Skip to content

Read the MRZ needed to derive the passport chip’s BAC/PACE key

GET/v1/kyc/checks/{id}/chip-keys

Requires an API client bearer token.

The applicant’s own bounded reveal (spec §8, ADR-0075): the document MRZ, and nothing else, so the calling client can derive its own BAC/PACE session key and read the passport chip over NFC. Available only while the case is genuinely awaiting a chip read — before a policy-required chip read has ever attached, and not after one has. Deliberately narrower than POST .../chip-data: this reveal opens while the case is pending (collecting or evaluating) AND awaiting a chip read, and closes the moment chip data attaches or the case turns terminal, turns referred, or opens an evaluating recapture window — whereas the attach endpoint also accepts on a referred case without that window — an API caller that already holds the MRZ itself has no need of this reveal first. Every read is reported to pii-vault’s audit pipeline (`access_recorded: true`) on a best-effort basis.

Parameters

Path parameters

NameRequiredDescription
idrequired

Example

curl https://api.rigid.fi/v1/kyc/checks/{id}/chip-keys \
  -H "Authorization: Bearer $RIGID_API_TOKEN"

Responses

200

The MRZ needed to derive the chip’s BAC/PACE session key.

document_mrzstringrequired
access_recordedtruerequired
400

Validation error

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
401

Authentication required

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
403

Forbidden

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
404

KYC check not found

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
409

The case is not currently awaiting chip evidence, or has no MRZ on record

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
429

Too many reveals from this caller — see Retry-After

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
500

Internal server error

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring