> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.shimi.cash/access-and-kyb/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.shimi.cash/_mcp/server. # Access & KYB ## Authentication Every endpoint needs an `Authorization: Bearer ` header, except **Generate Access Token** and **Refresh Access Token**. | Token | How you get it | Lifetime | | ------------- | --------------------------------------------- | ------------------------------------------------------------- | | Access token | Generate Access Token or Refresh Access Token | 15 minutes | | Refresh token | Generate Access Token | Until you call Generate Access Token again, which replaces it | ## KYB requirement Your business must have an **approved KYB and an active account**. Shimi checks this when a token is issued, when it's refreshed, and on every request. Changes to your status take effect within 30 seconds. ## Errors on every authenticated call | HTTP | Body | Meaning | What to do | | ---- | ----------------------------------------------------- | ------------------------------------------- | --------------------------------------------------- | | 401 | `{"message":"Access token is missing"}` | No `Authorization` header | Send the Bearer token | | 403 | `{"message":"Invalid or expired access token"}` | Token expired (after 15 minutes) or invalid | Call Refresh Access Token | | 403 | `{"code":"KYB_REQUIRED","kybStatus":"SUBMITTED",...}` | KYB not approved | Complete KYB in the dashboard and wait for approval | | 403 | `{"code":"ACCOUNT_DEACTIVATED",...}` | Your account is switched off | Contact Shimi support | | 503 | `Service temporarily unavailable` | The KYB check itself failed | Retry shortly | `kybStatus` can be `NOT_STARTED`, `IN_PROGRESS`, `SUBMITTED`, `CHANGES_REQUESTED` or `REJECTED`. > Authentication, token lifetimes and the KYB check on every request.