Add one document to a session. Send the bytes one of two ways, never both: file_name names a file you already staged through the upload-url endpoint, and content_base64 carries the bytes inline. Use file_name for every real document, because a request body larger than about 8 KB is rejected at the network edge. An inline document must be 700 KB or smaller after decoding, and a staged file must be 5 MB or smaller. The session must be AWAITING_INPUT, and it must be HEADLESS. A HOSTED session refuses the call with a 422, because the end customer supplies the documents on the verification link. The response is the session, with steps.documents set to SUBMITTED. Signa must be enabled for your business. Required scope: compliance-kyc:create.
Authorization
oauth2ClientCredentials compliance-kyc:createUse your OAuth client credentials to obtain a short-lived Bearer token from POST /oauth/token.
In: header
Scope: compliance-kyc:create
Path Parameters
The verification session id returned by the create endpoint.
uuidRequest Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
curl --request POST \ --url 'https://example.com/api/external/compliance/kyc/sessions/9f2c7b41-6d3e-4c8a-9a20-1e6f0b5d7c33/documents' \ --header 'Content-Type: application/json' \ --data '{ "filename": "passport-front.jpg", "content_type": "image/jpeg", "id_doc_type": "PASSPORT", "country": "NGA", "file_name": "4a7f1c92e0_passport front.jpg"}'{ "message": "Verification session document uploaded successfully.", "data": { "id": "9f2c7b41-6d3e-4c8a-9a20-1e6f0b5d7c33", "business_id": "9d4c4ec5-572d-49de-a362-f01ed09f2b1b", "customer_reference": "user_10482", "requirements": [ "DOCUMENTS" ], "fulfilment_mode": "HEADLESS", "status": "AWAITING_INPUT", "steps": { "documents": "SUBMITTED", "selfie": null, "proof_of_address": null }, "rejection": null, "expires_at": "2026-08-30T09:14:22.000Z", "completed_at": null, "created_at": "2026-08-29T09:14:22.000Z" }}POSTCreate a document upload URL
Get a presigned URL for one document, then send the file to it with an HTTP PUT, then register the file on the documents endpoint. Use this transport for every real document: a request body larger than about 8 KB is rejected at the network edge. The URL is valid for 5 minutes and the staged file must be 5 MB or smaller. The session must be HEADLESS. A HOSTED session refuses the call with a 422, because the end customer supplies the documents on the verification link. Signa must be enabled for your business. Required scope: `compliance-kyc:create`.
POSTSubmit a verification session for review
Send the session for review. The session moves to IN_REVIEW, stops accepting documents, and no longer expires. The request takes no body. Blaaiz refuses the submit when any step of the requirement set is still PENDING, when the session already left AWAITING_INPUT, and when the session is HOSTED. A step that is null never blocks the submit. The person completes a HOSTED session on the verification link. A HOSTED session answers the submit with the message: This session is completed by the end customer on the verification link. Send the customer the verification_link, or call POST /sessions/{id}/verification-link to issue a new one. Signa must be enabled for your business. Required scope: `compliance-kyc:create`.