API reference
Every endpoint, request and response shape in the Rigid platform API. All routes are served from https://api.rigid.fi.
Authentication
Mint API access tokens with OAuth2 client credentials.
Programmes
Card programmes and their module configuration.
/v1/programsList programmesPOST/v1/programsCreate a programmeGET/v1/programs/{id}Retrieve a programmePATCH/v1/programs/{id}Update programme configurationGET/v1/programs/{id}/authorization-controlsList a programme's spend controlsPOST/v1/programs/{id}/authorization-controlsCreate a spend control on a programmePOST/v1/programs/{id}/authorization-controls/{controlId}/deactivateDeactivate a programme's spend controlGET/v1/programs/{id}/stip-activityList a programme's stand-in (STIP) activityGET/v1/programs/{id}/velocity-controlsList a programme's velocity controlsPOST/v1/programs/{id}/velocity-controlsCreate a velocity control on a programmeCard products
Product definitions cards are issued from.
Cardholders
The people and businesses cards are issued to.
/v1/cardholdersList cardholdersPOST/v1/cardholdersCreate a cardholderGET/v1/cardholders/{id}Retrieve a cardholderPATCH/v1/cardholders/{id}Update a cardholderPOST/v1/cardholders/{id}/attestationAttest a cardholderGET/v1/cardholders/{id}/authorization-controlsList a cardholder's spend controlsPOST/v1/cardholders/{id}/authorization-controlsCreate a spend control on a cardholderPOST/v1/cardholders/{id}/authorization-controls/{controlId}/deactivateDeactivate a cardholder's spend controlGET/v1/cardholders/{id}/passkeysList a cardholder's passkeysPOST/v1/cardholders/{id}/passkeysRegister a cardholder passkeyDELETE/v1/cardholders/{id}/passkeys/{credentialId}Revoke a cardholder passkeyPOST/v1/cardholders/{id}/passkeys/optionsGet cardholder passkey registration optionsCards
Issue cards, drive their lifecycle, top up and read balances.
/v1/cardsList cardsPOST/v1/cardsIssue a cardGET/v1/cards/{id}Retrieve a cardGET/v1/cards/{id}/authorization-controlsList a card's spend controlsPOST/v1/cards/{id}/authorization-controlsCreate a spend control on a cardPOST/v1/cards/{id}/authorization-controls/{controlId}/deactivateDeactivate a card's spend controlGET/v1/cards/{id}/balanceRead a card's funding-account balancePOST/v1/cards/{id}/secure-dataAuthorize a single-use grant for revealing the card PANPOST/v1/cards/{id}/topupTop up a card's funding account from the programme floatPOST/v1/cards/{id}/transitionsTransition card lifecycle stateKYC checks
Identity verification checks for cardholders.
/v1/kyc/brandingGet the capture-page branding for a programmePOST/v1/kyc/brandingSet or clear the capture-page branding for a programmeGET/v1/kyc/branding/logoGet a programme's capture-page branding logoGET/v1/kyc/capture-originsGet the registered embed origins for a programmePOST/v1/kyc/capture-originsReplace the registered embed origins for a programmeGET/v1/kyc/checksList KYC checksPOST/v1/kyc/checksStart a KYC checkGET/v1/kyc/checks/{id}Retrieve a KYC checkGET/v1/kyc/checks/{id}/applicantRead submitted applicant data for a KYC checkPOST/v1/kyc/checks/{id}/capture-sessionMint a capture-widget session token for a KYC checkPOST/v1/kyc/checks/{id}/chip-challengeMint a chip Active Authentication challengePOST/v1/kyc/checks/{id}/chip-dataAttach a chip passive-authentication read to a KYC checkGET/v1/kyc/checks/{id}/chip-keysRead the MRZ needed to derive the passport chip’s BAC/PACE keyPOST/v1/kyc/checks/{id}/decisionRecord a decision on a referred KYC checkGET/v1/kyc/checks/{id}/decisionsList decisions for a KYC checkGET/v1/kyc/checks/{id}/document-imageRead a KYC check’s captured document imageGET/v1/kyc/checks/{id}/evidenceList evidence for a KYC checkPOST/v1/kyc/checks/{id}/recaptureRequest a document re-capture on a referred KYC checkGET/v1/kyc/checks/{id}/selfie-imageRead a KYC check’s captured selfie imagePOST/v1/kyc/checks/{id}/selfie-imageAttach a selfie image to a KYC checkPOST/v1/kyc/checks/{id}/submissionsAttach applicant data to a KYC checkGET/v1/kyc/checks/applicantsBatch-resolve applicant display names for KYC checksGET/v1/kyc/flowsList the KYC flows for a programmePOST/v1/kyc/flowsCreate a KYC flow for a programmePATCH/v1/kyc/flows/{flow_key}Rename, archive or unarchive a KYC flowGET/v1/kyc/policyGet the active KYC policy for a programmePOST/v1/kyc/policyWrite a new KYC policy version by toggling required signalsGET/v1/kyc/policy/draftGet the KYC policy editor draft for a programme and flowPUT/v1/kyc/policy/draftSave the KYC policy editor draft for a programme and flowDELETE/v1/kyc/policy/draftDiscard the KYC policy editor draft for a programme and flowPOST/v1/kyc/policy/draft/preview-sessionMint a throwaway preview session for the KYC policy editorPOST/v1/kyc/policy/draft/publishPublish the KYC policy editor draft as the next policy versionSimulated spends
Drive test-mode authorizations end to end.
/v1/simulated-spendsList simulated-spend attemptsPOST/v1/simulated-spendsDrive one simulated authorization against a named cardGET/v1/simulated-spends/{id}Retrieve a simulated-spend attemptPOST/v1/simulated-spends/{id}/incrementFire a row-addressed incremental authorization against a decided simulated spendPOST/v1/simulated-spends/{id}/reversalFire a row-addressed reversal against a decided simulated spendSimulated deposits
Self-serve test-mode programme funding.
Fund your test programme guide →Simulated withdrawals
Self-serve test-mode programme float drawdown.
Fund your test programme guide →Transactions
The transaction timeline read model.
Decline reasons guide →Webhook endpoints
Manage where the platform delivers events.
/v1/webhook-endpointsList webhook endpointsPOST/v1/webhook-endpointsCreate a webhook endpointGET/v1/webhook-endpoints/{id}Retrieve a webhook endpointDELETE/v1/webhook-endpoints/{id}Delete a webhook endpointPATCH/v1/webhook-endpoints/{id}Update a webhook endpointPOST/v1/webhook-endpoints/{id}/rotate-secretRotate webhook signing secretEvents
The tenant event log and redelivery.
Screenings
Sanctions screening runs and the candidates they surfaced.
Screening candidates
The pending-review queue of surfaced sanctions candidates.
Hosted capture (vision)
OCR for the hosted capture widget. Served by a second, temporary host — see Servers.
Embedding the capture widget →/v1/vision/details-submitSubmit typed personal details for a hosted full-flow capture sessionPOST/v1/vision/document-scanOCR a capture-session document photoPOST/v1/vision/selfie-submitSubmit a capture-session selfie (liveness poll or upload)POST/v1/vision/set-document-typeBind a document class for a hosted full-flow capture session