Read a KYC check’s captured selfie image
/v1/kyc/checks/{id}/selfie-imageRequires an API client bearer token.
The case's captured selfie image, narrowed to the custody `review` purpose — the same human-adjudication slice `getCheckDocumentImage` reads from, extended (S5a Task 6) to include the retained selfie. Every read is reported to pii-vault’s audit pipeline (`access_recorded: true`) on a best-effort basis — an audit-publish failure never fails the read itself, so this is not an unconditional guarantee — attributed to the identity-kyc service principal, not to the individual console user who made the request. `provenance` states how the selfie was captured: `submitted` (API-population intake) or `controlled` (operator-supervised capture, S5b). `liveness` (S5b) carries the provider and verdict behind a `controlled` capture; absent for `submitted`.
Parameters
Path parameters
| Name | Required | Description |
|---|---|---|
| id | required |
Example
curl https://api.rigid.fi/v1/kyc/checks/{id}/selfie-image \
-H "Authorization: Bearer $RIGID_API_TOKEN"Responses
200The check's captured selfie image.
+ show properties− hide properties
400Validation error
401Authentication required
403Forbidden
404KYC check not found, or no selfie image has been captured yet
410Selfie image crypto-erased under the retention policy
429Too many image reveals from this caller — see Retry-After
500Internal server error