> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kirafin.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Surface map

Which operations are available where. The dashboard runs on the same API you build against, so almost nothing here is dashboard-only. Your webhook endpoints and your team are the exceptions.

| Operation                                          | API | Dashboard                 |
| -------------------------------------------------- | --- | ------------------------- |
| Create a sub-client                                | Yes | Yes                       |
| View sub-clients                                   | Yes | Yes                       |
| Open a virtual account                             | Yes | Yes                       |
| View accounts and balances                         | Yes | Yes                       |
| Save a counterparty                                | Yes | Yes                       |
| Price a movement                                   | Yes | Yes                       |
| Make a payout                                      | Yes | Yes, with a one-time code |
| View payouts and deposits                          | Yes | Yes                       |
| Answer a request for information                   | Yes | Yes                       |
| Complete an onboarding that is missing information | Yes | Yes                       |
| Register and manage a webhook endpoint             | —   | Yes                       |
| Look up or replay a delivery                       | —   | Yes                       |
| See who has dashboard access                       | —   | Yes                       |
| Change what a colleague can do                     | —   | Yes                       |

## The rows worth reading twice

**Creating a sub-client works on both, and belongs on the API.** The dashboard creates one from **Customers**, which is what you want for a handful onboarded by hand. Onboarding a customer is normally part of your product's own flow, though, and that is the API.

**Webhook endpoints are the dashboard alone.** Registering a URL, filtering its events, pausing it, rotating its secret and replaying a delivery all happen in the **Developers** section of the dashboard, and there is no `/v1` endpoint for any of them.

**Roles are a dashboard matter.** Who on your team may do what is set in the dashboard, by an administrator on your own team, and there is no `/v1` endpoint for it either. [Roles and permissions](/dashboard/roles) covers what each role grants.

**A dashboard payout takes a one-time code**, sent to the person making it, and an API payout does not. Same operation, same result, different check.

## Choosing between them

The question is not what is possible, it is who is doing it and how often:

* **Every time, automatically, inside your product** → the API.
* **Occasionally, by a person, with judgement involved** → the dashboard.

Answering a request for information is the clearest case for the second. Onboarding customers as they sign up inside your product is the clearest case for the first.

<Note>
  Whichever surface an operation happens on, the same webhooks fire. Your integration learns about a dashboard action without doing anything special, so you never have to reconcile the two.
</Note>
