Confirm / attach a company document
curl --request POST \
--url https://app.instantcompliance.ai/api/v1/entities/{id}/documents \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"s3Key": "check-documents/org-…/entity-…/…_asic-extract.pdf",
"file": {
"fileName": "asic-extract.pdf",
"fileSize": 482913,
"contentType": "application/pdf"
}
}
'import requests
url = "https://app.instantcompliance.ai/api/v1/entities/{id}/documents"
payload = {
"s3Key": "check-documents/org-…/entity-…/…_asic-extract.pdf",
"file": {
"fileName": "asic-extract.pdf",
"fileSize": 482913,
"contentType": "application/pdf"
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
s3Key: 'check-documents/org-…/entity-…/…_asic-extract.pdf',
file: {fileName: 'asic-extract.pdf', fileSize: 482913, contentType: 'application/pdf'}
})
};
fetch('https://app.instantcompliance.ai/api/v1/entities/{id}/documents', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.instantcompliance.ai/api/v1/entities/{id}/documents",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
's3Key' => 'check-documents/org-…/entity-…/…_asic-extract.pdf',
'file' => [
'fileName' => 'asic-extract.pdf',
'fileSize' => 482913,
'contentType' => 'application/pdf'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.instantcompliance.ai/api/v1/entities/{id}/documents"
payload := strings.NewReader("{\n \"s3Key\": \"check-documents/org-…/entity-…/…_asic-extract.pdf\",\n \"file\": {\n \"fileName\": \"asic-extract.pdf\",\n \"fileSize\": 482913,\n \"contentType\": \"application/pdf\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.instantcompliance.ai/api/v1/entities/{id}/documents")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"s3Key\": \"check-documents/org-…/entity-…/…_asic-extract.pdf\",\n \"file\": {\n \"fileName\": \"asic-extract.pdf\",\n \"fileSize\": 482913,\n \"contentType\": \"application/pdf\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.instantcompliance.ai/api/v1/entities/{id}/documents")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"s3Key\": \"check-documents/org-…/entity-…/…_asic-extract.pdf\",\n \"file\": {\n \"fileName\": \"asic-extract.pdf\",\n \"fileSize\": 482913,\n \"contentType\": \"application/pdf\"\n }\n}"
response = http.request(request)
puts response.read_body{
"file_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"job_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"outcome": "reading"
}{
"error": {
"code": "unauthorized",
"message": "Invalid or revoked API key."
}
}{
"error": {
"code": "forbidden_scope",
"message": "This API key does not have the required scope. customers:write",
"details": {
"required_scope": "customers:write"
}
}
}{
"error": {
"code": "not_found",
"message": "Customer not found."
}
}{
"error": {
"code": "validation_failed",
"message": "Invalid customer payload.",
"details": {
"issues": {
"email": [
"Must be a valid email address."
]
}
}
}
}{
"error": {
"code": "rate_limited",
"message": "Rate limit exceeded. Slow down and retry shortly.",
"details": {
"limit": 60,
"window_seconds": 60
}
}
}Entities
Attach a company document
Confirm a company document you already PUT to a presigned URL. Routes
through the shared deposit core, so the document runs the same triage
and kind-match gating and drives the same KYB completion recompute as an
officer upload — ownership, size and file type are re-checked
server-side. Requires documents:write.
POST
/
entities
/
{id}
/
documents
Confirm / attach a company document
curl --request POST \
--url https://app.instantcompliance.ai/api/v1/entities/{id}/documents \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"s3Key": "check-documents/org-…/entity-…/…_asic-extract.pdf",
"file": {
"fileName": "asic-extract.pdf",
"fileSize": 482913,
"contentType": "application/pdf"
}
}
'import requests
url = "https://app.instantcompliance.ai/api/v1/entities/{id}/documents"
payload = {
"s3Key": "check-documents/org-…/entity-…/…_asic-extract.pdf",
"file": {
"fileName": "asic-extract.pdf",
"fileSize": 482913,
"contentType": "application/pdf"
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
s3Key: 'check-documents/org-…/entity-…/…_asic-extract.pdf',
file: {fileName: 'asic-extract.pdf', fileSize: 482913, contentType: 'application/pdf'}
})
};
fetch('https://app.instantcompliance.ai/api/v1/entities/{id}/documents', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.instantcompliance.ai/api/v1/entities/{id}/documents",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
's3Key' => 'check-documents/org-…/entity-…/…_asic-extract.pdf',
'file' => [
'fileName' => 'asic-extract.pdf',
'fileSize' => 482913,
'contentType' => 'application/pdf'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.instantcompliance.ai/api/v1/entities/{id}/documents"
payload := strings.NewReader("{\n \"s3Key\": \"check-documents/org-…/entity-…/…_asic-extract.pdf\",\n \"file\": {\n \"fileName\": \"asic-extract.pdf\",\n \"fileSize\": 482913,\n \"contentType\": \"application/pdf\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.instantcompliance.ai/api/v1/entities/{id}/documents")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"s3Key\": \"check-documents/org-…/entity-…/…_asic-extract.pdf\",\n \"file\": {\n \"fileName\": \"asic-extract.pdf\",\n \"fileSize\": 482913,\n \"contentType\": \"application/pdf\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.instantcompliance.ai/api/v1/entities/{id}/documents")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"s3Key\": \"check-documents/org-…/entity-…/…_asic-extract.pdf\",\n \"file\": {\n \"fileName\": \"asic-extract.pdf\",\n \"fileSize\": 482913,\n \"contentType\": \"application/pdf\"\n }\n}"
response = http.request(request)
puts response.read_body{
"file_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"job_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"outcome": "reading"
}{
"error": {
"code": "unauthorized",
"message": "Invalid or revoked API key."
}
}{
"error": {
"code": "forbidden_scope",
"message": "This API key does not have the required scope. customers:write",
"details": {
"required_scope": "customers:write"
}
}
}{
"error": {
"code": "not_found",
"message": "Customer not found."
}
}{
"error": {
"code": "validation_failed",
"message": "Invalid customer payload.",
"details": {
"issues": {
"email": [
"Must be a valid email address."
]
}
}
}
}{
"error": {
"code": "rate_limited",
"message": "Rate limit exceeded. Slow down and retry shortly.",
"details": {
"limit": 60,
"window_seconds": 60
}
}
}Step 2 of the company-document upload: confirm a document you already
PUT to a
presigned URL. It routes through
the shared deposit core, so the document runs the same triage and kind-match
gating and drives the same KYB completion recompute as an officer upload —
ownership, size and file type are all re-checked server-side (the presigned URL
only says where you may write).
outcome: reading means it was accepted and queued for extraction;
wrong-document means the initial check judged it not to be the expected
document — replace it and confirm again. Requires the documents:write scope.Authorizations
Bearer API key issued from Settings → Developers in your
Instant Compliance organisation. Format: ic_live_….
Path Parameters
Entity identifier (UUID or your external_id).
Body
application/json
Response
The stored file / extraction-job ids and the triage outcome.

