marketplace

POST /v1/marketplace/vendor/verification/documents

Reserve a document slot and get a short-lived upload URL.

All marketplace endpoints

Authentication

Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/marketplace/vendor/verification/documents \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "kind": <MarketplaceDocumentKind>, "filename": <string>, "content_type": <string<image/jpeg, image/png, application/pdf>>, "size_bytes": <integer> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

docs/82 §7a. **The bytes never pass through the engine.** The response carries a presigned `PUT` the browser uploads straight to object storage with; a 10 MB scan routed through an API worker is 10 MB of a request thread and a request that outlives its timeout on a poor connection. ⛔ The stored object key is deliberately absent from the response — the seller needs the signed URL, never the address of an object in a bucket of identity documents. ⛔ **We ask for "a government-issued photo ID"** — passport, national identity card, driving licence or residence permit — and there is no country list. A student, workplace or library card is not government-issued and is not accepted.

Request body

NameTypeRequiredWhat it is
kindMarketplaceDocumentKindYesWhat a stored object is evidence of. `photo_id` covers passport, national identity card, driving licence and residence permit — there is no country list, and a student, workplac…
subject_idstringNoRequired for `photo_id` and `proof_of_address` — a personal document with no person satisfies nobody's requirement while looking uploaded on every screen.
filenamestringYes
content_typestring<image/jpeg, image/png, application/pdf>YesJPEG, PNG or PDF. An allow-list, not a deny-list.
size_bytesintegerYes

Response

NameTypeRequiredWhat it is
documentMarketplaceVerificationDocumentYesA pointer to one uploaded document. The bytes live in object storage and are reached only through a short-lived signed URL; the object key is never published.
uploadMarketplaceDocumentUploadGrantYesA presigned upload. The `headers` are part of the grant, not decoration — a signature computed over `content-type` fails with a 403 if the uploader omits it.

Errors this endpoint can return

401 · 404 · 422