Get all KYB answers
Lists stored answers for one actor. The path segment is named customer_id but is matched against the answers table's actor_id column. Record-scoped. A caller without the read-all mask has their permitted answer ids folded into the query, and a caller with NO permitted ids receives 200 with an EMPTY ARRAY — a refusal is indistinguishable from an actor who has answered nothing.
Authorization
bearerAuth In: header
Path Parameters
The actor whose answers to list. Matched against answers.actor_id.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/v1/kyb/customer/497f6eca-6276-4993-bfeb-53cbbbba6f08"[
{
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"actor_id": "04f37679-bfbf-4906-b749-01756515cecf",
"flow_name": "string",
"question_name": "string",
"previous_step": "string",
"answer": {},
"created_at": "2019-08-24T14:15:22Z",
"created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
"modified_at": "2019-08-24T14:15:22Z",
"modified_by": "e8d4374d-93a1-4e98-a6c6-fdcf00c5059f",
"active": true,
"metadata": {}
}
]{
"status": 400,
"message": "Invalid input",
"code": "common.invalid_input",
"class": "validation"
}{
"status": 401,
"message": "Unauthorized",
"code": "common.unauthorized",
"class": "business"
}{
"status": 403,
"message": "No access to the record",
"code": "common.rbac_no_rec_access",
"class": "business"
}{
"status": 429,
"message": "Rate limit for 203.0.113.7 to POST:/v1/kyb/navigate exceeded.",
"code": "rate_limits_m.exceeded",
"class": "temporary",
"retryable": true
}{
"status": 500,
"message": "Failed to get record type ID",
"code": "rbac_m.failed_to_get_rec_type_id",
"class": "business"
}{
"overall_status": "unhealthy",
"message": "Service is shutting down",
"timestamp": "2026-08-27T15:04:05Z"
}Deletes one stored answer. Requires the record-level delete permission. This is a HARD DELETE. models.KYBAnswer embeds BaseModel, which declares no gorm.DeletedAt, so gorm issues a real DELETE and the row is gone — unlike the flow and item config routes, which deactivate. There is no undo and no audit row. Answers 200 through apireply.Ok200: the shared StdResponse envelope, not the {message: "Answer deleted successfully"} object previously documented.
Updates one stored answer. Requires the record-level update permission. Answers 200 through apireply.Ok200, whose body is the shared StdResponse envelope ({status, message}) — NOT the {message: "Answer updated successfully"} object this spec used to document, which the code never produced. The update is a gorm Updates over the decoded struct, which writes every non-zero field it finds. Because the Go type embeds BaseModel, that includes audit columns — see KYBAnswerUpdate.