Public self-registration (introducer must supply sponsor code)
POST/agents/self-register
Public endpoint (no auth) rate-limited to 3 requests per 5 minutes per IP. Creates a pending agent record. Introducers must supply a sponsorCode referencing a licensed agent; ZFA does not engage introducers directly. Applicants must complete KYC and be approved before they can transact. Records an audit event under a synthetic actor.
Request
Responses
- 201
- 400
- 409
- 429
- 500
Agent registration accepted; the response includes the new agent code and pending status.
Payload invalid or sponsor code unknown.
Email, phone or IRA number already registered.
Rate limit exceeded. Global default is 120 requests/minute per IP; auth-flow, OTP, self-registration, WebAuthn, IRA lookup, and public-lead endpoints carry tighter per-endpoint limits. Retry after the delay indicated by the Retry-After header.
Response Headers
Seconds to wait before retrying.
Unhandled server error. The response carries a meta.requestId correlator you can hand to platform operations to trace the failure through structured logs and the hash-chained audit trail. Retry with the same Idempotency-Key header if the endpoint accepts idempotency.