> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kirafin.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Get an RFI

> Retrieve a single RFI by its UUID, with its items nested. The RFI must belong to you.



## OpenAPI

````yaml /openapi/kira-api.2026-06-01.json get /v1/rfis/{rfi_id}
openapi: 3.1.0
info:
  title: Kira API
  version: '2026-06-01'
  description: >-
    REST API for users, KYC/KYB verification, virtual accounts, payouts,
    recipients, and webhooks. Every request requires an `x-api-key` header and a
    bearer access token (see Authentication). Pin your account to version
    `2026-04-14` before integrating.
  contact:
    name: Kira API Support
    email: support@kirafin.ai
servers:
  - url: https://api.balampay.com
    description: Production
  - url: https://api.balampay.com/sandbox
    description: Sandbox
security:
  - bearerAuth: []
    apiKeyAuth: []
tags:
  - name: Authentication
  - name: Versioning
  - name: Users
  - name: Virtual Accounts
  - name: Recipients
  - name: Quotations
  - name: Payouts
  - name: Reference
  - name: RFIs
paths:
  /v1/rfis/{rfi_id}:
    get:
      tags:
        - RFIs
      summary: Get an RFI
      description: >-
        Retrieve a single RFI by its UUID, with its items nested. The RFI must
        belong to you.
      operationId: get_v1-rfis-rfi-id
      parameters:
        - in: path
          name: rfi_id
          required: true
          schema:
            type: string
            format: uuid
          description: RFI UUID.
        - in: header
          name: X-Api-Version
          required: false
          description: >-
            Version applied to this request. It wins over your account's pinned
            version — see [Versioning](/using-the-api/versioning).
          schema:
            type: string
            example: '2026-06-01'
      responses:
        '200':
          description: Success.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Rfi'
              example:
                rfi_id: 7f1c9a20-3b4d-4e5f-8a91-2c3d4e5f6a7b
                user_id: aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee
                status: pending
                due_at: '2026-09-15T23:59:59.000Z'
                blocking:
                  type: transfer
                  transfer_uuid: 99999999-aaaa-bbbb-cccc-dddddddddddd
                resolution_reason: null
                created_at: '2026-09-01T12:00:00.000Z'
                first_answered_at: null
                updated_at: null
                closed_at: null
                items:
                  - item_id: 1a2b3c4d-5e6f-4708-9a1b-2c3d4e5f6a7b
                    ordinal: 1
                    prompt: >-
                      Upload the certificate of good standing issued in the last
                      90 days.
                    answer_type: document
                    answer_spec:
                      max_files: 3
                    target_key: null
                    subject: null
                    status: pending
                    answer_value: null
                    documents: []
                    review_note: null
                    updated_at: null
                    returned_at: null
        '400':
          description: >-
            Malformed id — `rfi_id` is not a valid UUID. Ids are
            format-validated before lookup, so a syntactically invalid id
            returns `400` (not `404`).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationErrorResponse'
              example:
                code: validation_error
                message: Invalid request body
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                code: invalid_request
                message: >-
                  The request could not be authenticated. Check the x-api-key
                  and Authorization headers.
        '404':
          description: >-
            Not found — belongs to another client, or is `withdrawn` (a
            withdrawn RFI 404s; it is never a visible empty row).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                code: not_found
                message: RFI not found
      security:
        - bearerAuth: []
          apiKeyAuth: []
      servers:
        - url: https://api.balampay.com/sandbox
          description: Sandbox
        - url: https://api.balampay.com
          description: Production
components:
  schemas:
    Rfi:
      type: object
      properties:
        rfi_id:
          type: string
          format: uuid
        user_id:
          type: string
          format: uuid
          description: The subclient this RFI is about.
        status:
          type: string
          enum:
            - pending
            - answered
            - resolved
            - not_resolved
          description: >-
            Where the request is. See [RFI
            values](/reference/rfis/values#status).
        due_at:
          type: string
          format: date-time
        blocking:
          oneOf:
            - $ref: '#/components/schemas/RfiBlockingTransfer'
            - $ref: '#/components/schemas/RfiBlockingDeposit'
            - type: 'null'
          description: >-
            What the request is anchored to, or `null` when it is about the
            sub-client rather than one movement. It never names which account is
            blocked. See [RFI values](/reference/rfis/values#blocking-type).
        resolution_reason:
          type:
            - string
            - 'null'
          enum:
            - expired
            - rejected
            - null
          description: >-
            Set only when `status` is `not_resolved`. See [RFI
            values](/reference/rfis/values#resolution_reason).
        created_at:
          type: string
          format: date-time
        first_answered_at:
          type:
            - string
            - 'null'
          format: date-time
          description: >-
            When you first handed an answer back. It measures the hand-off to
            Kira, not when your own customer answered you.
        updated_at:
          type:
            - string
            - 'null'
          format: date-time
          description: >-
            When this need was last answered. Moves on every answer round; a
            return that walks `status` back to `pending` doesn't touch it.
        closed_at:
          type:
            - string
            - 'null'
          format: date-time
          description: >-
            Set for all three closed outcomes — `resolved`, `not_resolved`,
            `withdrawn` — dating whichever occurred.
        items:
          type: array
          items:
            $ref: '#/components/schemas/RfiItem'
    ValidationErrorResponse:
      type: object
      description: >-
        Validation / request error. The body shape is **not uniform** across the
        API — it varies by endpoint and by which validation layer rejects the
        request. The fields below are the union of what may appear; treat them
        all as optional. Observed shapes include `{ code, message }`, `{ code,
        message, errors[] }`, `{ code, error, details[] }`, `{ error, details[]
        }`, and a nested `{ error: { code, message, details } }`. Always branch
        on the HTTP status, not on a fixed body shape.
      properties:
        code:
          type: string
        message:
          type: string
        error:
          type:
            - string
            - object
          description: >-
            A short error label (e.g. `"Invalid data"`), or on some endpoints a
            nested `{ code, message, details }` object.
        errors:
          type: array
          items:
            type: object
            properties:
              field:
                type: string
              message:
                type: string
            required:
              - field
              - message
        details:
          type:
            - array
            - object
          description: >-
            Per-issue detail. Shape varies by endpoint — typically an array of
            `{ message }` or `{ path, message, code }`, occasionally an object.
    ErrorResponse:
      type: object
      properties:
        message:
          type: string
        code:
          type: string
        statusCode:
          type: number
        error:
          type: string
        timestamp:
          type: string
        path:
          type: string
        details: {}
      required:
        - message
    RfiBlockingTransfer:
      type: object
      properties:
        type:
          type: string
          enum:
            - transfer
        transfer_uuid:
          type: string
          format: uuid
    RfiBlockingDeposit:
      type: object
      properties:
        type:
          type: string
          enum:
            - virtual_account_deposit
        virtual_account_deposit_uuid:
          type: string
          format: uuid
    RfiItem:
      type: object
      description: >-
        One thing being asked for. The addressable unit of an RFI — a `PATCH` or
        a document upload always names an `item_id`, never the parent RFI.
      properties:
        item_id:
          type: string
          format: uuid
        ordinal:
          type: integer
          description: Display order within the RFI.
        prompt:
          type: string
          description: What is being asked, in prose.
        answer_type:
          type: string
          enum:
            - text_long
            - text_short
            - number
            - date
            - boolean
            - choice
            - identifier
            - document
            - ubo_link
          description: >-
            What the item is asking for, and therefore what a valid answer looks
            like. See [RFI values](/reference/rfis/values#answer_type).
        answer_spec:
          type: object
          additionalProperties: true
          description: >-
            The complete set of rules this item validates an answer against, not
            a suggestion. Which keys it holds is fixed by `answer_type` — see
            [RFI values](/reference/rfis/values#answer_spec-by-answer-type).
          example:
            options:
              - ssn
              - itin
        target_key:
          type:
            - string
            - 'null'
          description: >-
            The named subclient field this answer writes on acceptance (e.g.
            `ein`), or `null` when the answer lives only on this item.
        subject:
          type:
            - object
            - 'null'
          description: >-
            Who the item is about. `null` for the sub-client itself; otherwise
            the associated person it names.
          properties:
            person_id:
              type: string
              description: >-
                The `person_id` of the entry in the subclient's
                `associated_persons`.
            display_name:
              type:
                - string
                - 'null'
              description: >-
                The person's name as currently stored — first, middle and last —
                or `null` when they can no longer be found.
          example:
            person_id: 3f1c2a9b7e0d4c6a8b5f1e2d3c4b5a69
            display_name: María López
          required:
            - person_id
            - display_name
        status:
          type: string
          enum:
            - pending
            - answered
          description: >-
            Whether this item is answered. An item has no ending of its own —
            whether the request is satisfied is the request's own `status`. See
            [RFI values](/reference/rfis/values#item-status).
        answer_value:
          type:
            - string
            - number
            - boolean
            - 'null'
          description: >-
            The answer recorded, in the shape `answer_type` expects. `null` on a
            `document` item, whose answer lives in `documents`.
        documents:
          type: array
          items:
            $ref: '#/components/schemas/RfiDocument'
          description: Always present; empty unless `answer_type` is `document`.
        review_note:
          type:
            - string
            - 'null'
          description: >-
            Why the item was sent back for another answer. Cleared the next time
            it is answered.
        updated_at:
          type:
            - string
            - 'null'
          format: date-time
          description: >-
            When this item was last answered. Moves on every round, whether or
            not it changes the item's status.
        returned_at:
          type:
            - string
            - 'null'
          format: date-time
          description: >-
            When the item was last sent back for another answer. `null` if it
            never has been, including while it is under review.
    RfiDocument:
      type: object
      properties:
        document_id:
          type: string
          format: uuid
        file_name:
          type: string
          description: >-
            The name the file was uploaded under, sanitized. This is the name it
            downloads as — the internal storage path is never exposed.
          example: january.pdf
        mime_type:
          type: string
          example: application/pdf
        size_bytes:
          type: integer
        checksum:
          type: string
          description: Content hash of the uploaded file.
        uploaded_at:
          type: string
          format: date-time
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        The `data.access_token` value from [Get access
        token](/api-reference/authentication/get-access-token).
    apiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: API key issued by Kira.

````