Skip to content

Attach a chip passive-authentication read to a KYC check

POST/v1/kyc/checks/{id}/chip-data

Requires an API client bearer token.

Attaches a chip's read Document Security Object, DG1, DG2, and optionally DG15 plus an Active Authentication response, to a case (S3b). The SOD/DG2/data-groups are stored under purpose-bound custody; DG1 is parsed server-side into its MRZ text, which folds into the case's submission on a collecting case (re-running required_inputs readiness) or, on an evaluating case, enqueues a fresh chip_authenticity evaluation. The case's PINNED policy must list chip_authenticity in required_signals, checked BEFORE anything else — a case on a programme that never enabled it 409s (chip_not_accepted). When the body carries `aa`, the named challenge (minted via POST .../chip-challenge) is consumed exactly once; an expired, already-consumed, or foreign challenge 400s before anything is stored. Unlike GET .../chip-keys (reveal-only while the case is pending — collecting or evaluating — and awaiting a chip read, RIGID-587 follow-up), this endpoint also accepts on a referred case too — an API caller holds the MRZ itself and does not need this service to hand it back first. Requires an Idempotency-Key header. Callable by `user` or `admin` callers, which includes API clients (OAuth2 client-credentials).

Parameters

Path parameters

NameRequiredDescription
idrequired

Header parameters

NameRequiredDescription
Idempotency-Keyrequired

Client-chosen. An identical retry with the same key returns the stored response; reusing the key with a different payload returns 409.

Request body

access_protocol"bac" | "pace"required
sod_base64stringrequired
dg1_base64stringrequired
dg2_base64stringrequired
dg15_base64string
aaobject
+ show properties
challenge_idstring (uuid)required
signature_base64stringrequired

Example

curl -X POST https://api.rigid.fi/v1/kyc/checks/{id}/chip-data \
  -H "Authorization: Bearer $RIGID_API_TOKEN" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "access_protocol": "bac",
  "sod_base64": "string",
  "dg1_base64": "string",
  "dg2_base64": "string"
}'

Responses

200

The chip read was attached.

case_idstringrequired
chip_attachedtruerequired
400

Validation error

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
401

Authentication required

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
403

Forbidden

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
404

No such check

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
409

The case is in a terminal state and can no longer accept a chip read, the case's pinned policy does not include chip_authenticity (chip_not_accepted), or the Idempotency-Key was reused with a different payload

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
429

Too many KYC writes from this caller — see Retry-After

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring
500

Internal server error

typestringrequired
titlestringrequired
statusintegerrequired
detailstring
instancestring