Skip to main content
POST
Submit a customer onboarding application

Authorizations

x-api-key
string
header
required

Headers

Idempotency-Key
string
required

Caller-generated unique key that lets the server safely replay this request. The cached response is returned for 5 minutes on any retry with the same key from the same API principal. Required on every state-changing money-moving or resource-creating POST.

Required string length: 1 - 128
Pattern: ^[A-Za-z0-9_.:-]{1,128}$

Body

application/json
businessInfo
object

Business-level data (e.g. taxId, legalName, tradeName). Inner shape resolved from GET /v2/onboarding/requirements.

registeredAddress
object

Registered business address. Inner shape (e.g. addressLine1, city, state, postalCode, country) resolved from requirements; country accepts ISO 3166-1 alpha-2 or alpha-3.

operatingAddress
object

Operating address when different from registeredAddress. Same inner shape and country rules.

companyClassification
object

Legal-structure and industry classification (e.g. legalStructure, coreIndustry). Inner shape resolved from requirements.

businessActivity
object

Operating-activity descriptors (e.g. countries of activity, expected volumes). Inner shape resolved from requirements.

compliance
object

Compliance-attestation fields. Inner shape resolved from requirements.

regulatoryHistory
object

Regulatory and adverse-action history. Inner shape resolved from requirements.

ownership
object

Beneficial-owner and controlling-person disclosure under ownership.persons[]. Inner shape resolved from individualRequirements[]; each person carries roles[], scalar identity fields, and documentIds[].

Related-company disclosure for affiliated entities. Inner shape resolved from requirements.

certification
object

Legal certifications the customer must affirm (e.g. termsAndConditions: true). Inner shape resolved from requirements; mustEqual: true markers in discovery indicate exact-value gates.

documentIds
string[]

Customer-level document IDs from POST /v2/documents to attach to this onboarding. Per-person documents go on ownership.persons[i].documentIds[].

Maximum array length: 100
Minimum string length: 1
Example:
clientReferenceId
string

Optional integrator-supplied identifier echoed back on the application record for cross-system correlation. 1-255 characters from A-Za-z, 0-9, underscore, hyphen, colon, and period — no spaces.

Pattern: ^[A-Za-z0-9_\-:.]{1,255}$
Example:

"ext_customer_8421"

Response

The submitted onboarding application

id
string
required

Unique application identifier

Pattern: ^app_[0-9A-Za-z]{22}$
status
enum<string>
required

Current lifecycle status of the application

Available options:
pending,
processing,
approved,
rejected,
cancelled
Example:

"pending"

createdAt
string<date-time>
required

Timestamp when the application was created

Example:

"2026-01-15T09:30:00.000Z"

updatedAt
string<date-time>
required

Timestamp when the application was last modified

Example:

"2026-01-15T09:30:00.000Z"

type
enum<string>
required
Available options:
customer_onboarding
clientReferenceId
string

Client-provided identifier for cross-referencing. Omitted when the client did not supply one. 1-255 characters from A-Za-z, 0-9, underscore, hyphen, colon, and period — no spaces.

Pattern: ^[A-Za-z0-9_\-:.]{1,255}$
Example:

"ext-12345"

submittedAt
string<date-time>

Timestamp when the application was submitted for review. Omitted while still in progress.

Example:

"2026-01-15T09:30:00.000Z"

failureCode
enum<string>

Machine-readable failure code on rejected applications. Omitted on non-rejected applications.

Available options:
rejected_by_ops,
compliance_denied
failureMessage
string

Customer-facing failure message accompanying failureCode. Omitted on non-rejected applications.

customerId
string

Customer this onboarding application produced. Omitted while the application is still being reviewed; present after approval persists the customer row.

Pattern: ^cus_[0-9A-Za-z]{22}$
persons
object[]

People declared on the submission (beneficial owners and controlling persons), in submit order. Omitted before the application carries a submission.