Skip to main content
Cardholders who reside in, or hold identity documents issued by, a restricted country or region cannot be onboarded. The restriction is applied during provider verification and is not configurable per partner.

Restricted list

This list changes as sanctions programs are updated. Treat it as indicative rather than authoritative in your own code — always handle a rejected outcome at runtime instead of pre-filtering against a hardcoded copy.

What gets checked

Screening is evaluated against the cardholder’s identity data, not their IP address or the country your platform operates from:
  • Residence country — residenceCountryCode on the cardholder, or the address extracted from their KYC session
  • Nationality and document issuing country — taken from the verified identity document
A cardholder is rejected if either matches the restricted list.

How rejection surfaces

When the cardholder is rejected, cardholder.rejected fires:
kycStatus moves to "rejected" and no cardholder.approved event follows. Cards cannot be issued to a rejected cardholder. The reason field is present only when the provider supplies one, and is redacted to a safe summary. Rejection is terminal for that cardholder. Resubmitting the same identity produces the same outcome — do not retry.

Handling it in your integration

To avoid onboarding users you already know are ineligible, screen for residence country in your own signup flow before calling POST /partner/cardholders.