> ## Documentation Index
> Fetch the complete documentation index at: https://developers.staging01.melio.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# List beneficial owners

> The people recorded against the business for compliance: its ultimate beneficial owners, its directors, and the individual who acts for it towards the currency provider.

This is distinct from the entity's `owner`, which is the person the Melio account belongs to. The two are usually the same human, but `owner` carries no address, tax identifier or ownership stake, so it cannot satisfy international onboarding on its own.




## OpenAPI

````yaml /openapi.json get /entities/{entityId}/beneficial-owners
openapi: 3.0.3
info:
  title: Melio Payouts API
  version: '1.0'
  description: >
    Self-serve payouts API. Partners onboard an Entity, which is the business

    (organization plus owner, with the details required to be payment-eligible),

    then attach accounts (internal accounts and external accounts) and make

    payments.


    ## Resource ids


    Every resource has an opaque, prefixed id that is stable for the life of the
    resource:

    `ent_` (entity), `pay_` (payment), `acct_` (account, internal or external).

    Ids are Melio-issued; treat them as opaque strings and never parse or
    construct them. To

    attach your own identifier to a resource, use `externalId`.


    ## Pagination


    List endpoints are cursor-paginated and always return results newest-first

    (`createdAt` descending). The response envelope is:


    ```json

    { "data": [ /* resources */ ], "hasMore": true }

    ```


    Page through results with `limit` (1 to 50, default 50) plus a cursor:


    - `startingAfter=<id>`: return the page immediately **after** the given
    resource id
      (the next, older page). This is how you walk forward through a list.
    - `endingBefore=<id>`: return the page immediately **before** the given
    resource id
      (the previous, newer page).

    `startingAfter` and `endingBefore` are mutually exclusive. The cursor is a
    resource id

    you already received (e.g. the `id` of the last item on the current page),
    not an index.

    Keep requesting the next page until `hasMore` is `false`.


    ## Filtering & sorting


    Ordering is fixed (newest-first); there is no `sortBy`. To narrow a list,
    filter it.

    Each list endpoint documents its own filter parameters (there is no generic
    query

    language). Date-range filters use bracket suffixes and accept RFC 3339
    timestamps:

    `created[gte]`, `created[lte]`. Filter by your own identifier with
    `externalId`, and

    by metadata with `metadata[<key>]=<value>` (matches resources whose metadata
    contains

    every supplied key/value pair). Filters combine with AND and compose with
    pagination.


    ## External ids


    Every created resource accepts an optional `externalId`, your own unique
    identifier for

    the resource (≤255 chars, letters/digits/`-`/`_`). It is unique per partner
    per resource

    type: reusing one returns `409 DUPLICATE_EXTERNAL_ID`. Use it to correlate
    Melio resources

    with records in your system and to look resources up (`?externalId=`)
    without storing

    Melio ids. `externalId` identifies a *resource*; it is not a
    request-deduplication key

    (that is the `Idempotency-Key` header, below); the two are complementary.


    ## Idempotency


    Send an `Idempotency-Key` header on every create so retries are safe: the
    original response

    is replayed instead of creating a second resource. It is required on `POST
    /payments`.


    ## Metadata


    Most resources accept a `metadata` object: free-form string key/value pairs
    that Melio

    stores and returns verbatim but never interprets. Limits: up to 50 keys, key
    ≤40 chars,

    value ≤100 chars. Use it to stash your own structured context on a resource;
    it is also

    filterable (see above).


    ## Melio Sonar Session Token


    Write endpoints optionally accept a `Melio-Sonar-Token` header: a signed
    session token

    minted by the MelioSonar SDK on the end user's device, carrying device
    signals used for

    risk evaluation. Omit it when no SDK session is available.
  contact:
    name: Melio Platform External API
    email: platform@melio.com
servers:
  - description: Production
    url: https://api.melio.com/v2
  - description: Staging01
    url: https://api.staging01.melio.com/v2
security: []
tags:
  - name: Entities
    description: >-
      A business you onboard and operate on behalf of: its profile, compliance
      details, and per-operation limitations.
  - name: Accounts
    description: Accounts the entity pays from (internal) and payees it pays to (external).
  - name: Attachments
    description: Supporting documents an entity uploads once and references from a payment.
  - name: Payments
    description: >-
      Money moved from an internal account to an external account, and their
      lifecycle.
  - name: Tools
    description: >-
      Pre-flight calculators for fees, fast-payment eligibility, and delivery
      estimates. No resource is created.
  - name: Webhooks
    description: >-
      Your single endpoint for event notifications, and the events you can
      subscribe to.
paths:
  /entities/{entityId}/beneficial-owners:
    parameters:
      - name: entityId
        in: path
        required: true
        schema:
          type: string
    get:
      tags:
        - Entities
      summary: List beneficial owners
      description: >
        The people recorded against the business for compliance: its ultimate
        beneficial owners, its directors, and the individual who acts for it
        towards the currency provider.


        This is distinct from the entity's `owner`, which is the person the
        Melio account belongs to. The two are usually the same human, but
        `owner` carries no address, tax identifier or ownership stake, so it
        cannot satisfy international onboarding on its own.
      responses:
        '200':
          description: The business's beneficial owners. Empty until any are recorded.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BeneficialOwnerList'
        '404':
          description: Entity not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - ApiKey: []
components:
  schemas:
    BeneficialOwnerList:
      type: object
      required:
        - data
      properties:
        data:
          type: array
          items:
            $ref: '#/components/schemas/BeneficialOwner'
    ErrorResponse:
      type: object
      required:
        - error
      properties:
        error:
          $ref: '#/components/schemas/Error'
    BeneficialOwner:
      type: object
      description: >
        A person recorded against the business. Identifiers are never echoed in
        full — `taxInfo` reports only the last four digits, and
        `internationalId` only its last four characters.
      required:
        - id
        - firstName
        - lastName
        - dateOfBirth
        - address
        - usResident
        - types
        - hasIdentityDocument
      properties:
        id:
          type: integer
        firstName:
          type: string
        lastName:
          type: string
        dateOfBirth:
          type: string
          format: date
        address:
          $ref: '#/components/schemas/InternationalAddress'
        usResident:
          type: boolean
        ownershipPercentage:
          type: number
          description: Decimal share (0.25 = 25%)
        jobTitle:
          $ref: '#/components/schemas/BeneficialOwnerJobTitle'
        taxInfo:
          type: object
          properties:
            type:
              type: string
              enum:
                - ssn
                - itin
            identifierLast4:
              type: string
        internationalIdType:
          type: string
          enum:
            - passport
            - driver-license
            - national-id
        internationalId:
          type: string
          description: Last four characters of the identifier on file
        hasIdentityDocument:
          type: boolean
          description: >
            Whether a government ID is on file for this person. The document
            itself cannot be read back through this API.
        types:
          type: array
          items:
            $ref: '#/components/schemas/BeneficialOwnerType'
        email:
          type: string
        phoneNumber:
          type: string
        createdAt:
          type: string
          format: date-time
        updatedAt:
          type: string
          format: date-time
    Error:
      type: object
      required:
        - type
        - code
        - message
      properties:
        type:
          type: string
          description: >-
            Coarse, machine-readable error category. Branch on this to handle a
            whole class of failures without enumerating every `code`.
          enum:
            - invalid_request_error
            - authentication_error
            - authorization_error
            - not_found_error
            - conflict_error
            - rate_limit_error
            - service_unavailable_error
            - internal_error
        code:
          type: string
          description: Machine-readable error code.
          enum:
            - VALIDATION_ERROR
            - INVALID_ACCOUNT_TYPE
            - ACCOUNT_NOT_VERIFIED
            - INVALID_DELIVERY_PREFERENCE
            - MCC_REQUIRED
            - MERCHANT_ADDRESS_REQUIRED
            - GOODS_RECEIVED_REQUIRED
            - IDEMPOTENCY_KEY_REQUIRED
            - FEE_CALCULATION_FAILED
            - UNSUPPORTED_CURRENCY
            - FX_QUOTE_INVALID
            - ATTACHMENT_REQUIRED
            - COMPLIANCE_UPLOAD_FAILED
            - ATTACHMENT_UPLOAD_FAILED
            - INTERNATIONAL_NOT_ENABLED
            - ENTITY_ONBOARDING_INCOMPLETE
            - UNAUTHORIZED
            - NOT_FOUND
            - NO_ACTIVE_API_KEY
            - DUPLICATE_ENTITY
            - DUPLICATE_ACCOUNT
            - DUPLICATE_PAYMENT
            - DUPLICATE_EXTERNAL_ID
            - ACCOUNT_IN_USE
            - BUSINESS_NOT_ELIGIBLE
            - PAYMENT_NOT_EDITABLE
            - PAYMENT_NOT_CANCELABLE
            - IDEMPOTENCY_KEY_REUSED
            - IDEMPOTENCY_KEY_IN_PROGRESS
            - IDEMPOTENCY_STORE_UNAVAILABLE
            - INTERNAL_ERROR
        message:
          type: string
          description: Human-readable error message.
        details:
          type: object
          description: Additional error context (e.g. field-level validation failures).
    InternationalAddress:
      type: object
      description: >
        A counterparty address outside the US. Unlike `Address`, `state` is
        free-form (most countries have no state; send an empty string or omit
        it) and `postalCode` is not a US ZIP. `countryCode` is required and must
        not be `US` — a US-domiciled counterparty belongs on a domestic account
        type.
      required:
        - line1
        - city
        - postalCode
        - countryCode
      properties:
        line1:
          type: string
          description: Street address. Must be a real street address, not a PO box.
        line2:
          type: string
        city:
          type: string
        state:
          type: string
          description: >-
            State, province or region. Optional — send an empty string where the
            country has none.
        postalCode:
          type: string
        countryCode:
          type: string
          description: Two-letter ISO 3166-1 alpha-2 country code.
          pattern: ^[A-Za-z]{2}$
    BeneficialOwnerJobTitle:
      type: string
      enum:
        - chief-executive-officer
        - chief-financial-officer
        - managing-member
        - general-partner
        - president
        - vice-president
        - treasurer
    BeneficialOwnerType:
      type: string
      description: >
        The role a person holds in the business. `ubo` is an ultimate beneficial
        owner (someone with a material ownership stake), `director` is a control
        person, and `fx-account-holder` is the individual who acts for the
        business towards the currency provider. One person may hold several
        roles; exactly one person must be the `fx-account-holder`.
      enum:
        - ubo
        - director
        - fx-account-holder
  securitySchemes:
    ApiKey:
      type: apiKey
      in: header
      name: api-key

````