Write a new KYC policy version by toggling required signals
/v1/kyc/policyRequires an API client bearer token.
Recomposes the programme policy from its currently active version plus the requested `required_signals` set — the server owns weights/refer_on/reject_on derivation (spec §2 D1); a caller may only toggle signals on or off, never wire their evidence out of the score/veto path directly. `data_quality` is always required. Requires Idempotency-Key; an identical retry returns the SAME version. New versions apply to newly opened cases and to cases explicitly re-pinned by a recapture request; in-flight cases keep evaluating under the version pinned at open. Also accepts the flow-builder knobs `step_order`, `required_fields`, `optional_fields`, `field_order`, and `rules` (`min_age`/`allowed_nationalities`) — `step_order`/`required_fields`/`optional_fields`/`field_order` carry forward untouched when omitted, replace outright when sent; `rules` alone is nullable — omitted carries the active policy's rules forward, `null` clears them, a value replaces them. `eligibility` is RULES-OWNED: it is auto-enabled whenever `rules` is non-empty and MUST NOT be named directly in `required_signals` (400 `eligibility_rules_owned`). The response echoes the composed, ready-to-render flow under `flow`. Also accepts an optional `flow_key` selector (default `'default'`); an unknown key 400s `unknown_flow`. The resolved key is echoed back as `flow_key`. `field_config` configures the details step per field: how the hosted form asks for it (`input`: `text`, `dropdown` or `date`, limited to the shapes the field's value domain allows), the `hint` shown to the applicant, and a dropdown's `options` — carried forward when omitted, replaced when sent, `{}` clears it, and kept only for fields the flow asks for. Any entry, asked for or not, with a shape the field cannot take or a non-alpha-3 option on a country field is a 400 `invalid_field_config`, and so is a nationality dropdown offering no nationality `rules.allowed_nationalities` accepts. A dropdown with no options never gets that far: the request schema refuses it, a 400 `validation failed` with no `code`.
Parameters
Header parameters
| Name | Required | Description |
|---|---|---|
| Idempotency-Key | required | Client-chosen. An identical retry with the same key returns the stored response; reusing the key with a different payload returns 409. |
Request body
+ show properties− hide properties
No properties.
+ show properties− hide properties
Example
curl -X POST https://api.rigid.fi/v1/kyc/policy \
-H "Authorization: Bearer $RIGID_API_TOKEN" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{
"programme_id": "uuid",
"required_signals": [
"string"
]
}'Responses
201The newly written policy version.
+ show properties− hide properties
+ show properties− hide properties
+ show properties− hide properties
No properties.
+ show properties− hide properties
+ show properties− hide properties
+ show properties− hide properties
No properties.
+ show properties− hide properties
+ show properties− hide properties
+ show properties− hide properties
+ show properties− hide properties
+ show properties− hide properties
+ show properties− hide properties
400Validation error
401Authentication required
403Forbidden
409Idempotency-Key reused with a different payload
429Too many policy writes from this caller — see Retry-After (the tightest rate-limit class in this service: every call mints an immutable policy version row)
500Internal server error