Register one or both of the owner's ID document slots (id_document_front, id_document_back). Each file_id must come from a fresh POST /api/external/customer/{customer}/owner/{owner}/file/presigned-url call. Send only the slots you want to set or replace.
Lock guards.
- The parent customer must be in
PENDINGorREJECTED. Calls against aPROCESSINGorVERIFIEDcustomer return400. - The owner itself must be in
PENDINGorREJECTED. Calls against anAPPROVEDorPROCESSINGowner return400. - Replacing a file on a previously
REJECTEDowner automatically resets that owner'sstatustoPENDINGand clears itsadmin_comments— the corrected record is re-routed through review on the next/submit.
File checks. The server verifies S3 existence, file size (max 25 MB), and MIME type (PDF, JPEG, or PNG) before persisting.
Slot vs. type consistency is enforced at /submit time, not on this call. The eventual rule is:
passport→id_document_frontonly;id_document_backmust be absent.drivers_license,id_card,resident_permit→ bothid_document_frontandid_document_backare required.
If you change the owner's id_document_type later, make sure the slot set still matches — otherwise /submit will reject the customer.
All uploaded documents must be clear, legible, and authentic. Blurry, cropped, obscured, or otherwise unclear images will be rejected. Fraudulent or falsified documents will not be tolerated — repeated attempts to submit false or invalid documents will result in the customer being permanently blacklisted from the platform. There are no exceptions or compromises.
Required scope: customer:write.
Authorization
oauth2ClientCredentials customer:writeUse your OAuth client credentials to obtain a short-lived Bearer token from POST /oauth/token.
In: header
Scope: customer:write
Path Parameters
uuiduuidRequest Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
curl --request POST \ --url 'https://example.com/api/external/customer/497f6eca-6276-4993-bfeb-53cbbbba6f08/owner/497f6eca-6276-4993-bfeb-53cbbbba6f08/files' \ --header 'Content-Type: application/json' \ --data '{}'{ "message": "Owner files uploaded successfully", "data": { "id": "019a6e22-8b4c-7c8d-9d12-c0c1ab3f1a90", "first_name": "Jane", "last_name": "Doe", "id_document_path": "business-data/api-services/customer/.../owner/.../id_document_front_...", "id_document_back_path": null, "status": "PENDING", "admin_comments": null }}POSTGet an owner ID-file upload URL
Two-step upload, step one. Returns a `file_id`, a presigned `url`, and the headers required to PUT the file directly to S3. URL is valid for 5 minutes and accepts a single PUT. Step two: call `POST /api/external/customer/{customer}/owner/{owner}/files` with the same `file_id` to register the file against the owner. Max file size 25 MB. Allowed MIME: `application/pdf`, `image/jpeg`, `image/png`. Owner must not be locked (status `APPROVED` or `PROCESSING`). Required scope: `customer:write`.
DELETEDelete a customer owner
Removes a beneficial owner from the customer. Returns 400 if the owner is locked (status APPROVED or PROCESSING). Required scope: `customer:write`. Note: owners can also be created and edited as part of `POST /api/external/customer` and `PUT /api/external/customer/{id}` via the `owners` array — only deletion has its own dedicated endpoint.