> ## Documentation Index
> Fetch the complete documentation index at: https://docs.services.payward.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Start Verification from URL

> Start a Payward-performed verification for a user with evidence provided via presigned URLs.

This endpoint accepts the same verification families as Submit Verification from URL: identity document, residence document, and liveness. Liveness checks use three-point images. Use this endpoint when Payward should verify the submitted evidence. Use Submit Verification from URL when your integration already verified the evidence and Payward should trust the verifier result you provide.

## URL and file requirements

Evidence URLs must be HTTPS URLs on allowlisted domains, up to 4096 characters. Each redirect target must also use HTTPS and an allowlisted domain. The server follows up to three redirects.

The server extracts the decoded filename from the submitted URL path. The filename must be 255 bytes or less, cannot be `.` or `..`, and cannot contain path separators or control characters. It must include an extension matching the detected file content.

Downloaded files can be up to 150 MiB (157286400 bytes). The size limit is enforced from the `Content-Length` header and while streaming the response body. Accepted file types are JPEG/JPG, PNG, PDF, MP4/M4V, WebM, and MOV/QuickTime. Passport identity document submissions must omit `back_url`.

## Verification result fields

Do not send `verifier`, `verified_at`, `verifier_response`, or `verifier_response_url` to this endpoint. Those fields belong to Submit Verification from URL because that endpoint trusts a verification result supplied by your integration.

## Domain allowlisting

For security, the domains you use for presigned URLs must be allowlisted before you can use this endpoint. Contact your account manager to configure the allowed domains for your integration.



## OpenAPI

````yaml /api-reference/openapi_v3_pws.json post /v1/users/{user_id}/verifications/start/url
openapi: 3.1.0
info:
  title: Payward Services API
  description: >-
    The Payward Services (PWS) public API.


    PWS exposes Swaps (institutional FX-style trading), Conversions (rule-driven
    and one-shot fiat ↔ crypto value movement), retail-style Quotes and Price
    Trigger Swaps, end-user Users / Verifications, Funds (deposits, withdrawals,
    addresses, transactions), Portfolio, Earn, Reports, Webhooks, and Ramp
    (hosted fiat-to-crypto on-ramp checkout).


    All requests must be authenticated. All monetary values are decimal strings;
    all timestamps are ISO 8601 UTC. List endpoints are cursor-paginated. Errors
    follow a uniform shape (see `*ErrorResponse` schemas).
  version: v1
  contact:
    name: Payward Services API Support
    url: https://docs.payward.com
    email: api-support@payward.com
servers:
  - url: https://api.services.payward.com
    description: Production
security:
  - ApiKey: []
    ApiNonce: []
    ApiSign: []
tags:
  - name: Users
    description: >-
      Users and headless-user onboarding flows that the partner manages.


      - **Create User** provisions a user with full identity verification fields
      collected up front.

      - **Create Headless User** provisions a lightweight user when your
      licensing agreement allows you to manage KYC data outside Payward.

      - **Get User** retrieves the user's profile, verification status, and
      required actions.

      - **Update User** updates user profile fields and may re-trigger
      verification.


      Use the returned user `id` for calls that require the user's identifier.
  - name: Assets
    description: >-
      Catalog of assets available on the platform with retail-display metadata
      (logos, market data, descriptions).
  - name: Conversions
    description: >-
      Rule-driven and one-shot fiat ↔ crypto value movement, including
      conversion rules, deposits, and whitelisted wallets.
  - name: Earn
    description: >-
      Manage auto-earn preferences and retrieve allocation and reward
      information.
  - name: Funds
    description: >-
      Deposits, withdrawals, addresses, methods, and the consolidated
      funding-transactions ledger.
  - name: Portfolio
    description: End-user portfolio summary, history, and transaction views.
  - name: Price Trigger Swaps
    description: Limit-style orders that execute when a configured price trigger is met.
  - name: On-chain Swaps
    description: >-
      Wallet-funded onchain quote trading for xStock and USDC pairs. On-chain
      quotes settle on-chain through the Payward on-chain proxy contract.
  - name: Ramp
    description: >-
      Hosted fiat-to-crypto on-ramp checkout: country / fiat / payment-method /
      cryptocurrency-asset discovery, transaction limits and prospective quotes,
      and the hosted checkout URL.
  - name: Reports
    description: Settlement and reconciliation reports for the partner.
  - name: Swaps
    description: >-
      Direct partner-to-Payward swap quotes and executions (institutional
      FX-style trading).
  - name: Verifications
    description: Identity verification (KYC) submission and status for end users.
  - name: Webhooks
    description: Manage webhook subscriptions for asynchronous event delivery.
paths:
  /v1/users/{user_id}/verifications/start/url:
    post:
      tags:
        - Verifications
      summary: Start Verification from URL
      description: >-
        Start a Payward-performed verification for a user with evidence provided
        via presigned URLs.


        This endpoint accepts the same verification families as Submit
        Verification from URL: identity document, residence document, and
        liveness. Liveness checks use three-point images. Use this endpoint when
        Payward should verify the submitted evidence. Use Submit Verification
        from URL when your integration already verified the evidence and Payward
        should trust the verifier result you provide.


        ## URL and file requirements


        Evidence URLs must be HTTPS URLs on allowlisted domains, up to 4096
        characters. Each redirect target must also use HTTPS and an allowlisted
        domain. The server follows up to three redirects.


        The server extracts the decoded filename from the submitted URL path.
        The filename must be 255 bytes or less, cannot be `.` or `..`, and
        cannot contain path separators or control characters. It must include an
        extension matching the detected file content.


        Downloaded files can be up to 150 MiB (157286400 bytes). The size limit
        is enforced from the `Content-Length` header and while streaming the
        response body. Accepted file types are JPEG/JPG, PNG, PDF, MP4/M4V,
        WebM, and MOV/QuickTime. Passport identity document submissions must
        omit `back_url`.


        ## Verification result fields


        Do not send `verifier`, `verified_at`, `verifier_response`, or
        `verifier_response_url` to this endpoint. Those fields belong to Submit
        Verification from URL because that endpoint trusts a verification result
        supplied by your integration.


        ## Domain allowlisting


        For security, the domains you use for presigned URLs must be allowlisted
        before you can use this endpoint. Contact your account manager to
        configure the allowed domains for your integration.
      operationId: startVerificationFromUrl
      parameters:
        - $ref: '#/components/parameters/UserIdPath'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/StartUrlVerificationRequest'
            examples:
              identity-document:
                summary: Identity document
                value:
                  type: identity_document
                  metadata:
                    identity:
                      full_name:
                        first_name: Alex
                        last_name: Morgan
                      birth:
                        date: '1990-01-31'
                    document_type: passport
                    document_number: A1234567
                    issuing_country: US
                  front_url: >-
                    https://your-allowlisted-bucket.s3.amazonaws.com/front.png?X-Amz-Algorithm=AWS4-HMAC-SHA256
              residence-document:
                summary: Residence document
                value:
                  type: residence_document
                  metadata:
                    address:
                      line1: 800 Market Street
                      line2: Suite 210
                      city: San Francisco
                      postal_code: '94102'
                      province: CA
                      country: US
                    document_type: utility_bill
                  document_url: >-
                    https://your-allowlisted-bucket.s3.amazonaws.com/address.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256
              liveness:
                summary: Liveness
                value:
                  type: liveness
                  left_url: >-
                    https://your-allowlisted-bucket.s3.amazonaws.com/liveness-left.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256
                  center_url: >-
                    https://your-allowlisted-bucket.s3.amazonaws.com/liveness-center.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256
                  right_url: >-
                    https://your-allowlisted-bucket.s3.amazonaws.com/liveness-right.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256
      responses:
        '200':
          description: Verification started.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StartUrlVerificationResponse'
              example:
                data:
                  verification_id: PVABCDE-FGHIJ-KLMNOP
          headers:
            Request-Id:
              $ref: '#/components/headers/RequestId'
            X-RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/RateLimitReset'
            Strict-Transport-Security:
              $ref: '#/components/headers/StrictTransportSecurity'
            X-Content-Type-Options:
              $ref: '#/components/headers/XContentTypeOptions'
            Content-Security-Policy:
              $ref: '#/components/headers/ContentSecurityPolicy'
            Cache-Control:
              $ref: '#/components/headers/CacheControl'
        '400':
          description: Validation error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BadRequestError'
          headers:
            Request-Id:
              $ref: '#/components/headers/RequestId'
            X-RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/RateLimitReset'
            Strict-Transport-Security:
              $ref: '#/components/headers/StrictTransportSecurity'
            X-Content-Type-Options:
              $ref: '#/components/headers/XContentTypeOptions'
            Content-Security-Policy:
              $ref: '#/components/headers/ContentSecurityPolicy'
            Cache-Control:
              $ref: '#/components/headers/CacheControl'
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnauthenticatedError'
          headers:
            Request-Id:
              $ref: '#/components/headers/RequestId'
            X-RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/RateLimitReset'
            Strict-Transport-Security:
              $ref: '#/components/headers/StrictTransportSecurity'
            X-Content-Type-Options:
              $ref: '#/components/headers/XContentTypeOptions'
            Content-Security-Policy:
              $ref: '#/components/headers/ContentSecurityPolicy'
            Cache-Control:
              $ref: '#/components/headers/CacheControl'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ForbiddenError'
          headers:
            Request-Id:
              $ref: '#/components/headers/RequestId'
            X-RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/RateLimitReset'
            Strict-Transport-Security:
              $ref: '#/components/headers/StrictTransportSecurity'
            X-Content-Type-Options:
              $ref: '#/components/headers/XContentTypeOptions'
            Content-Security-Policy:
              $ref: '#/components/headers/ContentSecurityPolicy'
            Cache-Control:
              $ref: '#/components/headers/CacheControl'
        '429':
          description: Rate limit exceeded
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ResourceExhaustedError'
          headers:
            Request-Id:
              $ref: '#/components/headers/RequestId'
            X-RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/RateLimitReset'
            Strict-Transport-Security:
              $ref: '#/components/headers/StrictTransportSecurity'
            X-Content-Type-Options:
              $ref: '#/components/headers/XContentTypeOptions'
            Content-Security-Policy:
              $ref: '#/components/headers/ContentSecurityPolicy'
            Cache-Control:
              $ref: '#/components/headers/CacheControl'
            Retry-After:
              $ref: '#/components/headers/RetryAfter'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InternalError'
          headers:
            Request-Id:
              $ref: '#/components/headers/RequestId'
            X-RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/RateLimitReset'
            Strict-Transport-Security:
              $ref: '#/components/headers/StrictTransportSecurity'
            X-Content-Type-Options:
              $ref: '#/components/headers/XContentTypeOptions'
            Content-Security-Policy:
              $ref: '#/components/headers/ContentSecurityPolicy'
            Cache-Control:
              $ref: '#/components/headers/CacheControl'
        '501':
          description: Error response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnimplementedError'
          headers:
            Request-Id:
              $ref: '#/components/headers/RequestId'
            X-RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/RateLimitReset'
            Strict-Transport-Security:
              $ref: '#/components/headers/StrictTransportSecurity'
            X-Content-Type-Options:
              $ref: '#/components/headers/XContentTypeOptions'
            Content-Security-Policy:
              $ref: '#/components/headers/ContentSecurityPolicy'
            Cache-Control:
              $ref: '#/components/headers/CacheControl'
        '503':
          description: Service unavailable
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnavailableError'
          headers:
            Request-Id:
              $ref: '#/components/headers/RequestId'
            X-RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/RateLimitReset'
            Strict-Transport-Security:
              $ref: '#/components/headers/StrictTransportSecurity'
            X-Content-Type-Options:
              $ref: '#/components/headers/XContentTypeOptions'
            Content-Security-Policy:
              $ref: '#/components/headers/ContentSecurityPolicy'
            Cache-Control:
              $ref: '#/components/headers/CacheControl'
        '504':
          description: Deadline exceeded
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DeadlineExceededError'
          headers:
            Request-Id:
              $ref: '#/components/headers/RequestId'
            X-RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/RateLimitReset'
            Strict-Transport-Security:
              $ref: '#/components/headers/StrictTransportSecurity'
            X-Content-Type-Options:
              $ref: '#/components/headers/XContentTypeOptions'
            Content-Security-Policy:
              $ref: '#/components/headers/ContentSecurityPolicy'
            Cache-Control:
              $ref: '#/components/headers/CacheControl'
      security:
        - ApiKey: []
          ApiNonce: []
          ApiSign: []
      x-codeSamples:
        - lang: bash
          label: curl
          source: >-
            curl -X POST
            "https://api.services.payward.com/v1/users/AA45N8G4MLDYWAR7/verifications/start/url"
            \
              -H "API-Key: $PWS_API_KEY" \
              -H "API-Nonce: $PWS_API_NONCE" \
              -H "API-Sign: $PWS_API_SIGN" \
              -H "Content-Type: application/json" \
              -d '{
                "type": "identity_document",
                "metadata": {
                  "identity": {
                    "full_name": {
                      "first_name": "Alex",
                      "last_name": "Morgan"
                    },
                    "birth": {
                      "date": "1990-01-31"
                    }
                  },
                  "document_type": "passport",
                  "document_number": "A1234567",
                  "issuing_country": "US"
                },
                "front_url": "https://your-allowlisted-bucket.s3.amazonaws.com/front.png?X-Amz-Algorithm=AWS4-HMAC-SHA256"
              }'
components:
  parameters:
    UserIdPath:
      in: path
      name: user_id
      required: true
      description: >-
        ID of the user the request applies to. For partners operating in the
        B2B2C model, this is the Sub-User the request is acting on behalf of.
      schema:
        $ref: '#/components/schemas/UserId'
      example: AA45N8G4MLDYWAR7
  schemas:
    StartUrlVerificationRequest:
      description: >-
        Verification request body. The `type` discriminator selects exactly one
        start verification payload.
      oneOf:
        - $ref: '#/components/schemas/StartIdentityDocumentVerificationRequest'
        - $ref: '#/components/schemas/StartResidenceDocumentVerificationRequest'
        - $ref: '#/components/schemas/StartLivenessVerificationRequest'
      discriminator:
        propertyName: type
        mapping:
          identity_document:
            $ref: '#/components/schemas/StartIdentityDocumentVerificationRequest'
          residence_document:
            $ref: '#/components/schemas/StartResidenceDocumentVerificationRequest'
          liveness:
            $ref: '#/components/schemas/StartLivenessVerificationRequest'
    StartUrlVerificationResponse:
      type: object
      properties:
        data:
          type: object
          properties:
            verification_id:
              $ref: '#/components/schemas/VerificationId'
          required:
            - verification_id
      required:
        - data
    BadRequestError:
      description: Request validation failed or the request could not be processed.
      allOf:
        - $ref: '#/components/schemas/PwsValidationErrorEnvelope'
        - type: object
          required:
            - error
          properties:
            error:
              allOf:
                - $ref: '#/components/schemas/PwsValidationError'
                - type: object
                  required:
                    - status
                    - code
                  properties:
                    status:
                      type: integer
                      format: int32
                      enum:
                        - 400
                    code:
                      type: string
                      enum:
                        - bad_request
    UnauthenticatedError:
      description: Authentication credentials are missing, invalid, or not accepted.
      allOf:
        - $ref: '#/components/schemas/PwsGeneralErrorEnvelope'
        - type: object
          required:
            - error
          properties:
            error:
              allOf:
                - $ref: '#/components/schemas/PwsGeneralError'
                - type: object
                  required:
                    - status
                    - code
                  properties:
                    status:
                      type: integer
                      format: int32
                      enum:
                        - 401
                    code:
                      type: string
                      enum:
                        - unauthenticated
    ForbiddenError:
      description: The authenticated caller is not allowed to perform this operation.
      allOf:
        - $ref: '#/components/schemas/PwsGeneralErrorEnvelope'
        - type: object
          required:
            - error
          properties:
            error:
              allOf:
                - $ref: '#/components/schemas/PwsGeneralError'
                - type: object
                  required:
                    - status
                    - code
                  properties:
                    status:
                      type: integer
                      format: int32
                      enum:
                        - 403
                    code:
                      type: string
                      enum:
                        - forbidden
    ResourceExhaustedError:
      description: The request was rate limited or a resource quota was exhausted.
      allOf:
        - $ref: '#/components/schemas/PwsGeneralErrorEnvelope'
        - type: object
          required:
            - error
          properties:
            error:
              allOf:
                - $ref: '#/components/schemas/PwsGeneralError'
                - type: object
                  required:
                    - status
                    - code
                  properties:
                    status:
                      type: integer
                      format: int32
                      enum:
                        - 429
                    code:
                      type: string
                      enum:
                        - resource_exhausted
    InternalError:
      description: An unexpected server-side error occurred.
      allOf:
        - $ref: '#/components/schemas/PwsGeneralErrorEnvelope'
        - type: object
          required:
            - error
          properties:
            error:
              allOf:
                - $ref: '#/components/schemas/PwsGeneralError'
                - type: object
                  required:
                    - status
                    - code
                  properties:
                    status:
                      type: integer
                      format: int32
                      enum:
                        - 500
                    code:
                      type: string
                      enum:
                        - internal
    UnimplementedError:
      description: The operation is not implemented by the upstream service.
      allOf:
        - $ref: '#/components/schemas/PwsGeneralErrorEnvelope'
        - type: object
          required:
            - error
          properties:
            error:
              allOf:
                - $ref: '#/components/schemas/PwsGeneralError'
                - type: object
                  required:
                    - status
                    - code
                  properties:
                    status:
                      type: integer
                      format: int32
                      enum:
                        - 501
                    code:
                      type: string
                      enum:
                        - unimplemented
    UnavailableError:
      description: The service is temporarily unavailable.
      allOf:
        - $ref: '#/components/schemas/PwsGeneralErrorEnvelope'
        - type: object
          required:
            - error
          properties:
            error:
              allOf:
                - $ref: '#/components/schemas/PwsGeneralError'
                - type: object
                  required:
                    - status
                    - code
                  properties:
                    status:
                      type: integer
                      format: int32
                      enum:
                        - 503
                    code:
                      type: string
                      enum:
                        - unavailable
    DeadlineExceededError:
      description: The upstream service did not complete the request before the deadline.
      allOf:
        - $ref: '#/components/schemas/PwsGeneralErrorEnvelope'
        - type: object
          required:
            - error
          properties:
            error:
              allOf:
                - $ref: '#/components/schemas/PwsGeneralError'
                - type: object
                  required:
                    - status
                    - code
                  properties:
                    status:
                      type: integer
                      format: int32
                      enum:
                        - 504
                    code:
                      type: string
                      enum:
                        - deadline_exceeded
    UserId:
      type: string
      description: Canonical identifier for a user in the Payward public API.
      minLength: 14
      maxLength: 42
    StartIdentityDocumentVerificationRequest:
      type: object
      description: >-
        Start an identity document verification from front and optional back
        document HTTPS URLs.
      additionalProperties: false
      properties:
        type:
          type: string
          enum:
            - identity_document
        metadata:
          $ref: '#/components/schemas/StartIdentityDocumentVerificationMetadata'
        front_url:
          description: >-
            Presigned URL to the front side of the identity document. The
            filename is extracted from the URL path and must meet the URL and
            file requirements.
          allOf:
            - $ref: '#/components/schemas/StartVerificationDocumentUrl'
        back_url:
          description: >-
            Presigned URL to the back side of the identity document. The
            filename is extracted from the URL path and must meet the URL and
            file requirements. Passport submissions must omit this field.
          anyOf:
            - allOf:
                - $ref: '#/components/schemas/StartVerificationDocumentUrl'
            - type: 'null'
      required:
        - metadata
        - type
        - front_url
    StartResidenceDocumentVerificationRequest:
      type: object
      description: Start a residence document verification from a document HTTPS URL.
      additionalProperties: false
      properties:
        type:
          type: string
          enum:
            - residence_document
        metadata:
          $ref: '#/components/schemas/StartResidenceDocumentVerificationMetadata'
        document_url:
          description: >-
            Presigned URL to the residence document. The filename is extracted
            from the URL path and must meet the URL and file requirements.
          allOf:
            - $ref: '#/components/schemas/StartVerificationDocumentUrl'
      required:
        - metadata
        - type
        - document_url
    StartLivenessVerificationRequest:
      type: object
      description: Start a liveness verification from three-point HTTPS image URLs.
      additionalProperties: false
      properties:
        type:
          type: string
          enum:
            - liveness
        left_url:
          description: >-
            Presigned URL to the user's left-facing liveness image. The filename
            is extracted from the URL path and must meet the URL and file
            requirements.
          allOf:
            - $ref: '#/components/schemas/StartVerificationDocumentUrl'
        center_url:
          description: >-
            Presigned URL to the user's center-facing liveness image. The
            filename is extracted from the URL path and must meet the URL and
            file requirements.
          allOf:
            - $ref: '#/components/schemas/StartVerificationDocumentUrl'
        right_url:
          description: >-
            Presigned URL to the user's right-facing liveness image. The
            filename is extracted from the URL path and must meet the URL and
            file requirements.
          allOf:
            - $ref: '#/components/schemas/StartVerificationDocumentUrl'
      required:
        - type
        - left_url
        - center_url
        - right_url
    VerificationId:
      type: string
      description: Public identifier for a Payward-managed verification.
      pattern: ^PV[A-Z0-9]{5}-[A-Z0-9]{5}-[A-Z0-9]{6}$
      minLength: 20
      maxLength: 20
      example: PVABCDE-FGHIJ-KLMNOP
    PwsValidationErrorEnvelope:
      description: Error envelope for request validation failures.
      type: object
      required:
        - error
      properties:
        error:
          $ref: '#/components/schemas/PwsValidationError'
    PwsValidationError:
      description: Standard PWS API error object for request validation failures.
      type: object
      required:
        - type
        - status
        - instance
        - code
      properties:
        type:
          description: Machine-readable error class.
          type: string
        status:
          description: HTTP status code returned for this error.
          type: integer
          format: int32
        instance:
          description: Request identifier for this specific error occurrence.
          type: string
        code:
          description: Stable machine-readable error code.
          type: string
        doc_url:
          description: Optional link to documentation for this error.
          type: string
          format: uri
        causes:
          description: Validation failures that contributed to the error.
          type: array
          items:
            $ref: '#/components/schemas/PwsErrorCause'
    PwsGeneralErrorEnvelope:
      description: Error envelope for operational or domain failures.
      type: object
      required:
        - error
      properties:
        error:
          $ref: '#/components/schemas/PwsGeneralError'
    PwsGeneralError:
      description: Standard PWS API error object for non-validation failures.
      allOf:
        - $ref: '#/components/schemas/PwsErrorBase'
        - type: object
          properties:
            causes:
              description: Additional error details, when present.
              type: array
              items:
                type: object
                additionalProperties: true
    StartIdentityDocumentVerificationMetadata:
      description: Metadata about the identity document to verify.
      type: object
      additionalProperties: false
      properties:
        identity:
          $ref: '#/components/schemas/StartVerificationIdentity'
        document_type:
          description: Type of identity document.
          type: string
          enum:
            - passport
            - drivers_license
            - id_card
            - residence_card
            - special_permanent_residence_card
        document_number:
          description: Number of the document, such as a driver's license number.
          type: string
          minLength: 1
          maxLength: 256
        issuing_country:
          description: Country of issuance of the identity document.
          allOf:
            - $ref: '#/components/schemas/CountryCode'
        nationality:
          description: Nationality of the identified person according to the document.
          anyOf:
            - allOf:
                - $ref: '#/components/schemas/CountryCode'
            - type: 'null'
        expiration_date:
          description: >-
            Optional expiration date of the verification when it is no longer
            valid in ISO 8601 format.
          type:
            - string
            - 'null'
          pattern: ^[0-9]{4}-[0-9]{2}-[0-9]{2}$
          format: date
          example: '2028-03-13'
      required:
        - identity
        - document_type
        - document_number
        - issuing_country
    StartVerificationDocumentUrl:
      type: string
      description: >-
        HTTPS presigned URL to a document or image on an allowlisted domain. The
        filename is extracted from the URL path and must meet the URL and file
        requirements.
      minLength: 1
      maxLength: 4096
      format: uri
      pattern: ^https://
      example: >-
        https://your-allowlisted-bucket.s3.amazonaws.com/front.png?X-Amz-Algorithm=AWS4-HMAC-SHA256
    StartResidenceDocumentVerificationMetadata:
      description: Metadata about the residence document to verify.
      type: object
      additionalProperties: false
      properties:
        address:
          $ref: '#/components/schemas/StartVerificationAddress'
        document_type:
          description: Type of residence verification document.
          type: string
          enum:
            - bank_statement
            - credit_card_statement
            - employer_letter_or_work_contract
            - government_issued_document
            - home_or_rental_insurance
            - internet_or_cable_bill
            - mobile_phone_bill
            - mortgage_statement
            - official_government_letter
            - passport_address_page
            - rental_or_lease_agreement
            - residence_certificate
            - social_insurance_payment_receipt
            - tax_receipt
            - tax_return
            - utility_bill
            - other
        document_number:
          description: Number of the document, when available.
          type:
            - string
            - 'null'
          minLength: 1
          maxLength: 256
        expiration_date:
          description: >-
            Optional expiration date of the verification when it is no longer
            valid in ISO 8601 format.
          type:
            - string
            - 'null'
          pattern: ^[0-9]{4}-[0-9]{2}-[0-9]{2}$
          format: date
          example: '2028-03-13'
      required:
        - address
        - document_type
    PwsErrorCause:
      description: A single request validation failure.
      type: object
      required:
        - field
        - message
      properties:
        field:
          description: Dot-notation path to the offending request field.
          type: string
        message:
          description: Human-readable explanation of the failed validation rule.
          type: string
    PwsErrorBase:
      description: Common fields present on every PWS API error object.
      type: object
      required:
        - type
        - status
        - instance
        - code
      properties:
        type:
          description: Machine-readable error class.
          type: string
        status:
          description: HTTP status code returned for this error.
          type: integer
          format: int32
        instance:
          description: Request identifier for this specific error occurrence.
          type: string
        code:
          description: Stable machine-readable error code.
          type: string
        doc_url:
          description: Optional link to documentation for this error.
          type: string
          format: uri
    StartVerificationIdentity:
      type: object
      description: The identity of the person in the document.
      properties:
        full_name:
          $ref: '#/components/schemas/StartVerificationFullName'
        birth:
          description: User birth details.
          type: object
          properties:
            date:
              description: User's date of birth.
              type: string
              pattern: ^[0-9]{4}-[0-9]{2}-[0-9]{2}$
              format: date
              example: '1990-01-31'
          required:
            - date
      required:
        - full_name
        - birth
    CountryCode:
      description: ISO 3166-1 alpha-2 country code.
      type: string
      enum:
        - AD
        - AE
        - AF
        - AG
        - AI
        - AL
        - AM
        - AO
        - AQ
        - AR
        - AS
        - AT
        - AU
        - AW
        - AX
        - AZ
        - BA
        - BB
        - BD
        - BE
        - BF
        - BG
        - BH
        - BI
        - BJ
        - BL
        - BM
        - BN
        - BO
        - BQ
        - BR
        - BS
        - BT
        - BV
        - BW
        - BY
        - BZ
        - CA
        - CC
        - CD
        - CF
        - CG
        - CH
        - CI
        - CK
        - CL
        - CM
        - CN
        - CO
        - CR
        - CU
        - CV
        - CW
        - CX
        - CY
        - CZ
        - DE
        - DJ
        - DK
        - DM
        - DO
        - DZ
        - EC
        - EE
        - EG
        - EH
        - ER
        - ES
        - ET
        - FI
        - FJ
        - FK
        - FM
        - FO
        - FR
        - GA
        - GB
        - GD
        - GE
        - GF
        - GG
        - GH
        - GI
        - GL
        - GM
        - GN
        - GP
        - GQ
        - GR
        - GS
        - GT
        - GU
        - GW
        - GY
        - HK
        - HM
        - HN
        - HR
        - HT
        - HU
        - ID
        - IE
        - IL
        - IM
        - IN
        - IO
        - IQ
        - IR
        - IS
        - IT
        - JE
        - JM
        - JO
        - JP
        - KE
        - KG
        - KH
        - KI
        - KM
        - KN
        - KP
        - KR
        - KW
        - KY
        - KZ
        - LA
        - LB
        - LC
        - LI
        - LK
        - LR
        - LS
        - LT
        - LU
        - LV
        - LY
        - MA
        - MC
        - MD
        - ME
        - MF
        - MG
        - MH
        - MK
        - ML
        - MM
        - MN
        - MO
        - MP
        - MQ
        - MR
        - MS
        - MT
        - MU
        - MV
        - MW
        - MX
        - MY
        - MZ
        - NA
        - NC
        - NE
        - NF
        - NG
        - NI
        - NL
        - 'NO'
        - NP
        - NR
        - NU
        - NZ
        - OM
        - PA
        - PE
        - PF
        - PG
        - PH
        - PK
        - PL
        - PM
        - PN
        - PR
        - PS
        - PT
        - PW
        - PY
        - QA
        - RE
        - RO
        - RS
        - RU
        - RW
        - SA
        - SB
        - SC
        - SD
        - SE
        - SG
        - SH
        - SI
        - SJ
        - SK
        - SL
        - SM
        - SN
        - SO
        - SR
        - SS
        - ST
        - SV
        - SX
        - SY
        - SZ
        - TC
        - TD
        - TF
        - TG
        - TH
        - TJ
        - TK
        - TL
        - TM
        - TN
        - TO
        - TR
        - TT
        - TV
        - TW
        - TZ
        - UA
        - UG
        - UM
        - US
        - UY
        - UZ
        - VA
        - VC
        - VE
        - VG
        - VI
        - VN
        - VU
        - WF
        - WS
        - YE
        - YT
        - ZA
        - ZM
        - ZW
        - AC
        - AN
        - AP
        - CP
        - DG
        - EA
        - EU
        - IC
        - JX
        - TA
        - QO
        - XK
        - 0C
      minLength: 2
      maxLength: 2
      example: US
    StartVerificationAddress:
      type: object
      description: The address captured in this document.
      properties:
        city:
          description: City.
          type: string
          minLength: 1
          maxLength: 128
        postal_code:
          description: Postal code.
          type: string
          minLength: 1
          maxLength: 32
        province:
          description: Province or state.
          type:
            - string
            - 'null'
          minLength: 1
          maxLength: 128
        country:
          description: Country.
          allOf:
            - $ref: '#/components/schemas/CountryCode'
        line1:
          description: Address line 1.
          type: string
          minLength: 1
          maxLength: 256
        line2:
          description: Address line 2.
          type:
            - string
            - 'null'
          minLength: 1
          maxLength: 256
      required:
        - city
        - country
        - line1
        - postal_code
    StartVerificationFullName:
      type: object
      description: User's full name.
      properties:
        first_name:
          description: User's first name.
          type: string
          minLength: 1
          maxLength: 256
        middle_name:
          description: User's middle name.
          type:
            - string
            - 'null'
          minLength: 1
          maxLength: 256
        last_name:
          description: User's last name.
          type: string
          minLength: 1
          maxLength: 256
      required:
        - first_name
        - last_name
  headers:
    RequestId:
      description: >-
        Unique identifier for tracing this request across services. Include in
        support tickets.
      schema:
        type: string
        format: uuid
        example: 5f4d2a8e-91a4-4d6c-8a17-9b1e2c3f4a5b
    RateLimitLimit:
      description: Total requests allowed in the current window.
      schema:
        type: integer
        example: 1000
    RateLimitRemaining:
      description: Requests remaining in the current window.
      schema:
        type: integer
        example: 955
    RateLimitReset:
      description: Unix timestamp (seconds) when the rate-limit window resets.
      schema:
        type: integer
        format: int64
        example: 1713182400
    StrictTransportSecurity:
      description: >-
        Enforces HTTPS for the configured period. Always `max-age=63072000;
        includeSubDomains; preload`.
      schema:
        type: string
        example: max-age=63072000; includeSubDomains; preload
    XContentTypeOptions:
      description: Disables MIME sniffing. Always `nosniff`.
      schema:
        type: string
        enum:
          - nosniff
        example: nosniff
    ContentSecurityPolicy:
      description: >-
        Prevents embedding and resource loading. Always `default-src 'none';
        frame-ancestors 'none'`.
      schema:
        type: string
        example: default-src 'none'; frame-ancestors 'none'
    CacheControl:
      description: Prevents caching of sensitive financial data. Always `no-store`.
      schema:
        type: string
        enum:
          - no-store
        example: no-store
    RetryAfter:
      description: Seconds the client should wait before retrying.
      schema:
        type: integer
        example: 30
  securitySchemes:
    ApiKey:
      type: apiKey
      name: API-Key
      in: header
      description: Your public API key. Identifies the partner making the request.
    ApiNonce:
      type: apiKey
      name: API-Nonce
      in: header
      description: Monotonically increasing nonce included in the request signature.
    ApiSign:
      type: apiKey
      name: API-Sign
      in: header
      description: HMAC signature over the request, computed with your private key.

````