# Set up Travel Rule

To set up Travel Rule, connect your Notabene account to Wallet-as-a-Service, prepare your address book, and then create Travel Rule policy rules on your wallets.

## Before you begin

| Requirement | Description |
|  --- | --- |
| **Feature access** | Ripple has turned on Travel Rule and Policy Engine v2 for your organization. |
| **Notabene account** | Your organization has its own Notabene workspace, with OAuth API credentials (client ID and client secret) and your VASP DID. |
| **Organization legal name** | Wallet-as-a-Service sends your organization's legal name as the originator. Confirm with Ripple that your organization's legal name is correct. |
| **Role** | You're an owner or administrator. Connecting Notabene changes organization settings. |


## Connect your Notabene account

1. In the Wallet-as-a-Service console, go to **Settings** > **Integrations**.
2. On the **Notabene** card, select **Connect**.
![The Integrations page with the Notabene card](/assets/travel-rule-integrations.2eb751f0201ecafd2f31f5b232b3f25296e01855d7c65b7fcf745a881715e31e.0ba50ef8.png)
3. Enter your **Client ID**, **Client secret**, and **Notabene VASP DID**. The DID looks like `did:ethr:0x…`.
4. Select **Connect**.


Wallet-as-a-Service checks the credentials and DID with Notabene, and then registers a webhook with Notabene so it receives message updates. The **Travel Rule** page shows your VASP name, VASP DID, webhook URL, and one of these statuses:

![The Travel Rule connection page with status Webhook pending, the VASP name and DID, and the webhook URL](/assets/travel-rule-connection.95e454feec4ba95e19057f1e4180ded2f9b9fbd4acd458d57a8e6c608f53f6c8.0ba50ef8.png)

| Status | Meaning |
|  --- | --- |
| **Connected** | The connection is ready, and you can create Travel Rule policy rules. |
| **Webhook pending** | The credentials are valid, and Wallet-as-a-Service stored the webhook signing secret. It's waiting for the first verified webhook delivery from Notabene. |
| **Credentials invalid** | Notabene rejected the credentials. Select **Update credentials** and enter new ones. |
| **Disconnected** | Your organization doesn't have a connected Notabene account. |


If Notabene rejects the credential and DID pair, the console shows an error and doesn't save the connection.

The **Notabene** card on the **Integrations** page shows **Connected** as soon as you save the connection, even while the **Travel Rule** page shows **Webhook pending**. To check the connection status, select **View** on the card.

One connection per DID
Notabene delivers updates for a VASP DID to one webhook only. If two of your Wallet-as-a-Service organizations connect with the same DID, only the organization that connected most recently receives updates. Use a separate DID for each organization.

### Disconnect Notabene

On the Notabene connection page, select **Disconnect**. Disconnecting removes your Notabene credentials and stops Travel Rule checks for your organization.

Your Travel Rule policy rules stay in place. While you're disconnected, Wallet-as-a-Service **rejects** every outbound transfer that matches a Travel Rule rule, with reason `TRAVEL_RULE_NOT_CONFIGURED`. If you no longer need the rules, delete them.

## Prepare your address book

Wallet-as-a-Service takes beneficiary information from your address book. For every external destination that a Travel Rule rule covers:

1. Save the destination as an address on a [counterparty](/products/wallet/admin-guide/manage-counterparties) of type **organization**, with its legal name.
2. On the address, select **Add custodian details**. Under **Select custodian**, enter the beneficiary VASP's name, select **Search**, and then select the VASP from the Notabene directory.
3. Confirm that the custodial information is correct, and then select **Add address**. The address takes effect after your **Addresses** approvers approve it.
![The Add address form with custodian details added](/assets/address-book-custodian-details.b35ccdc667488485234038a7a7a569d92e7b935e7cd54ab7e577920a672f9dce.0ba50ef8.png)


Wallet-as-a-Service rejects a covered transfer to a destination that isn't in the address book, has no custodian details, or belongs to an individual counterparty.

## Create a Travel Rule policy rule

You need a connected Notabene account before you can create Travel Rule rules. Without one, the console shows **Integrate a travel rule provider to add this policy type**, and the API returns `PAL006.046`.

### In the console

1. Open the wallet and go to the **Policy** tab.
2. Select **Add a new rule**.
3. On the **Direction** step, select **Outbound** for transfers from this wallet, or **Inbound** for deposits into this wallet, and then select **Next**.
4. On the **Conditions** step, select the asset, and then select **Travel rule** under **Rule**.
5. For an outbound rule, select a level under **Release the withdrawal when**. See [Release levels](#release-levels).
![The Conditions step for an outbound Travel rule, with the four release levels](/assets/policy-stepper-travel-rule-conditions.6ebe25d031ab2a259ab52960b368d7ef643de50840b30be7efd3549fd824dfe5.0ba50ef8.png)
6. On the **Scope** step, select the destinations the rule covers. For an inbound rule, the selection applies to the **sender**, even though the step labels it **To**.
7. On the **Advanced** step, leave **All** selected, or restrict the rule to one user or API credential.
8. On the **Confirm** step, review the rule, and then select **Add policy rule**.


The console creates a Travel Rule rule for one asset, with no amount threshold. To cover all assets, or only transfers of more than an amount, [use the API](#with-the-api).

### With the API

```
POST /v2/vaults/{vaultId}/wallets/{walletId}/policy-rules
```

**Outbound:** This rule requires an accepted Travel Rule exchange for counterparty transfers of more than 1,000 of the asset:

```json
{
  "trigger": "OUTBOUND_INITIATED",
  "assetId": "3::XRP",
  "matchers": [
    { "type": "ALL_COUNTERPARTIES", "values": [] }
  ],
  "definition": {
    "kind": "TRAVEL_RULE",
    "travelRule": {
      "travelRuleReleaseLevel": "TRAVEL_RULE_RELEASE_LEVEL_ACCEPTED",
      "amount": {
        "threshold": "1000",
        "operator": "GT",
        "aggregation": "SINGLE_TX"
      }
    }
  }
}
```

**Inbound:** This rule checks every deposit into the wallet, for any asset:

```json
{
  "trigger": "INBOUND_DETECTED",
  "definition": {
    "kind": "TRAVEL_RULE",
    "travelRule": {}
  }
}
```

| Field | Rules |
|  --- | --- |
| `trigger` | Set to `OUTBOUND_INITIATED` or `INBOUND_DETECTED`. |
| `assetId` | Optional. To cover all assets, leave it out. If you set `amount`, you must also set `assetId`. |
| `travelRule.travelRuleReleaseLevel` | Outbound rules require it. Inbound rules don't accept it. |
| `travelRule.amount` | Optional. Set the operator to `GT` and the aggregation to `SINGLE_TX`. If you leave out the amount, the rule covers every matching transfer. |
| `matchers` | Optional. On outbound rules, destination matchers match the recipient. On inbound rules, they match the **sender**. |


### Release levels

The release level sets how far the outbound Travel Rule message must progress before Wallet-as-a-Service lets the transfer continue to signing.

| API value | Console label | The transfer continues when |
|  --- | --- | --- |
| `TRAVEL_RULE_RELEASE_LEVEL_NEW` | Message created | Notabene creates the message. |
| `TRAVEL_RULE_RELEASE_LEVEL_SENT` | Message sent | The message reaches the beneficiary VASP. |
| `TRAVEL_RULE_RELEASE_LEVEL_ACK` | Address confirmed | The beneficiary VASP confirms the destination address. |
| `TRAVEL_RULE_RELEASE_LEVEL_ACCEPTED` | Transfer accepted | The beneficiary VASP accepts the transfer. The console selects this level by default. |


A stricter level is safer but slower. If the counterparty doesn't respond, the transfer waits until it times out.

### When more than one rule applies

If several Travel Rule rules apply to the same transfer, the most specific rule wins. For example, a rule for one counterparty overrides a rule for the whole wallet. When rules are equally specific, a rule with an amount threshold overrides a rule without one.

### What Travel Rule rules don't cover

- Sweeps, Web3 signing, plaintext signing, passkey signing, and passkey transfers.
- Transfers to your own wallets, unless a rule covers them. A rule with no matchers, or with a `WALLET_ID` matcher, covers transfers to your own wallets. Wallet-as-a-Service sends these as same-VASP transfers, which Notabene settles without a counterparty response. Rules with `ALL_COUNTERPARTIES`, `COUNTERPARTY_ID`, or `ADDRESS_ID` matchers don't cover your own wallets.


## Related documentation

- [Travel Rule transactions](/products/wallet/user-interface/travel-rule/travel-rule-transactions)
- [Policy rules (Policy Engine v2)](/products/wallet/user-interface/policies/policy-rules-v2)
- [Manage counterparties](/products/wallet/admin-guide/manage-counterparties)