Skip to main content
POST
kycProviderShareToken belongs to Reusable KYC (Sumsub share token). It is separate from Ripio KYC reuse via OTP, which uses Start KYC and Validate KYC OTP. If your account is configured for OTP reuse, this endpoint always requires kycSubmission — it cannot open that flow on its own. Calling it before the OTP is confirmed returns 400 with the error code 20094 (KycEmailOtpNotConfirmedException).For the Partner-submitted (API) model, send kycProviderShareToken in Start KYC instead — that’s the call that opens the verification, and where the token is redeemed. Sending it here has no effect for that model. This endpoint only accepts the token directly for the Ripio-hosted (redirect) model, where it has no separate Start KYC call. See Reusable KYC (Sumsub share token) for the full behavior per model.
Reusable KYC via Sumsub share token is an account-level opt-in. A share token by itself does not enable this flow: if the feature is not enabled for your account, sending kycProviderShareToken returns 403 with KycProviderTokenSharingNotEnabledException and no KYC is created.

Authorizations

Authorization
string
header
required

Access token obtained via /oauth2/token/. Use as Authorization: Bearer <access_token>.

Path Parameters

customerId
string<uuid>
required

Unique identifier for the customer.

Body

application/json

KYC data for the customer. Structure should align with fields from /kycRequirements/.

Request body for KYC submission. Use kycSubmission + redirectUrl for the standard API flow, or only redirectUrl for the Ripio KYC delegated flow. If your account is enabled for Reusable KYC (Sumsub share token), you can add kycProviderShareToken to reuse a verification the customer already completed in your own Sumsub account. This is separate from Ripio KYC reuse via OTP: if your account is configured for it, open the verification with Start KYC first and confirm the OTP with Validate KYC OTP — this endpoint cannot open that flow on its own, and calling it before the OTP is confirmed returns 400 with the error code 20094 (KycEmailOtpNotConfirmedException).

kycSubmission
object

Customer KYC data. Which fields are accepted, and which are required, depends on country — the four countries have four different schemas, so the required list below is only their intersection. Each field's description states its per-country requiredness.

See KYC fields by country for the full matrix and the cross-field rules, and call /kycRequirements/ for the live catalogs of the CHOICE fields. Not required when using the Ripio KYC delegated flow.

redirectUrl
string<uri>

URL to redirect the user after completing the KYC flow. Required for the Ripio KYC delegated flow; optional for the API flow.

Example:

"https://www.example.com/"

kycProviderShareToken
string

Optional. Sumsub share token for a customer already verified in your own Sumsub account (reusable KYC). Ripio redeems it so that, when both verifications are compatible, the customer does not have to upload documents or repeat the liveness check. On this endpoint, it only takes effect for the Ripio KYC delegated flow (no kycSubmission, only redirectUrl). For the API flow, send it on Start KYC instead — that is the call that opens the verification for that flow, and sending it here has no effect.

Two prerequisites must be met before this field does anything. First, reusable KYC is an opt-in feature that must be enabled for your account by the Ripio team: while it is disabled, sending this field returns 403 with the error code 20065 (KycProviderTokenSharingNotEnabledException) and no KYC is created. Second, your Sumsub account must be paired with Ripio's as a sharing partner — you add the partner token Ripio gives you under Reusable identity → Partners → Recipients → Add recipient in your Sumsub dashboard; without that pairing, the tokens you generate are rejected when Ripio tries to redeem them. See Reusable KYC prerequisites and Sumsub's Add recipient.

Generate the token with Sumsub's Generate share token endpoint, using the customer's applicantId and forClientId set to Ripio's Sumsub client ID.

Reuse is subject to Sumsub's compatibility rules: only the verification steps that overlap between your level and Ripio's are transferred, and the shared documents are re-checked against Ripio's requirements. When the levels have no matching steps, or a re-check fails, the customer is asked to complete the missing steps — see Sumsub's Reusable KYC share documentation.

Share tokens are short-lived and single-use: generate a fresh token right before each call to this endpoint. The token is only used when a new verification process is opened — if a verification is already in progress for the customer, the response is idempotent and the token is ignored.

Maximum string length: 2000

Response

KYC submission received successfully. Includes providerUrl for document upload and liveness check.

submissionId
string<uuid>
required

Unique identifier for the submitted KYC data.

createdAt
string<date-time>
required

Date and time the KYC submission was created (UTC format).

providerUrl
string<url>
required

Points to a third-party KYC provider's widget to handle file uploads and liveness checks. Only available in production.

otpRequired
boolean

Whether the OTP sent to the customer's email still needs to be validated with Validate KYC OTP before continuing. Only present for accounts configured for Ripio KYC reuse via OTP.