Skip to main content
POST
JavaScript

Authorizations

Authorization
string
header
required

A company API key, company scoped JWT, app API key, or user OAuth token. You must prepend your key/token with the word 'Bearer', which will look like Bearer ***************************

Headers

Idempotency-Key
string

A unique key that makes this request safe to retry. See Idempotent requests.

Maximum string length: 255
Example:

"d9105228-4a08-46b1-8b91-42fed586d383"

Api-Version-Date
string

Pins the request to a dated API version.

Example:

"2026-07-25"

Query Parameters

account_id
string
required

Account or user ID whose identity you want to verify. Use a biz_ account ID for account verifications, or the caller's user_ ID for personal verification.

Body

application/json

Request body for an individual (KYC) verification. Omit kind or set it to individual. KYC is required to pay out funds and is a prerequisite for Whop Card access. Accepting payments does not require verification until a business reaches $5000 in payments.

Add business_name and business_structure if the individual operates under a business entity — this enables payouts to be received by a business bank account. country is always the individual's own country, and the supported business_structure values vary by it — see Business structures.

address
object
business_name
string

Legal business name for a sole proprietor or single-member LLC.

business_structure
string

Entity type for sole proprietors, such as single_member_llc. Supported values vary by country of incorporation — see Business structures.

business_tax_identification_number
string

The business ID number of the company, as appropriate for the company's country. Examples are an Employer Identification Number (EIN) in the US, a Business Number in Canada, or a Company Number in the UK.

business_website
string

Business website URL. Whop store pages are not accepted.

country
string

Two-letter ISO 3166-1 country code, for example US, DE, or GB.

date_of_birth
string

Formatted as YYYY-MM-DD.

document_type
enum<string>

Identity document being sent, when verifying with documents. Decides exactly which file slots to send: ID_CARDid_card_front + id_card_back + selfie; DRIVERSdrivers_front + drivers_back + selfie; RESIDENCE_PERMITresidence_permit_front + residence_permit_back + selfie; PASSPORTpassport_front + selfie. See Identity documents.

Available options:
ID_CARD,
DRIVERS,
RESIDENCE_PERMIT,
PASSPORT
documents
object

Identity document files, each value the file's raw bytes base64-encoded (JPEG, PNG, or PDF, up to 5MB per file before encoding). Sending this object verifies the person from the files in this request instead of a hosted session — individual verifications only, and the request must also carry document_type, first_name, last_name, date_of_birth, country, phone, tax_identification_number, and an address with line1, city, state, and postal_code. Send every slot for your document_type — a missing or rejected file fails the whole request and nothing is submitted; review starts automatically once every document is accepted. See Identity documents for a full walkthrough.

first_name
string
kind
enum<string>

Verification type. Defaults to individual.

Available options:
individual
last_name
string
phone
string
tax_identification_number
string

The government-issued ID number of the person being verified — the individual for a KYC verification, or the business representative for a KYB verification — as appropriate for their country. Examples are a Social Security Number (SSN) in the US, or a Social Insurance Number in Canada.

Response

OK

address
object | null

Address on the verification profile. null when no address is set.

business_name
string | null

Legal business name.

business_structure
string | null

Legal entity structure of the business, such as private_corporation or sole_proprietorship. Supported values vary by country of incorporation — see Business structures.

country
string | null

Two-letter ISO 3166-1 country code, for example US, DE, or GB.

created_at
string

When the verification profile was created, as an ISO 8601 timestamp.

date_of_birth
string | null

Formatted as YYYY-MM-DD.

first_name
string | null
id
string

Verification profile ID, prefixed idpf_.

kind
enum<string>
Available options:
individual,
business
last_name
string | null
requested_information
object[]

Fields or documents Whop still needs before review can continue. Submit answers with the Update Verification endpoint.

required_documents
object[]

Documents for a document-upload verification and their progress. Present only on verifications created by sending documents. pending_upload documents were not accepted yet — send the full set again with another Create Verification call.

session_url
string | null

Hosted verification session URL for the user to complete identity checks. Expires 7 days after creation.

status
enum<string>

Current verification state. not_started before any session has been created; pending while a session is in progress and needs the user's input; processing while the provider reviews submitted documents — nothing to do but wait; action_required when items in requested_information need answers before review can continue; approved once verification succeeds; rejected if it fails. Call the Create Verification endpoint again to start a new session.

Available options:
not_started,
pending,
processing,
approved,
rejected,
action_required
updated_at
string

When the verification profile was last updated, as an ISO 8601 timestamp.