Skip to the operations

Identity verification

Sumsub in a decision flow.

4 Sumsub operations a decision flow can call directly, with the credentials your own contract issued. The response is data the rest of the flow reads, branches on, and keeps in the trace.

Category
Identity verification
Type
Integration
Authentication
HMAC-signed requests
Test environment
Production host only

Who they are

Global KYC, KYB and AML verification in one platform.

Sumsub runs the full verification cycle — identity documents, liveness, company checks, sanctions screening and ongoing monitoring — with rule sets configured per country. It is used by firms onboarding across several jurisdictions, where the required checks differ market by market.

What a flow can call

4 operations, each one a step you can place on the canvas.

  1. POST/resources/applicants

    Create an applicant profile

    Creates the applicant record used by the verification workflow.

  2. POST/resources/accessTokens/sdk

    Generate a WebSDK or MobileSDK token

    Issues a short-lived token for Sumsub's applicant-facing SDK.

  3. GET/resources/applicants/$data.sumsub_applicant_id/status

    Get an applicant review status

    Reads the current verification decision. A transport 200 only means the lookup worked; use reviewStatus and reviewResult.reviewAnswer in the response to decide whether the applicant passed.

  4. GET/resources/applicants/$data.sumsub_applicant_id/one

    Get an applicant profile

    Retrieves the full applicant profile and information obtained during verification.

Where it sits in the decision

Identity verification calls have a natural place in a flow.

An identity check gates everything downstream — a score computed against an unverified identity is a score about nobody. These calls sit near the top of a flow, with the branch for a partial or failed match written explicitly rather than left as an exception.

Whatever Sumsub returns is part of the run, so it is part of the record. When someone asks months later why an applicant was declined, the answer cites what came back at the time rather than re-fetching from a service whose answer has since changed.

  • 01Add Sumsub as a connection authenticating with HMAC-signed requests.
  • 02Sumsub has one host for both environments, so guard test runs with your own credentials and limits.
  • 03Place a Connection node and pick an operation — “Create an applicant profile” is usually the first one a flow needs.
  • 04Map the response into the fields your rules read, then test the whole path before it carries live traffic.

Common questions

Using Sumsub in a flow.

How do I connect Sumsub to a decision flow?

Add Sumsub as a connection in your workspace authenticating with HMAC-signed requests, with the credentials your own contract issued — ArboRule calls the provider as you, and never holds a contract on your behalf. Once the connection exists, any flow in the workspace can place a Connection node and choose one of its operations. The credentials live on the connection, not in the flow, so a policy owner can use Sumsub in a decision without ever seeing the secret.

Can I test Sumsub without touching production?

Sumsub exposes one host for both environments, so there is no separate sandbox to point at. Test runs still execute in Sandbox and are recorded separately in decision history, but the call goes to the same place as production — so guard it with your own test credentials, rate limits, or data.

What can a flow call on Sumsub?

4 operations, including “Create an applicant profile”, “Generate a WebSDK or MobileSDK token”, “Get an applicant review status”. Each one is a step you place on the canvas and map into the fields your rules read, and most flows start with “Create an applicant profile”. The list comes from the same manifest the engine uses to make the call, so this page cannot describe an operation the product does not have.

Where in a decision should Sumsub be called?

An identity check gates everything downstream — a score computed against an unverified identity is a score about nobody. These calls sit near the top of a flow, with the branch for a partial or failed match written explicitly rather than left as an exception.

Ready when you are

Wire Sumsub into a real decision.

Build the flow in Sandbox, connect your account, and watch the decision pull what it needs before it answers.

Read the docs