A signed-in user becomes a customer by completing the onboarding steps their program requires. KYC or KYB is always part of it; depending on the program there may also be a risk and compliance review and legal agreements. You create one application and then poll it, showing the screen that matches the step the server reports.
Every onboarding call uses the user’s bearer token (Authorization: Bearer <access_token>) from authentication.

How it works

  1. Create an application once with POST /v2/applications, passing isCompany to pick the individual or company flow.
  2. Poll GET /v2/applications and read status.currentStep. The reference app polls about once a second; slow down on IN_REVIEW (see below).
  3. Show the screen for that step. Some steps need input from the user (a form, the identity check, accepting terms); others just wait while we process. The step advances on the next poll once the work is done.
  4. When currentStep is COMPLETED, onboarding is finished. Send the user into the app.

After approval: from application to customer

Approval turns the applicant into a customer, and that hand-off gives you everything the rest of the API needs:
  • The application object (from GET /v2/applications) carries the customerId — every customer-scoped endpoint takes it.
  • The customer’s primary account is created automatically — you don’t call anything. Fetch it with List accounts; the accountId from that response is what cards, payments, and beneficiaries hang off.
So the sequence after currentStep: "COMPLETED" is simply: read customerId from the application → GET /v1/customers/{customerId}/accounts → build the app around the returned accountId. The server decides the order, so don’t hard-code the sequence: render whatever currentStep comes back. The order depends on the program: most collect the legal agreements first, before KYC/KYB, and some collect them after the risk review. On v2 there are ten values, one per screen, and the set doesn’t grow when we add internal processing steps: those show up as PROCESSING.

Steps

Pick the tab for the version you poll. New integrations should use v2.

Companies (KYB)

Create the application with isCompany: true and the flow uses the same steps. On KYC_FORM you fetch the form from the same schema endpoint (it returns company and beneficial-owner fields), but you submit the answers to POST /v1/applications/kyb instead of the individual KYC endpoint. A company can also reach ADD_UBOS while its beneficial owners verify.

Endpoints

Create an application

Get the current application

Get the KYC form schema

Submit KYC data

Submit KYB data

Get a Sumsub SDK token

Accept legal agreements