Mint a throwaway preview session for the KYC policy editor
/v1/kyc/policy/draft/preview-sessionRequires an API client bearer token.
Mints a short-lived (15 minute), throwaway preview session so the console's step-through preview pane can render the open editor draft — or, when no draft exists, the current active policy as-is — inside the real hosted capture widget. `source` reports which one was actually used. `capture_url` uses the SAME URL shape `POST .../capture-session` produces, but its `#token=preview` fragment is never redeemable: no `capture_sessions` row is ever created for a preview mint. No `Idempotency-Key` is required — every call mints a brand-new, independently expiring session. 400s `unknown_flow` for a `flow_key` naming no lineage. 503s with problem code `preview_unavailable` when this environment has no console origin configured to frame a preview session. Requires the programme_admin role and shares `PUT .../draft`'s looser rate-limit class.
Request body
Example
curl -X POST https://api.rigid.fi/v1/kyc/policy/draft/preview-session \
-H "Authorization: Bearer $RIGID_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"programme_id": "uuid"
}'Responses
200A minted, throwaway preview session and ready-made capture-widget URL.
400Validation error
401Authentication required
403Forbidden
500Internal server error
503No console origin is configured to frame a preview session (`code: preview_unavailable`) — this environment has no `KYC_PREVIEW_FRAME_ORIGIN` set.