Skip to main content
Identity verification (KYC) for an individual account runs on a page hosted by a verification provider. You start a session, send the customer to the verificationUrl it returns, and read the result. The hosted link is the only way to verify an individual. There is no partner-collected KYC: no API accepts identity data or documents from you, and the provider’s decision and documents are never returned to you.
1

Verify the email

KYC needs a verified email first. See Email verification.
2

Start a session

POST /v2/accounts/{accountId}/kyc/session. It returns the hosted verificationUrl.
3

Send the customer to the link

Open verificationUrl for the customer. The page takes no return URL and does not redirect back to you.
4

Wait for the result

Act on the kyc.updated webhook, or poll GET /v2/accounts/{accountId}/kyc.
5

Read eligibility

Offer a bank rail only when eligibility.status is eligible. Then activate a capability.

Start a session

  • No body, no return URL. The account path fixes the subject, and the provider configuration is Stableyard’s.
  • Repeated calls reuse the active session and return the same link. A session still being prepared returns status: "pending" without verificationUrl; call again shortly or wait for kyc.updated.
  • An approved, current verification is returned without a link. Nothing new is created.
  • At most three provider sessions per account. A rejected or expired session can be retried with a new session; the fourth attempt is refused with 409 and needs manual review.
verificationUrl is returned only while a session is open. It is absent once the verification is approved, rejected or expired. What the customer sees on the page is on Branding and your frontend.

Read the result

current is the newest verification, and verifications holds the ten most recent, newest first. Before the first session, current is absent and verifications is empty.

KYC states

rejected and expired are final for that verification. Another attempt is a new session.

Eligibility

eligibility.status is what regulated operations check, and they recheck it every time they run. Read it, not status, before you offer a bank rail.

Next actions

Errors

Webhooks

Email verification

The gate before KYC.

Capability activation

The gate after KYC: approval for a bank service.

Onboarding overview

Every gate between an account and a fiat rail.

Event catalog

Every KYC and compliance event.