Skip to main content
GET
Get the active hosted payment-compliance action
Reads the action bound to the HttpOnly cookie from Exchange action code. The request must come from the configured hosted origin. The browser sends the cookie; an app secret or Payment client secret does not replace it. The response contains action and csrfToken. Render the returned fields using their keys, labels, types and options; only still-missing fields are returned. Use the CSRF token when submitting those fields. Do not log or cache identity data or credentials. Responses use Cache-Control: no-store, private.

Authorizations

__Host-stableyard_partner_kyc
string
cookie
required

Scoped HttpOnly cookie set by POST /v2/public/partner-kyc-actions/{code}/exchange. The browser sends it automatically from the configured hosted origin; non-secure local development uses stableyard_partner_kyc. It is not an app secret or bearer token.

Response

Hosted action and CSRF proof

action
object
required
csrfToken
string
required
Pattern: ^[A-Za-z0-9_-]{43}$
Example:

"ccccccccccccccccccccccccccccccccccccccccccc"