Skip to main content
Some exchanges require Travel Rule information, the originator’s or beneficiary’s personal data (PII), for deposits to and withdrawals from your exchange account. You send it with the transaction itself, as an encrypted piiData object in extraParameters of POST /transactions. This doesn’t go through a Travel Rule provider or your Travel Rule policy. Fireblocks passes the data directly to the exchange, and the exchange applies its own requirements. Fireblocks doesn’t validate piiData. The API accepts any payload, so it’s up to you to send the fields the exchange requires for each transaction. Requirements differ by venue, direction, relationship, and, for Binance, jurisdiction. When piiData is missing or incomplete, the transaction may fail if the exchange requires Travel Rule data. You can also provide this data in the Console. See Exchanges Travel Rule Overview on the Help Center.

Supported venues

Each venue has its own guide, with the fields it requires for every direction and scenario. TrustCo is a custodian, not an exchange; it’s covered here because its requirements work the same way. It’s unrelated to TRUST, the Travel Rule network.

How it works

  1. Work out which fields to send. See Find the fields to send.
  2. Build the piiData payload.
  3. Get the public key for encryption.
  4. Encrypt every value in piiData.data.
  5. Create the transaction with the encrypted piiData in extraParameters.
Never send unencrypted PII in an API call.

Find the fields to send

Answer these in order, then look up the matching row in the venue’s guide:
  1. Venue: Binance, Bitstamp, Bitfinex, OKX, or TrustCo.
  2. Direction: withdrawal from the exchange, or deposit to it.
  3. Jurisdiction (Binance only): the country of your Binance entity, sent as vaspCountry.
  4. Relationship: is the other party you (FirstParty) or someone else (ThirdParty)?
  5. Counterparty wallet: a private (unhosted) wallet, or an account at another VASP?
  6. Entity type: Individual or Business.

The piiData payload

type and typeVersion stay in plain text. Everything inside data is encrypted. Which party you describe depends on direction:

Party fields

VASP fields

Transaction fields

Encryption

Exchanges require RSA-only encryption. Hybrid encryption (RSA with AES) is rejected.
  • Algorithm: RSA-OAEP with SHA-256.
  • Scope: encrypt each value in data individually, keeping the object structure. The result is the same shape, with every value replaced by a base64-encoded ciphertext.
  • Key: encrypt with your workspace’s exchange public key. This is a workspace-wide key, not tied to any specific exchange. Get it with Get public key to encrypt exchange credentials.

Example: encrypt the payload and create the transaction

1. Initialize the Fireblocks SDK.
2. Get your workspace exchange public key. The same key encrypts exchange credentials and PII values.
3. Encrypt the piiData values with the public key.
4. Create the transaction, with piiData in extraParameters.
For a complete plaintext piiData object for a specific scenario, see the venue’s guide.

Before you go live

  • Map your customer data to the piiData fields each venue requires.
  • Decide the required fields per transaction, following Find the fields to send.
  • Check that the plaintext PII matches the KYC records you hold.
  • Test in a sandbox workspace.

On the Help Center

To provide Travel Rule data for exchange transactions in the Console, see Exchanges Travel Rule Overview.