piiData object in extraParameters of POST /transactions.
This doesn’t go through a Travel Rule provider or your Travel Rule policy. Fireblocks passes the data directly to the exchange, and the exchange applies its own requirements.
Fireblocks doesn’t validate piiData. The API accepts any payload, so it’s up to you to send the fields the exchange requires for each transaction. Requirements differ by venue, direction, relationship, and, for Binance, jurisdiction. When piiData is missing or incomplete, the transaction may fail if the exchange requires Travel Rule data.
You can also provide this data in the Console. See Exchanges Travel Rule Overview on the Help Center.
Supported venues
Each venue has its own guide, with the fields it requires for every direction and scenario.
TrustCo is a custodian, not an exchange; it’s covered here because its requirements work the same way. It’s unrelated to TRUST, the Travel Rule network.
How it works
- Work out which fields to send. See Find the fields to send.
- Build the
piiDatapayload. - Get the public key for encryption.
- Encrypt every value in
piiData.data. - Create the transaction with the encrypted
piiDatainextraParameters.
Find the fields to send
Answer these in order, then look up the matching row in the venue’s guide:- Venue: Binance, Bitstamp, Bitfinex, OKX, or TrustCo.
- Direction: withdrawal from the exchange, or deposit to it.
- Jurisdiction (Binance only): the country of your Binance entity, sent as
vaspCountry. - Relationship: is the other party you (
FirstParty) or someone else (ThirdParty)? - Counterparty wallet: a private (unhosted) wallet, or an account at another VASP?
- Entity type:
IndividualorBusiness.
The piiData payload
type and typeVersion stay in plain text. Everything inside data is encrypted.
Which party you describe depends on direction:
Party fields
VASP fields
Transaction fields
Encryption
Exchanges require RSA-only encryption. Hybrid encryption (RSA with AES) is rejected.- Algorithm: RSA-OAEP with SHA-256.
- Scope: encrypt each value in
dataindividually, keeping the object structure. The result is the same shape, with every value replaced by a base64-encoded ciphertext. - Key: encrypt with your workspace’s exchange public key. This is a workspace-wide key, not tied to any specific exchange. Get it with Get public key to encrypt exchange credentials.
Example: encrypt the payload and create the transaction
1. Initialize the Fireblocks SDK.piiData values with the public key.
piiData in extraParameters.
piiData object for a specific scenario, see the venue’s guide.
Before you go live
- Map your customer data to the
piiDatafields each venue requires. - Decide the required fields per transaction, following Find the fields to send.
- Check that the plaintext PII matches the KYC records you hold.
- Test in a sandbox workspace.