Get a user
Returns one user in full, by id.
Headers
Version applied to this request. It wins over your account's pinned version — see Versioning.
"2026-04-14"
Path Parameters
The id of the user, as returned when you created it. It must be a UUID.
Response
The user.
One user, in full.
User UUID.
Whether the user is a company or a person.
Available options: business, individual.
See User values for what each one means.
Email address.
Where the user sits in its lifecycle.
Available options: CREATED, VERIFYING, REVIEW, VERIFIED, REJECTED, plus the legacy ACTIVE, INACTIVE and SUSPENDED.
See User values for what each one means.
The result of the user's identity or business check.
Available options: unverified, started, in_review, verified, rejected, needs_action.
See User values for what each one means.
Creation timestamp (ISO 8601).
Last-update timestamp (ISO 8601).
automatic or verification_link.
Hosted KYC URL — present only in verification_link mode.
A plain-text note about something the request could not finish — the hosted verification link, or a move of this user to a different bank.
The wording can change, so branch on verification_link_error_severity, never on this string.
Whether the note in verification_link_error asks anything of you.
See User values for what each value means.
deferred, failed Which banks this user has said it needs.
When the field comes back it always carries requested_banks, using an empty array when the user has declared nothing.
The key-value pairs you stored on this user.
If your account has default metadata configured, it is merged in when the user is created and your own keys win on a conflict.
Given name (individual users).
Family name (individual users).
Middle name (individual users), when provided.
Contact phone in E.164 form (e.g. +525512345678).
Date of birth, YYYY-MM-DD (individual users).
The person's nationality, as an ISO alpha-3 country code — USA, MEX.
Where the person was born, as an ISO alpha-3 country code. Absent when it was never set.
male, female, or other, when provided.
The person's address, as a nested object.
Country the business was formed in, as an ISO alpha-3 code.
The registered legal name of the business.
The registered, legal address of the business.
The user's identity or registration records. null when none are stored, and absent on users whose verification runs through a hosted link.
The people tied to a business. null for a person, and absent on users whose verification runs through a hosted link.
What this user can already use, product by product.
Each entry carries eligible, and when that is false, the reason why:
missing_fields— data is missing. Send it, and the product turns eligible once the user passes verification.unsupported_reason— nothing you send will change the answer.
A product stays eligible: false until the user reaches the status that product asks for, which is usually VERIFIED.
The gaps that remain, grouped by product code, plus a general key holding every token once.
A product with nothing outstanding is left out of the map, so it can come back with only general, or empty.