> ## Documentation Index
> Fetch the complete documentation index at: https://docs.apocor.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Update applicant profile

> Merges allowlisted profile fields into the applicant. Contact fields (phone, etc.) can usually be updated. Identity fields (name, DOB, nationality, address) are locked after issuer KYC is complete or cards exist. `ssn` may be set once when missing (required for US card issuance after hosted KYC). Never changes status or issuer references.



## OpenAPI

````yaml /openapi.json patch /v1/applicants/{id}
openapi: 3.1.0
info:
  title: Apocor Core API
  version: 1.0.0
  description: >-
    The Apocor Cards API is the integration surface for issuing and managing
    cards. Authenticate with your Apocor API key, onboard applicants, run KYC,
    and issue virtual or physical cards — all through one white-labeled API.
  contact:
    name: Apocor Support
    url: https://apocor.ai
servers:
  - url: https://sandbox.apocor.ai
    description: Sandbox (live)
  - url: https://api.apocor.ai
    description: Production
  - url: http://localhost:4000
    description: Local development
security:
  - bearerAuth: []
tags:
  - name: Authentication
    description: Exchange Apocor API keys for a short-lived access token.
  - name: Applicants
    description: End-users and businesses, plus their identity verification (KYC).
  - name: KYC
    description: >-
      Identity verification settings, hosted sessions, BYOK share tokens, direct
      document upload, and issuer readiness.
    x-group: Identity verification (KYC)
  - name: Accounts
    description: Funding accounts that back issued cards.
  - name: Programs
    description: Card programs that define product type, currency, and BIN.
  - name: Cardholders
    description: Approved applicants turned into cardholders.
  - name: Cards
    description: Issue and manage virtual and physical cards.
  - name: Transactions
    description: Card transaction history from the issuer or local ledger.
  - name: Widget SDK
    description: >-
      Public Apocor-branded proxy for Method 1 Widget.js (no auth). PAN/CVV
      still render in issuer PCI iframes.
  - name: Card funding
    description: >-
      Fund prepaid cards with stablecoins: Apocor wallet service or
      bring-your-own (BYO) external wallet.
    x-group: Card funding
paths:
  /v1/applicants/{id}:
    patch:
      tags:
        - Applicants
      summary: Update applicant profile
      description: >-
        Merges allowlisted profile fields into the applicant. Contact fields
        (phone, etc.) can usually be updated. Identity fields (name, DOB,
        nationality, address) are locked after issuer KYC is complete or cards
        exist. `ssn` may be set once when missing (required for US card issuance
        after hosted KYC). Never changes status or issuer references.
      operationId: patchApplicantsById
      parameters:
        - $ref: '#/components/parameters/IdPath'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                email:
                  type: string
                  format: email
                  nullable: true
                data:
                  type: object
                  additionalProperties: true
                  properties:
                    ssn:
                      type: string
                      description: >-
                        9-digit US SSN (digits or dashed). Once-write when
                        missing.
                      example: '123456789'
                    phone:
                      type: string
                    phoneCountryCode:
                      type: string
            example:
              data:
                ssn: '123456789'
      responses:
        '200':
          description: Updated applicant.
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    $ref: '#/components/schemas/Applicant'
        '400':
          $ref: '#/components/responses/BadRequest'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          description: Profile or SSN locked.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  parameters:
    IdPath:
      name: id
      in: path
      required: true
      schema:
        type: string
      description: Resource identifier.
  schemas:
    Applicant:
      type: object
      description: >-
        An end-user or business. Provider-internal identity references are
        white-labeled away.
      properties:
        id:
          type: string
        orgId:
          type: string
        type:
          type: string
          enum:
            - PERSON
            - BUSINESS
        status:
          type: string
          enum:
            - PENDING
            - APPROVED
            - REVIEW
            - REJECTED
          description: >-
            Single verification verdict. APPROVED means the applicant has fully
            passed identity verification and cards can be issued. PENDING covers
            every in-progress stage; REVIEW means the application needs
            attention; REJECTED is terminal.
        email:
          type:
            - string
            - 'null'
        data:
          type: object
          additionalProperties: true
        createdAt:
          type: string
          format: date-time
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              description: Stable, machine-readable error code.
            message:
              type: string
              description: Human-readable explanation.
  responses:
    BadRequest:
      description: The request was invalid.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: INVALID_REQUEST
              message: Applicant must be approved
    NotFound:
      description: Resource not found.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: NOT_FOUND
              message: Not found
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Bearer access token obtained from `POST /v1/oauth/token` using your
        Apocor API key.

````