> ## Documentation Index
> Fetch the complete documentation index at: https://docs.spritz.finance/llms.txt
> Use this file to discover all available pages before exploring further.

# Submit regional compliance fields

> Submits the additional compliance fields required for the authenticated user's region.

All required fields must be supplied together — partial submissions are rejected with field-level errors rather than being stored.

If the user has accepted the provider's terms, submitting these fields creates or updates the provider customer immediately and `bridgeCustomerUpdated` is true. Otherwise, the fields are stored and included when the customer is created.



## OpenAPI

````yaml https://platform.spritz.finance/openapi.json post /v1/users/me/compliance
openapi: 3.0.3
info:
  title: Spritz Finance API
  version: 1.0.0
  description: API for the Spritz Finance platform with RFC 9457 error handling
servers:
  - url: https://platform.spritz.finance
    description: Production
  - url: https://sandbox.spritz.finance
    description: Sandbox
security: []
tags:
  - name: Users
    description: User management endpoints
  - name: Bank Accounts
    description: Manage bank accounts for off-ramp destinations
  - name: Bills
    description: Manage bill pay accounts
  - name: Cards
    description: Spritz-issued debit cards
  - name: Auto-Ramp Accounts
    description: Virtual bank accounts that automatically convert fiat deposits to crypto
  - name: Spritz App
    description: >-
      Endpoints used by the Spritz app and internal SDKs. Excluded from the
      public partner spec.
paths:
  /v1/users/me/compliance:
    post:
      tags:
        - Compliance
      summary: Submit regional compliance fields
      description: >-
        Submits the additional compliance fields required for the authenticated
        user's region.


        All required fields must be supplied together — partial submissions are
        rejected with field-level errors rather than being stored.


        If the user has accepted the provider's terms, submitting these fields
        creates or updates the provider customer immediately and
        `bridgeCustomerUpdated` is true. Otherwise, the fields are stored and
        included when the customer is created.
      operationId: postV1UsersMeCompliance
      requestBody:
        description: Regional compliance fields for the authenticated user.
        required: true
        content:
          application/json:
            schema:
              description: Regional compliance fields for the authenticated user.
              anyOf:
                - description: Compliance fields with a predefined account purpose.
                  type: object
                  properties:
                    placeOfBirth:
                      description: Where the user was born.
                      type: object
                      properties:
                        country:
                          minLength: 3
                          maxLength: 3
                          description: Country of birth as an ISO 3166-1 alpha-3 code.
                          type: string
                          example: DEU
                        city:
                          description: >-
                            City of birth. Recommended now, required by EU law
                            from 2027.
                          type: string
                          example: Berlin
                      required:
                        - country
                    nationalities:
                      minItems: 1
                      description: >-
                        Every nationality the user holds, not just their primary
                        one.
                      type: array
                      items:
                        minLength: 3
                        maxLength: 3
                        description: ISO 3166-1 alpha-3 country code.
                        type: string
                      example:
                        - DEU
                    accountPurpose:
                      description: What the user intends to use the account for.
                      anyOf:
                        - type: string
                          enum:
                            - charitable_donations
                        - type: string
                          enum:
                            - ecommerce_retail_payments
                        - type: string
                          enum:
                            - investment_purposes
                        - type: string
                          enum:
                            - operating_a_company
                        - type: string
                          enum:
                            - payments_to_friends_or_family_abroad
                        - type: string
                          enum:
                            - personal_or_living_expenses
                        - type: string
                          enum:
                            - protect_wealth
                        - type: string
                          enum:
                            - purchase_goods_and_services
                        - type: string
                          enum:
                            - receive_payment_for_freelancing
                        - type: string
                          enum:
                            - receive_salary
                  required:
                    - placeOfBirth
                    - nationalities
                    - accountPurpose
                - description: Compliance fields with a free-text account purpose.
                  type: object
                  properties:
                    placeOfBirth:
                      description: Where the user was born.
                      type: object
                      properties:
                        country:
                          minLength: 3
                          maxLength: 3
                          description: Country of birth as an ISO 3166-1 alpha-3 code.
                          type: string
                          example: DEU
                        city:
                          description: >-
                            City of birth. Recommended now, required by EU law
                            from 2027.
                          type: string
                          example: Berlin
                      required:
                        - country
                    nationalities:
                      minItems: 1
                      description: >-
                        Every nationality the user holds, not just their primary
                        one.
                      type: array
                      items:
                        minLength: 3
                        maxLength: 3
                        description: ISO 3166-1 alpha-3 country code.
                        type: string
                      example:
                        - DEU
                    accountPurpose:
                      type: string
                      enum:
                        - other
                    accountPurposeOther:
                      minLength: 1
                      description: >-
                        Free-text purpose. Required because accountPurpose is
                        "other".
                      type: string
                  required:
                    - placeOfBirth
                    - nationalities
                    - accountPurpose
                    - accountPurposeOther
          application/x-www-form-urlencoded:
            schema:
              description: Regional compliance fields for the authenticated user.
              anyOf:
                - description: Compliance fields with a predefined account purpose.
                  type: object
                  properties:
                    placeOfBirth:
                      description: Where the user was born.
                      type: object
                      properties:
                        country:
                          minLength: 3
                          maxLength: 3
                          description: Country of birth as an ISO 3166-1 alpha-3 code.
                          type: string
                          example: DEU
                        city:
                          description: >-
                            City of birth. Recommended now, required by EU law
                            from 2027.
                          type: string
                          example: Berlin
                      required:
                        - country
                    nationalities:
                      minItems: 1
                      description: >-
                        Every nationality the user holds, not just their primary
                        one.
                      type: array
                      items:
                        minLength: 3
                        maxLength: 3
                        description: ISO 3166-1 alpha-3 country code.
                        type: string
                      example:
                        - DEU
                    accountPurpose:
                      description: What the user intends to use the account for.
                      anyOf:
                        - type: string
                          enum:
                            - charitable_donations
                        - type: string
                          enum:
                            - ecommerce_retail_payments
                        - type: string
                          enum:
                            - investment_purposes
                        - type: string
                          enum:
                            - operating_a_company
                        - type: string
                          enum:
                            - payments_to_friends_or_family_abroad
                        - type: string
                          enum:
                            - personal_or_living_expenses
                        - type: string
                          enum:
                            - protect_wealth
                        - type: string
                          enum:
                            - purchase_goods_and_services
                        - type: string
                          enum:
                            - receive_payment_for_freelancing
                        - type: string
                          enum:
                            - receive_salary
                  required:
                    - placeOfBirth
                    - nationalities
                    - accountPurpose
                - description: Compliance fields with a free-text account purpose.
                  type: object
                  properties:
                    placeOfBirth:
                      description: Where the user was born.
                      type: object
                      properties:
                        country:
                          minLength: 3
                          maxLength: 3
                          description: Country of birth as an ISO 3166-1 alpha-3 code.
                          type: string
                          example: DEU
                        city:
                          description: >-
                            City of birth. Recommended now, required by EU law
                            from 2027.
                          type: string
                          example: Berlin
                      required:
                        - country
                    nationalities:
                      minItems: 1
                      description: >-
                        Every nationality the user holds, not just their primary
                        one.
                      type: array
                      items:
                        minLength: 3
                        maxLength: 3
                        description: ISO 3166-1 alpha-3 country code.
                        type: string
                      example:
                        - DEU
                    accountPurpose:
                      type: string
                      enum:
                        - other
                    accountPurposeOther:
                      minLength: 1
                      description: >-
                        Free-text purpose. Required because accountPurpose is
                        "other".
                      type: string
                  required:
                    - placeOfBirth
                    - nationalities
                    - accountPurpose
                    - accountPurposeOther
          multipart/form-data:
            schema:
              description: Regional compliance fields for the authenticated user.
              anyOf:
                - description: Compliance fields with a predefined account purpose.
                  type: object
                  properties:
                    placeOfBirth:
                      description: Where the user was born.
                      type: object
                      properties:
                        country:
                          minLength: 3
                          maxLength: 3
                          description: Country of birth as an ISO 3166-1 alpha-3 code.
                          type: string
                          example: DEU
                        city:
                          description: >-
                            City of birth. Recommended now, required by EU law
                            from 2027.
                          type: string
                          example: Berlin
                      required:
                        - country
                    nationalities:
                      minItems: 1
                      description: >-
                        Every nationality the user holds, not just their primary
                        one.
                      type: array
                      items:
                        minLength: 3
                        maxLength: 3
                        description: ISO 3166-1 alpha-3 country code.
                        type: string
                      example:
                        - DEU
                    accountPurpose:
                      description: What the user intends to use the account for.
                      anyOf:
                        - type: string
                          enum:
                            - charitable_donations
                        - type: string
                          enum:
                            - ecommerce_retail_payments
                        - type: string
                          enum:
                            - investment_purposes
                        - type: string
                          enum:
                            - operating_a_company
                        - type: string
                          enum:
                            - payments_to_friends_or_family_abroad
                        - type: string
                          enum:
                            - personal_or_living_expenses
                        - type: string
                          enum:
                            - protect_wealth
                        - type: string
                          enum:
                            - purchase_goods_and_services
                        - type: string
                          enum:
                            - receive_payment_for_freelancing
                        - type: string
                          enum:
                            - receive_salary
                  required:
                    - placeOfBirth
                    - nationalities
                    - accountPurpose
                - description: Compliance fields with a free-text account purpose.
                  type: object
                  properties:
                    placeOfBirth:
                      description: Where the user was born.
                      type: object
                      properties:
                        country:
                          minLength: 3
                          maxLength: 3
                          description: Country of birth as an ISO 3166-1 alpha-3 code.
                          type: string
                          example: DEU
                        city:
                          description: >-
                            City of birth. Recommended now, required by EU law
                            from 2027.
                          type: string
                          example: Berlin
                      required:
                        - country
                    nationalities:
                      minItems: 1
                      description: >-
                        Every nationality the user holds, not just their primary
                        one.
                      type: array
                      items:
                        minLength: 3
                        maxLength: 3
                        description: ISO 3166-1 alpha-3 country code.
                        type: string
                      example:
                        - DEU
                    accountPurpose:
                      type: string
                      enum:
                        - other
                    accountPurposeOther:
                      minLength: 1
                      description: >-
                        Free-text purpose. Required because accountPurpose is
                        "other".
                      type: string
                  required:
                    - placeOfBirth
                    - nationalities
                    - accountPurpose
                    - accountPurposeOther
      responses:
        '200':
          description: Result of a compliance field submission.
          content:
            application/json:
              schema:
                description: Result of a compliance field submission.
                type: object
                properties:
                  complianceFieldsComplete:
                    description: Whether the user has now supplied every required field.
                    type: boolean
                  bridgeCustomerUpdated:
                    description: >-
                      Whether the fields were forwarded to the provider. False
                      when the customer does not exist yet — they are included
                      at creation instead.
                    type: boolean
                required:
                  - complianceFieldsComplete
                  - bridgeCustomerUpdated
        '401':
          description: Response for status 401
          content:
            application/json:
              schema:
                type: object
                properties:
                  type:
                    default: about:blank
                    description: A URI reference that identifies the problem type
                    type: string
                    example: urn:problem-type:auth:unauthorized
                  title:
                    description: A short, human-readable summary of the problem type
                    type: string
                    example: Unauthorized
                  status:
                    description: The HTTP status code
                    type: number
                    example: 401
                  detail:
                    description: A human-readable explanation specific to this occurrence
                    type: string
                    example: Bearer token required
                  instance:
                    description: A URI reference that identifies the specific occurrence
                    type: string
                  realm:
                    description: The authentication realm
                    type: string
                    example: API
                  scope:
                    description: The required scope for this resource
                    type: string
                    example: read:users
                required:
                  - title
                  - status
                additionalProperties: false
        '404':
          description: Response for status 404
          content:
            application/json:
              schema:
                type: object
                properties:
                  type:
                    default: about:blank
                    description: A URI reference that identifies the problem type
                    type: string
                  title:
                    description: A short, human-readable summary of the problem type
                    type: string
                  status:
                    description: The HTTP status code
                    type: number
                    example: 404
                  detail:
                    description: A human-readable explanation specific to this occurrence
                    type: string
                  instance:
                    description: A URI reference that identifies the specific occurrence
                    type: string
                  resourceType:
                    description: The type of resource that was not found
                    type: string
                    example: user
                  resourceId:
                    description: The identifier of the resource that was not found
                    type: string
                required:
                  - title
                  - status
                  - resourceType
                  - resourceId
                additionalProperties: false
        '500':
          description: Response for status 500
          content:
            application/json:
              schema:
                type: object
                properties:
                  type:
                    default: about:blank
                    description: A URI reference that identifies the problem type
                    type: string
                    example: urn:problem-type:auth:unauthorized
                  title:
                    description: A short, human-readable summary of the problem type
                    type: string
                    example: Unauthorized
                  status:
                    description: The HTTP status code
                    type: number
                    example: 400
                  detail:
                    description: A human-readable explanation specific to this occurrence
                    type: string
                  instance:
                    description: A URI reference that identifies the specific occurrence
                    type: string
                    example: /errors/1234567890
                  code:
                    description: >-
                      Machine-readable cause, present when exactly one thing
                      failed. Branch on this, never on `detail`, which is
                      human-facing copy and may change. For deposit limits the
                      vocabulary matches the `reason` values the limits API
                      returns pre-flight.
                    type: string
                    example: transaction_limit
                  field:
                    description: The offending request field, present alongside `code`.
                    type: string
                    example: amountUsd
                  retryable:
                    description: >-
                      Whether retrying the same request later may succeed
                      without changing its inputs.
                    type: boolean
                    example: true
                required:
                  - title
                  - status
                additionalProperties: false
      security:
        - bearerAuth: []
        - integratorJwt: []
        - hmacAuth: []
          integratorKey: []
          timestamp: []
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: Cognito JWT token for regular user authentication
    integratorJwt:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Integrator JWT token (prefix: spr_) for frontend integrator
        authentication. Obtained via token exchange endpoint.
    hmacAuth:
      type: apiKey
      in: header
      name: X-Signature
      description: >-
        HMAC signature authentication for backend integrators.


        **Required Headers:**

        - X-Integrator-Key: Integrator API key (format: int_...)

        - X-Signature: HMAC signature (format: sha256={hex})

        - X-Timestamp: Unix timestamp in milliseconds

        - Authorization: Bearer {user-api-key}


        **Signature Algorithm:** HMAC-SHA256


        **Signature Format:** {timestamp}.{METHOD}.{path}.{bodyHash}

        - timestamp: Unix timestamp in milliseconds

        - METHOD: HTTP method in UPPERCASE (GET, POST, etc.)

        - path: Request path (e.g., /v1/transactions)

        - bodyHash: SHA256 hex digest of request body (empty string if no body)


        **Timestamp Tolerance:** ±5 minutes (300 seconds)


        **Example:**

        For POST /v1/transactions with body {"amount":100} and timestamp
        1234567890000:

        Payload: 1234567890000.POST./v1/transactions.{sha256(body)}

        Signature: sha256=abc123...
    integratorKey:
      type: apiKey
      in: header
      name: X-Integrator-Key
      description: 'Integrator API key (format: int_...) used with HMAC authentication'
    timestamp:
      type: apiKey
      in: header
      name: X-Timestamp
      description: >-
        Unix timestamp in milliseconds for replay attack prevention. Must be
        within 5 minutes of server time.

````