Get KYB answer
Fetches one stored answer. Requires the record-level read permission for this answer id. A permission refusal is reported as 401 with code common.invalid_input — see the 401 below.
Authorization
bearerAuth In: header
Path Parameters
Id of the answer row (kyb.answers.id). Read from the chi route context inside the service, not passed as an argument.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/v1/kyb/497f6eca-6276-4993-bfeb-53cbbbba6f08"{
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"actor_id": "04f37679-bfbf-4906-b749-01756515cecf",
"flow_name": "string",
"question_name": "string",
"previous_step": "string",
"answer": {},
"created_at": "2019-08-24T14:15:22Z",
"created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
"modified_at": "2019-08-24T14:15:22Z",
"modified_by": "e8d4374d-93a1-4e98-a6c6-fdcf00c5059f",
"active": true,
"metadata": {}
}{
"status": 400,
"message": "Invalid input",
"code": "common.invalid_input",
"class": "validation"
}{
"status": 401,
"message": "Invalid input",
"code": "common.invalid_input",
"class": "business"
}{
"status": 403,
"message": "No access to the record",
"code": "common.rbac_no_rec_access",
"class": "business"
}{
"status": 404,
"message": "Record not found",
"code": "common.record_not_found",
"class": "business"
}{
"status": 429,
"message": "Rate limit for 203.0.113.7 to POST:/v1/kyb/navigate exceeded.",
"code": "rate_limits_m.exceeded",
"class": "temporary",
"retryable": true
}{
"status": 500,
"message": "Database error",
"code": "common.database_error",
"class": "business"
}{
"overall_status": "unhealthy",
"message": "Service is shutting down",
"timestamp": "2026-08-27T15:04:05Z"
}Upserts one item of a snapshot and busts the flow's config cache. Admin only: the handler calls requireKYBConfigAdmin, which resolves the caller and then checks Storage.IsAdminAccount. A non-admin gets 403 common.forbidden. Both path segments are validated before the admin check. The server OVERWRITES five fields of the body: flow_id and name from the path, active to TRUE, and created_by / modified_by from the caller. An item therefore cannot be deactivated through this route. The response echoes the amended input struct rather than re-reading the stored row. The cache is ALWAYS invalidated on success, whatever the body carried. The handler hands the item to the repository by pointer and only reads FlowName back afterwards; because it always sets FlowID from the {flow_id} path segment, resolveItemFlowIdentity takes the by-id branch and fillFlowNameFromFlowID writes the name into that same struct before the row is written. The one real caveat is ordering: the invalidation happens AFTER the write and is not rolled back if it fails, so a cache that cannot be reached leaves the write committed and the config stale.
Deletes one stored answer. Requires the record-level delete permission. This is a HARD DELETE. models.KYBAnswer embeds BaseModel, which declares no gorm.DeletedAt, so gorm issues a real DELETE and the row is gone — unlike the flow and item config routes, which deactivate. There is no undo and no audit row. Answers 200 through apireply.Ok200: the shared StdResponse envelope, not the {message: "Answer deleted successfully"} object previously documented.