Skip to main content
GET
Get a user

Authorizations

Authorization
string
header
required

The data.access_token value from Get access token.

x-api-key
string
header
required

API key issued by Kira.

Headers

X-Api-Version
string

Version applied to this request. It wins over your account's pinned version — see Versioning.

Example:

"2026-04-14"

Path Parameters

user_id
string<uuid>
required

The id of the user, as returned when you created it. It must be a UUID.

Response

The user.

One user, in full.

id
string<uuid>

User UUID.

type
string

Whether the user is a company or a person.

Available options: business, individual.

See User values for what each one means.

email
string<email>

Email address.

status
string

Where the user sits in its lifecycle.

Available options: CREATED, VERIFYING, REVIEW, VERIFIED, REJECTED, plus the legacy ACTIVE, INACTIVE and SUSPENDED.

See User values for what each one means.

verification_status
string

The result of the user's identity or business check.

Available options: unverified, started, in_review, verified, rejected, needs_action.

See User values for what each one means.

created_at
string<date-time>

Creation timestamp (ISO 8601).

updated_at
string<date-time>

Last-update timestamp (ISO 8601).

verification_mode
string

automatic or verification_link.

Hosted KYC URL — present only in verification_link mode.

A plain-text note about something the request could not finish — the hosted verification link, or a move of this user to a different bank.

The wording can change, so branch on verification_link_error_severity, never on this string.

Whether the note in verification_link_error asks anything of you.

See User values for what each value means.

Available options:
deferred,
failed
capabilities
object

Which banks this user has said it needs.

When the field comes back it always carries requested_banks, using an empty array when the user has declared nothing.

metadata
object

The key-value pairs you stored on this user.

If your account has default metadata configured, it is merged in when the user is created and your own keys win on a conflict.

first_name
string

Given name (individual users).

last_name
string

Family name (individual users).

middle_name
string

Middle name (individual users), when provided.

phone
string

Contact phone in E.164 form (e.g. +525512345678).

birth_date
string

Date of birth, YYYY-MM-DD (individual users).

nationality
string

The person's nationality, as an ISO alpha-3 country code — USA, MEX.

country_of_birth
string

Where the person was born, as an ISO alpha-3 country code. Absent when it was never set.

gender
string

male, female, or other, when provided.

residential_address
object

The person's address, as a nested object.

formation_country
string

Country the business was formed in, as an ISO alpha-3 code.

The registered legal name of the business.

registered_address
object

The registered, legal address of the business.

identifying_information
object[] | null

The user's identity or registration records. null when none are stored, and absent on users whose verification runs through a hosted link.

associated_persons
object[] | null

The people tied to a business. null for a person, and absent on users whose verification runs through a hosted link.

eligible_products
object[]

What this user can already use, product by product.

Each entry carries eligible, and when that is false, the reason why:

  • missing_fields — data is missing. Send it, and the product turns eligible once the user passes verification.
  • unsupported_reason — nothing you send will change the answer.

A product stays eligible: false until the user reaches the status that product asks for, which is usually VERIFIED.

missing_fields
object

The gaps that remain, grouped by product code, plus a general key holding every token once.

A product with nothing outstanding is left out of the map, so it can come back with only general, or empty.