Send an application back to DRAFT
Admin override that resets an application to DRAFT from any status, clearing the provider session, verification result, rejection reason and reapply cooldown so it can re-run verification from scratch. resubmission_count is preserved. Optionally set `force_new_enroll` to make the applicant’s next Smile ID session a fresh enrollment (overwriting the enrolled biometric). Org-scoped and gated on the backend `accounts.write` permission (override with KYC_REVIEWER_PERMISSION).
Authorization
Cowdi_Sales_KYC_backendBearerAuth Cowdi backend-compatible RS256 JWT. sub may be the global user id or a Firebase auth id; Firebase auth-id subjects and missing organization claims are resolved through the backend user/access endpoints. Validated against the configured JWKS (lib/backend-auth.ts).
In: header
Path Parameters
KYC application id.
uuidRequest Body
application/json
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/v1/kyc/applications/497f6eca-6276-4993-bfeb-53cbbbba6f08/draft" \ -H "Content-Type: application/json" \ -d '{}'{ "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "user_id": "a169451c-8525-4352-b8ca-070dd449a1a5", "organization_id": "string", "user_type": "INDIVIDUAL", "merchant_type": "SOLE_PROPRIETOR", "status": "DRAFT", "source": "string", "documents": [ { "id": "string", "document_type": "string", "document_sub_type": "string", "document_number": "string", "expiry_date": "string", "presigned_url": "string", "uploaded_at": "2026-06-04T10:20:00.000Z" } ], "verification": { "provider": "string", "provider_job_id": "string", "result": "string", "confidence_score": 0, "completed_at": "2026-06-04T10:20:00.000Z" }, "verification_reason_code": "string", "verification_reason": "string", "resubmission_count": 0, "force_new_enroll": true, "reapply_blocked_until": "2026-06-04T10:20:00.000Z", "rejection_reason": "string", "submitted_at": "2026-06-04T10:20:00.000Z", "created_at": "2026-06-04T10:20:00.000Z", "updated_at": "2026-06-04T10:20:00.000Z"}{ "code": "INVALID_PARAMS", "description": "user_id must be a UUID", "identifier": "string", "invalid_params": [ { "path": "user_id", "reason": "must be a UUID", "sub_code": "string" } ]}{ "code": "INVALID_PARAMS", "description": "user_id must be a UUID", "identifier": "string", "invalid_params": [ { "path": "user_id", "reason": "must be a UUID", "sub_code": "string" } ]}{ "code": "INVALID_PARAMS", "description": "user_id must be a UUID", "identifier": "string", "invalid_params": [ { "path": "user_id", "reason": "must be a UUID", "sub_code": "string" } ]}{ "code": "INVALID_PARAMS", "description": "user_id must be a UUID", "identifier": "string", "invalid_params": [ { "path": "user_id", "reason": "must be a UUID", "sub_code": "string" } ]}{ "code": "INVALID_PARAMS", "description": "user_id must be a UUID", "identifier": "string", "invalid_params": [ { "path": "user_id", "reason": "must be a UUID", "sub_code": "string" } ]}Submit a captured selfie + ID for verification (deprecated) POST
Deprecated — use POST /applications/{id}/verification with `channel: "server_upload"`. Kept as a thin alias over the same engine. Server-side capture-then-submit: the browser captures a liveness selfie (with its liveness frames) and the ID document (front + optional back) with Smile ID’s smart-camera-web component and POSTs the base64 images here. They are submitted server-side to Smile ID Enhanced Document Verification (job_type 11) — keeping the government database cross-check while also capturing the back of the ID, which the hosted widget cannot. Include `liveness_images` to run Smile ID’s active-liveness / anti-spoofing check (a lone selfie only gets the passive check). The result arrives asynchronously via the provider callback, so the application is left ID_VERIFICATION_PENDING.
Re-open a terminal application for re-verification POST
Next Page