> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stableyard.fi/llms.txt
> Use this file to discover all available pages before exploring further.

# Get the hosted payment-verification action

> Read the remaining fields for the action bound to the browser session.

Reads the action bound to the HttpOnly cookie from [Exchange action code](/api-reference/hosted-kyc/exchange-action-code). The request must come from the configured hosted origin. The browser sends the cookie; an app secret or Payment client secret does not replace it.

The response contains `action` and `csrfToken`. Render the returned `fields` using their keys, labels, types and options; only still-missing fields are returned. Use the CSRF token when [submitting those fields](/api-reference/hosted-kyc/submit-fields). Do not log or cache identity data or credentials. Responses use `Cache-Control: no-store, private`.


## OpenAPI

````yaml frontend-openapi.json GET /v2/public/partner-kyc-actions/me
openapi: 3.1.0
info:
  title: Stableyard Interfaces & SDK API
  version: 2.0.0-staging
  x-stableyard-api-version: '2026-09-09'
  x-stableyard-supported-api-versions:
    - '2026-09-09'
  summary: >-
    Advanced browser API used by Stableyard Checkout, Add Money, and
    account-bound interfaces.
  description: >

    These endpoints power Stableyard's official interface SDKs, hosted checkout,
    Add Money, and advanced custom browser integrations.


    Most partners should use `@stableyard/react` or `@stableyard/sdk` instead of
    calling these routes directly. A browser must never receive an app secret.
    Public checkout uses a Payment-scoped client secret, while account-bound
    experiences use a short-lived client bearer token created by the partner
    backend.
  x-stableyard-documentation-surface: frontend
servers:
  - url: https://prod-api.stableyard.fi
    description: Production
  - url: https://staging-api-v2.stableyard.fi
    description: Staging
  - url: http://localhost:3001
    description: Local
security: []
tags:
  - name: Authentication
    x-displayName: API authentication
    description: Verify your app ID and app secret before calling UPA APIs.
  - name: Client API
    description: >-
      Account-bound browser and mobile routes authenticated with a short-lived
      client bearer token. App secrets never enter client code.
  - name: Identity & KYC
    description: >-
      Verify the UPA email and run provider-neutral identity verification.
      Managed vaults and fiat payment rails use this same verified UPA identity.
  - name: Payments
    description: >-
      Create escrow-first payments, issue partner-authenticated send
      instructions or executions, power public checkout, and reconcile
      collection through final account settlement.
paths:
  /v2/public/partner-kyc-actions/me:
    get:
      tags:
        - Identity & KYC
      summary: Get the active hosted payment-compliance action
      description: >-
        Reads the action bound to the HttpOnly browser cookie. Only the
        still-missing provider-neutral fields are returned.
      operationId: getHostedPaymentComplianceAction
      responses:
        '200':
          description: Hosted action and CSRF proof
          headers:
            Stableyard-Version:
              description: >-
                Effective date-based Stableyard API contract version for this
                response.
              schema:
                type: string
                enum:
                  - '2026-09-09'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HostedPaymentComplianceEnvelope'
              examples:
                example:
                  summary: Get the active hosted payment-compliance action 200 response
                  value:
                    action:
                      id: info_req_1234567890abcdef
                      app:
                        name: Example account
                      capability:
                        name: external_payout
                        label: Payment verification
                      status: pending_user_input
                      expiresAt: '2026-08-28T10:00:00.000Z'
                      emailVerification:
                        required: false
                        verifiedAt: null
                      fields:
                        - key: example
                          type: text
                          label: example
                          description: Example payment
                          options:
                            - example
                      documents: []
                      disclosures: []
                    csrfToken: ccccccccccccccccccccccccccccccccccccccccccc
        '403':
          $ref: '#/components/responses/Forbidden'
        '410':
          $ref: '#/components/responses/Gone'
      security:
        - partnerKycSessionCookie: []
components:
  schemas:
    HostedPaymentComplianceEnvelope:
      type: object
      additionalProperties: false
      required:
        - action
        - csrfToken
      properties:
        action:
          $ref: '#/components/schemas/HostedPaymentComplianceAction'
        csrfToken:
          type: string
          pattern: ^[A-Za-z0-9_-]{43}$
          example: ccccccccccccccccccccccccccccccccccccccccccc
    HostedPaymentComplianceAction:
      type: object
      additionalProperties: false
      required:
        - id
        - app
        - capability
        - status
        - expiresAt
        - emailVerification
        - fields
        - documents
        - disclosures
      properties:
        id:
          type: string
          pattern: ^info_req_[A-Za-z0-9]+$
          example: info_req_1234567890abcdef
        app:
          type: object
          additionalProperties: false
          required:
            - name
          properties:
            name:
              type: string
              minLength: 1
              maxLength: 120
        capability:
          type: object
          additionalProperties: false
          required:
            - name
            - label
          properties:
            name:
              type: string
              const: external_payout
            label:
              type: string
              const: Payment verification
        status:
          type: string
          enum:
            - pending_user_input
            - completed
        expiresAt:
          type: string
          format: date-time
        emailVerification:
          type: object
          additionalProperties: false
          required:
            - required
            - verifiedAt
          properties:
            required:
              type: boolean
              const: false
            verifiedAt:
              type: 'null'
        fields:
          type: array
          maxItems: 32
          items:
            $ref: '#/components/schemas/HostedPaymentComplianceField'
        documents:
          type: array
          maxItems: 0
        disclosures:
          type: array
          maxItems: 0
    ErrorResponse:
      type: object
      additionalProperties: false
      required:
        - error
      properties:
        error:
          type: object
          additionalProperties: false
          required:
            - code
            - message
          properties:
            code:
              type: string
              minLength: 1
              maxLength: 128
              example: bad_request
            message:
              type: string
              minLength: 1
              maxLength: 1000
              example: The request is invalid
            details: {}
    HostedPaymentComplianceField:
      type: object
      additionalProperties: false
      required:
        - key
        - type
        - label
        - description
        - options
      properties:
        key:
          type: string
          minLength: 1
          maxLength: 64
        type:
          type: string
          enum:
            - text
            - sensitive_text
            - date
            - country
            - select
        label:
          type: string
          minLength: 1
          maxLength: 160
        description:
          type: string
          minLength: 1
          maxLength: 500
        options:
          type: array
          maxItems: 32
          items:
            type: string
            minLength: 1
            maxLength: 96
  responses:
    Forbidden:
      description: The app secret does not include the required scope
      headers:
        Stableyard-Version:
          description: >-
            Effective date-based Stableyard API contract version for this
            response.
          schema:
            type: string
            enum:
              - '2026-09-09'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            example:
              summary: Forbidden response
              value:
                error:
                  code: bad_request
                  message: The request is invalid
                  details: example
    Gone:
      description: The one-time action is invalid, expired, consumed, or no longer active
      headers:
        Stableyard-Version:
          description: >-
            Effective date-based Stableyard API contract version for this
            response.
          schema:
            type: string
            enum:
              - '2026-09-09'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            example:
              summary: Gone response
              value:
                error:
                  code: bad_request
                  message: The request is invalid
                  details: example
  securitySchemes:
    partnerKycSessionCookie:
      type: apiKey
      in: cookie
      name: __Host-stableyard_partner_kyc
      description: >-
        Scoped HttpOnly cookie set by POST
        /v2/public/partner-kyc-actions/{code}/exchange. The browser sends it
        automatically from the configured hosted origin; non-secure local
        development uses stableyard_partner_kyc. It is not an app secret or
        bearer token.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.