curl --request POST \
--url https://api.contro.me/v1/partner/cardholders \
--header 'Content-Type: application/json' \
--header 'x-contro-api-key: <api-key>' \
--data '
{
"externalUserId": "user_42",
"email": "jane@example.com",
"phoneNumber": "+14155552671",
"kycSource": "web",
"kycSessionId": "<string>"
}
'import requests
url = "https://api.contro.me/v1/partner/cardholders"
payload = {
"externalUserId": "user_42",
"email": "jane@example.com",
"phoneNumber": "+14155552671",
"kycSource": "web",
"kycSessionId": "<string>"
}
headers = {
"x-contro-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'x-contro-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
externalUserId: 'user_42',
email: 'jane@example.com',
phoneNumber: '+14155552671',
kycSource: 'web',
kycSessionId: '<string>'
})
};
fetch('https://api.contro.me/v1/partner/cardholders', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.contro.me/v1/partner/cardholders",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'externalUserId' => 'user_42',
'email' => 'jane@example.com',
'phoneNumber' => '+14155552671',
'kycSource' => 'web',
'kycSessionId' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-contro-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.contro.me/v1/partner/cardholders"
payload := strings.NewReader("{\n \"externalUserId\": \"user_42\",\n \"email\": \"jane@example.com\",\n \"phoneNumber\": \"+14155552671\",\n \"kycSource\": \"web\",\n \"kycSessionId\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-contro-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.contro.me/v1/partner/cardholders")
.header("x-contro-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"externalUserId\": \"user_42\",\n \"email\": \"jane@example.com\",\n \"phoneNumber\": \"+14155552671\",\n \"kycSource\": \"web\",\n \"kycSessionId\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.contro.me/v1/partner/cardholders")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-contro-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"externalUserId\": \"user_42\",\n \"email\": \"jane@example.com\",\n \"phoneNumber\": \"+14155552671\",\n \"kycSource\": \"web\",\n \"kycSessionId\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"id": "ch_abc123",
"externalUserId": "user_42",
"firstName": "Jane",
"lastName": "Doe",
"email": "jane@example.com",
"phoneNumber": "+14155552671",
"kycSource": "api",
"kycStatus": "approved",
"status": "active",
"createdAt": "2026-03-20T14:30:00Z"
}{
"id": "ch_abc123",
"externalUserId": "user_42",
"firstName": "Jane",
"lastName": "Doe",
"email": "jane@example.com",
"phoneNumber": "+14155552671",
"kycSource": "api",
"kycStatus": "approved",
"status": "active",
"createdAt": "2026-03-20T14:30:00Z"
}{
"success": false,
"error": {
"code": "EMAIL_ALREADY_REGISTERED",
"message": "<string>",
"existingCardholderId": "ch_abc123"
}
}Create cardholder
Create a new cardholder with KYC data for this partner, or re-import KYC onto an existing one.
Share-token sources (sumsub, didit) capture a point-in-time snapshot of the donor session. If you later correct your KYC workflow — for example by adding address verification — re-submit this endpoint with the same externalUserId and a freshly minted share token to re-import the corrected session onto the existing cardholder. Extracted identity and address fields overwrite the stored values; unrelated data is preserved. The kycSource must match the one the cardholder was created with, and the cardholder must still be active.
Responds 201 when a new cardholder was created and 200 when an existing one was re-imported. Re-import is refused with 409 CARDHOLDER_KYC_LOCKED once the identity has left our system: the KYC was already submitted to the card provider, or a card has been issued. Share tokens are single-use, so a refused re-import does not consume the token — but every accepted one does.
curl --request POST \
--url https://api.contro.me/v1/partner/cardholders \
--header 'Content-Type: application/json' \
--header 'x-contro-api-key: <api-key>' \
--data '
{
"externalUserId": "user_42",
"email": "jane@example.com",
"phoneNumber": "+14155552671",
"kycSource": "web",
"kycSessionId": "<string>"
}
'import requests
url = "https://api.contro.me/v1/partner/cardholders"
payload = {
"externalUserId": "user_42",
"email": "jane@example.com",
"phoneNumber": "+14155552671",
"kycSource": "web",
"kycSessionId": "<string>"
}
headers = {
"x-contro-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'x-contro-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
externalUserId: 'user_42',
email: 'jane@example.com',
phoneNumber: '+14155552671',
kycSource: 'web',
kycSessionId: '<string>'
})
};
fetch('https://api.contro.me/v1/partner/cardholders', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.contro.me/v1/partner/cardholders",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'externalUserId' => 'user_42',
'email' => 'jane@example.com',
'phoneNumber' => '+14155552671',
'kycSource' => 'web',
'kycSessionId' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-contro-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.contro.me/v1/partner/cardholders"
payload := strings.NewReader("{\n \"externalUserId\": \"user_42\",\n \"email\": \"jane@example.com\",\n \"phoneNumber\": \"+14155552671\",\n \"kycSource\": \"web\",\n \"kycSessionId\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-contro-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.contro.me/v1/partner/cardholders")
.header("x-contro-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"externalUserId\": \"user_42\",\n \"email\": \"jane@example.com\",\n \"phoneNumber\": \"+14155552671\",\n \"kycSource\": \"web\",\n \"kycSessionId\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.contro.me/v1/partner/cardholders")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-contro-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"externalUserId\": \"user_42\",\n \"email\": \"jane@example.com\",\n \"phoneNumber\": \"+14155552671\",\n \"kycSource\": \"web\",\n \"kycSessionId\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"id": "ch_abc123",
"externalUserId": "user_42",
"firstName": "Jane",
"lastName": "Doe",
"email": "jane@example.com",
"phoneNumber": "+14155552671",
"kycSource": "api",
"kycStatus": "approved",
"status": "active",
"createdAt": "2026-03-20T14:30:00Z"
}{
"id": "ch_abc123",
"externalUserId": "user_42",
"firstName": "Jane",
"lastName": "Doe",
"email": "jane@example.com",
"phoneNumber": "+14155552671",
"kycSource": "api",
"kycStatus": "approved",
"status": "active",
"createdAt": "2026-03-20T14:30:00Z"
}{
"success": false,
"error": {
"code": "EMAIL_ALREADY_REGISTERED",
"message": "<string>",
"existingCardholderId": "ch_abc123"
}
}Authorizations
Partner API key (sk_live_* for production, sk_test_* for sandbox)
Body
- Option 1
- Option 2
Your unique identifier for this user. Min 1 character
1"user_42"
Valid email address
"jane@example.com"
E.164 formatted phone number
"+14155552671"
KYC via Contro-hosted web link
web KYC session ID from POST /partner/kyc-sessions
1Response
Existing cardholder re-imported from a fresh share token. Returned instead of 201 when a cardholder already existed for this externalUserId.
Contro cardholder ID
"ch_abc123"
Your unique identifier for this user
"user_42"
Cardholder's first name
"Jane"
Cardholder's last name
"Doe"
Email address
"jane@example.com"
E.164 formatted phone number, or null if not provided
"+14155552671"
KYC submission method. One of: api, sumsub, web
"api"
KYC verification status. One of: pending, approved, rejected
"approved"
Cardholder account status. One of: active, suspended, closed
"active"
ISO 8601 creation timestamp
"2026-03-20T14:30:00Z"