> For the complete documentation index, see [llms.txt](https://docs.ur.app/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.ur.app/api-reference/api/kyc-and-kyb/external-wallet-access-kyc.md).

# External Wallet Access KYC

Sumsub token reuse and network KYC status for External Wallet Access Mode.

## Hand off a Sumsub share token for an external wallet user

> External Wallet Access variant of the shared-token handoff: Partner Auth signs the raw body and urId travels in the body, not a header. The first handoff lazily creates the onboarding session; UR copies the applicant, validates the data, and returns the same passed, incomplete, or terminal verdict as the Managed Custody handoff.

```json
{"openapi":"3.1.0","info":{"title":"UR API","version":"1.0.0"},"tags":[{"name":"External Wallet Access KYC","description":"Sumsub token reuse and network KYC status for External Wallet Access Mode."}],"servers":[{"url":"https://openapi.ur.app","description":"Production (partner API)"},{"url":"https://uropenapi-qa.ur-inc.xyz","description":"Testnet (partner API)"}],"security":[{"partnerAuth":[]},{"userWalletAuth":[]}],"components":{"securitySchemes":{"partnerAuth":{"type":"apiKey","in":"header","name":"X-Api-Signature","description":"Partner Auth: EIP-191 signature by the partner's registered backend key, with X-Api-Deadline and optional X-Api-PublicKey headers. See the Signature and verify guide."},"userWalletAuth":{"type":"apiKey","in":"header","name":"sign","description":"User wallet auth (External Wallet Access Mode): EIP-191 signature by the user's wallet key, with tokenId, network, hash, and deadline headers. See the Signature and verify guide."}},"schemas":{"KycEwaReuseShareTokenRequest":{"type":"object","required":["shareToken","urId"],"properties":{"shareToken":{"type":"string","description":"Single-use Sumsub share token minted in your tenant with forClientId set to UR's clientId. Mint a fresh token for every handoff attempt."},"urId":{"type":"integer","format":"int64","description":"The user's URID (NFT token id). Travels in the body in External Wallet Access Mode."}}},"KycEwaReuseShareTokenResponse":{"type":"object","properties":{"code":{"type":"integer","description":"Business result code. 0 means success; business rejections return HTTP 200 with a non-zero code."},"message":{"type":"string","description":"Human-readable diagnostic for non-zero codes."},"data":{"type":"object","properties":{"status":{"type":"string","enum":["passed","incomplete","terminal"],"description":"Conclusive verdict for this handoff attempt. The envelope code mirrors it: passed maps to code 0, incomplete to 20004, terminal to a numeric eligibility code (30010, 30011, or 30012)."},"applicantId":{"type":"string","description":"The imported applicant id in UR's Sumsub tenant."},"sessionId":{"type":"string","description":"Onboarding session UUID, for audit correlation. The first handoff lazily creates the session."},"attempt":{"type":"integer","format":"int64","description":"1-indexed handoff attempt within this session."},"missingFields":{"type":"array","items":{"type":"string"},"description":"Present on incomplete; machine paths of the gaps the user must remediate in your workflow."},"requiredLevels":{"type":"array","items":{"$ref":"#/components/schemas/KycRequiredLevel"},"description":"Present on incomplete; the cloned-workflow levels the user must rerun."}}}}},"KycRequiredLevel":{"type":"object","description":"Groups missing fields into a cloned-workflow level the user must rerun on your side. Present only on incomplete verdicts.","properties":{"levelName":{"type":"string","description":"Name of the Sumsub level in your cloned workflow."},"action":{"type":"string","description":"Remediation action; always RERUN_LEVEL in v1."},"fields":{"type":"array","items":{"type":"string"},"description":"Machine paths of the missing fields covered by this level."}}}}},"paths":{"/api/v1/sumsub/reuse-share-token":{"post":{"tags":["External Wallet Access KYC"],"operationId":"kycEwaReuseShareToken","summary":"Hand off a Sumsub share token for an external wallet user","description":"External Wallet Access variant of the shared-token handoff: Partner Auth signs the raw body and urId travels in the body, not a header. The first handoff lazily creates the onboarding session; UR copies the applicant, validates the data, and returns the same passed, incomplete, or terminal verdict as the Managed Custody handoff.","parameters":[{"name":"X-Api-Signature","in":"header","required":true,"schema":{"type":"string"},"description":"Partner Auth EIP-191 signature over the canonical message plus the deadline."},{"name":"X-Api-Deadline","in":"header","required":true,"schema":{"type":"string"},"description":"Unix timestamp in seconds after which the signature is no longer valid."},{"name":"X-Api-PublicKey","in":"header","required":true,"schema":{"type":"string"},"description":"Partner public key used to verify the signature."}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/KycEwaReuseShareTokenRequest"}}}},"responses":{"200":{"description":"Business result envelope. code 0 means success; business rejections return HTTP 200 with a non-zero code.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/KycEwaReuseShareTokenResponse"}}}}}}}}}
```

## Check KYC data completeness for an external wallet user

> Pure read of the last handoff attempt's verdict, mirroring the Managed Custody check endpoint; an incomplete session returns code 20004 with missingFields. Use it as a fallback to the fma.kyc.reuse\_check.result webhook while the user remediates in your Sumsub workflow.

```json
{"openapi":"3.1.0","info":{"title":"UR API","version":"1.0.0"},"tags":[{"name":"External Wallet Access KYC","description":"Sumsub token reuse and network KYC status for External Wallet Access Mode."}],"servers":[{"url":"https://openapi.ur.app","description":"Production (partner API)"},{"url":"https://uropenapi-qa.ur-inc.xyz","description":"Testnet (partner API)"}],"security":[{"partnerAuth":[]},{"userWalletAuth":[]}],"components":{"securitySchemes":{"partnerAuth":{"type":"apiKey","in":"header","name":"X-Api-Signature","description":"Partner Auth: EIP-191 signature by the partner's registered backend key, with X-Api-Deadline and optional X-Api-PublicKey headers. See the Signature and verify guide."},"userWalletAuth":{"type":"apiKey","in":"header","name":"sign","description":"User wallet auth (External Wallet Access Mode): EIP-191 signature by the user's wallet key, with tokenId, network, hash, and deadline headers. See the Signature and verify guide."}},"schemas":{"KycEwaCheckRequest":{"type":"object","required":["urId"],"properties":{"urId":{"type":"integer","format":"int64","description":"The user's URID (NFT token id)."}}},"KycEwaCheckResponse":{"type":"object","properties":{"code":{"type":"integer","description":"Business result code. 0 means success; business rejections return HTTP 200 with a non-zero code."},"message":{"type":"string","description":"Human-readable diagnostic for non-zero codes."},"data":{"type":"object","properties":{"state":{"type":"string","description":"Current session state."},"complete":{"type":"boolean","description":"True when the shared KYC data is complete."},"missingFields":{"type":"array","items":{"type":"string"},"description":"Machine paths of the missing fields. Empty or omitted when complete."},"requiredLevels":{"type":"array","items":{"$ref":"#/components/schemas/KycRequiredLevel"},"description":"Present on incomplete; the cloned-workflow levels the user must rerun."},"sessionId":{"type":"string","description":"Onboarding session UUID."}}}}},"KycRequiredLevel":{"type":"object","description":"Groups missing fields into a cloned-workflow level the user must rerun on your side. Present only on incomplete verdicts.","properties":{"levelName":{"type":"string","description":"Name of the Sumsub level in your cloned workflow."},"action":{"type":"string","description":"Remediation action; always RERUN_LEVEL in v1."},"fields":{"type":"array","items":{"type":"string"},"description":"Machine paths of the missing fields covered by this level."}}}}},"paths":{"/api/v1/sumsub/kyc-check":{"post":{"tags":["External Wallet Access KYC"],"operationId":"kycEwaCheck","summary":"Check KYC data completeness for an external wallet user","description":"Pure read of the last handoff attempt's verdict, mirroring the Managed Custody check endpoint; an incomplete session returns code 20004 with missingFields. Use it as a fallback to the fma.kyc.reuse_check.result webhook while the user remediates in your Sumsub workflow.","parameters":[{"name":"X-Api-Signature","in":"header","required":true,"schema":{"type":"string"},"description":"Partner Auth EIP-191 signature over the canonical message plus the deadline."},{"name":"X-Api-Deadline","in":"header","required":true,"schema":{"type":"string"},"description":"Unix timestamp in seconds after which the signature is no longer valid."},{"name":"X-Api-PublicKey","in":"header","required":true,"schema":{"type":"string"},"description":"Partner public key used to verify the signature."}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/KycEwaCheckRequest"}}}},"responses":{"200":{"description":"Business result envelope. code 0 means success; business rejections return HTTP 200 with a non-zero code.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/KycEwaCheckResponse"}}}}}}}}}
```

## Submit KYC for an external wallet user

> Advances the flow to register after the handoff verdict is passed and the user signed Form A with their own wallet; there is no custodial signer in this mode. UR registers the account asynchronously and delivers the fma.account.result webhook when the account activates.

```json
{"openapi":"3.1.0","info":{"title":"UR API","version":"1.0.0"},"tags":[{"name":"External Wallet Access KYC","description":"Sumsub token reuse and network KYC status for External Wallet Access Mode."}],"servers":[{"url":"https://openapi.ur.app","description":"Production (partner API)"},{"url":"https://uropenapi-qa.ur-inc.xyz","description":"Testnet (partner API)"}],"security":[{"partnerAuth":[]},{"userWalletAuth":[]}],"components":{"securitySchemes":{"partnerAuth":{"type":"apiKey","in":"header","name":"X-Api-Signature","description":"Partner Auth: EIP-191 signature by the partner's registered backend key, with X-Api-Deadline and optional X-Api-PublicKey headers. See the Signature and verify guide."},"userWalletAuth":{"type":"apiKey","in":"header","name":"sign","description":"User wallet auth (External Wallet Access Mode): EIP-191 signature by the user's wallet key, with tokenId, network, hash, and deadline headers. See the Signature and verify guide."}},"schemas":{"KycEwaSubmitRequest":{"type":"object","required":["urId"],"properties":{"urId":{"type":"integer","format":"int64","description":"The user's URID (NFT token id)."}}},"KycEwaSubmitResponse":{"type":"object","properties":{"code":{"type":"integer","description":"Business result code. 0 means success; business rejections return HTTP 200 with a non-zero code."},"message":{"type":"string","description":"Human-readable diagnostic for non-zero codes."},"data":{"type":"object","properties":{"state":{"type":"string","description":"Session state after submit; the register runs asynchronously from here."},"sessionId":{"type":"string","description":"Onboarding session UUID."}}}}}}},"paths":{"/api/v1/sumsub/kyc-submit":{"post":{"tags":["External Wallet Access KYC"],"operationId":"kycEwaSubmit","summary":"Submit KYC for an external wallet user","description":"Advances the flow to register after the handoff verdict is passed and the user signed Form A with their own wallet; there is no custodial signer in this mode. UR registers the account asynchronously and delivers the fma.account.result webhook when the account activates.","parameters":[{"name":"X-Api-Signature","in":"header","required":true,"schema":{"type":"string"},"description":"Partner Auth EIP-191 signature over the canonical message plus the deadline."},{"name":"X-Api-Deadline","in":"header","required":true,"schema":{"type":"string"},"description":"Unix timestamp in seconds after which the signature is no longer valid."},{"name":"X-Api-PublicKey","in":"header","required":true,"schema":{"type":"string"},"description":"Partner public key used to verify the signature."}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/KycEwaSubmitRequest"}}}},"responses":{"200":{"description":"Business result envelope. code 0 means success; business rejections return HTTP 200 with a non-zero code.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/KycEwaSubmitResponse"}}}}}}}}}
```

## Create a Sumsub access token by network

> Creates a Sumsub access token for External Wallet Access Mode users whose URID NFT lives on an external network. UR issues the token only after an on-chain ownership check: walletProvider(tokenId) on the account contract of the requested network must equal the calling partner's id. The token TTL is fixed at 20 minutes server-side.

```json
{"openapi":"3.1.0","info":{"title":"UR API","version":"1.0.0"},"tags":[{"name":"External Wallet Access KYC","description":"Sumsub token reuse and network KYC status for External Wallet Access Mode."}],"servers":[{"url":"https://openapi.ur.app","description":"Production (partner API)"},{"url":"https://uropenapi-qa.ur-inc.xyz","description":"Testnet (partner API)"}],"security":[{"partnerAuth":[]},{"userWalletAuth":[]}],"components":{"securitySchemes":{"partnerAuth":{"type":"apiKey","in":"header","name":"X-Api-Signature","description":"Partner Auth: EIP-191 signature by the partner's registered backend key, with X-Api-Deadline and optional X-Api-PublicKey headers. See the Signature and verify guide."},"userWalletAuth":{"type":"apiKey","in":"header","name":"sign","description":"User wallet auth (External Wallet Access Mode): EIP-191 signature by the user's wallet key, with tokenId, network, hash, and deadline headers. See the Signature and verify guide."}},"schemas":{"KycByNetworkRequest":{"type":"object","required":["tokenId","network"],"properties":{"tokenId":{"type":"string","description":"URID NFT token id."},"network":{"type":"string","description":"Network or chain identifier, for example 5000 or 11155111."}}},"KycAccessTokenByNetworkResponse":{"type":"object","properties":{"code":{"type":"integer","description":"Business result code. 0 means success; business rejections return HTTP 200 with a non-zero code."},"message":{"type":"string","description":"Human-readable diagnostic for non-zero codes."},"data":{"type":"object","properties":{"token":{"type":"string","description":"Sumsub access token, usually starting with act-. Used to initialize the Sumsub SDK. This endpoint returns only the token; it does not return a Sumsub applicant id."}}}}}}},"paths":{"/v1/create-access-token-by-network":{"post":{"tags":["External Wallet Access KYC"],"operationId":"kycEwaCreateAccessTokenByNetwork","summary":"Create a Sumsub access token by network","description":"Creates a Sumsub access token for External Wallet Access Mode users whose URID NFT lives on an external network. UR issues the token only after an on-chain ownership check: walletProvider(tokenId) on the account contract of the requested network must equal the calling partner's id. The token TTL is fixed at 20 minutes server-side.","parameters":[{"name":"X-Api-Signature","in":"header","required":true,"schema":{"type":"string"},"description":"Partner Auth EIP-191 signature over the canonical message plus the deadline."},{"name":"X-Api-Deadline","in":"header","required":true,"schema":{"type":"string"},"description":"Unix timestamp in seconds after which the signature is no longer valid."},{"name":"X-Api-PublicKey","in":"header","required":true,"schema":{"type":"string"},"description":"Partner public key used to verify the signature."}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/KycByNetworkRequest"}}}},"responses":{"200":{"description":"Business result envelope. code 0 means success; business rejections return HTTP 200 with a non-zero code.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/KycAccessTokenByNetworkResponse"}}}}}}}}}
```

## Get Sumsub status by network

> Returns the latest Sumsub webhook-derived KYC state for the given tokenId and network; poll it after starting Sumsub on an external network to display review progress without creating a new access token. data is an empty object when UR has not yet received a Sumsub webhook for that tokenId and network.

```json
{"openapi":"3.1.0","info":{"title":"UR API","version":"1.0.0"},"tags":[{"name":"External Wallet Access KYC","description":"Sumsub token reuse and network KYC status for External Wallet Access Mode."}],"servers":[{"url":"https://openapi.ur.app","description":"Production (partner API)"},{"url":"https://uropenapi-qa.ur-inc.xyz","description":"Testnet (partner API)"}],"security":[{"partnerAuth":[]},{"userWalletAuth":[]}],"components":{"securitySchemes":{"partnerAuth":{"type":"apiKey","in":"header","name":"X-Api-Signature","description":"Partner Auth: EIP-191 signature by the partner's registered backend key, with X-Api-Deadline and optional X-Api-PublicKey headers. See the Signature and verify guide."},"userWalletAuth":{"type":"apiKey","in":"header","name":"sign","description":"User wallet auth (External Wallet Access Mode): EIP-191 signature by the user's wallet key, with tokenId, network, hash, and deadline headers. See the Signature and verify guide."}},"schemas":{"KycByNetworkRequest":{"type":"object","required":["tokenId","network"],"properties":{"tokenId":{"type":"string","description":"URID NFT token id."},"network":{"type":"string","description":"Network or chain identifier, for example 5000 or 11155111."}}},"KycSumsubStatusByNetworkResponse":{"type":"object","properties":{"code":{"type":"integer","description":"Business result code. 0 means success; business rejections return HTTP 200 with a non-zero code."},"message":{"type":"string","description":"Human-readable diagnostic for non-zero codes."},"data":{"type":"object","description":"Latest Sumsub webhook-derived state. An empty object when UR has not yet received a Sumsub webhook for that tokenId and network.","properties":{"type":{"type":"string","description":"Sumsub webhook type, for example applicantWorkflowCompleted."},"reviewStatus":{"type":"string","description":"Review status, for example init, pending, completed."},"reviewAnswer":{"type":"string","description":"Review answer: GREEN for success, RED for failure."},"reviewRejectType":{"type":"string","description":"Rejection type, for example FINAL or RETRY."},"levelName":{"type":"string","description":"Sumsub level name."},"rejectLabels":{"type":"array","items":{"type":"string"},"description":"Rejection labels when applicable."},"applicantId":{"type":"string","description":"Sumsub applicant id."},"applicantType":{"type":"string","description":"Applicant type, for example individual."},"createdAtMs":{"type":"integer","format":"int64","description":"Event time in milliseconds."}}}}}}},"paths":{"/v1/sumsub-status-by-network":{"post":{"tags":["External Wallet Access KYC"],"operationId":"kycEwaGetSumsubStatusByNetwork","summary":"Get Sumsub status by network","description":"Returns the latest Sumsub webhook-derived KYC state for the given tokenId and network; poll it after starting Sumsub on an external network to display review progress without creating a new access token. data is an empty object when UR has not yet received a Sumsub webhook for that tokenId and network.","parameters":[{"name":"X-Api-Signature","in":"header","required":true,"schema":{"type":"string"},"description":"Partner Auth EIP-191 signature over the canonical message plus the deadline."},{"name":"X-Api-Deadline","in":"header","required":true,"schema":{"type":"string"},"description":"Unix timestamp in seconds after which the signature is no longer valid."},{"name":"X-Api-PublicKey","in":"header","required":true,"schema":{"type":"string"},"description":"Partner public key used to verify the signature."}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/KycByNetworkRequest"}}}},"responses":{"200":{"description":"Business result envelope. code 0 means success; business rejections return HTTP 200 with a non-zero code.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/KycSumsubStatusByNetworkResponse"}}}}}}}}}
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.ur.app/api-reference/api/kyc-and-kyb/external-wallet-access-kyc.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
