curl --request POST \
--url https://api.sumvin.com/v0/kyc/sessions/redemption \
--header 'x-juno-jwt: <api-key>'import requests
url = "https://api.sumvin.com/v0/kyc/sessions/redemption"
headers = {"x-juno-jwt": "<api-key>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {'x-juno-jwt': '<api-key>'}};
fetch('https://api.sumvin.com/v0/kyc/sessions/redemption', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sumvin.com/v0/kyc/sessions/redemption",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"x-juno-jwt: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.sumvin.com/v0/kyc/sessions/redemption"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("x-juno-jwt", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.sumvin.com/v0/kyc/sessions/redemption")
.header("x-juno-jwt", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.sumvin.com/v0/kyc/sessions/redemption")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-juno-jwt"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"_links": {
"applicant": {
"href": "/v0/kyc/applicant",
"method": "POST"
},
"self": {
"href": "/v0/kyc/sessions/redemption",
"method": "POST"
},
"status": {
"href": "/v0/kyc/status"
}
},
"access_token": "_act-sbx-...",
"expires_in": 600,
"level_name": "basic-kyc-level",
"origin": "connector",
"session_id": "kycs-9f21ce4a",
"user_id": "usr_abc123"
}{
"detail": "No wallet found with ID 12345 for this user.",
"error_code": "WAL-404-001",
"instance": "/v0/wallets/12345",
"status": 404,
"title": "Wallet Not Found",
"trace_id": "abc123-def456-ghi789",
"type": "https://api.sumvin.com/errors/wal-404-001"
}{
"detail": "No wallet found with ID 12345 for this user.",
"error_code": "WAL-404-001",
"instance": "/v0/wallets/12345",
"status": 404,
"title": "Wallet Not Found",
"trace_id": "abc123-def456-ghi789",
"type": "https://api.sumvin.com/errors/wal-404-001"
}{
"detail": "No wallet found with ID 12345 for this user.",
"error_code": "WAL-404-001",
"instance": "/v0/wallets/12345",
"status": 404,
"title": "Wallet Not Found",
"trace_id": "abc123-def456-ghi789",
"type": "https://api.sumvin.com/errors/wal-404-001"
}{
"detail": "No wallet found with ID 12345 for this user.",
"error_code": "WAL-404-001",
"instance": "/v0/wallets/12345",
"status": 404,
"title": "Wallet Not Found",
"trace_id": "abc123-def456-ghi789",
"type": "https://api.sumvin.com/errors/wal-404-001"
}{
"detail": "No wallet found with ID 12345 for this user.",
"error_code": "WAL-404-001",
"instance": "/v0/wallets/12345",
"status": 404,
"title": "Wallet Not Found",
"trace_id": "abc123-def456-ghi789",
"type": "https://api.sumvin.com/errors/wal-404-001"
}{
"detail": "No wallet found with ID 12345 for this user.",
"error_code": "WAL-404-001",
"instance": "/v0/wallets/12345",
"status": 404,
"title": "Wallet Not Found",
"trace_id": "abc123-def456-ghi789",
"type": "https://api.sumvin.com/errors/wal-404-001"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>",
"input": "<unknown>",
"ctx": {}
}
]
}{
"detail": "No wallet found with ID 12345 for this user.",
"error_code": "WAL-404-001",
"instance": "/v0/wallets/12345",
"status": 404,
"title": "Wallet Not Found",
"trace_id": "abc123-def456-ghi789",
"type": "https://api.sumvin.com/errors/wal-404-001"
}Redeem a verification session ticket
Exchange a verification session’s ticket for the token that starts identity capture. Send the ticket in the x-sumvin-kyc-ticket header — it is a secret, and a header can be redacted from logs and traces where a URL cannot. Call this as the signed-in user the session was created for; the session is checked against that identity before it is spent.
A ticket can be redeemed once. A ticket that belongs to someone else is refused without being spent, so signing in as the right account and trying again works. An unknown, spent, or expired ticket is final — start a new session instead.
Send an Idempotency-Key header to make a retry safe: a repeat of the same redemption returns a token rather than spending a second session.
curl --request POST \
--url https://api.sumvin.com/v0/kyc/sessions/redemption \
--header 'x-juno-jwt: <api-key>'import requests
url = "https://api.sumvin.com/v0/kyc/sessions/redemption"
headers = {"x-juno-jwt": "<api-key>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {'x-juno-jwt': '<api-key>'}};
fetch('https://api.sumvin.com/v0/kyc/sessions/redemption', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sumvin.com/v0/kyc/sessions/redemption",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"x-juno-jwt: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.sumvin.com/v0/kyc/sessions/redemption"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("x-juno-jwt", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.sumvin.com/v0/kyc/sessions/redemption")
.header("x-juno-jwt", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.sumvin.com/v0/kyc/sessions/redemption")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-juno-jwt"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"_links": {
"applicant": {
"href": "/v0/kyc/applicant",
"method": "POST"
},
"self": {
"href": "/v0/kyc/sessions/redemption",
"method": "POST"
},
"status": {
"href": "/v0/kyc/status"
}
},
"access_token": "_act-sbx-...",
"expires_in": 600,
"level_name": "basic-kyc-level",
"origin": "connector",
"session_id": "kycs-9f21ce4a",
"user_id": "usr_abc123"
}{
"detail": "No wallet found with ID 12345 for this user.",
"error_code": "WAL-404-001",
"instance": "/v0/wallets/12345",
"status": 404,
"title": "Wallet Not Found",
"trace_id": "abc123-def456-ghi789",
"type": "https://api.sumvin.com/errors/wal-404-001"
}{
"detail": "No wallet found with ID 12345 for this user.",
"error_code": "WAL-404-001",
"instance": "/v0/wallets/12345",
"status": 404,
"title": "Wallet Not Found",
"trace_id": "abc123-def456-ghi789",
"type": "https://api.sumvin.com/errors/wal-404-001"
}{
"detail": "No wallet found with ID 12345 for this user.",
"error_code": "WAL-404-001",
"instance": "/v0/wallets/12345",
"status": 404,
"title": "Wallet Not Found",
"trace_id": "abc123-def456-ghi789",
"type": "https://api.sumvin.com/errors/wal-404-001"
}{
"detail": "No wallet found with ID 12345 for this user.",
"error_code": "WAL-404-001",
"instance": "/v0/wallets/12345",
"status": 404,
"title": "Wallet Not Found",
"trace_id": "abc123-def456-ghi789",
"type": "https://api.sumvin.com/errors/wal-404-001"
}{
"detail": "No wallet found with ID 12345 for this user.",
"error_code": "WAL-404-001",
"instance": "/v0/wallets/12345",
"status": 404,
"title": "Wallet Not Found",
"trace_id": "abc123-def456-ghi789",
"type": "https://api.sumvin.com/errors/wal-404-001"
}{
"detail": "No wallet found with ID 12345 for this user.",
"error_code": "WAL-404-001",
"instance": "/v0/wallets/12345",
"status": 404,
"title": "Wallet Not Found",
"trace_id": "abc123-def456-ghi789",
"type": "https://api.sumvin.com/errors/wal-404-001"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>",
"input": "<unknown>",
"ctx": {}
}
]
}{
"detail": "No wallet found with ID 12345 for this user.",
"error_code": "WAL-404-001",
"instance": "/v0/wallets/12345",
"status": 404,
"title": "Wallet Not Found",
"trace_id": "abc123-def456-ghi789",
"type": "https://api.sumvin.com/errors/wal-404-001"
}Authorizations
Session JWT from the identity provider that signed the user in — Dynamic Labs, Privy, or Clerk (consumer sign-in). Send it in the x-juno-jwt header on every authenticated request. An Authorization: Bearer <jwt> header carrying the same JWT is also accepted, and takes precedence when both are present.
Headers
Ticket issued when the verification session was created. Treat it as a secret: it is single-use, short-lived, and buys a token that acts as the user.
Client-generated key identifying one logical redemption. Reuse the same value when retrying so a lost response cannot spend the session twice.
Tenant org ID for multi-tenant auth
Controls how timestamp fields are serialized in JSON response bodies.
Default (header omitted or any other value): epoch milliseconds as integers.
iso8601: UTC ISO 8601 strings of the form YYYY-MM-DDTHH:MM:SSZ.
Example: with X-Timestamp-Format: iso8601, the field value 1704067200000 becomes "2024-01-01T00:00:00Z".
Affected fields (recursively, in dicts and arrays): any field whose name ends in _at, plus the literal field names timestamp, period_start, and period_end. All other fields are passed through unchanged.
Only iso8601 is recognized. Any other value (or omitting the header) yields the default epoch-ms representation; the server does not reject unknown values, so this is documented as an example rather than an enum to keep generated clients permissive.
"iso8601"
Response
Session redeemed
The verification credential a redeemed session buys.
HAL-style hypermedia links for navigation.
Show child attributes
Show child attributes
Short-lived access token for Sumsub Web SDK initialization.
Token validity period in seconds.
User ID associated with this token.
Verification level the token was minted against — use it to configure the SDK.
Identifier of the verification session that was redeemed.
Where this person began verification, so the completion screen can send them back to it: cli for a terminal, connector for a conversation with an assistant, app for the Sumvin app. Null when the session predates this field.
cli, connector, app