> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hifi.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Generate a compliance link

> Generate a hosted compliance (KYC/KYB) link for a user. Exactly one of
`userId` or `userType` must be provided. When `userType` is supplied without
`userId`, a new user of that type is created and associated with the link.

The response includes the hosted `url` and a `sessionToken` authorizing the
flow. If `recipientEmail` is provided, the link is also emailed to that address.




## OpenAPI

````yaml https://production.hifi.com/api/v3/openapi.json post /v3/compliance-links
openapi: 3.0.0
info:
  title: Hifi API
  version: 3.0.0
  description: API documentation for HIFI
servers:
  - url: https://production.hifi.com
    description: Production server
  - url: https://sandbox.hifi.com
    description: Sandbox server
security:
  - bearerAuth: []
tags:
  - name: Common
    description: Common endpoints
  - name: User
    description: User endpoints
  - name: Counter Party
    description: Counter party endpoints
  - name: Crypto Transfer
    description: Crypto transfer and batch transfer endpoints
  - name: Wallet
    description: Wallet and wallet offer endpoints
  - name: External Account
    description: External bank account endpoints (under a counter party)
  - name: External Wallet
    description: External wallet endpoints (under a counter party)
  - name: External Card
    description: External card endpoints (under a counter party)
  - name: Token Swap
    description: Token swap endpoints
  - name: Bridge
    description: Bridge endpoints
  - name: Virtual Account
    description: Virtual account endpoints
  - name: Compliance
    description: Compliance and compliance link endpoints
  - name: Webhook Endpoint
    description: Webhook endpoint endpoints
  - name: File
    description: File upload endpoints
  - name: Onramp
    description: Onramp (fiat to crypto) endpoints
  - name: Offramp
    description: Offramp (crypto to fiat) endpoints
  - name: Orchestration Address
    description: Orchestration (liquidation) address endpoints
  - name: KYC Link
    description: Hosted and custom KYC/KYB link endpoints
  - name: Transfer Approval
    description: Transfer approval endpoints
  - name: Corridor
    description: Supported fiat/crypto transfer corridor endpoints
  - name: Migration
    description: v2-to-v3 ID mapping endpoints
paths:
  /v3/compliance-links:
    post:
      tags:
        - Compliance
      summary: Generate a compliance link
      description: >
        Generate a hosted compliance (KYC/KYB) link for a user. Exactly one of

        `userId` or `userType` must be provided. When `userType` is supplied
        without

        `userId`, a new user of that type is created and associated with the
        link.


        The response includes the hosted `url` and a `sessionToken` authorizing
        the

        flow. If `recipientEmail` is provided, the link is also emailed to that
        address.
      operationId: v3CreateComplianceLink
      requestBody:
        $ref: '#/components/requestBodies/GenerateComplianceLinkBody'
      responses:
        '200':
          $ref: '#/components/responses/GenerateComplianceLinkResponse'
        '400':
          $ref: '#/components/responses/BadRequestResponse'
        '401':
          $ref: '#/components/responses/UnauthorizedResponse'
        '500':
          $ref: '#/components/responses/InternalServerErrorResponse'
components:
  requestBodies:
    GenerateComplianceLinkBody:
      required: true
      description: >
        Compliance link generation parameters. Exactly one of `userId` or
        `userType`

        must be provided.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ComplianceLinkCreate'
          examples:
            ExistingUserExample:
              summary: Generate a link for an existing user
              value:
                userId: usr_3Kf9dQ2mNpXwZ7bV1aLcs
                redirectUrl: https://app.example.com/onboarding/complete
            NewIndividualExample:
              summary: Generate a link and create a new individual user
              value:
                userType: INDIVIDUAL
                recipientEmail: jane.doe@example.com
                redirectUrl: https://app.example.com/onboarding/complete
            NewBusinessExample:
              summary: Generate a link and create a new business user
              value:
                userType: BUSINESS
                templateId: a1b2c3d4-e5f6-4789-a012-3456789abcde
  responses:
    GenerateComplianceLinkResponse:
      description: Compliance link generated successfully.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ComplianceLinkObject'
          example:
            id: cl_3Kf9dQ2mNpXwZ7bV1aLcs
            userId: usr_3Kf9dQ2mNpXwZ7bV1aLcs
            userType: INDIVIDUAL
            url: >-
              https://dashboard.example.com/sandbox/compliance-link?complianceLinkId=cl_3Kf9dQ2mNpXwZ7bV1aLcs&sessionToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
            sessionToken: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
            template: null
    BadRequestResponse:
      description: Bad Request — the request was malformed or failed validation.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
          example:
            type: VALIDATION_ERROR
            message: One or more fields are invalid or missing.
            fields:
              - code: invalid_value
                message: Must be a valid email address
                field: email
    UnauthorizedResponse:
      description: Unauthorized
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Unauthorized'
    InternalServerErrorResponse:
      description: Internal Server Error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/InternalServerError'
  schemas:
    ComplianceLinkCreate:
      type: object
      description: >
        Compliance link generation parameters. Exactly one of `userId` or
        `userType`

        must be provided. When `userType` is supplied without `userId`, a new
        user of

        that type is created and associated with the link.
      required:
        - userId
        - userType
      properties:
        userId:
          type: string
          description: >
            Public ID of an existing user (prefixed with `usr_`). Provide this
            OR

            `userType`, not both.
          example: usr_3Kf9dQ2mNpXwZ7bV1aLcs
        userType:
          type: string
          description: >
            Type of user to create the compliance link for. Provide this OR
            `userId`,

            not both.
          enum:
            - INDIVIDUAL
            - BUSINESS
            - individual
            - business
          example: INDIVIDUAL
        requestId:
          type: string
          format: uuid
          description: Optional idempotency identifier for the link generation request.
          example: f47ac10b-58cc-4372-a567-0e02b2c3d479
        redirectUrl:
          type: string
          format: uri
          description: URL the user is redirected to after completing the compliance flow.
          example: https://app.example.com/onboarding/complete
        recipientEmail:
          type: string
          format: email
          description: If provided, the compliance link is emailed to this address.
          example: jane.doe@example.com
        templateId:
          type: string
          format: uuid
          description: Optional terms-of-service template ID to brand the compliance flow.
          example: a1b2c3d4-e5f6-4789-a012-3456789abcde
        isInitialOnboarding:
          type: boolean
          description: >
            Marks this as the initial onboarding link for the client's own
            entity.

            Extends link expiry and forces a business user type.
          example: false
    ComplianceLinkObject:
      type: object
      description: A compliance link.
      properties:
        id:
          type: string
          description: Public ID of the compliance link (prefixed with `cl_`).
          example: cl_3Kf9dQ2mNpXwZ7bV1aLcs
        userId:
          type: string
          description: Public ID of the user this link belongs to (prefixed with `usr_`).
          example: usr_3Kf9dQ2mNpXwZ7bV1aLcs
        userType:
          type: string
          enum:
            - INDIVIDUAL
            - BUSINESS
            - individual
            - business
          example: INDIVIDUAL
        url:
          type: string
          nullable: true
          description: >
            Hosted compliance link URL. Returned when generating a link; `null`
            when

            retrieving an existing link.
          example: >-
            https://dashboard.example.com/sandbox/compliance-link?complianceLinkId=cl_3Kf9dQ2mNpXwZ7bV1aLcs&sessionToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
        sessionToken:
          type: string
          description: Session token authorizing the hosted compliance flow.
          example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
        template:
          $ref: '#/components/schemas/ComplianceLinkTemplate'
    ApiError:
      type: object
      description: >-
        Standard v3 error shape, returned by validation failures and
        business-logic errors alike.
      properties:
        type:
          type: string
          description: >-
            Machine-readable error type, e.g. VALIDATION_ERROR,
            ACTION_NOT_ALLOWED, RESOURCE_CONFLICT.
          example: VALIDATION_ERROR
        message:
          type: string
          description: Human-readable error message.
          example: One or more fields are invalid or missing.
        fields:
          type: array
          description: >-
            Present on field-level validation errors. One entry per problem
            field.
          items:
            type: object
            properties:
              code:
                type: string
                description: Error code related to the field issue.
              message:
                type: string
                description: Error message for the specific issue.
              field:
                type: string
                description: The name of the field that has an issue.
    Unauthorized:
      type: object
      properties:
        type:
          type: string
          description: Unauthorized enum
          example: UNAUTHORIZED
        message:
          type: string
          description: Unauthorized message
          example: Authentication required
    InternalServerError:
      type: object
      properties:
        type:
          type: string
          example: INTERNAL_SERVER_ERROR
          description: Internal server error enum
        message:
          type: string
          example: An internal server error occurred
          description: Internal server error message
    ComplianceLinkTemplate:
      type: object
      nullable: true
      description: >
        Branding and legal template applied to the compliance flow. Populated
        when

        retrieving a compliance link; `null` when generating one.
      properties:
        entityName:
          type: string
          nullable: true
          description: Organization name displayed in the compliance flow.
          example: Acme Financial
        logo:
          type: string
          nullable: true
          description: URL of the logo displayed in the compliance flow.
          example: https://cdn.example.com/logo.png
        termsOfServiceLink:
          type: string
          description: Terms of service URL.
          example: https://policy.hifi.com/terms-conditions
        privacyPolicyLink:
          type: string
          description: Privacy policy URL.
          example: https://policy.hifi.com/privacy-policy
        customText:
          type: string
          nullable: true
          description: Custom text displayed in the compliance flow.
          example: By continuing you agree to our partner terms.
        customTextLink:
          type: string
          nullable: true
          description: URL associated with the custom text.
          example: https://app.example.com/partner-terms
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT

````