---
name: cas-deeplink
description: "Integrate Cas Deeplink: integration steps, the APIs to call and the pre-production checklist."
---

# Cas — Deeplink

> Source: https://cas.so/en/product/deeplink · Markdown: https://cas.so/en/product/deeplink.md

_This skill is generated from the Cas documentation. When you need details (schemas, error codes, examples), fetch the latest Markdown from the links below instead of guessing._

## When to use this skill

When integrating, extending or debugging Cas **Deeplink** in your system.

## Product summary

Deeplink (short for mobile deep link) is a mobile technology that functions similarly to a website URL.
It enables navigation from a mobile app (or a website) to a financial application that the customer wants to use for making a payment.
After the payment is completed, the deep link redirects the customer back to your application.

## Scopes

Not derivable from the docs — read the product page for the exact `scopes` value.

## Integration flow

Below are the steps to integrate Deep Link into your product:

1. Retrieve the list of supported financial apps that offer Deep Link functionality via the endpoint [/deeplink/apps](https://cas.so/en/general/api/get-deeplink-apps.md)

2. Generate a deeplinkUrl for the payment based on the recipient's information and the selected financial app. [See details](https://cas.so/en/general/api/create-deeplink.md).

3. Open the deeplinkUrl returned from the API for your customer.

4. The financial app will launch and the payment information will be automatically filled in (for apps with autofill=1).

5. Once the payment is successful, the financial app will either automatically redirect or provide a button to navigate back to your application (for apps with autofill=1).

## APIs used in this flow

- [Deeplink Apps](https://cas.so/en/general/api/get-deeplink-apps.md)
- [Deeplink](https://cas.so/en/general/api/create-deeplink.md)

## Read before writing code

- [Cas core](https://cas.so/en/skills/cas-core/SKILL.md)
- [Cas Link](https://cas.so/en/general/link.md)
- [Webhook](https://cas.so/en/general/api/webhook.md)
- [Errors](https://cas.so/en/errors.md)

## Rules you must follow when writing code

- `clientId` / `secretKey` live on the server in environment variables only — never ship them to a client, never commit them.
- Request only the `scopes` the product needs; extra scopes mean extra cost and risk.
- Avoid duplicate grants: check your database for a live grant before opening Cas Link again.
- Store `accessToken` and `grantId` encrypted and linked to your user; one user may hold several grants. Never surface these values in the UI.
- Log `requestId` (on every response) and `grantId` (on grant-related responses) for every call — this is what Cas support needs to trace an issue.
- Every API call needs a timeout and backoff retry for transient failures; never blindly retry money-moving calls (use your own idempotency key).
- Webhooks: accept them only from Cas IPs, return 2xx fast and process asynchronously, and make handling idempotent — deliveries can repeat or arrive out of order.
- Handle `GRANT_LOGIN_REQUIRED` by reopening Cas Link in Update mode instead of making the user relink from scratch.
- Handle `GRANT` webhooks: `USER_PERMISSION_REVOKED`, `GRANT_DELETED`, `GRANT_PAUSED`, `DEFAULT_UPDATE` — reflect the link state in your system.
- Call `/grant/remove` when a user unlinks in your app, and handle the OTP-verification branch.
- Run the whole flow on `https://sandbox.bankhub.dev` first; switch to `https://production.bankhub.dev` together with the production secrets.

## Before going to production

Verify against the **entire** production checklist: https://cas.so/en/launch-checklist.md

For every checklist item, point at the code (file path + line) that proves it is handled, or state why it does not apply. Never tick an item without evidence.

## Other Cas skills

Full catalogue (use it to add more Cas products later):

https://cas.so/en/skills/index.json
