# Sumsub Reusable KYC



If your users have already completed KYC verification through Sumsub with your platform, you can import their verification data to Paytrie. This eliminates the need for users to complete identity verification again.

## Overview [#overview]

Sumsub's Reusable KYC feature allows identity verification data to be shared between platforms. As a "Donor" platform, you generate a share token for a user's verification data, which Paytrie then imports as the "Recipient" platform.

## Prerequisites [#prerequisites]

* Your platform must be integrated with [Sumsub](https://sumsub.com/)
* The user must have completed KYC verification on your platform
* You must have API access to generate Sumsub share tokens
* The user must already exist in Paytrie under your API key — create them first using `POST /v2/users` with the same API key you'll use for the import
* The Sumsub applicant must be enrolled and verified in the `id-and-liveness` verification level

## Integration flow [#integration-flow]

<Steps>
  <Step>
    ### Create API user in Paytrie [#create-api-user-in-paytrie]

    Register the user in Paytrie first using `POST /v2/users` and note the returned user ID — the import writes the KYC data to that user.
  </Step>

  <Step>
    ### Generate share token [#generate-share-token]

    Use the Sumsub API to generate a share token for the user's verification data from an applicant verified in the `id-and-liveness` level.
  </Step>

  <Step>
    ### Submit to Paytrie [#submit-to-paytrie]

    Send the share token to the Paytrie import endpoint.
  </Step>

  <Step>
    ### User verified [#user-verified]

    If successful, the user is automatically verified on Paytrie without additional KYC.
  </Step>
</Steps>

## Quick start [#quick-start]

### 1. Create the user in Paytrie [#1-create-the-user-in-paytrie]

Create the Paytrie user first:

```bash
curl -X POST "https://api.paytrie.com/v2/users" \
  -H "x-api-key: your-api-key" \
  -H "Content-Type: application/json" \
  -d '{
    "email": "john.doe@example.com",
    "firstName": "John",
    "lastName": "Doe",
    "dob": "1990-01-15",
    "phone": "4165551234",
    "addressLine1": "123 Main Street",
    "addressLine2": "Suite 100",
    "city": "Toronto",
    "province": "on",
    "postalCode": "M5V1A1",
    "occupation": "Software Engineer",
    "pep": false,
    "tpd": false
  }'
```

<Card title="API Reference: Create a new user" href="/v2/api-reference/users/createUser" icon="arrow-right-left">
  View complete request parameters and response schema
</Card>

### 2. Generate a share token (Sumsub API) [#2-generate-a-share-token-sumsub-api]

Use the Sumsub API to generate a share token for a specific applicant that is
verified in your Sumsub `id-and-liveness` level:

```bash
curl -X POST "https://api.sumsub.com/resources/applicants/{applicantId}/shareToken" \
  -H "X-App-Token: your-sumsub-token" \
  -H "X-App-Access-Sig: your-signature" \
  -H "X-App-Access-Ts: timestamp"
```

See the [Sumsub documentation](https://docs.sumsub.com/reference/generate-share-token) for complete details.

### 3. Import to Paytrie [#3-import-to-paytrie]

Submit the Sumsub share token to import the user's verification, using the `userId` returned when you created the user in step 1.

```bash
curl -X PUT "https://api.paytrie.com/v2/users/{userId}/kyc" \
  -H "x-api-key: your-api-key" \
  -H "Content-Type: application/json" \
  -d '{
    "type": "sumsub",
    "payload": {
      "shareToken": "_act-sb-jwt-eyJHGCi........tN0."
    }
  }'
```

<Card title="API Reference: Import KYC data for a user" href="/v2/api-reference/users/importUserKyc" icon="arrow-right-left">
  View complete request parameters and response schema
</Card>

## Common errors [#common-errors]

| Error                                                                             | Description                                                                                                        | Solution                                                                                                                                    |
| --------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------- |
| Token expired                                                                     | The share token has expired                                                                                        | Generate a new share token                                                                                                                  |
| Token invalid                                                                     | The share token is malformed                                                                                       | Verify the token format                                                                                                                     |
| Applicant not found                                                               | The applicant doesn't exist in Sumsub                                                                              | Verify the applicant ID                                                                                                                     |
| Verification incomplete                                                           | The user hasn't completed verification                                                                             | Ensure KYC is complete before generating token                                                                                              |
| Share token not suitable for level                                                | The share token comes from a different Sumsub level                                                                | Enroll and verify applicants in `id-and-liveness`, then generate a new token                                                                |
| `Email is required: the Sumsub share token does not carry an email...`            | Your Sumsub applicant doesn't have `applicantIdentifiers.email` set, and you didn't include `email` in the request | Pass the user's email in the request body (the same email you used when creating the user with `POST /v2/users`)                            |
| `Email in request does not match the email on the Sumsub applicant.`              | The `email` you sent and the email Sumsub has on the applicant differ                                              | Send the email that matches the applicant on Sumsub, or create the user with `POST /v2/users` using the email Sumsub holds before importing |
| `Unable to import: please complete registration on Paytrie before importing KYC.` | No Paytrie user exists for that email **under your API key**                                                       | Make sure you created the user with `POST /v2/users` first, using the same email *and* the same API key you're using for the import         |

## Additional resources [#additional-resources]

<Cards>
  <Card title="Sumsub Reusable KYC" href="https://docs.sumsub.com/docs/reusable-kyc" icon="external-link">
    Sumsub's official documentation on Reusable KYC
  </Card>

  <Card title="Generate Share Token" href="https://docs.sumsub.com/reference/generate-share-token" icon="external-link">
    API reference for generating share tokens
  </Card>

  <Card title="Error Codes" href="https://docs.sumsub.com/reference/reuse-applicant-for-reusable-kyc#error-codes-with-descriptions" icon="external-link">
    Complete list of Sumsub error codes
  </Card>
</Cards>
