Skip to content

Read a KYC check’s captured selfie image

GET/v1/kyc/checks/{id}/selfie-image

Requires an API client bearer token.

The case's captured selfie image, narrowed to the custody `review` purpose — the same human-adjudication slice `getCheckDocumentImage` reads from, extended (S5a Task 6) to include the retained selfie. Every read is reported to pii-vault’s audit pipeline (`access_recorded: true`) on a best-effort basis — an audit-publish failure never fails the read itself, so this is not an unconditional guarantee — attributed to the identity-kyc service principal, not to the individual console user who made the request. `provenance` states how the selfie was captured: `submitted` (API-population intake) or `controlled` (operator-supervised capture, S5b). `liveness` (S5b) carries the provider and verdict behind a `controlled` capture; absent for `submitted`.

Parameters

Path parameters

NameRequiredDescription
idrequired

Example

curl https://api.rigid.fi/v1/kyc/checks/{id}/selfie-image \
  -H "Authorization: Bearer $RIGID_API_TOKEN"

Responses

200

The check's captured selfie image.

selfie_image_base64stringrequired
content_typestringrequired
provenance"submitted" | "controlled"required
livenessobject
+ show properties
providerstringrequired
verdict"realface" | "spoofface" | "uncertain"required
access_recordedtruerequired
400

Validation error

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
401

Authentication required

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
403

Forbidden

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
404

KYC check not found, or no selfie image has been captured yet

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
410

Selfie image crypto-erased under the retention policy

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
429

Too many image reveals from this caller — see Retry-After

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
500

Internal server error

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring