Skip to main content
Resolve compliance team requests so your application can proceed to approval. List RFI bundles to see what’s needed, update the requested fields or documents, respond with comments, and resubmit the application.
The End User Onboarding API base URL is https://api-sandbox.circle.com for sandbox and https://api.circle.com for production. All requests require a Bearer token obtained via Circle key exchange in the Authorization header. All POST requests require an X-Idempotency-Key header with a client-generated UUID v4.

Prerequisites

Before you begin, ensure that you’ve:
In the sandbox, Know Your Business (KYB) applications auto-approve on submission. To get an application into review so an RFI can be issued, submit it with a reserved business name. See Magic numbers for testing.

Steps

Step 1. List RFI bundles

When an application moves to PENDING_CUSTOMER_INFORMATION, the pendingRfis array on the application response contains the bundle IDs. List all bundles:
Example response:
Each RFI identifies the section and field that needs attention. The systemComment explains what the compliance team requires. RFI types and statuses: Resubmitting the application returns 409 while any RFI is still PENDING.
Array sections and refId: Some sections, such as beneficialOwnerPersons, beneficialOwnerEntity, or trustRelatedPersons, can contain multiple entries (for example, multiple beneficial owners). When an RFI targets a field in one of these sections, the response includes a refId identifying which specific entity the RFI is for. refId is null for RFIs on single-instance sections (such as businessRegistrationDetails) and for NOTE RFIs. Use refId when responding. See Step 3.

Step 2. View RFI detail and comments

Retrieve the full detail for a specific RFI, including any prior comments:

Step 3. Update the requested data

For RFIs with type UPDATE_FIELD or NEW_FIELD, submit the corrected field data directly to the RFI. The request body shape depends on whether the RFI targets a single-instance section or an array section. Single-instance section (refId is null): submit a flat JSON object with the field name as the key:
Array section (refId is present): submit a single-element JSON array containing the refId from the RFI response alongside the updated field. This tells the API exactly which entity to update:
The refId in the body must match the refId on the RFI. The API rejects mismatches. Replace the field name with the field value from the RFI. The API validates the submitted value against the application schema and marks the RFI as responded. When the RFI’s field is a document field, such as passport_document, upload a new file first. Then save the document field with the documentId from the upload response. This applies to any RFI type. Uploading alone does not respond to the RFI. When the RFI has a refId, include it in the upload request to associate the file with the correct entity. See Upload documents for the upload workflow. You can also respond by saving the field with a section save (PUT /v1/onboarding/partner/applications/{applicationId}/sections/{sectionName}) or a bulk save (PATCH /v1/onboarding/partner/applications/{applicationId}/data). You don’t need to pass the rfiId. The API matches the RFI by section, field, and refId.
An RFI is marked as responded only when the saved value changes. If the current value is correct, reply with a comment instead. See Step 4.

Step 4. Respond with a comment

Add a comment to an RFI to communicate with the compliance team:

Step 5. Resubmit the application

After you address all open RFIs, resubmit the application so it moves back to SUBMITTED for another round of review. For Stablecoin KYB, collect device risk signals in the browser first. See Collect device risk signals. Then resubmit:
This is the same endpoint used during initial submission. For details on optional fields such as certificationIds, see Submit and track applications. Device-check outcomes use the same codes as initial submit (181110, 181111, 181108).

See also