Generate an agent customer KYC link
Generate a single-use hosted KYC link for the authenticated agent’s individual customer. Requires the MANAGE_IDENTITY permission in the agent’s policy.
Authorizations
Bearer token authentication for agent-scoped endpoints. The token is the accessToken returned when redeeming a device code via POST /agents/device-codes/redeem. Agent credentials are user-scoped: all requests are automatically bound to the agent's associated customer and subject to the agent's policy.
Body
Request body for generating a hosted KYC link for an existing customer.
URI the customer is redirected to after completing the hosted KYC flow. Must start with https:// (or http:// for local development). Embedded in the returned kycUrl.
"https://app.example.com/onboarding/completed"
Response
KYC link generated
A hosted KYC link that the customer can complete to verify their identity.
Hosted URL the customer should be sent to in order to complete verification. The URL is single-use and expires at expiresAt. To generate a new link (for example, after the previous one expires or is abandoned), call this endpoint again.
"https://kyc.lightspark.com/onboard/abc123def456"
Time at which the hosted link expires and can no longer be used.
"2027-01-15T14:32:00Z"
The KYC provider that will perform identity verification for the customer. Grid selects the provider based on the customer's region and platform configuration; the value is informational for platforms that want to integrate directly with the provider's SDK.
SUMSUB "SUMSUB"
Provider-specific token that can be used in place of the hosted URL — for example, to embed the provider's SDK directly in your application. Only returned for providers that support direct SDK integration. Whether to use the hosted URL or the embedded SDK is up to you; both flows result in the same kycStatus update on the customer.
"_act-sbx-jwt-eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."