Update a ComplianceEntity

Updates the current ComplianceEntity in place. Before verification, material and immaterial corrections are both accepted. Once any verification lane is Verified, a material scalar change returns 409 with detailCode: users.MaterialChangeRequiresAdvance; use /advance. Replacing an occupied tax-identifier registration also requires advance. PATCH never creates a successor and subject cannot be changed. The id is resolved with the same authorized-lane and primary-wins semantics as GET, and the resolved owner kind is retained through the mutation.

Requires a session with recent MFA step-up for HighRiskWriteAction. If step-up is missing or expired, this operation returns 403 StepUpMfaRequired; create and verify an MFA challenge at /v3/platform/mfa-challenges with requiredFor: "HighRiskWriteAction", then retry.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
string
required

Unique identifier of a ComplianceEntity record within the subject's chain (current or historical).

Body Params

Request body for updating the current ComplianceEntity in place. Before verification, material and immaterial corrections are accepted. After any lane is Verified, material scalar changes return 409 with detailCode: users.MaterialChangeRequiresAdvance. Tax identifiers are PATCH add-only: a supported new (countryCode, type) registration may be added in place, while changing an existing registration requires advance. subject cannot be changed.

string

ISO 3166-1 alpha-2 country code for the subject's primary compliance jurisdiction.

string
string
physicalAddress
object

Postal address. Subdivision codes per locale; country ISO 3166-1 alpha-2.

mailingAddress
object

Optional correspondence address (PO box / registered agent / mail-forwarding).

string
string
uri
string
string

Primary contact number (both types).

string

Primary email address (Individual only).

string

Free-text job title or occupation (Individual only).

string
individualLegalName
object

Globalization-aware natural-person name. Application invariant: either fullLegalName, or both familyName and givenName, must be populated.

usTaxProfile
object

U.S. tax identity for a non-US individual. The name is distinct from the ComplianceEntity's local legal name. Only givenName, middleNames, and familyName are stored; fullLegalName, suffix, prefix, and transliteration are rejected on write.

string
governmentIds
array of objects
governmentIds
taxIdentifiers
array of objects

Add-only supported tax-identifier registrations. A new (countryCode, type) entry is stored in place. Replacing an existing registration's value or type is a material change and returns 409 ResourceConflict with detailCode: users.MaterialChangeRequiresAdvance. Identifier values are required, write-only, and never returned. Unsupported country/type pairs return 422 ValidationError rather than being ignored. A PATCH cannot combine a country/jurisdiction change (including physicalAddress.countryCode) with taxIdentifiers; apply them as separate transitions.

taxIdentifiers
enhancedDueDiligence
object

Atomic Enhanced Due Diligence questionnaire. Stable missing-field names are purposeOfAccount, cashFlow, monthlyTransactionVolume, sourceOfFunds, annualRevenue, businessOperatingGeography, primaryCustomerType, and prohibitedJurisdictionExposure. prohibitedJurisdictionExposureDetails is required when exposure is Yes and is cleared for No or Unsure.

metadata
object

Free-form key-value pairs. Max 50 keys; key length at most 40 characters; value length at most 500 characters. Where a list endpoint declares metadata filtering, it uses the QueryQL namespace via filter[metadata.{key}][eq]=value or filter[metadata.{key}][in][]=value. Endpoints that do not declare the dynamic Metadata filter do not support Metadata filtering.

Headers
string
length between 1 and 255
^[\x21-\x7e]{1,255}$

Optional idempotency token for authenticated POST and PATCH requests. Reusing the same key and body returns the cached response for 24 hours, except credential operations that explicitly document a 409 because one-time secret material is never cached; reusing it with a different body returns 409 IdempotencyKeyConflict. Use 1-255 printable ASCII characters.

string
^(?:[A-Za-z0-9_.]{22}|[a-f0-9]{24})$

Select the Account for an Account-scoped operation. A direct ServiceAccount API key MUST supply this header, and the target must be within the ServiceAccount owner's or Authorization grant's Account boundary. A Person bearer may select an Account on which it has an active Stakeholder, and an Account session may select its bound Account (or a descendant only when the session explicitly includes descendants).

string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json