id}/decisions200Example Client C10:45:59
PATCH/v0/bank/accounts/{id}/restrictions200OnePay Internal10:44:12
GET/v0/bank/accounts/{id}/transactions200Example Client A10:43:07
POST/v0/legal-persons/{id}/verifications201OnePay Internal10:41:55
POST/v0/organizations/{id}/legal-persons201OnePay Internal10:31:02
GET/v0/bank/accounts/{id}401Unknown (revoked key)10:28:44
Showing 12 of 4,812 calls today