SumsubHelperBeta

Generate SDK access token (Sumsub)

Generates a short-lived secret Sumsub WebSDK/MobileSDK token for a subject, level, and optionally one precise action.

Vue d’ensemble

This helper creates temporary SDK access. It opens a Sumsub experience for a known subject; it produces no business decision and persists no compliance check.

Exemple

An embedded application must open Sumsub WebSDK for the current contact's basic-kyc-level: generate a short-lived token and pass it only to the relevant component.

Parameters 6

extension_config_idRequisref(extension_config:sumsub)
Sumsub configuration used to issue the SDK token.
subjectRequisobject
Ormuz subject to which the SDK session must be attached. Its identity becomes the Sumsub token userId.
level_nameRequisstring
Sumsub level the SDK must run for this session.
sumsub_applicantOptionnelSumsub applicant
Explicit Sumsub applicant to attach to the token. When absent, Ormuz attempts to find the applicant already mapped to the subject.
ttl_secondsOptionnelinteger
Requested SDK-token lifetime in seconds. Default: 600 seconds.
external_action_idOptionnelstring
Optional Applicant Action identifier when a step-up journey must restrict the token to one precise Sumsub action.

Outputs 2

access_tokenstring
Secret, temporary Sumsub SDK token intended only for the client component that must open the verification session.
expires_in_secondsinteger
Configured lifetime of the returned token, in seconds.

Behavior

Ormuz resolves the configuration and subject, reuses a mapped applicant when available, then requests a Sumsub SDK token linked to the userId, level, and optionally an external action.

Limits and responsibilities

Key point access_token is secret data. Do not log it, persist it in business metadata, or share it with anything other than the SDK component that needs it.
  • A valid token does not mean the user completed the journey or Sumsub approved them.
  • Prefer a short lifetime appropriate to the time needed to open the session.
  • The token replaces neither applicant nor review result: these are separate contracts.