POST
Add a beneficial owner
ENDPOINT/v1/wallet-entities/{wallet_entity_id}/beneficial-owners
Adds a natural person who owns 25 percent or more of a business wallet entity. Returns 409 when the wallet entity is not BUSINESS. Send
Idempotency-Key so retries return the original owner.
Authentication & Headers
| Header | Type | Requirement | Description |
|---|---|---|---|
| Authorization | string | REQUIRED | API key passed as an HTTP Bearer token: Bearer rk_live_... |
| X-Program-ID | UUID | PROGRAM-SCOPED | Program boundary UUID that scopes the issuing card, wallet, or transfer. |
| Content-Type | string | REQUIRED | Must be application/json. |
| Idempotency-Key | string | OPTIONAL | Unique UUID to prevent duplicate execution of financial creations or mutations. |
Path Parameters
| Parameter | Type | Requirement | Description |
|---|---|---|---|
| wallet_entity_id | string | REQUIRED | Unique identifier of the wallet entity. |
Request Body Schema
application/jsonfirst_namestring
REQUIREDGiven name.
last_namestring
REQUIREDFamily name.
date_of_birthstringdate
REQUIREDDate of birth, `YYYY-MM-DD`.
ssn_last4string
optionalLast four digits of the US Social Security Number.
government_idobject
optionalGovernment-issued identification. Send `number` on create and update. Reads return `last4` and never the full number.
Properties of government_id
typestringrequired
Kind of identification document.
countrystringrequired
ISO 3166-1 alpha-2 country that issued the document.
numberstring
Full identification number. Write-only; never returned on reads.
last4string
Last four characters of the identification number.
emailstringemail
REQUIREDEmail address.
phonestring
REQUIREDPhone number in E.164.
addressobject
REQUIREDPostal address. `country` is an ISO 3166-1 alpha-2 code. For US addresses, `state` is the two-letter subdivision and `postal_code` is the ZIP or ZIP+4.
Properties of address
line_1stringrequired
Street number and name.
line_2stringnull
Apartment, suite, or unit. Null when unused.
citystringrequired
City or locality.
statestringrequired
State, province, or subdivision.
postal_codestringrequired
Postal code.
countrystringrequired
ISO 3166-1 alpha-2 country code.
ownership_percentinteger
REQUIREDWhole-number percent of the business owned. Minimum 25. `40` is 40%.
titlestring
REQUIREDRole at the business.
Response Codes & Schemas
201The beneficial owner was added.
application/json{
"id": "3c7d2e91-6a4b-4f18-b0c5-8d1e9f2a3756",
"object": "beneficial_owner",
"first_name": "Priya",
"last_name": "Shah",
"date_of_birth": "1978-11-21",
"ssn_last4": "4411",
"email": "priya.shah@northstar.example",
"phone": "+15125550177",
"address": {
"line_1": "88 Rainey St",
"line_2": null,
"city": "Austin",
"state": "TX",
"postal_code": "78701",
"country": "US"
},
"ownership_percent": 40,
"title": "Member",
"wallet_entity_id": "1a4f8c23-9e6d-4b70-a2c8-5d7e1f0b3942",
"created_at": "2026-08-20T16:42:00Z",
"updated_at": "2026-08-20T16:42:00Z"
}400Bad Request: malformed JSON, failed schema validation, or conflicting parameters.
application/json{
"error": {
"type": "invalid_request_error",
"code": "invalid_request",
"message": "invalid order by: foo. Valid options are: [created_at updated_at]",
"param": "order_by",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/invalid_request"
}
}401Unauthorized: missing, malformed, or unknown API key.
application/json{
"error": {
"type": "authentication_error",
"code": "authentication_error",
"message": "A valid API key is required.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/authentication_error"
}
}403Forbidden: the API key is denied by RBAC, or it cannot access this
program. A resource that exists on another program or organization
returns `404 not_found`, not `403`.
application/json{
"error": {
"type": "permission_error",
"code": "permission_denied",
"message": "The API key cannot access this program.",
"param": "X-Program-ID",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/permission_denied"
}
}404Not Found: unknown id, or the resource is not visible to this API key.
application/json{
"error": {
"type": "not_found_error",
"code": "not_found",
"message": "No card found for the given id.",
"param": "card_id",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/not_found"
}
}409Conflict: incompatible state, or Idempotency-Key reused with a different body.
application/json{
"error": {
"type": "conflict_error",
"code": "conflict",
"message": "The card cannot be reissued from its current state.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/conflict"
}
}422Unprocessable Entity: the document is valid JSON but violates a business rule.
application/json{
"error": {
"type": "invalid_request_error",
"code": "insufficient_funds",
"message": "The source financial account does not have enough available balance.",
"param": "amount",
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/insufficient_funds"
}
}429Too Many Requests: the API key exceeded its rate limit.
application/json{
"error": {
"type": "rate_limit_error",
"code": "rate_limited",
"message": "Rate limit exceeded. Retry after the number of seconds in Retry-After.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/rate_limited"
}
}500Internal Server Error: unexpected failure. Retry with the same Idempotency-Key.
application/json{
"error": {
"type": "api_error",
"code": "internal_error",
"message": "An unexpected error occurred. Retry with the same Idempotency-Key.",
"param": null,
"request_id": "550e8400-e29b-41d4-a716-446655440000",
"doc_url": "https://docs.rookpayments.com/errors/internal_error"
}
}