> ## Documentation Index
> Fetch the complete documentation index at: https://docs.dakota.xyz/llms.txt
> Use this file to discover all available pages before exploring further.

# Get presigned URL for individual document upload

> Generates a presigned URL for uploading large individual documents directly to cloud storage.
Supports identity documents and EDD documents. Use this endpoint for files larger than 10MB.
After uploading to the presigned URL, call the verify endpoint to complete the upload process.

**Authentication:** Accepts Application Token (X-Application-Token header).

**Post-decision PoA upload**

Uploading a PoA-equivalent document (`proof_of_address`, `bank_statement`, or
`utility_bill`) on an already-decided individual application (status `approved` or
`completed`) automatically transitions the application to `compliance_review` and sets
`poa_status` to `submitted_pending_review`.




## OpenAPI

````yaml /openapi.yaml post /applications/{application_id}/associated-individuals/{individual_id}/document-uploads
openapi: 3.0.3
info:
  title: Dakota Platform API
  version: 1.0.0
  description: >-
    Combined API specification for Dakota Platform services:

    - Issuance API: Asset minting and burning operations

    - Onboarding API: Know Your Business/Customer verification

    - On/Off Ramp API: Managing on-ramp and off-ramp accounts

    - Recipients API: Managing destinations for KYB'd entities

    - Transactions API: Viewing transaction history across platform operations


    ## Authentication and API Headers


    All API endpoints require the following headers:


    - `x-idempotency-key`: Required for all POST endpoints to ensure request
    idempotency

    - `x-api-key`: Required for authentication across all endpoints


    Note: On /applications endpoints you need a token for authentication instead
    of a x-api-key

    - `x-application-token`: Required for authentication on public /applications
    endpoints (alternative to `x-api-key` where documented)



    ## Rate Limits


    Requests are rate limited per API key. Every response includes the following
    headers:


    | Header | Description |

    | --- | --- |

    | `X-RateLimit-Limit` | Maximum requests allowed in the current one-minute
    window. |

    | `X-RateLimit-Remaining` | Requests remaining in the current window. |

    | `X-RateLimit-Reset` | Absolute Unix timestamp (seconds since epoch) when
    the current rate-limit window resets. |


    When a request is throttled (`429`), responses also include `Retry-After`
    with seconds to wait before retrying.
servers:
  - url: https://api.platform.dakota.xyz
    description: Production environment
  - url: https://api.platform.sandbox.dakota.xyz
    description: Sandbox — safe for testing with simulated data
security:
  - ApiKeyAuth: []
tags:
  - name: Agentic Payments
    x-alpha: true
    description: >-
      Alpha — agent-driven payments: provision agents, draft and approve
      spending mandates, accept reviewed instructions, and manage scheduled
      payments.


      **Prerequisites:** Customer onboarded; signer groups attached for
      recognition.

      **Related:** Wallets, Signer Groups, Transactions
  - name: Mandates
    x-alpha: true
    description: >-
      Alpha — spending mandates: signed, signer-bound authorizations governing
      what may be spent, approved or cancelled by a second recognized signer (§8
      — the dual-control rule that every mandate mutation must be signed by a
      recognized signer OTHER than the bound one). Independent of agents and
      scheduled payments.


      **Prerequisites:** Signer groups attached for recognition.

      **Related:** Signer Groups, Transactions
  - name: Insights
    x-alpha: true
    description: >-
      Alpha — read-only account insight: a deterministic report over a
      customer's agentic activity (funding balances, upcoming obligations,
      failures, mandate headroom and expiry) plus an advisory chat that narrates
      it. Never moves money, never creates or changes anything.


      **Prerequisites:** Customer onboarded; insight is computed from the
      customer's scheduled payments, mandates, and wallets.

      **Related:** Agentic Payments, Mandates
  - name: Customers
    description: >-
      Manage customer entities representing businesses and organizations
      onboarded to Dakota.


      **Prerequisites:** Complete KYB via Onboarding endpoints before initiating
      money movement.

      **Related:** Onboarding, Recipients, Transactions, Accounts, Wallets
  - name: Wallets
    description: >-
      Manage wallets, balances, and wallet-to-signer-group relationships for
      custody and movement controls.


      **Prerequisites:** Customer must exist. Configure signer groups before
      policy-enforced workflows.

      **Related:** Signer Groups, Policies, Transactions, Customers
  - name: Transactions
    description: >-
      Create, cancel, and retrieve transaction records across account and wallet
      flows.


      **Prerequisites:** Accounts or destinations must be configured based on
      flow type.

      **Related:** Accounts, Recipients, Policies, Events
  - name: Recipients
    description: >-
      Manage recipient entities and destination rails used by customers for
      payouts and transfers.


      **Prerequisites:** Customer must be onboarded and active.

      **Related:** Customers, Transactions, Accounts, Onboarding
  - name: Accounts
    description: >-
      Manage account resources used for onramp, offramp, and swap operations.


      **Prerequisites:** Customer must be created and network/asset constraints
      must be known.

      **Related:** Customers, Transactions, Auto Transactions, Info
  - name: Auto Transactions
    description: >-
      Manage automated transaction configurations and execution history for
      account automation workflows.


      **Prerequisites:** Source account must exist and be configured for
      automation.

      **Related:** Accounts, Transactions, Events
  - name: Onboarding
    description: >-
      Manage KYB/KYC onboarding lifecycle, application documents, attestations,
      and verification steps.


      **Prerequisites:** Customer context and required entity/application
      metadata.

      **Related:** Customers, Exceptions, Recipients, Transactions
  - name: Policies
    description: >-
      Define and manage policy objects and rules used for transaction governance
      and risk controls.


      **Prerequisites:** Wallet and signer group resources should be configured
      for enforcement scenarios.

      **Related:** Wallets, Signer Groups, Transactions
  - name: Signer Groups
    description: >-
      Manage signer groups and signer assignments for multi-party authorization
      models.


      **Prerequisites:** Wallets should exist before linking signer groups.

      **Related:** Wallets, Policies, Transactions
  - name: Authentication
    description: >-
      Manage API authentication credentials and key lifecycle for platform
      access.


      **Prerequisites:** Client organization must be provisioned.

      **Related:** Users, Info
  - name: Users
    description: >-
      Manage client users, roles, and identity metadata for platform access
      control.


      **Prerequisites:** Auth credentials and client context must be
      established.

      **Related:** Authentication
  - name: Webhooks
    description: >-
      Manage outbound webhook targets and delivery configuration for event
      notifications.


      **Prerequisites:** Subscriber endpoint must be reachable and secured.

      **Related:** Events, Authentication
  - name: Payouts
    description: >-
      Manage where Dakota sends your accrued developer-fee payouts.


      **Prerequisites:** Auth credentials and client context must be
      established.

      **Related:** Events
  - name: Events
    description: >-
      Retrieve event records emitted by platform operations for audit and
      troubleshooting.


      **Prerequisites:** Requesting client must have access to referenced
      resources.

      **Related:** Webhooks, Transactions, Onboarding
  - name: Info
    description: >-
      Read platform capability metadata, such as supported rails, networks, and
      assets.


      **Prerequisites:** Valid authentication headers.

      **Related:** Accounts, Transactions
  - name: Sandbox
    description: >-
      Trigger sandbox-only simulation endpoints for safe end-to-end integration
      testing with synthetic data. The sandbox host
      (`https://api.platform.sandbox.dakota.xyz`) also accepts a family of
      `X-Sandbox-*` request headers on most write endpoints (`Customers`,
      `Accounts`, `Transactions`, simulate endpoints) that let integrators drive
      deterministic failure modes — pick a preset via `X-Sandbox-Scenario`, or
      compose a custom one with
      `X-Sandbox-Error-Step`/`X-Sandbox-Error-Status`/`X-Sandbox-Error-Message`.
      `X-Sandbox-Instant-Completion` collapses async flows to a single
      synchronous step, and `X-Sandbox-Skip-Auto-Approval` keeps newly created
      KYB applications in `pending` for manual-review testing. All `X-Sandbox-*`
      headers are ignored in production.


      **Prerequisites:** Sandbox environment and test customer data.

      **Related:** Customers, Accounts, Transactions, Onboarding
paths:
  /applications/{application_id}/associated-individuals/{individual_id}/document-uploads:
    post:
      tags:
        - Onboarding
      summary: Get presigned URL for individual document upload
      description: >
        Generates a presigned URL for uploading large individual documents
        directly to cloud storage.

        Supports identity documents and EDD documents. Use this endpoint for
        files larger than 10MB.

        After uploading to the presigned URL, call the verify endpoint to
        complete the upload process.


        **Authentication:** Accepts Application Token (X-Application-Token
        header).


        **Post-decision PoA upload**


        Uploading a PoA-equivalent document (`proof_of_address`,
        `bank_statement`, or

        `utility_bill`) on an already-decided individual application (status
        `approved` or

        `completed`) automatically transitions the application to
        `compliance_review` and sets

        `poa_status` to `submitted_pending_review`.
      operationId: createAssociatedIndividualDocumentUpload
      parameters:
        - name: application_id
          in: path
          required: true
          description: The unique identifier for the application
          schema:
            $ref: '#/components/schemas/KSUID'
        - name: individual_id
          in: path
          required: true
          description: The unique identifier for the individual
          schema:
            $ref: '#/components/schemas/KSUID'
        - $ref: '#/components/parameters/IdempotencyKeyHeader'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/IndividualDocumentUploadUrlRequest'
            example:
              document_type: passport
              id_number: AB1234567
              country: US
              file_type: pdf
              filename: passport_front.jpg
      responses:
        '200':
          description: Presigned URL generated successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DocumentUploadUrlResponse'
              example:
                upload_url: https://storage.googleapis.com/bucket/path?...
                upload_id: 2hCjxJzUAW6JVRkZqaF9E0KpM3a
                object_path: >-
                  applications/business/2hCjxJzUAW6JVRkZqaF9E0KpM3a/business-documents/2hDeFgHiJkLmNoPqRsTuVwXyZ
                expires_at: '2025-01-15T18:30:00Z'
        '400':
          description: Invalid request
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: https://docs.dakota.xyz/api-reference/errors#invalid-request
                title: Invalid request
                status: 400
                detail: Invalid request
                instance: >-
                  https://api.platform.dakota.xyz/applications/example-id/associated-individuals/example-id/document-uploads
                request_id: req_01hzy6y7v8w9x0y1z2a3b4c5d6
        '401':
          description: Unauthorized
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: >-
                  https://docs.dakota.xyz/api-reference/errors#authentication-error
                title: Unauthorized
                status: 401
                detail: Unauthorized
                instance: >-
                  https://api.platform.dakota.xyz/applications/example-id/associated-individuals/example-id/document-uploads
                request_id: req_01hzy6y7v8w9x0y1z2a3b4c5d6
        '403':
          description: Forbidden
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: https://docs.dakota.xyz/api-reference/errors#forbidden
                title: Forbidden
                status: 403
                detail: Forbidden
                instance: >-
                  https://api.platform.dakota.xyz/applications/example-id/associated-individuals/example-id/document-uploads
                request_id: req_01hzy6y7v8w9x0y1z2a3b4c5d6
        '404':
          description: Application or individual not found
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: https://docs.dakota.xyz/api-reference/errors#not-found
                title: Application or individual not found
                status: 404
                detail: Application or individual not found
                instance: >-
                  https://api.platform.dakota.xyz/applications/example-id/associated-individuals/example-id/document-uploads
                request_id: req_01hzy6y7v8w9x0y1z2a3b4c5d6
        default:
          description: Unexpected error
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: https://docs.dakota.xyz/api-reference/errors#internal-error
                title: Unexpected error
                status: 500
                detail: Unexpected error
                instance: >-
                  https://api.platform.dakota.xyz/applications/example-id/associated-individuals/example-id/document-uploads
                request_id: req_01hzy6y7v8w9x0y1z2a3b4c5d6
      security:
        - ApplicationTokenAuth: []
      externalDocs:
        description: Read full guide in docs
        url: >-
          https://docs.dakota.xyz/api-reference/onboarding/get-presigned-url-for-individual-document-upload
components:
  schemas:
    KSUID:
      type: string
      title: KSUID
      description: >-
        KSUID is a 27-character globally unique ID that combines a timestamp
        with a random component. Used for all entity identifiers in the Dakota
        platform.
      pattern: ^[0-9A-Za-z]{27}$
      minLength: 27
      maxLength: 27
      example: 1NFHrqBHb3cTfLVkFSGmHZqdDPi
    IndividualDocumentUploadUrlRequest:
      type: object
      description: >-
        Request to generate a presigned URL for uploading an individual document
        (identity or EDD). For identity documents (passport,
        drivers_license_front, drivers_license_back, residence_permit_front,
        residence_permit_back), id_number is required.
      required:
        - document_type
        - file_type
        - country
      properties:
        document_type:
          $ref: '#/components/schemas/IndividualDocumentType'
        id_number:
          type: string
          description: >-
            REQUIRED for identity documents (passport, driver's license,
            residence permit). The ID number on the document (e.g., passport
            number, driver's license number). Not required for EDD documents
            like bank statements.
          example: AB1234567
        country:
          type: string
          description: >-
            ISO 3166-1 alpha-2 country code of the issuing country. Required for
            identity documents, not required for EDD documents.
          minLength: 2
          maxLength: 2
          example: US
        file_type:
          $ref: '#/components/schemas/FileType'
        filename:
          type: string
          maxLength: 100
          description: >-
            Optional original filename. Will be sanitized for safe storage and
            display.
          example: passport_front.jpg
    DocumentUploadUrlResponse:
      type: object
      description: Response containing a presigned URL for document upload
      required:
        - upload_url
        - upload_id
        - object_path
        - expires_at
      properties:
        upload_url:
          type: string
          format: uri
          description: >-
            Presigned URL to upload the document to. Use PUT method with the
            file content.
          example: https://storage.googleapis.com/bucket/path?...
        upload_id:
          type: string
          description: >-
            Unique identifier for this upload. Use this when calling the verify
            endpoint.
          example: 2hCjxJzUAW6JVRkZqaF9E0KpM3a
        object_path:
          type: string
          description: >-
            The GCS object path where the document will be stored. Pass this to
            the verify endpoint.
          example: >-
            applications/business/2hCjxJzUAW6JVRkZqaF9E0KpM3a/business-documents/2hDeFgHiJkLmNoPqRsTuVwXyZ
        expires_at:
          type: string
          format: date-time
          description: ISO 8601 timestamp when the presigned URL expires
          example: '2025-01-15T18:30:00Z'
    ProblemDetails:
      type: object
      required:
        - type
        - title
        - status
      description: |
        Error response following RFC 9457 Problem Details.
        Public API error responses use this format.
      example:
        type: https://docs.dakota.xyz/api-reference/errors#not-found
        title: Customer Not Found
        status: 404
        detail: Customer cst_2abc123 was not found in your organization.
        instance: https://api.platform.dakota.xyz/customers/cst_2abc123
        request_id: req_7f3a8b2c
      properties:
        type:
          type: string
          format: uri
          description: |
            URI reference identifying the problem type.
            Resolves to human-readable documentation.
          example: https://docs.dakota.xyz/api-reference/errors#not-found
        title:
          type: string
          description: >-
            Short, human-readable summary of the problem type. Stable across
            occurrences.
          example: Customer Not Found
        status:
          type: integer
          description: HTTP status code for this occurrence.
          example: 404
        detail:
          type: string
          description: Human-readable explanation specific to this occurrence.
          example: Customer cst_2abc123 was not found in your organization.
        instance:
          type: string
          format: uri
          description: The request path that triggered this error.
          example: https://api.platform.dakota.xyz/customers/cst_2abc123
        request_id:
          type: string
          description: Unique request identifier. Include when contacting support.
          example: req_7f3a8b2c
        errors:
          type: array
          description: Field-level validation errors (present for validation failures).
          items:
            $ref: '#/components/schemas/ValidationError'
    IndividualDocumentType:
      type: string
      description: >-
        Type of document that can be uploaded for individuals (identity
        documents + EDD documents)
      enum:
        - passport
        - drivers_license_front
        - drivers_license_back
        - residence_permit_front
        - residence_permit_back
        - proof_of_address
        - bank_statement
        - utility_bill
        - source_of_wealth
        - payslip
        - employment_contract
        - income_verification_letter
        - savings_statement
        - crypto_statement
        - investment_statement
      example: passport
    FileType:
      type: string
      description: Supported file type
      enum:
        - pdf
        - jpeg
        - png
      example: pdf
    ValidationError:
      type: object
      required:
        - field
        - message
      properties:
        field:
          type: string
          description: Field path using dot notation for nested fields.
          example: bank_account.routing_number
        message:
          type: string
          description: Human-readable description of the field error.
          example: Routing number must be exactly 9 digits
        code:
          type: string
          description: Machine-readable error code for this field.
          example: invalid_format
  parameters:
    IdempotencyKeyHeader:
      name: x-idempotency-key
      in: header
      required: true
      description: >-
        Unique key to ensure request idempotency. If the same key is used within
        a certain time window, the original response will be returned instead of
        executing the request again.
      schema:
        type: string
        format: uuid
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
    ApplicationTokenAuth:
      type: apiKey
      in: header
      name: X-Application-Token
      description: >
        Application-specific token for public URL access. Generated when a
        customer is created.

        Provides access to a single application without requiring an API key.

        Token is valid for 30 days and rate-limited to 250 requests per hour.

````