> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapyd.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Add KYC Data

> Submits a customer's identity documents and personal details and starts KYC verification.

<Prompt description="Add KYC Data" actions={["cursor"]}>
  Add the Zapyd "Add KYC Data" call (`POST /cms/api/v1/kyc/add-kyc-data`) to my backend. Submits a customer's identity documents and personal details and starts KYC verification.

  * Sandbox: `POST https://sandbox.zapyd.com/cms/api/v1/kyc/add-kyc-data`
  * Production: `POST https://api.zapyd.com/cms/api/v1/kyc/add-kyc-data`

  JSON body:

  * `customer_id` (string, uuid, required): Zapyd customer ID (UUID) returned by Create Customer.
  * `full_name` (string, required): Name as it appears on the identity document. Example: `John Doe`.
  * `phone` (string, required): National mobile number without the country code (9–10 digits), validated for the customer's country. Example: `9911002211`.
  * `full_address` (string, required): Residential address. Example: `FULL_ADDRESS_OF_THE_CUSTOMER`.
  * `dob` (string, date, required): Date of birth, DD-MM-YYYY. Example: `DD-MM-YYYY`.
  * `registered_date` (string, date, required): Registration date, DD-MM-YYYY. Example: `DD-MM-YYYY`.
  * `tax_number` (string, optional): Tax number, up to 15 characters. For India, the PAN; it is checked against the name and date of birth. Example: `ABCPG1234N`.
  * `document_type` (string, required): Document type as returned by /kyc/configuration/`{customer_id}` (e.g. PASSPORT, etc.).
  * `document_front_image_url` (string, optional): Front image URL (JPG, JPEG, PNG or PDF). Required for every document type except AADHAAR, which accepts either both images or aadhaar\_json in document\_details.additional\_data.
  * `document_back_image_url` (string, optional): Back image URL (JPG, JPEG, PNG or PDF). Same rule as document\_front\_image\_url.
  * `document_details` (object, required): Must include document\_number.
    * `document_number` (string, required): Document number: 6–20 letters, digits or hyphens. Example: `123456123456`.
    * `additional_data` (object, optional): For AADHAAR without images, send aadhaar\_json or aadhaar\_xml here.
  * `selfie_url` (string, required): Accepts JPG, JPEG and PNG links.
  * `additional_info` (object, optional): Extra fields required by your organization's KYC configuration; see GET /kyc/configuration/`{customer_id}`. Unknown keys are rejected.
  * `ip_address` (string, optional): The end user's IP address. Example: `203.0.113.10`.

  Success: HTTP 200, `{status: true, message, data}`. `data`: `id`, `status`, `failure_reason`.
  Errors (`{status: false, message, err_code, errors}`):

  * 400 `Customer not found or access denied`: Customer not found; Customer does not belong to the organization
  * 400 `KYC already exists`: KYC already exists for the customer
  * 400 `KYC already in use`: KYC is being used by another customer
  * 500 `Internal Server Error`
    Every endpoint can also return 401 `AUTH_*` (signature, timestamp or key: fix, don't retry), and 429 or 5xx (retry with backoff).

  Rules:

  * KYC sharing: for India (`IND`) customers whose identity you already verified. USA customers must use `POST /kyc/generate-link`.
  * Read `GET /kyc/configuration/{customer_id}` first for the allowed `document_type` values and the `additional_info` keys.
  * Dates are DD-MM-YYYY. Send image URLs that Zapyd can download, never base64.
  * The customer moves to `PROCESSING`. The result arrives as a `CUSTOMER` webhook, usually within 60 seconds (manual review up to 24 hours).
  * On `FAILED`, fix only the failed part: `DOCUMENT_VERIFICATION_FAILED` with `PATCH /kyc/update-document-info`, `TAX_VERIFICATION_FAILED` with `PATCH /kyc/update-tax-info`, `SELFIE_VERIFICATION_FAILED` with `PATCH /kyc/update-selfie-info`. `KYC_FAILED` is final: contact support. Each customer has 3 attempts.
  * Payins (onramp) in India need an Aadhaar-verified customer.

  Signing (every request):

  * Headers: `X-API-KEY`, `X-TIMESTAMP` (Unix seconds, within 300 s of server time; generate per request) and `X-SIGNATURE`.
  * `X-SIGNATURE` = Base64(HMAC-SHA256(key = API secret, message = apiKey + "|" + timestamp + "|" + canonicalBody)). Base64 of the raw digest, not hex.
  * canonicalBody: the JSON body with keys sorted at every nesting level, no whitespace (separators `,` and `:`), and every non-ASCII character escaped as lowercase `\uXXXX` (Python `json.dumps(body, sort_keys=True, separators=(",", ":"))`). Requests with no body (GET, DELETE) sign `{}`. Query parameters are not signed.
  * Send the exact canonicalBody string you signed as the request body, with `Content-Type: application/json`.
  * Test vector: key `3f1b2c4d-5e6f-4a7b-8c9d-0e1f2a3b4c5d`, secret `test-secret-do-not-use`, timestamp `1735689600`. Signing `{}` gives `6sCtVSRQjU9+2/af8gdwUAvY1l6Ii6ENcbRfanPkhY0=`. Body `{"customer_id":"78c99d71-f28f-47a9-8302-93b286efbe0e","amount":100.5,"currency":"INR","meta":{"note":"Café","b":2,"a":1}}` gives `l+DvQrzlKbsOSxSYOdWoWHEehcFRZfDJPKlLDkm2cSI=`.

  Deliver:

  1. A typed `addKycData` function in this codebase's language and HTTP client. Reuse an existing Zapyd client and signer, or write one small shared client.
  2. Config from `ZAPYD_API_KEY`, `ZAPYD_API_SECRET` and `ZAPYD_BASE_URL`. The secret stays on the server, never in a browser or app.
  3. Return `data`. When `status` is false, throw an error with the HTTP status, `err_code`, `message` and `errors`. Don't show raw errors to end users.
  4. Retry only 429 and 5xx: exponential backoff from 1 s, capped at 30 s, at most 5 attempts.
  5. Amounts as strings. Types for every field above.
  6. Tests: the signer against the test vector, and this call against sandbox.

  Reference: `https://docs.zapyd.com/api-reference-exchange/endpoint/kyc/add-kyc-data.md`
</Prompt>

<Note>
  Currently, Payins (on-ramp) is only supported for Aadhaar verified customers.
</Note>

## Error Codes and Messages

| API Status Code | Response | Reason |
| - | - | - |
| 400 | Customer not found or access denied | Customer not found |
| 400 | Customer not found or access denied | Customer does not belong to the organization |
| 400 | KYC already exists | KYC already exists for the customer |
| 400 | KYC already in use | KYC is being used by another customer |
| 500 | Internal Server Error | Internal Server Error |


## OpenAPI

````yaml POST /kyc/add-kyc-data
openapi: 3.1.0
info:
  title: Zapyd API
  description: API for Zapyd - Customer, Payout, and Webhook services
  license:
    name: MIT
  version: 1.0.0
servers:
  - url: https://sandbox.zapyd.com/pos/api/v1
    description: Payout API Base URL
    variables:
      base_url:
        default: https://sandbox.zapyd.com
  - url: https://sandbox.zapyd.com/cms/api/v1
    description: Customer API Base URL
    variables:
      base_url:
        default: https://sandbox.zapyd.com
security:
  - ApiKeyAuth: []
    TimestampAuth: []
    SignatureAuth: []
tags:
  - name: Customer
    description: Customer related operations
    x-displayName: Customer
    x-traitTag: true
  - name: Payout
    description: Payout related operations
  - name: Webhooks
    description: Webhook related operations
  - name: Widget
    description: Hosted buy/sell widget session initialization
paths:
  /kyc/add-kyc-data:
    post:
      tags:
        - KYC
      description: >-
        Share KYC data you have already collected for a customer (KYC sharing).
        Supported for customers in India (IND). USA customers must use POST
        /kyc/generate-link instead. KYC must be enabled for your organization.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - customer_id
                - full_name
                - phone
                - full_address
                - dob
                - registered_date
                - document_type
                - document_details
                - selfie_url
              properties:
                customer_id:
                  type: string
                  format: uuid
                  example: 4e6f1b20-a73c-11ec-b909-0242ac120002
                  description: Zapyd customer ID (UUID) returned by Create Customer.
                full_name:
                  type: string
                  example: John Doe
                  description: Name as it appears on the identity document.
                phone:
                  type: string
                  example: '9911002211'
                  description: >-
                    National mobile number without the country code (9–10
                    digits), validated for the customer's country.
                full_address:
                  type: string
                  example: FULL_ADDRESS_OF_THE_CUSTOMER
                  description: Residential address.
                dob:
                  type: string
                  format: date
                  example: DD-MM-YYYY
                  description: Date of birth, DD-MM-YYYY
                registered_date:
                  type: string
                  format: date
                  example: DD-MM-YYYY
                  description: Registration date, DD-MM-YYYY
                tax_number:
                  type: string
                  example: ABCPG1234N
                  description: >-
                    Optional. Tax number, up to 15 characters. For India, the
                    PAN; it is checked against the name and date of birth.
                document_type:
                  type: string
                  description: >-
                    Document type as returned by
                    /kyc/configuration/{customer_id} (e.g. PASSPORT, etc.)
                document_front_image_url:
                  type: string
                  description: >-
                    Front image URL (JPG, JPEG, PNG or PDF). Required for every
                    document type except AADHAAR, which accepts either both
                    images or aadhaar_json in document_details.additional_data.
                  format: uri
                document_back_image_url:
                  type: string
                  description: >-
                    Back image URL (JPG, JPEG, PNG or PDF). Same rule as
                    document_front_image_url.
                  format: uri
                document_details:
                  type: object
                  required:
                    - document_number
                  properties:
                    document_number:
                      type: string
                      example: '123456123456'
                      description: 'Document number: 6–20 letters, digits or hyphens.'
                    additional_data:
                      type: object
                      description: >-
                        Optional. For AADHAAR without images, send aadhaar_json
                        or aadhaar_xml here.
                  description: Required. Must include document_number.
                selfie_url:
                  type: string
                  description: Accepts JPG, JPEG and PNG links
                  format: uri
                additional_info:
                  type: object
                  description: >-
                    Extra fields required by your organization's KYC
                    configuration; see GET /kyc/configuration/{customer_id}.
                    Unknown keys are rejected.
                ip_address:
                  type: string
                  description: Optional. The end user's IP address.
                  example: 203.0.113.10
      responses:
        '200':
          description: KYC data added successfully
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: boolean
                    example: true
                  message:
                    type: string
                    example: Success
                  data:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                        example: 550e8400-e29b-41d4-a716-446655440000
                      status:
                        type: string
                        example: PROCESSING
                      failure_reason:
                        type: string
                        example: null
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: boolean
                    example: false
                  message:
                    type: string
                    example: Internal Server Error
                  data:
                    type: 'null'
                  err_code:
                    type: string
                    example: SYS_INTERNAL_ERROR
                  errors:
                    type: string
                    example: Unexpected error occurred. Please try again later.
      servers:
        - url: https://sandbox.zapyd.com/cms/api/v1
          description: KYC API Base URL
components:
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-API-KEY
      description: API Key for authentication
    TimestampAuth:
      type: apiKey
      in: header
      name: X-TIMESTAMP
      description: Current timestamp in seconds since epoch
    SignatureAuth:
      type: apiKey
      in: header
      name: X-SIGNATURE
      description: HMAC SHA256 signature of the request encoded in Base64

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.