Partial update via JSON Merge Patch (RFC 7396), limited to externalId and metadata.
No domain field is writable here, and that is deliberate rather than an omission. status, resultFiles, the embedded verification and every timestamp are driven by the identity-verification vendor's webhook, so a write path into any of them would be a second, competing writer on the same row. externalId and metadata have no such driver: the vendor does not know they exist, so a caller owns them outright.
The calling account must be the request's PAYER — externalId is unique per payer account, so a payee write would reserve a value inside the other party's namespace. A payee receives 404, not 403.
Supplying an externalId already in use for this payer account returns 409 ResourceConflict.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||