POST
Simulate a document review
ENDPOINT/v1/simulate/wallet-entities/{wallet_entity_id}/documents/{document_id}/review
Completes review of an uploaded identity document in sandbox.
ACCEPTED sets Document status ACCEPTED. REJECTED sets
REJECTED and copies reasons onto rejection_reasons. Platform
events: wallet_entity.verification.updated when the wallet entity's
check depends on this file. Documents that are still PENDING
(bytes not uploaded) or already terminal reject this transition.
Served only on the sandbox host.
Authentication & Headers
| Header | Type | Requirement | Description |
|---|---|---|---|
| Authorization | string | REQUIRED | API key passed as an HTTP Bearer token: Bearer rk_live_... |
| X-Program-ID | UUID | PROGRAM-SCOPED | Program boundary UUID that scopes the issuing card, wallet, or transfer. |
| Content-Type | string | REQUIRED | Must be application/json. |
| Idempotency-Key | string | OPTIONAL | Unique UUID to prevent duplicate execution of financial creations or mutations. |
Path Parameters
| Parameter | Type | Requirement | Description |
|---|---|---|---|
| wallet_entity_id | string | REQUIRED | Unique identifier of the wallet entity. |
| document_id | string | REQUIRED | Unique identifier of the document. |
Request Body Schema
application/jsonstatusstring
REQUIREDOutcome to apply to an uploaded identity document. `ACCEPTED` counts toward verification. `REJECTED` does not; send `reasons`.
Enum values:
ACCEPTEDREJECTEDreasonsarray
REQUIREDCopied onto `rejection_reasons` when `status` is `REJECTED`. Empty when `status` is `ACCEPTED`.
Response Codes & Schemas
200The Document after the review decision.
application/json{
"id": "5e8a3c21-7b94-4d06-a1f2-9c4e6b8d0a37",
"object": "document",
"document_type": "DRIVERS_LICENSE",
"status": "ACCEPTED",
"rejection_reasons": [],
"file_name": "drivers-license.jpg",
"content_type": "image/jpeg",
"wallet_entity_id": "2e9c4b71-8a5d-4f03-b6e2-1c7d9a0f3e58",
"application_id": null,
"upload_url": null,
"upload_url_expires_at": null,
"created_at": "2026-08-12T10:18:00Z",
"updated_at": "2026-08-12T10:21:00Z"
}400Bad Request: malformed JSON, failed schema validation, or conflicting parameters.
application/json{
"error": {
"type": "invalid_request_error",
"code": "invalid_request",
"message": "invalid order by: foo. Valid options are: [created_at updated_at]",
"param": "order_by",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/invalid_request"
}
}401Unauthorized: missing, malformed, or unknown API key.
application/json{
"error": {
"type": "authentication_error",
"code": "authentication_error",
"message": "A valid API key is required.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/authentication_error"
}
}403Forbidden: the API key is denied by RBAC, or it cannot access this
program. A resource that exists on another program or organization
returns `404 not_found`, not `403`.
application/json{
"error": {
"type": "permission_error",
"code": "permission_denied",
"message": "The API key cannot access this program.",
"param": "X-Program-ID",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/permission_denied"
}
}404Not Found: unknown id, or the resource is not visible to this API key.
application/json{
"error": {
"type": "not_found_error",
"code": "not_found",
"message": "No card found for the given id.",
"param": "card_id",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/not_found"
}
}409Conflict: incompatible state, or Idempotency-Key reused with a different body.
application/json{
"error": {
"type": "conflict_error",
"code": "conflict",
"message": "The card cannot be reissued from its current state.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/conflict"
}
}422Unprocessable Entity: the document is valid JSON but violates a business rule.
application/json{
"error": {
"type": "invalid_request_error",
"code": "insufficient_funds",
"message": "The source financial account does not have enough available balance.",
"param": "amount",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/insufficient_funds"
}
}429Too Many Requests: the API key exceeded its rate limit.
application/json{
"error": {
"type": "rate_limit_error",
"code": "rate_limited",
"message": "Rate limit exceeded. Retry after the number of seconds in Retry-After.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/rate_limited"
}
}500Internal Server Error: unexpected failure. Retry with the same Idempotency-Key.
application/json{
"error": {
"type": "api_error",
"code": "internal_error",
"message": "An unexpected error occurred. Retry with the same Idempotency-Key.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/internal_error"
}
}