Skip to main content

Product overview

Partners who are doing some form of KYC collection/verification using Sumsub will be able to pass KYC information to MoonPay via a share token so that we can expedite your users’ verification. Doing so will dramatically reduce friction with your users by only having to KYC once. This is in addition to MoonPay’s 20M verified users, millions of which we’ve KYCed with an ID & selfie.

Product benefits

  • Higher conversion – users skip a second ID & selfie step inside MoonPay, dramatically reducing drop‑offs.
  • Expanded reach – MoonPay’s >20 M verified‑user database increases the chance we already know your customers.
  • Simple and secure integration – a single endpoint, no sensitive PII passed directly to MoonPay.

Prerequisites

  1. Verify required KYC information
    Make sure your app collects the information required for MoonPay’s KYC process.
  2. Integrate Sumsub’s Reusable KYC
    Build Sumsub’s reusable KYC feature using their SDK or API.
  3. Connect to Sumsub’s Share-Token API
    See Sumsub’s Share-Token API documentation. This will generate the share token you use to provide to MoonPay. Sumsub allows partners and their data to be transferred between services.
    forClientId must be exactly Moonpay — capital M, lowercase p, no space. Any other casing or spelling produces a token MoonPay cannot redeem. This is the most common integration failure on this flow.
    ttlInSecs is the lifetime of the share token, 600 seconds in the example above. The token is single use, so generate one per import call rather than caching it and reusing it across customers or retries.

Sandbox and production

Sandbox and production are two separate switches, and they have to match: A sandbox share token cannot be imported with a live key, and the reverse also fails.

Integration guide

  1. Enable KYC Sharing
    Reach out to your MoonPay representative and we will enable your account for KYC sharing in our backend.
  2. Share your customers data with MoonPay
    Call our POST /v3/customers/import endpoint with the externalCustomerId and the SumSub share token (see payload below). The externalCustomerId is a unique identifier for the customer in your platform. A successful import returns HTTP 200 with an empty body.
    This call authenticates with your secret key (sk_test_ or sk_live_), so it must be made from your server. Never ship a secret key in client-side code or expose it in a browser or mobile app.
  3. Calling the MoonPay widget
    When loading the MoonPay widget, make sure the same externalCustomerId is passed as a parameter. MoonPay will require the exact identifier to retrieve the user data and verify their KYC.

Sharing KYC data in the other direction

Shared KYC imports identity data into MoonPay from your Sumsub account. If you instead need MoonPay-verified KYC data to leave MoonPay and land in another system, that is the opposite direction — see Export customer data.