Access & KYB
Authentication, token lifetimes and the KYB check on every request.
Authentication
Every endpoint needs an Authorization: Bearer <accessToken> header, except Generate Access Token and Refresh Access Token.
KYB requirement
Your business must have an approved KYB and an active account. Shimi checks this when a token is issued, when it’s refreshed, and on every request. Changes to your status take effect within 30 seconds.
Errors on every authenticated call
kybStatus can be NOT_STARTED, IN_PROGRESS, SUBMITTED, CHANGES_REQUESTED or REJECTED.
