Validate Corporate KYC OTP
Confirms the OTP and finalises BVN verification. Returns a kyc_id — pass this into Create Corporate Sub-account.
Body
Behaviour
- On success a final corporate KYC record is created and the session is marked
VERIFIED. The returneddata.kyc_idis a new id (different fromsession_id) - store it and pass it to Create Corporate Sub-account. - A wrong, expired or missing OTP all return the same
400 BVN OTP validation failed; the session stays open, so you can call Resend Corporate KYC OTP (subject to the attempt limit) and try again. Validate calls themselves are not counted against the attempt limit. - Calling again after success does not return the existing kyc_id: the session is no longer awaiting an OTP and the request fails.
- Unknown/foreign session (
Session not found, 404) and already-verified session (Session not awaiting OTP, 400) are raised outside any error handler in the current build, so they are not returned as the standard JSON envelope - expect a framework default error response (or a timeout) rather than{status,message}.
Authentication
AuthorizationBearer
Access token from Generate Access Token (valid 15 minutes).
Request
This endpoint expects an object.
session_id
otp
Response
OK
status
message
data
Errors
400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error
