Create Verification
Starts a hosted verification session for an account or user, or returns the active session when one already exists. Any fields you include in the request body are used to prefill the session. Send documents (with document_type) to instead verify the person from identity documents included in this request — no hosted session involved. If the account already has an approved verification the request is rejected; unlink it first to start a new one.
Authorizations
A company API key, company scoped JWT, app API key, or user OAuth token. You must prepend your key/token with the word 'Bearer', which will look like Bearer ***************************
Headers
A unique key that makes this request safe to retry. See Idempotent requests.
255"d9105228-4a08-46b1-8b91-42fed586d383"
Pins the request to a dated API version.
"2026-07-25"
Query Parameters
Account or user ID whose identity you want to verify. Use a biz_ account ID for account verifications, or the caller's user_ ID for personal verification.
Body
- CreateIndividualVerification
- CreateBusinessVerification
Request body for an individual (KYC) verification. Omit kind or set it to individual. KYC is required to pay out funds and is a prerequisite for Whop Card access. Accepting payments does not require verification until a business reaches $5000 in payments.
Add business_name and business_structure if the individual operates under a business entity — this enables payouts to be received by a business bank account. country is always the individual's own country, and the supported business_structure values vary by it — see Business structures.
Legal business name for a sole proprietor or single-member LLC.
Entity type for sole proprietors, such as single_member_llc. Supported values vary by country of incorporation — see Business structures.
The business ID number of the company, as appropriate for the company's country. Examples are an Employer Identification Number (EIN) in the US, a Business Number in Canada, or a Company Number in the UK.
Business website URL. Whop store pages are not accepted.
Two-letter ISO 3166-1 country code, for example US, DE, or GB.
Formatted as YYYY-MM-DD.
Identity document being sent, when verifying with documents. Decides exactly which file slots to send: ID_CARD → id_card_front + id_card_back + selfie; DRIVERS → drivers_front + drivers_back + selfie; RESIDENCE_PERMIT → residence_permit_front + residence_permit_back + selfie; PASSPORT → passport_front + selfie. See Identity documents.
ID_CARD, DRIVERS, RESIDENCE_PERMIT, PASSPORT Identity document files, each value the file's raw bytes base64-encoded (JPEG, PNG, or PDF, up to 5MB per file before encoding). Sending this object verifies the person from the files in this request instead of a hosted session — individual verifications only, and the request must also carry document_type, first_name, last_name, date_of_birth, country, phone, tax_identification_number, and an address with line1, city, state, and postal_code. Send every slot for your document_type — a missing or rejected file fails the whole request and nothing is submitted; review starts automatically once every document is accepted. See Identity documents for a full walkthrough.
Verification type. Defaults to individual.
individual The government-issued ID number of the person being verified — the individual for a KYC verification, or the business representative for a KYB verification — as appropriate for their country. Examples are a Social Security Number (SSN) in the US, or a Social Insurance Number in Canada.
Response
OK
Address on the verification profile. null when no address is set.
Legal business name.
Legal entity structure of the business, such as private_corporation or sole_proprietorship. Supported values vary by country of incorporation — see Business structures.
Two-letter ISO 3166-1 country code, for example US, DE, or GB.
When the verification profile was created, as an ISO 8601 timestamp.
Formatted as YYYY-MM-DD.
Verification profile ID, prefixed idpf_.
individual, business Fields or documents Whop still needs before review can continue. Submit answers with the Update Verification endpoint.
Documents for a document-upload verification and their progress. Present only on verifications created by sending documents. pending_upload documents were not accepted yet — send the full set again with another Create Verification call.
Hosted verification session URL for the user to complete identity checks. Expires 7 days after creation.
Current verification state. not_started before any session has been created; pending while a session is in progress and needs the user's input; processing while the provider reviews submitted documents — nothing to do but wait; action_required when items in requested_information need answers before review can continue; approved once verification succeeds; rejected if it fails. Call the Create Verification endpoint again to start a new session.
not_started, pending, processing, approved, rejected, action_required When the verification profile was last updated, as an ISO 8601 timestamp.

