Reject an agent KYC submission
POST/agents/:id/kyc/reject
Moves the agent to rejected KYC state, clears any prior verification, and stores the rejection reason (surfaced to the agent). Records agent.kyc.reject in the audit log. Requires the agent-kyc:reject permission.
Request
Responses
- 200
- 201
- 400
- 401
- 403
- 404
- 409
- 422
- 429
- 500
Updated Agent with rejected KYC status.
Resource created. Body follows the shared { data, meta } envelope; data is the newly-created resource.
Reason missing or otherwise invalid.
Missing or invalid access token.
Caller lacks the required permission.
Agent not found.
The request conflicts with the current state of the target resource — a duplicate unique field on registration, an idempotency-key replay with a different payload, or a webhook eventId that has already been processed. error.code may be CONFLICT or IDEMPOTENCY_CONFLICT depending on the cause.
The request is syntactically valid but violates a business invariant — a referral state transition not permitted from the current status, a wallet withdrawal exceeding the available balance, or a POP being confirmed before it has been ZFA-verified. error.code is one of INVALID_TRANSITION, INVARIANT_VIOLATION, or a domain-specific value; error.message explains the invariant.
Rate limit exceeded. Global default is 120 requests/minute per IP; auth-flow, OTP, self-registration, WebAuthn, IRA lookup, and public-lead endpoints carry tighter per-endpoint limits. Retry after the delay indicated by the Retry-After header.
Response Headers
Seconds to wait before retrying.
Unhandled server error. The response carries a meta.requestId correlator you can hand to platform operations to trace the failure through structured logs and the hash-chained audit trail. Retry with the same Idempotency-Key header if the endpoint accepts idempotency.