Register or update a customer
PUT/subjects/:externalUserRef
Machine token. Called by your backend, using your client_credentials token.
Idempotent by your own user id, so replaying it after a timeout is safe. Registers who the person is and the contact channels we may verify for them. Registering a contact is not the same as proving it — see the OTP operations.
Request
Responses
- 200
- 400
- 401
- 403
- 404
- 409
- 422
- 500
Subject registered or updated. Idempotent by natural key — no Idempotency-Key header is required or accepted.
Malformed request — validation failure, or a header such as Idempotency-Key is missing or not a UUID.
Missing, expired, or untrusted bearer token.
Authenticated but not permitted — the caller's role or scope does not grant this operation, or the resource belongs to another tenant.
The referenced wallet, transaction, user, or tenant does not exist within the caller's tenant.
Idempotency conflict — a request with this Idempotency-Key is still in flight. Retry once it settles. A key belonging to an already-completed request is NOT an error: the original response is replayed with its original status.
The request is well-formed but violates a business rule — for example a posting that would breach a wallet fund's balance floor, a transaction type not enabled for the tenant, a per-transaction or daily issuance cap, or an operation on a frozen wallet.
Unexpected server error.