---
name: cas-ekyc
description: "Integrate Cas EKYC (scopes: ekyc): integration steps, the APIs to call and the pre-production checklist."
---

# Cas — EKYC

> Source: https://cas.so/en/product/ekyc · Markdown: https://cas.so/en/product/ekyc.md

_This skill is generated from the Cas documentation. When you need details (schemas, error codes, examples), fetch the latest Markdown from the links below instead of guessing._

## When to use this skill

When integrating, extending or debugging Cas **EKYC** in your system.

## Product summary

Query verified personal and business identity information via Cas ID

With the [Cas ID](https://cas.so/cas-id) app, Cas can verify both the customer's identity and any businesses owned by them.
From there, Cas provides this API to allow customers to grant your application access to their verified information.

## Scopes

`ekyc`

## Integration flow

Below are the steps to integrate eKYC into your product.

1. Create a grant [/grant/token](https://cas.so/en/general/api/grant/create.md) with the `scopes` value set to `ekyc`.

2. Open the Cas Link interface using the `grantToken` returned from the step above. [See details](https://cas.so/en/general/link.md)

3. Your customer opens the [Cas ID](https://cas.so/cas-id) app and scans the QR code on Cas Link.

4. After the user completes the authorization to allow your application access to their information,  
   your interface will receive a `publicToken`, which is used to obtain an `accessToken` for the grant.  
   This `accessToken` is only valid for 5 minutes. If your application needs to access the information again after that, you must repeat from step 1.

5. You can now call the [Identity Query API](https://cas.so/en/general/api/ekyc.md).

## APIs used in this flow

- [Create grant token](https://cas.so/en/general/api/grant/create.md)
- [EKYC](https://cas.so/en/general/api/ekyc.md)
- [Exchange public token for an access token](https://cas.so/en/general/api/grant/exchange.md)

## Read before writing code

- [Cas core](https://cas.so/en/skills/cas-core/SKILL.md)
- [Cas Link](https://cas.so/en/general/link.md)
- [Webhook](https://cas.so/en/general/api/webhook.md)
- [Errors](https://cas.so/en/errors.md)

## Rules you must follow when writing code

- `clientId` / `secretKey` live on the server in environment variables only — never ship them to a client, never commit them.
- Request only the `scopes` the product needs; extra scopes mean extra cost and risk.
- Avoid duplicate grants: check your database for a live grant before opening Cas Link again.
- Store `accessToken` and `grantId` encrypted and linked to your user; one user may hold several grants. Never surface these values in the UI.
- Log `requestId` (on every response) and `grantId` (on grant-related responses) for every call — this is what Cas support needs to trace an issue.
- Every API call needs a timeout and backoff retry for transient failures; never blindly retry money-moving calls (use your own idempotency key).
- Webhooks: accept them only from Cas IPs, return 2xx fast and process asynchronously, and make handling idempotent — deliveries can repeat or arrive out of order.
- Handle `GRANT_LOGIN_REQUIRED` by reopening Cas Link in Update mode instead of making the user relink from scratch.
- Handle `GRANT` webhooks: `USER_PERMISSION_REVOKED`, `GRANT_DELETED`, `GRANT_PAUSED`, `DEFAULT_UPDATE` — reflect the link state in your system.
- Call `/grant/remove` when a user unlinks in your app, and handle the OTP-verification branch.
- Run the whole flow on `https://sandbox.bankhub.dev` first; switch to `https://production.bankhub.dev` together with the production secrets.

## Before going to production

Verify against the **entire** production checklist: https://cas.so/en/launch-checklist.md

For every checklist item, point at the code (file path + line) that proves it is handled, or state why it does not apply. Never tick an item without evidence.

## Other Cas skills

Full catalogue (use it to add more Cas products later):

https://cas.so/en/skills/index.json
