Skip to main content
The Instant Compliance API lets your systems send customers — individuals and entities — into Instant Compliance and read their KYC / KYB / AML status back out. It is designed for server-to-server integrations — CRMs (Salesforce, HubSpot, Pipedrive), automation platforms (Zapier, Make, n8n), and internal back-office tooling.

Quickstart

Create your first key and ingest a customer in under five minutes.

API reference

Every endpoint, every parameter, every response — with live “Try it” code samples.

Zapier guide

Wire Instant Compliance into your no-code workflows.

Authentication

Issue, rotate, and revoke API keys and choose the right scopes.

What v1 does

  • Create or update an individual customer in your Instant Compliance organisation. The customer lands tagged INTEGRATION with kyc_status derived by the same rule as in-app onboarding — NOT_STARTED when a designated service makes due diligence required, NOT_REQUIRED otherwise. Ingesting never triggers KYC and never charges.
  • Create or update an entity customer (company, trust, partnership, SMSF) on /entities — including its identifiers (ABN/ACN or country + registration number) and contact person. The entity’s kyb_status follows the same rule; ingesting never triggers KYB and never charges.
  • Start a verification when you’re ready — POST /customers/{id}/kyc and POST /entities/{id}/kyb run the same KYC/KYB flows as the app. These spend credits (or bill the customer) and need the separate verification:write scope, so ingesting and billing stay independently grantable.
  • Read a customer back including a safe, integrator-friendly slice of its KYC / KYB and AML status fields.
  • Poll for status changes using the updated_since filter on the list endpoints — perfect for syncing results into your CRM.
  • Receive webhooks for KYC/KYB and AML events — signed, retried real-time delivery so you don’t have to poll. See Webhooks.

What v1 does not do

These are coming in v2 and are intentionally out of scope today:
  • Trigger KYC / KYB checks via API. Starting a real verification is the billable moment and stays a human action inside Instant Compliance (your back-office team completes the risk questions and clicks Start Verification in-app).
  • UBO / beneficial-owner graphs. Entities are ingested and their KYB status is readable, but ownership resolution happens in-app during KYB.
  • EDD (Enhanced Due Diligence) source-of-funds / source-of-wealth.

Base URL

All endpoints accept and return application/json. All timestamps are ISO-8601 UTC. All identifiers are UUIDs unless otherwise noted.

Security defaults

  • HTTPS only. Plaintext HTTP requests are rejected.
  • Org-scoped keys. Every key belongs to exactly one organisation — cross-tenant data access is structurally impossible.
  • Least-privilege scopes. Grant only the scopes your integration needs (customers:write, customers:read, aml:read).
  • Data minimisation. Responses never include raw AML hit data, full date of birth, full address, document references, or moderator notes. See Data minimisation for the full deny-list.