Z Zise Developers 简体中文

Upload a member's KYC file to Zinfra private storage

POST /v1/kyc/files scope: kyc:write
On behalf of a member · x-on-behalf-of required Requires x-idempotency-key

Called on behalf of a member. Put the raw bytes of a single file directly in the request body. JPEG, PNG, WebP, and PDF are supported, with a maximum of 8 MB per file. The server does not trust the declared Content-Type; it determines the actual type from the file's magic bytes.

The returned file_url belongs to the private KYC directory of the member specified by x-on-behalf-of. Use it in profile.identity_photos.front/back/handheld when calling POST /v1/kyc/applications. Do not place external S3 URLs or base64 directly into the KYC profile.

Files are not anonymously accessible; only the member or a Zinfra administrator with KYC review permission may read them.

FieldTypeRequiredDescription
x-idempotency-key string Required
x-on-behalf-of string Required The member's external_member_id or mem_<uuid>.

Request Body

Request body fields have not been declared in the specification for this operation.

Response

201File written to the member's private R2 directory.
{
  "file_url": "https://api.zinfra.dev/kyc/file/member-uuid/file-uuid.jpg"
}
400member_context_required · kyc_upload_invalid · kyc_upload_too_large
409idempotency_key_reused · idempotency_in_progress
429rate_limited
Request
curl -X POST 'https://api.zinfra.vip/v1/kyc/files' \
  -H 'x-auth-token: Bearer $TOKEN' \
  -H 'x-on-behalf-of: $MEMBER_ID' \
  -H 'x-idempotency-key: $IDEMPOTENCY_KEY'
const res = await fetch("https://api.zinfra.vip/v1/kyc/files", {
  method: "POST",
  headers: {
    "x-auth-token": "Bearer $TOKEN",
    "x-on-behalf-of": "$MEMBER_ID",
    "x-idempotency-key": "$IDEMPOTENCY_KEY",
  },
});
// Keep monetary amounts as strings, never numbers.
const data = await res.json();
import requests

res = requests.post(
    "https://api.zinfra.vip/v1/kyc/files",
    headers={
        "x-auth-token": "Bearer $TOKEN",
        "x-on-behalf-of": "$MEMBER_ID",
        "x-idempotency-key": "$IDEMPOTENCY_KEY",
    },
)
# Use Decimal(str(...)) for amounts, not float.
data = res.json()
req, _ := http.NewRequest("POST", "https://api.zinfra.vip/v1/kyc/files",
    nil)
req.Header.Set("x-auth-token", "Bearer $TOKEN")
req.Header.Set("x-on-behalf-of", "$MEMBER_ID")
req.Header.Set("x-idempotency-key", "$IDEMPOTENCY_KEY")
res, err := http.DefaultClient.Do(req)
// Decode amount fields as string, not float64.
HttpRequest req = HttpRequest.newBuilder()
    .uri(URI.create("https://api.zinfra.vip/v1/kyc/files"))
    .header("x-auth-token", "Bearer $TOKEN")
    .header("x-on-behalf-of", "$MEMBER_ID")
    .header("x-idempotency-key", "$IDEMPOTENCY_KEY")
    .method("POST", HttpRequest.BodyPublishers.noBody())
    .build();
// Use String / BigDecimal for amounts, not double.
$ch = curl_init('https://api.zinfra.vip/v1/kyc/files');
curl_setopt_array($ch, [
  CURLOPT_CUSTOMREQUEST => 'POST',
  CURLOPT_RETURNTRANSFER => true,
  CURLOPT_HTTPHEADER => [
    'x-auth-token: Bearer $TOKEN',
    'x-on-behalf-of: $MEMBER_ID',
    'x-idempotency-key: $IDEMPOTENCY_KEY',
  ],
]);
$res = curl_exec($ch);
// Use bcmath / strings for amounts, not floatval.
201
{
  "file_url": "https://api.zinfra.dev/kyc/file/member-uuid/file-uuid.jpg"
}