Review a single KYC document
POST/agents/:id/kyc/documents/:docId/review
Marks an individual KYC document as verified or rejected. Rejections must include a reason. Emits an agent.kyc.document.review audit entry. Requires the agent-kyc:review permission (typically compliance staff).
Request
Responses
- 201
- 400
- 401
- 403
- 404
- 409
- 429
- 500
Updated AgentKycDocument record.
Rejection reason missing or invalid status.
Missing or invalid access token.
Caller lacks the required permission.
Agent or KYC document not found.
The request conflicts with the current state of the target resource — a duplicate unique field on registration, an idempotency-key replay with a different payload, or a webhook eventId that has already been processed. error.code may be CONFLICT or IDEMPOTENCY_CONFLICT depending on the cause.
Rate limit exceeded. Global default is 120 requests/minute per IP; auth-flow, OTP, self-registration, WebAuthn, IRA lookup, and public-lead endpoints carry tighter per-endpoint limits. Retry after the delay indicated by the Retry-After header.
Response Headers
Seconds to wait before retrying.
Unhandled server error. The response carries a meta.requestId correlator you can hand to platform operations to trace the failure through structured logs and the hash-chained audit trail. Retry with the same Idempotency-Key header if the endpoint accepts idempotency.