> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapyd.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Save Payin EDD

> Submits enhanced due diligence (EDD) details when a payin quotation triggers EDD.

<Prompt description="Save Payin EDD" actions={["cursor"]}>
  Add the Zapyd "Save Payin EDD" call (`POST /ren/api/v1/payin/edd/save`) to my backend. Submits enhanced due diligence (EDD) details when a payin quotation triggers EDD.

  * Sandbox: `POST https://sandbox.zapyd.com/ren/api/v1/payin/edd/save`
  * Production: `POST https://api.zapyd.com/ren/api/v1/payin/edd/save`

  JSON body:

  * `customer_id` (string, uuid, required): Zapyd customer ID (UUID) returned by Create Customer.
  * `source_of_income` (string, required): Customer's main source of income. One of: `SALARY`, `BUSINESS_INCOME`, `OTHERS`.
  * `bank_statement_url` (array of string, required): URLs of bank statement PDFs. At least one. Example: `["https://storage.example.com/uploads/bank1.pdf", "https://storage.example.com/uploads/bank2.pdf"]`.
  * `bank_statement_passwords` (array of string, optional): Passwords for the bank statement PDFs, in the same order. Use an empty string for no password. Example: `["pass1", ""]`.
  * `tax_document_url` (array of string, optional): URLs of tax documents (for India, ITR reports). Example: `["https://storage.example.com/uploads/itr1.pdf"]`.
  * `tax_document_passwords` (array of string, optional): Passwords for the tax document PDFs, in the same order. Use an empty string for no password. Example: `[""]`.
  * `country_specific_documents` (object, optional): Extra documents your country requires, keyed by document type: `{"doc_type": ["url"]}`.
  * `purpose` (string, required): Why the customer needs higher limits. Free text; the values below are the ones the widget offers. Example: `Investment`.
  * `supporting_purpose_doc_url` (array of string, optional): URLs of documents that support the purpose. Example: `["https://storage.example.com/uploads/example1.pdf", "https://storage.example.com/uploads/example2.pdf"]`.
  * `account_operator` (string, required): Who operates the account. One of: `SELF`, `FAMILY`, `THIRD PARTY`.
  * `account_operator_name` (string, required): Name of the person who operates the account. Example: `John Doe`.
  * `relation_with_account_operator` (string, conditional): Required when account\_operator is not SELF. The customer's relation to the operator. Example: `brother`.
  * `p2p_trading_status` (boolean, required): Is customer involved in P2P trading? Example: `false`.

  Success: HTTP 200, `{status: true, message, data}`. `data`: `id`, `status`.
  Errors (`{status: false, message, err_code, errors}`):

  * 400 `Customer is unverified`: Customer is added but KYC is unverified; Customer does not belong to Organization; Customer is not KYC verified
  * 400 `EDD not required`: EDD for the customer is not currently required or applicable
  * 500 `Internal Server Error`
    Every endpoint can also return 401 `AUTH_*` (signature, timestamp or key: fix, don't retry), and 429 or 5xx (retry with backoff).

  Rules:

  * Enhanced Due Diligence: submit it when the limits endpoint returns `is_edd_required: true`, or when the customer wants a higher limit. A verified payin EDD also covers payouts.
  * Upload the documents to storage Zapyd can reach and send the URLs. At least one bank statement. Password arrays follow the file order, with `""` for no password.
  * The EDD starts as `PROCESSING`, may move to `DOCS_REQ` or `IN_REVIEW`, and ends `VERIFIED` or `FAILED`, each with an `EDD` webhook (usually 24 to 48 hours). On `VERIFIED`, read the limits again. A `FAILED` reason may not be shared.

  Signing (every request):

  * Headers: `X-API-KEY`, `X-TIMESTAMP` (Unix seconds, within 300 s of server time; generate per request) and `X-SIGNATURE`.
  * `X-SIGNATURE` = Base64(HMAC-SHA256(key = API secret, message = apiKey + "|" + timestamp + "|" + canonicalBody)). Base64 of the raw digest, not hex.
  * canonicalBody: the JSON body with keys sorted at every nesting level, no whitespace (separators `,` and `:`), and every non-ASCII character escaped as lowercase `\uXXXX` (Python `json.dumps(body, sort_keys=True, separators=(",", ":"))`). Requests with no body (GET, DELETE) sign `{}`. Query parameters are not signed.
  * Send the exact canonicalBody string you signed as the request body, with `Content-Type: application/json`.
  * Test vector: key `3f1b2c4d-5e6f-4a7b-8c9d-0e1f2a3b4c5d`, secret `test-secret-do-not-use`, timestamp `1735689600`. Signing `{}` gives `6sCtVSRQjU9+2/af8gdwUAvY1l6Ii6ENcbRfanPkhY0=`. Body `{"customer_id":"78c99d71-f28f-47a9-8302-93b286efbe0e","amount":100.5,"currency":"INR","meta":{"note":"Café","b":2,"a":1}}` gives `l+DvQrzlKbsOSxSYOdWoWHEehcFRZfDJPKlLDkm2cSI=`.

  Deliver:

  1. A typed `savePayinEdd` function in this codebase's language and HTTP client. Reuse an existing Zapyd client and signer, or write one small shared client.
  2. Config from `ZAPYD_API_KEY`, `ZAPYD_API_SECRET` and `ZAPYD_BASE_URL`. The secret stays on the server, never in a browser or app.
  3. Return `data`. When `status` is false, throw an error with the HTTP status, `err_code`, `message` and `errors`. Don't show raw errors to end users.
  4. Retry only 429 and 5xx: exponential backoff from 1 s, capped at 30 s, at most 5 attempts.
  5. Amounts as strings. Types for every field above.
  6. Tests: the signer against the test vector, and this call against sandbox.

  Reference: `https://docs.zapyd.com/api-reference-exchange/endpoint/payin/edd/edd-save.md`
</Prompt>

<Note>
  Payin EDD results apply to both payins and payouts. This means that doing Payin EDD is enough to suffice for both payin and payout EDD requirements.
</Note>

## Error Codes and Messages

| API Status Code | Response | Reason |
| - | - | - |
| 400 | Customer is unverified | Customer is added but KYC is unverified |
| 400 | Customer is unverified | Customer does not belong to Organization |
| 400 | Customer is unverified | Customer is not KYC verified |
| 400 | EDD not required | EDD for the customer is not currently required or applicable |
| 500 | Internal Server Error | Internal Server Error |


## OpenAPI

````yaml POST /ren/api/v1/payin/edd/save
openapi: 3.1.0
info:
  title: Zapyd API
  description: API for Zapyd - Customer, Payout, and Webhook services
  license:
    name: MIT
  version: 1.0.0
servers:
  - url: https://sandbox.zapyd.com/pos/api/v1
    description: Payout API Base URL
    variables:
      base_url:
        default: https://sandbox.zapyd.com
  - url: https://sandbox.zapyd.com/cms/api/v1
    description: Customer API Base URL
    variables:
      base_url:
        default: https://sandbox.zapyd.com
security:
  - ApiKeyAuth: []
    TimestampAuth: []
    SignatureAuth: []
tags:
  - name: Customer
    description: Customer related operations
    x-displayName: Customer
    x-traitTag: true
  - name: Payout
    description: Payout related operations
  - name: Webhooks
    description: Webhook related operations
  - name: Widget
    description: Hosted buy/sell widget session initialization
paths:
  /ren/api/v1/payin/edd/save:
    post:
      tags:
        - Payin
      description: Create a payin EDD log
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - customer_id
                - source_of_income
                - bank_statement_url
                - purpose
                - account_operator
                - account_operator_name
                - p2p_trading_status
              properties:
                customer_id:
                  type: string
                  format: uuid
                  description: Zapyd customer ID (UUID) returned by Create Customer.
                  example: 2e104290-07c8-49f1-a5ca-0d27f0078f8a
                source_of_income:
                  type: string
                  enum:
                    - SALARY
                    - BUSINESS_INCOME
                    - OTHERS
                  example: SALARY
                  description: Customer's main source of income.
                bank_statement_url:
                  type: array
                  description: URLs of bank statement PDFs. At least one.
                  example:
                    - https://storage.example.com/uploads/bank1.pdf
                    - https://storage.example.com/uploads/bank2.pdf
                bank_statement_passwords:
                  type: array
                  description: >-
                    Optional. Passwords for the bank statement PDFs, in the same
                    order. Use an empty string for no password.
                  example:
                    - pass1
                    - ''
                tax_document_url:
                  type: array
                  items:
                    type: string
                    format: uri
                  description: Optional. URLs of tax documents (for India, ITR reports).
                  example:
                    - https://storage.example.com/uploads/itr1.pdf
                tax_document_passwords:
                  type: array
                  items:
                    type: string
                  description: >-
                    Optional. Passwords for the tax document PDFs, in the same
                    order. Use an empty string for no password.
                  example:
                    - ''
                country_specific_documents:
                  type: object
                  description: >-
                    Optional. Extra documents your country requires, keyed by
                    document type: {"<doc_type>": ["<url>"]}.
                  additionalProperties:
                    type: array
                    items:
                      type: string
                      format: uri
                purpose:
                  type: string
                  description: >-
                    Why the customer needs higher limits. Free text; the values
                    below are the ones the widget offers.
                  example: Investment
                  examples:
                    - Investment
                    - Trading
                    - Payments
                    - Lending / Repayments
                    - Gifting
                    - Donations / Charity
                    - Remittance
                    - Legal Settlements
                supporting_purpose_doc_url:
                  type: array
                  description: Optional. URLs of documents that support the purpose.
                  example:
                    - https://storage.example.com/uploads/example1.pdf
                    - https://storage.example.com/uploads/example2.pdf
                account_operator:
                  type: string
                  enum:
                    - SELF
                    - FAMILY
                    - THIRD PARTY
                  example: FAMILY
                  description: Who operates the account.
                account_operator_name:
                  type: string
                  example: John Doe
                  description: Name of the person who operates the account.
                relation_with_account_operator:
                  type: string
                  example: brother
                  description: >-
                    Required when account_operator is not SELF. The customer's
                    relation to the operator.
                p2p_trading_status:
                  type: boolean
                  description: Is customer involved in P2P trading?
                  example: false
      responses:
        '200':
          description: Payin EDD submitted successfully
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: boolean
                    example: true
                  message:
                    type: string
                    example: Success
                  data:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                        example: 550e8400-e29b-41d4-a716-446655440000
                      status:
                        type: string
                        example: PROCESSING
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: boolean
                    example: false
                  message:
                    type: string
                    example: Bad Request
                  err_code:
                    type: string
                    example: REQ_FIELD_MISSING
                  errors:
                    type: object
                    properties:
                      customer_id:
                        type: array
                        items:
                          type: string
                        customer_id:
                          - This field is required
                  data:
                    type: 'null'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: boolean
                    example: false
                  message:
                    type: string
                    example: Internal Server Error
                  data:
                    type: 'null'
                  err_code:
                    type: string
                    example: SYS_INTERNAL_ERROR
                  errors:
                    type: string
                    example: Unexpected error occurred. Please try again later.
      servers:
        - url: https://sandbox.zapyd.com
          description: Payin EDD API Base URL
components:
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-API-KEY
      description: API Key for authentication
    TimestampAuth:
      type: apiKey
      in: header
      name: X-TIMESTAMP
      description: Current timestamp in seconds since epoch
    SignatureAuth:
      type: apiKey
      in: header
      name: X-SIGNATURE
      description: HMAC SHA256 signature of the request encoded in Base64

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.