Flow
Step 1: Create a KYC session
url that you open or embed for your user. Sessions expire after 1 hour.
Step 2: User completes KYC
Open or embed theurl in your application. The user completes identity verification on the Contro-hosted page.
Step 3: Check session status
Poll the session status or subscribe to thekyc_session.completed webhook event.
Session statuses
Step 4: Create the cardholder
Once the session status iscompleted, create the cardholder referencing the session:
Key details
firstNameandlastNameare extracted automatically from the completed verification.- Each session can only be used for one cardholder (enforced by a unique constraint). Attempting to reuse a session returns
409 Conflict. - The session must be
completedbefore cardholder creation. If the session is stillpending, the endpoint re-checks the latest verification result synchronously as a fallback for delayed updates.
Required fields
Sandbox behavior
In sandbox mode,POST /partner/kyc-sessions returns a mock URL and the session auto-completes immediately. No real identity verification is performed.