> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kirafin.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Mint a beneficiary's verification link

> Mint a link for a `ubo_link` item whose `answer_spec` carries `applicant_id` rather than a ready-made `url` — see [RFI values](/reference/rfis/values#the-two-ubo_link-shapes).

Each link is short-lived, so mint one when the person clicks rather than when the page renders.



## OpenAPI

````yaml /openapi/kira-api.2026-06-01.json post /v1/rfis/{rfi_id}/items/{item_id}/ubo-link
openapi: 3.1.0
info:
  title: Kira API
  version: '2026-06-01'
  description: >-
    REST API for users, KYC/KYB verification, virtual accounts, payouts,
    recipients, and webhooks. Every request requires an `x-api-key` header and a
    bearer access token (see Authentication). Pin your account to version
    `2026-04-14` before integrating.
  contact:
    name: Kira API Support
    email: support@kirafin.ai
servers:
  - url: https://api.balampay.com
    description: Production
  - url: https://api.balampay.com/sandbox
    description: Sandbox
security:
  - bearerAuth: []
    apiKeyAuth: []
tags:
  - name: Authentication
  - name: Versioning
  - name: Users
  - name: Virtual Accounts
  - name: Recipients
  - name: Quotations
  - name: Payouts
  - name: Reference
  - name: RFIs
paths:
  /v1/rfis/{rfi_id}/items/{item_id}/ubo-link:
    post:
      tags:
        - RFIs
      summary: Mint a beneficiary's verification link
      description: >-
        Mint a link for a `ubo_link` item whose `answer_spec` carries
        `applicant_id` rather than a ready-made `url` — see [RFI
        values](/reference/rfis/values#the-two-ubo_link-shapes).


        Each link is short-lived, so mint one when the person clicks rather than
        when the page renders.
      operationId: post_v1-rfis-rfi-id-items-item-id-ubo-link
      parameters:
        - in: path
          name: rfi_id
          required: true
          schema:
            type: string
            format: uuid
          description: RFI UUID.
        - in: path
          name: item_id
          required: true
          schema:
            type: string
            format: uuid
          description: >-
            Item UUID. Must be a `ubo_link` item of this RFI whose `answer_spec`
            carries `applicant_id`, not a pasted `url`.
        - in: header
          name: X-Api-Version
          required: false
          schema:
            type: string
            example: '2026-06-01'
          description: >-
            Optional. The date-versioned API version to apply for this request
            (e.g. `2026-04-14`). When sent it always wins, even over your pinned
            account default. When omitted, the API uses your account's pinned
            version if set, otherwise a baseline default.
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RfiUboLinkResponse'
              example:
                url: https://verify.balampay.com/ubo/8f3a…
                expires_at: '2026-09-11T12:00:00.000Z'
          description: The link was minted.
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                code: invalid_request
                message: >-
                  The request could not be authenticated. Check the x-api-key
                  and Authorization headers.
        '404':
          description: >-
            The RFI belongs to another client or is `withdrawn`, or the item
            does not belong to this RFI.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                code: not_found
                message: RFI not found
        '409':
          description: >-
            The RFI is already closed (`resolved` or `not_resolved`) and no
            longer needs this beneficiary.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                code: conflict
                message: This RFI is closed and no longer accepts answers
        '422':
          description: >-
            This item's `answer_spec` already carries a ready-made `url`, so
            there is nothing to mint. Render that link instead.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                code: unprocessable
                message: The answer does not satisfy the item's answer_spec
      security:
        - bearerAuth: []
          apiKeyAuth: []
      servers:
        - url: https://api.balampay.com/sandbox
          description: Sandbox
        - url: https://api.balampay.com
          description: Production
components:
  schemas:
    RfiUboLinkResponse:
      type: object
      properties:
        url:
          type: string
          format: uri
          description: >-
            An `https` link to the identity-verification page for the subclient
            to open. Render it as a link, not a form field; there is nothing to
            submit back through this API.
        expires_at:
          type: string
          format: date-time
          description: >-
            When this specific link stops working — about an hour out, though
            read the field rather than hard-coding that. Past it, mint a new one
            instead of reusing this one.
    ErrorResponse:
      type: object
      properties:
        message:
          type: string
        code:
          type: string
        statusCode:
          type: number
        error:
          type: string
        timestamp:
          type: string
        path:
          type: string
        details: {}
      required:
        - message
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        The `data.access_token` value from [Get access
        token](/api-reference/authentication/get-access-token).
    apiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: API key issued by Kira.

````