Skip to navigation

Access & KYB

Authentication, token lifetimes and the KYB check on every request.
View as Markdown

Authentication

Every endpoint needs an Authorization: Bearer <accessToken> header, except Generate Access Token and Refresh Access Token.

TokenHow you get itLifetime
Access tokenGenerate Access Token or Refresh Access Token15 minutes
Refresh tokenGenerate Access TokenUntil you call Generate Access Token again, which replaces it

KYB requirement

Your business must have an approved KYB and an active account. Shimi checks this when a token is issued, when it’s refreshed, and on every request. Changes to your status take effect within 30 seconds.

Errors on every authenticated call

HTTPBodyMeaningWhat to do
401{"message":"Access token is missing"}No Authorization headerSend the Bearer token
403{"message":"Invalid or expired access token"}Token expired (after 15 minutes) or invalidCall Refresh Access Token
403{"code":"KYB_REQUIRED","kybStatus":"SUBMITTED",...}KYB not approvedComplete KYB in the dashboard and wait for approval
403{"code":"ACCOUNT_DEACTIVATED",...}Your account is switched offContact Shimi support
503Service temporarily unavailableThe KYB check itself failedRetry shortly

kybStatus can be NOT_STARTED, IN_PROGRESS, SUBMITTED, CHANGES_REQUESTED or REJECTED.