CorebanqCorebanq Developer Docs
KYCv1KYCIDV

Get identity verification status

Returns the cached verification state for one signatory. ?refresh=true re-reads it from the provider first. status can be aborted, which this spec previously omitted — a terminal outcome distinct from failed and expired. A PROVIDER FAULT IS NOT AN ERROR ON THIS ROUTE. No 502 is declared because none is reachable: tryRefreshVerification swallows every error from refreshFromProvider, logs a warning and returns the cached verification. ?refresh=true against a dead provider answers 200 with STALE data and no indication that the refresh failed — compare updated_at against now if freshness matters — tryRefreshVerification returns the row untouched on a provider failure, so updated_at is the only staleness signal in the body. DO NOT CALL THIS FOR A SIGNATORY WITH NO VERIFICATION. That case is an unguarded nil dereference, not a 404 — see the 404 below.

GET
/v1/kyc/{customer_id}/signatories/{signatory_id}/idv

Authorization

bearerAuth
AuthorizationBearer <token>

JWT token from the authentication endpoint.

In: header

Path Parameters

customer_id*string

Customer owning the signatory. A non-UUID is 400 common.invalid_input with field=customer_id.

signatory_id*string

Signatory to verify. A non-UUID is 400 common.invalid_input with field=signatory_id.

Query Parameters

refresh?string

Re-read the session from the provider before answering. Compared against the literal string "true" CASE-SENSITIVELY — unlike force, include_matches and include_response on the screening routes, which are lowercased first. So ?refresh=TRUE does nothing while ?force=TRUE works.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X GET "https://example.com/v1/kyc/497f6eca-6276-4993-bfeb-53cbbbba6f08/signatories/497f6eca-6276-4993-bfeb-53cbbbba6f08/idv"
{
  "verification_id": "5bcbf7ac-c998-46ce-aa6e-a0c1a3f1f5bd",
  "session_id": "string",
  "status": "not_started",
  "provider": "string",
  "customer_id": "160c0c4b-9966-4dc1-a916-8407eb10d74e",
  "signatory_id": "9516df81-fc1b-44b5-9714-b62076b8800f",
  "verification_url": "string",
  "expires_at": "2019-08-24T14:15:22Z",
  "completed_at": "2019-08-24T14:15:22Z",
  "updated_at": "2019-08-24T14:15:22Z",
  "response_data": {}
}
{
  "status": 400,
  "message": "Invalid input",
  "code": "common.invalid_input",
  "class": "validation"
}
{
  "status": 401,
  "message": "Unauthorized",
  "code": "common.unauthorized",
  "class": "business"
}
{
  "status": 403,
  "message": "No access to the record",
  "code": "common.rbac_no_rec_access",
  "class": "business"
}
{
  "status": 404,
  "message": "Signatory record not found",
  "code": "kyc_m.idv_signatory_not_found",
  "class": "business"
}
{
  "status": 429,
  "message": "Rate limit for 203.0.113.7 to POST:/v1/kyc/screening exceeded.",
  "code": "rate_limits_m.exceeded",
  "class": "temporary",
  "retryable": true
}
{
  "status": 500,
  "message": "Database error",
  "code": "common.database_error",
  "class": "business"
}

{
  "overall_status": "unhealthy",
  "message": "Service is shutting down",
  "timestamp": "2026-08-27T15:04:05Z"
}