Skip to main content
The web link method lets you delegate KYC entirely to Contro. You request a hosted KYC session, redirect your user to the URL, and create the cardholder after the session completes. You never handle identity documents directly. Contro manages the underlying identity verification, so there is nothing for you to integrate or configure beyond the endpoints below.

Flow

Step 1: Create a KYC session

The response includes a url that you open or embed for your user. Sessions expire after 1 hour.

Step 2: User completes KYC

Open or embed the url in your application. The user completes identity verification on the Contro-hosted page.

Step 3: Check session status

Poll the session status or subscribe to the kyc_session.completed webhook event.

Session statuses

Step 4: Create the cardholder

Once the session status is completed, create the cardholder referencing the session:

Key details

  • firstName and lastName are extracted automatically from the completed verification.
  • Each session can only be used for one cardholder (enforced by a unique constraint). Attempting to reuse a session returns 409 Conflict.
  • The session must be completed before cardholder creation. If the session is still pending, the endpoint re-checks the latest verification result synchronously as a fallback for delayed updates.

Required fields

Sandbox behavior

In sandbox mode, POST /partner/kyc-sessions returns a mock URL and the session auto-completes immediately. No real identity verification is performed.