> ## Documentation Index
> Fetch the complete documentation index at: https://docs.apocor.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Presign a direct KYC document upload

> Step 1 of direct document KYC (Option C). Returns a short-lived PUT URL. Upload the file bytes to `uploadUrl` with the same `Content-Type`, then call POST /v1/applicants/{id}/kyc-direct/uploads/complete. Accepted types: JPEG, PNG, WEBP, PDF. Max 8 MB. Categories: id_front, id_back, selfie.



## OpenAPI

````yaml /openapi.json post /v1/applicants/{id}/kyc-direct/uploads
openapi: 3.1.0
info:
  title: Apocor Core API
  version: 1.0.0
  description: >-
    The Apocor Cards API is the integration surface for issuing and managing
    cards. Authenticate with your Apocor API key, onboard applicants, run KYC,
    and issue virtual or physical cards — all through one white-labeled API.
  contact:
    name: Apocor Support
    url: https://apocor.ai
servers:
  - url: https://sandbox.apocor.ai
    description: Sandbox (live)
  - url: https://api.apocor.ai
    description: Production
  - url: http://localhost:4000
    description: Local development
security:
  - bearerAuth: []
tags:
  - name: Authentication
    description: Exchange Apocor API keys for a short-lived access token.
  - name: Applicants
    description: End-users and businesses, plus their identity verification (KYC).
  - name: KYC
    description: >-
      Identity verification settings, hosted sessions, BYOK share tokens, direct
      document upload, and issuer readiness.
    x-group: Identity verification (KYC)
  - name: Accounts
    description: Funding accounts that back issued cards.
  - name: Programs
    description: Card programs that define product type, currency, and BIN.
  - name: Cardholders
    description: Approved applicants turned into cardholders.
  - name: Cards
    description: Issue and manage virtual and physical cards.
  - name: Transactions
    description: Card transaction history from the issuer or local ledger.
  - name: Widget SDK
    description: >-
      Public Apocor-branded proxy for Method 1 Widget.js (no auth). PAN/CVV
      still render in issuer PCI iframes.
  - name: Card funding
    description: >-
      Fund prepaid cards with stablecoins: Apocor wallet service or
      bring-your-own (BYO) external wallet.
    x-group: Card funding
paths:
  /v1/applicants/{id}/kyc-direct/uploads:
    post:
      tags:
        - Applicants
        - KYC
      summary: Presign a direct KYC document upload
      description: >-
        Step 1 of direct document KYC (Option C). Returns a short-lived PUT URL.
        Upload the file bytes to `uploadUrl` with the same `Content-Type`, then
        call POST /v1/applicants/{id}/kyc-direct/uploads/complete. Accepted
        types: JPEG, PNG, WEBP, PDF. Max 8 MB. Categories: id_front, id_back,
        selfie.
      operationId: createApplicantsByIdKycDirectUploads
      parameters:
        - $ref: '#/components/parameters/IdPath'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - category
                - contentType
              properties:
                category:
                  type: string
                  enum:
                    - id_front
                    - id_back
                    - selfie
                contentType:
                  type: string
                  enum:
                    - image/jpeg
                    - image/png
                    - image/webp
                    - application/pdf
                size:
                  type: integer
                  description: File size in bytes (optional; must be 8 MB or smaller).
            example:
              category: id_front
              contentType: image/jpeg
              size: 245760
      responses:
        '200':
          description: Presigned upload target.
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
                    properties:
                      uploadUrl:
                        type: string
                        format: uri
                      key:
                        type: string
                        description: Object key to pass as s3Key on uploads/complete.
                      expiresIn:
                        type: integer
                        description: Seconds until the PUT URL expires (300).
                      category:
                        type: string
              example:
                data:
                  uploadUrl: https://s3.amazonaws.com/…
                  key: kyc-direct/org_abc/app_abc123/id_front/….jpg
                  expiresIn: 300
                  category: id_front
        '400':
          $ref: '#/components/responses/BadRequest'
components:
  parameters:
    IdPath:
      name: id
      in: path
      required: true
      schema:
        type: string
      description: Resource identifier.
  responses:
    BadRequest:
      description: The request was invalid.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: INVALID_REQUEST
              message: Applicant must be approved
  schemas:
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              description: Stable, machine-readable error code.
            message:
              type: string
              description: Human-readable explanation.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Bearer access token obtained from `POST /v1/oauth/token` using your
        Apocor API key.

````