Read the MRZ needed to derive the passport chip’s BAC/PACE key
/v1/kyc/checks/{id}/chip-keysRequires an API client bearer token.
The applicant’s own bounded reveal (spec §8, ADR-0075): the document MRZ, and nothing else, so the calling client can derive its own BAC/PACE session key and read the passport chip over NFC. Available only while the case is genuinely awaiting a chip read — before a policy-required chip read has ever attached, and not after one has. Deliberately narrower than POST .../chip-data: this reveal opens while the case is pending (collecting or evaluating) AND awaiting a chip read, and closes the moment chip data attaches or the case turns terminal, turns referred, or opens an evaluating recapture window — whereas the attach endpoint also accepts on a referred case without that window — an API caller that already holds the MRZ itself has no need of this reveal first. Every read is reported to pii-vault’s audit pipeline (`access_recorded: true`) on a best-effort basis.
Parameters
Path parameters
| Name | Required | Description |
|---|---|---|
| id | required |
Example
curl https://api.rigid.fi/v1/kyc/checks/{id}/chip-keys \
-H "Authorization: Bearer $RIGID_API_TOKEN"Responses
200The MRZ needed to derive the chip’s BAC/PACE session key.
400Validation error
401Authentication required
403Forbidden
404KYC check not found
409The case is not currently awaiting chip evidence, or has no MRZ on record
429Too many reveals from this caller — see Retry-After
500Internal server error