> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapyd.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Add Payout Sender KYC

> Submits the beneficiary's address and the country-specific identity fields that the payout requires.

<Prompt description="Add Payout Sender KYC" actions={["cursor"]}>
  Add the Zapyd "Add Payout Sender KYC" call (`POST /cms/api/v1/kyc/payout/add-sender-kyc-data`) to my backend. Submits the beneficiary's address and the country-specific identity fields that the payout requires.

  * Sandbox: `POST https://sandbox.zapyd.com/cms/api/v1/kyc/payout/add-sender-kyc-data`
  * Production: `POST https://api.zapyd.com/cms/api/v1/kyc/payout/add-sender-kyc-data`

  JSON body:

  * `client_reference_id` (string, optional): The beneficiary's client\_reference\_id. Example: `beneficiary-001`.
  * `country_code` (string, optional): Beneficiary country, alpha-3. Must match the customer's country if sent. Example: `BRA`.
  * `tax_number` (string, optional): Tax number. Example: `12345678909`.
  * `document_type` (string, optional): Identity document type. One of: `ONLY_PAN`, `GOVT_ID`, `PASSPORT`.
  * `document_front_image_url` (string, optional): Document front image URL. Example: `https://example.com/front.jpg`.
  * `document_back_image_url` (string, optional): Document back image URL. Example: `https://example.com/back.jpg`.
  * `street` (string, optional): Street address. Example: `Av. Paulista 1000`.
  * `city` (string, optional): City. Example: `São Paulo`.
  * `state_province` (string, optional): State or province. Example: `SP`.
  * `postal_code` (string, optional): Postal code. Example: `01310-100`.
  * `beneficiary_identifiers` (object, optional): Country-specific beneficiary fields.

  Success: HTTP 200, `{status: true, message, data}`. `data`: `id`, `client_reference_id`.
  Every endpoint can also return 401 `AUTH_*` (signature, timestamp or key: fix, don't retry), and 429 or 5xx (retry with backoff).

  Rules:

  * Payout-only onboarding, step 3. There's no `customer_id`: identify the beneficiary with the same `client_reference_id` you sent to `POST /customer/payout/create`. Payout-only onboarding must be enabled for your organization and for the beneficiary's country.
  * Required address fields by country: United Arab Emirates `street`, `city`, `state_province`; Brazil `street`, `city`, `state_province`, `postal_code`; China `street`, `city`, `state_province`, `postal_code`; Colombia `street`, `city`, `state_province`, `postal_code`; United Kingdom `street`, `city`; Hong Kong `street`, `city`; Nigeria `street`, `city`, `state_province`, `postal_code`; Philippines `street`, `city`, `state_province`, `postal_code`; Singapore `street`, `city`, `state_province`, `postal_code`; Mexico `street`; United States `street`; SEPA countries `street`, `city`, `postal_code`.
  * `beneficiary_identifiers`: Colombia needs `beneficiary_id_doc_number` (plus `beneficiary_phone_number` for `BANK-TRANSFER`); Mexico needs `beneficiary_id_doc_number` and `beneficiary_dob` (YYYY-MM-DD).
  * Next: `POST /bank/payout/create`.

  Signing (every request):

  * Headers: `X-API-KEY`, `X-TIMESTAMP` (Unix seconds, within 300 s of server time; generate per request) and `X-SIGNATURE`.
  * `X-SIGNATURE` = Base64(HMAC-SHA256(key = API secret, message = apiKey + "|" + timestamp + "|" + canonicalBody)). Base64 of the raw digest, not hex.
  * canonicalBody: the JSON body with keys sorted at every nesting level, no whitespace (separators `,` and `:`), and every non-ASCII character escaped as lowercase `\uXXXX` (Python `json.dumps(body, sort_keys=True, separators=(",", ":"))`). Requests with no body (GET, DELETE) sign `{}`. Query parameters are not signed.
  * Send the exact canonicalBody string you signed as the request body, with `Content-Type: application/json`.
  * Test vector: key `3f1b2c4d-5e6f-4a7b-8c9d-0e1f2a3b4c5d`, secret `test-secret-do-not-use`, timestamp `1735689600`. Signing `{}` gives `6sCtVSRQjU9+2/af8gdwUAvY1l6Ii6ENcbRfanPkhY0=`. Body `{"customer_id":"78c99d71-f28f-47a9-8302-93b286efbe0e","amount":100.5,"currency":"INR","meta":{"note":"Café","b":2,"a":1}}` gives `l+DvQrzlKbsOSxSYOdWoWHEehcFRZfDJPKlLDkm2cSI=`.

  Deliver:

  1. A typed `addPayoutSenderKyc` function in this codebase's language and HTTP client. Reuse an existing Zapyd client and signer, or write one small shared client.
  2. Config from `ZAPYD_API_KEY`, `ZAPYD_API_SECRET` and `ZAPYD_BASE_URL`. The secret stays on the server, never in a browser or app.
  3. Return `data`. When `status` is false, throw an error with the HTTP status, `err_code`, `message` and `errors`. Don't show raw errors to end users.
  4. Retry only 429 and 5xx: exponential backoff from 1 s, capped at 30 s, at most 5 attempts.
  5. Amounts as strings. Types for every field above.
  6. Tests: the signer against the test vector, and this call against sandbox.

  Reference: `https://docs.zapyd.com/api-reference-exchange/endpoint/kyc/payout-add-sender-kyc-data.md`
</Prompt>

<Note>
  Part of the payout-only onboarding flow. See the [payout-only onboarding guide](/guides/customers/payout-only-onboarding) for the order of calls and the fields each country requires.
</Note>


## OpenAPI

````yaml POST /kyc/payout/add-sender-kyc-data
openapi: 3.1.0
info:
  title: Zapyd API
  description: API for Zapyd - Customer, Payout, and Webhook services
  license:
    name: MIT
  version: 1.0.0
servers:
  - url: https://sandbox.zapyd.com/pos/api/v1
    description: Payout API Base URL
    variables:
      base_url:
        default: https://sandbox.zapyd.com
  - url: https://sandbox.zapyd.com/cms/api/v1
    description: Customer API Base URL
    variables:
      base_url:
        default: https://sandbox.zapyd.com
security:
  - ApiKeyAuth: []
    TimestampAuth: []
    SignatureAuth: []
tags:
  - name: Customer
    description: Customer related operations
    x-displayName: Customer
    x-traitTag: true
  - name: Payout
    description: Payout related operations
  - name: Webhooks
    description: Webhook related operations
  - name: Widget
    description: Hosted buy/sell widget session initialization
paths:
  /kyc/payout/add-sender-kyc-data:
    post:
      tags:
        - KYC
      description: >-
        Submit the address and identity details the payout needs for the
        beneficiary. Address fields required depend on the country (see the
        guide). beneficiary_identifiers carries country-specific extra fields,
        for example beneficiary_id_doc_number and beneficiary_phone_number for
        Colombia, or beneficiary_id_doc_number and beneficiary_dob (YYYY-MM-DD)
        for Mexico. Call this before Add Payout Bank Account, with the same
        client_reference_id. Part of the payout-only onboarding flow; see the
        [payout-only onboarding
        guide](/guides/customers/payout-only-onboarding). Requires payout-only
        onboarding to be enabled for your organization and the customer's
        country.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                client_reference_id:
                  type: string
                  description: The beneficiary's client_reference_id
                  example: beneficiary-001
                country_code:
                  type: string
                  description: >-
                    Beneficiary country, alpha-3. Must match the customer's
                    country if sent.
                  example: BRA
                tax_number:
                  type: string
                  description: Tax number
                  example: '12345678909'
                document_type:
                  type: string
                  description: Identity document type
                  example: PASSPORT
                  enum:
                    - ONLY_PAN
                    - GOVT_ID
                    - PASSPORT
                document_front_image_url:
                  type: string
                  description: Document front image URL
                  example: https://example.com/front.jpg
                  format: uri
                document_back_image_url:
                  type: string
                  description: Document back image URL
                  example: https://example.com/back.jpg
                  format: uri
                street:
                  type: string
                  description: Street address
                  example: Av. Paulista 1000
                city:
                  type: string
                  description: City
                  example: São Paulo
                state_province:
                  type: string
                  description: State or province
                  example: SP
                postal_code:
                  type: string
                  description: Postal code
                  example: 01310-100
                beneficiary_identifiers:
                  type: object
                  description: Country-specific beneficiary fields
                  example: {}
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: boolean
                    example: true
                  message:
                    type: string
                    example: Success
                  data:
                    type: object
                    properties:
                      id:
                        type: string
                        description: Record ID
                        example: 7a1c0e7e-2b53-4f7e-9d2f-6d6e2b1c9a10
                        format: uuid
                      client_reference_id:
                        type: string
                        description: ''
                        example: beneficiary-001
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: boolean
                    example: false
                  message:
                    type: string
                    example: Bad Request
                  data:
                    type: 'null'
                  errors:
                    type: object
                    example:
                      postal_code:
                        - This field is required for BRA.
                  err_code:
                    type: string
                    example: UNKNOWN_ERROR
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: boolean
                    example: false
                  message:
                    type: string
                    example: Internal Server Error
                  data:
                    type: 'null'
                  errors:
                    type: object
                    example: {}
                  err_code:
                    type: string
                    example: SYS_INTERNAL_ERROR
      servers:
        - url: https://sandbox.zapyd.com/cms/api/v1
          description: Customer API Base URL
components:
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-API-KEY
      description: API Key for authentication
    TimestampAuth:
      type: apiKey
      in: header
      name: X-TIMESTAMP
      description: Current timestamp in seconds since epoch
    SignatureAuth:
      type: apiKey
      in: header
      name: X-SIGNATURE
      description: HMAC SHA256 signature of the request encoded in Base64

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.