Z Zise Developers 简体中文

Obtain a hosted-screen link for advanced L2 verification

POST /v1/kyc/l2/sessions scope: kyc:write
On behalf of a member · x-on-behalf-of required Requires x-idempotency-key

Optional compatibility endpoint returning a single-use hosted link valid for 24 hours. Merchant Apps should preferably submit parameters directly through POST /v1/kyc/l2/applications without this endpoint. Ticket issuance and submission both check that L2 is enabled, primary L1 is approved, and no non-rejected L2 application exists. Unmet prerequisites return state_invalid; validation failures do not consume the ticket.

Prerequisites

  • The global L2 switch is enabled.
  • The member's primary L1 profile is APPROVED.
  • The member has no non-rejected L2 application.
FieldTypeRequiredDescription
x-on-behalf-of string Required The member for whom to initiate verification. Accepts external_member_id or mem_<uuid>. ⚠ It participates in the idempotency fingerprint: changing the member while reusing a key returns 409.
x-idempotency-key string Required UUID v4. One per member.

Request Body

No fields. The member is determined entirely by x-on-behalf-of.

Response

201Issued. Pass hosted_url to the end user. The response deliberately has no session ID: that string is the credential itself.
{
  "hosted_url": "https://api.zinfra.vip/hosted/kyc/l2/kyc_3c81f0d29a4417d18e0b2f6a1c9d4e77",
  "expires_at": "2026-08-14T05:00:00.000Z"
}
400member_context_required: missing x-on-behalf-of. state_invalid: one of the three prerequisites is unmet. The specific prerequisite is not disclosed; use level and l2_status from GET /v1/kyc to determine it.
403insufficient_scope: missing kyc:write.
404member_not_found, including members belonging to another merchant or suspended members.
409idempotency_key_reused: same key with a different member or body. idempotency_in_progress: the original request is still being processed.
Request
curl -X POST 'https://api.zinfra.vip/v1/kyc/l2/sessions' \
  -H 'x-auth-token: Bearer $TOKEN' \
  -H 'x-on-behalf-of: $MEMBER_ID' \
  -H 'x-idempotency-key: $IDEMPOTENCY_KEY' \
  -H 'content-type: application/json' \
  -d '{}'
const res = await fetch("https://api.zinfra.vip/v1/kyc/l2/sessions", {
  method: "POST",
  headers: {
    "x-auth-token": "Bearer $TOKEN",
    "x-on-behalf-of": "$MEMBER_ID",
    "x-idempotency-key": "$IDEMPOTENCY_KEY",
    "content-type": "application/json",
  },
  body: JSON.stringify({}),
});
// Keep monetary amounts as strings, never numbers.
const data = await res.json();
import requests

res = requests.post(
    "https://api.zinfra.vip/v1/kyc/l2/sessions",
    headers={
        "x-auth-token": "Bearer $TOKEN",
        "x-on-behalf-of": "$MEMBER_ID",
        "x-idempotency-key": "$IDEMPOTENCY_KEY",
        "content-type": "application/json",
    },
    json={},
)
# Use Decimal(str(...)) for amounts, not float.
data = res.json()
req, _ := http.NewRequest("POST", "https://api.zinfra.vip/v1/kyc/l2/sessions",
    strings.NewReader(`{}`))
req.Header.Set("x-auth-token", "Bearer $TOKEN")
req.Header.Set("x-on-behalf-of", "$MEMBER_ID")
req.Header.Set("x-idempotency-key", "$IDEMPOTENCY_KEY")
req.Header.Set("content-type", "application/json")
res, err := http.DefaultClient.Do(req)
// Decode amount fields as string, not float64.
HttpRequest req = HttpRequest.newBuilder()
    .uri(URI.create("https://api.zinfra.vip/v1/kyc/l2/sessions"))
    .header("x-auth-token", "Bearer $TOKEN")
    .header("x-on-behalf-of", "$MEMBER_ID")
    .header("x-idempotency-key", "$IDEMPOTENCY_KEY")
    .header("content-type", "application/json")
    .method("POST", HttpRequest.BodyPublishers.ofString("""
{}
"""))
    .build();
// Use String / BigDecimal for amounts, not double.
$ch = curl_init('https://api.zinfra.vip/v1/kyc/l2/sessions');
curl_setopt_array($ch, [
  CURLOPT_CUSTOMREQUEST => 'POST',
  CURLOPT_RETURNTRANSFER => true,
  CURLOPT_HTTPHEADER => [
    'x-auth-token: Bearer $TOKEN',
    'x-on-behalf-of: $MEMBER_ID',
    'x-idempotency-key: $IDEMPOTENCY_KEY',
    'content-type: application/json',
  ],
  CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$res = curl_exec($ch);
// Use bcmath / strings for amounts, not floatval.
201
{
  "hosted_url": "https://api.zinfra.vip/hosted/kyc/l2/kyc_3c81f0d29a4417d18e0b2f6a1c9d4e77",
  "expires_at": "2026-08-14T05:00:00.000Z"
}