Z Zise Developers 简体中文

Update an identity profile: obtain a hosted-screen link

POST /v1/kyc/profile-sessions scope: kyc:write
On behalf of a member · x-on-behalf-of required Requires x-idempotency-key

Merchants may preferably update profiles directly through PATCH /v1/kyc. This endpoint remains for integrations requiring a hosted page.

A member may change their name, replace a document, or move. Previously there was no path: POST /v1/kyc/sessions rejected members with an existing profile because each account may have only one identity profile. The only workaround was creating a new member, producing a second account with a balance of 0 while the old account's funds and cards remained behind.

The hosted screen prefills existing details, so users edit only the relevant items. Document images not uploaded again retain their existing versions. Forcing three new photos would turn a one-character correction into full KYC resubmission, causing many users to abandon it.

⚠⚠ Every edit returns the profile to pending review, even if previously approved. Changed data is no longer what the reviewer approved. Either editing must be prohibited or review repeated; there is no third option. Therefore:

  • The member's level falls from 1 to 0.
  • Card issuing / remittances / high-value transfers stop until review is approved.
  • Explain this before providing the link, or the user may discover partway through that their card

can no longer be used.

⚠ This is deliberately different from the card document-supplement screen: that screen replaces document images only and does not change the review result.

An image-quality concern from one issuer should not suspend all business for the member.

⚠ If the member has no existing profile, returns 404; it does not fall back to a profile-creation ticket. Use POST /v1/kyc/sessions to create a profile. The two paths do not fall back to one another.

The link is single-use, bound to the member, and valid for 24 hours.

Prerequisites

  • The member already has an identity profile, in any status.
FieldTypeRequiredDescription
x-idempotency-key string Required
x-on-behalf-of string Required

Response

201Ticket issued
{
  "id": "kyc_1c8b7a45e9d24f3ab60e5c917f83d2b4",
  "hosted_url": "https://api.zinfra.vip/hosted/kyc/update/kyc_1c8b7a45e9d24f3ab60e5c917f83d2b4",
  "expires_at": 1786000000
}
400idempotency_key_required · member_context_required · member_not_found
404not_found: this member has no identity profile to edit. Create one through POST /v1/kyc/sessions first.
Request
curl -X POST 'https://api.zinfra.vip/v1/kyc/profile-sessions' \
  -H 'x-auth-token: Bearer $TOKEN' \
  -H 'x-on-behalf-of: $MEMBER_ID' \
  -H 'x-idempotency-key: $IDEMPOTENCY_KEY'
const res = await fetch("https://api.zinfra.vip/v1/kyc/profile-sessions", {
  method: "POST",
  headers: {
    "x-auth-token": "Bearer $TOKEN",
    "x-on-behalf-of": "$MEMBER_ID",
    "x-idempotency-key": "$IDEMPOTENCY_KEY",
  },
});
// Keep monetary amounts as strings, never numbers.
const data = await res.json();
import requests

res = requests.post(
    "https://api.zinfra.vip/v1/kyc/profile-sessions",
    headers={
        "x-auth-token": "Bearer $TOKEN",
        "x-on-behalf-of": "$MEMBER_ID",
        "x-idempotency-key": "$IDEMPOTENCY_KEY",
    },
)
# Use Decimal(str(...)) for amounts, not float.
data = res.json()
req, _ := http.NewRequest("POST", "https://api.zinfra.vip/v1/kyc/profile-sessions",
    nil)
req.Header.Set("x-auth-token", "Bearer $TOKEN")
req.Header.Set("x-on-behalf-of", "$MEMBER_ID")
req.Header.Set("x-idempotency-key", "$IDEMPOTENCY_KEY")
res, err := http.DefaultClient.Do(req)
// Decode amount fields as string, not float64.
HttpRequest req = HttpRequest.newBuilder()
    .uri(URI.create("https://api.zinfra.vip/v1/kyc/profile-sessions"))
    .header("x-auth-token", "Bearer $TOKEN")
    .header("x-on-behalf-of", "$MEMBER_ID")
    .header("x-idempotency-key", "$IDEMPOTENCY_KEY")
    .method("POST", HttpRequest.BodyPublishers.noBody())
    .build();
// Use String / BigDecimal for amounts, not double.
$ch = curl_init('https://api.zinfra.vip/v1/kyc/profile-sessions');
curl_setopt_array($ch, [
  CURLOPT_CUSTOMREQUEST => 'POST',
  CURLOPT_RETURNTRANSFER => true,
  CURLOPT_HTTPHEADER => [
    'x-auth-token: Bearer $TOKEN',
    'x-on-behalf-of: $MEMBER_ID',
    'x-idempotency-key: $IDEMPOTENCY_KEY',
  ],
]);
$res = curl_exec($ch);
// Use bcmath / strings for amounts, not floatval.
201
{
  "id": "kyc_1c8b7a45e9d24f3ab60e5c917f83d2b4",
  "hosted_url": "https://api.zinfra.vip/hosted/kyc/update/kyc_1c8b7a45e9d24f3ab60e5c917f83d2b4",
  "expires_at": 1786000000
}