> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapyd.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Customer

> Creates a customer. Email, phone and client reference ID must each be unique within your organization.

<Prompt description="Create Customer" actions={["cursor"]}>
  Add the Zapyd "Create Customer" call (`POST /cms/api/v1/customer/create`) to my backend. Creates a customer. Email, phone and client reference ID must each be unique within your organization.

  * Sandbox: `POST https://sandbox.zapyd.com/cms/api/v1/customer/create`
  * Production: `POST https://api.zapyd.com/cms/api/v1/customer/create`

  JSON body:

  * `client_reference_id` (string, required): Your unique reference for this customer. Required. Re-sending an existing client\_reference\_id returns the existing customer. Example: `test123`.
  * `full_name` (string, optional): Customer's full name. Required unless you send both first\_name and last\_name. Example: `John Doe`.
  * `first_name` (string, optional): First name. Send together with last\_name as an alternative to full\_name. Example: `John`.
  * `last_name` (string, optional): Last name. Send together with first\_name. Example: `Doe`.
  * `email` (string, optional): Customer email. Required only when email verification is enabled for your organization. Example: `john@example.com`.
  * `phone` (string, optional): National mobile number without country code (8–15 characters, validated per country). Required only when phone verification is enabled for your organization. Example: `9911002211`.
  * `alpha_3_country_code` (string, required): ISO 3166-1 alpha-3 country code. Must be enabled for your organization, otherwise the request fails with REQ\_INVALID\_COUNTRY. Example: `IND`.
  * `dob` (string, date, optional): Date of birth (YYYY-MM-DD). Required when alpha\_3\_country\_code is USA. Example: `1990-01-15`.

  Success: HTTP 200, `{status: true, message, data}`. `data`: `id`, `client_reference_id`, `full_name`, `email`, `phone` (Phone number with the country dial code), `country`, `type`, `status`, `failure_reason`, `document_type`.
  Errors (`{status: false, message, err_code, errors}`):

  * 400 `Email already in use`
  * 400 `Phone already in use`
  * 400 `Invalid country code`
  * 400 `Client Reference ID already exists`
  * 500 `Internal Server Error`
    Every endpoint can also return 401 `AUTH_*` (signature, timestamp or key: fix, don't retry), and 429 or 5xx (retry with backoff).

  Rules:

  * First call for every end user (India and USA standard onboarding, and the India remittance beneficiary). Save `data.id` as `customer_id`: every later call uses it.
  * Idempotent on `client_reference_id` (your user ID): re-sending it returns the existing customer, so retries are safe.
  * A new customer is `UNVERIFIED`. Next: KYC with `POST /kyc/add-kyc-data` (India, data you verified) or `POST /kyc/generate-link` (hosted flow, required for the USA). India remittance beneficiaries use `POST /kyc/remittance-beneficiary-kyc` instead.
  * Send `phone` without the country code. Send `dob` (YYYY-MM-DD) for USA customers.
  * Beneficiaries outside India use `POST /customer/payout/create`, not this endpoint.

  Signing (every request):

  * Headers: `X-API-KEY`, `X-TIMESTAMP` (Unix seconds, within 300 s of server time; generate per request) and `X-SIGNATURE`.
  * `X-SIGNATURE` = Base64(HMAC-SHA256(key = API secret, message = apiKey + "|" + timestamp + "|" + canonicalBody)). Base64 of the raw digest, not hex.
  * canonicalBody: the JSON body with keys sorted at every nesting level, no whitespace (separators `,` and `:`), and every non-ASCII character escaped as lowercase `\uXXXX` (Python `json.dumps(body, sort_keys=True, separators=(",", ":"))`). Requests with no body (GET, DELETE) sign `{}`. Query parameters are not signed.
  * Send the exact canonicalBody string you signed as the request body, with `Content-Type: application/json`.
  * Test vector: key `3f1b2c4d-5e6f-4a7b-8c9d-0e1f2a3b4c5d`, secret `test-secret-do-not-use`, timestamp `1735689600`. Signing `{}` gives `6sCtVSRQjU9+2/af8gdwUAvY1l6Ii6ENcbRfanPkhY0=`. Body `{"customer_id":"78c99d71-f28f-47a9-8302-93b286efbe0e","amount":100.5,"currency":"INR","meta":{"note":"Café","b":2,"a":1}}` gives `l+DvQrzlKbsOSxSYOdWoWHEehcFRZfDJPKlLDkm2cSI=`.

  Deliver:

  1. A typed `createCustomer` function in this codebase's language and HTTP client. Reuse an existing Zapyd client and signer, or write one small shared client.
  2. Config from `ZAPYD_API_KEY`, `ZAPYD_API_SECRET` and `ZAPYD_BASE_URL`. The secret stays on the server, never in a browser or app.
  3. Return `data`. When `status` is false, throw an error with the HTTP status, `err_code`, `message` and `errors`. Don't show raw errors to end users.
  4. Retry only 429 and 5xx: exponential backoff from 1 s, capped at 30 s, at most 5 attempts.
  5. Amounts as strings. Types for every field above.
  6. Tests: the signer against the test vector, and this call against sandbox.

  Reference: `https://docs.zapyd.com/api-reference-exchange/endpoint/customer/create.md`
</Prompt>

## Error Codes and Messages

| API Status Code | Response | Reason |
| - | - | - |
| 400 | Email already in use | Email already in use |
| 400 | Phone already in use | Phone already in use |
| 400 | Invalid country code | Invalid country code |
| 400 | Client Reference ID already exists | Client Reference ID already exists |
| 500 | Internal Server Error | Internal Server Error |


## OpenAPI

````yaml POST /customer/create
openapi: 3.1.0
info:
  title: Zapyd API
  description: API for Zapyd - Customer, Payout, and Webhook services
  license:
    name: MIT
  version: 1.0.0
servers:
  - url: https://sandbox.zapyd.com/pos/api/v1
    description: Payout API Base URL
    variables:
      base_url:
        default: https://sandbox.zapyd.com
  - url: https://sandbox.zapyd.com/cms/api/v1
    description: Customer API Base URL
    variables:
      base_url:
        default: https://sandbox.zapyd.com
security:
  - ApiKeyAuth: []
    TimestampAuth: []
    SignatureAuth: []
tags:
  - name: Customer
    description: Customer related operations
    x-displayName: Customer
    x-traitTag: true
  - name: Payout
    description: Payout related operations
  - name: Webhooks
    description: Webhook related operations
  - name: Widget
    description: Hosted buy/sell widget session initialization
paths:
  /customer/create:
    post:
      tags:
        - Customer
      description: >-
        Create a customer. Send either full_name, or first_name and last_name.
        email and phone are required only when your organization has email or
        phone verification enabled. dob is required for USA customers.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - client_reference_id
                - alpha_3_country_code
              properties:
                client_reference_id:
                  type: string
                  description: >-
                    Your unique reference for this customer. Required.
                    Re-sending an existing client_reference_id returns the
                    existing customer.
                  example: test123
                full_name:
                  type: string
                  description: >-
                    Customer's full name. Required unless you send both
                    first_name and last_name.
                  example: John Doe
                first_name:
                  type: string
                  description: >-
                    First name. Send together with last_name as an alternative
                    to full_name.
                  example: John
                last_name:
                  type: string
                  description: Last name. Send together with first_name.
                  example: Doe
                email:
                  type: string
                  description: >-
                    Customer email. Required only when email verification is
                    enabled for your organization.
                  example: john@example.com
                phone:
                  type: string
                  description: >-
                    National mobile number without country code (8–15
                    characters, validated per country). Required only when phone
                    verification is enabled for your organization.
                  example: '9911002211'
                alpha_3_country_code:
                  type: string
                  description: >-
                    ISO 3166-1 alpha-3 country code. Must be enabled for your
                    organization, otherwise the request fails with
                    REQ_INVALID_COUNTRY.
                  example: IND
                dob:
                  type: string
                  description: >-
                    Date of birth (YYYY-MM-DD). Required when
                    alpha_3_country_code is USA.
                  example: '1990-01-15'
                  format: date
      responses:
        '200':
          description: Customer created successfully
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: boolean
                    example: true
                  message:
                    type: string
                    example: Success
                  data:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                        example: 550e8400-e29b-41d4-a716-446655440000
                      client_reference_id:
                        type: string
                        example: test123
                      full_name:
                        type: string
                        example: John Doe
                      email:
                        type: string
                        example: john@example.com
                      phone:
                        type: string
                        example: '+919911002211'
                        description: Phone number with the country dial code
                      country:
                        type: string
                        example: IND
                      type:
                        type: string
                        example: INDIVIDUAL
                      status:
                        type: string
                        example: UNVERIFIED
                      failure_reason:
                        type: string
                        example: null
                      document_type:
                        type: string
                        example: AADHAAR
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: boolean
                    example: false
                  message:
                    type: string
                    example: Bad Request
                  err_code:
                    type: string
                    example: INPUT_MALFORMED
                  errors:
                    type: object
                    additionalProperties:
                      type: array
                      items:
                        type: string
                    example:
                      type:
                        - type is required
                      email:
                        - email is required
                  data:
                    type: 'null'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: boolean
                    example: false
                  message:
                    type: string
                    example: Internal Server Error
                  data:
                    type: 'null'
                  err_code:
                    type: string
                    example: SYS_INTERNAL_ERROR
                  errors:
                    type: string
                    example: Unexpected error occurred. Please try again later.
      servers:
        - url: https://sandbox.zapyd.com/cms/api/v1
          description: Customer API Base URL
components:
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-API-KEY
      description: API Key for authentication
    TimestampAuth:
      type: apiKey
      in: header
      name: X-TIMESTAMP
      description: Current timestamp in seconds since epoch
    SignatureAuth:
      type: apiKey
      in: header
      name: X-SIGNATURE
      description: HMAC SHA256 signature of the request encoded in Base64

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.