Skip to content

Customer checks

List customer checks

customerchecks:read
ParameterInTypeRequiredDescription
customerIdquerystringNoOnly checks for this customer
statusquerystringNoOPRETTET | UNDER_INDSAMLING | UNDER_VURDERING | GODKENDT | AFVIST | OPHOERT
riskquerystringNoLAV | MELLEM | HOEJ — the decided class, or the calculated one until a person has decided
limitqueryintegerNoPage size, 1-200 (default 50)
cursorquerystringNoOpaque cursor from meta.nextCursor
Request exampleNo request body
curl https://api.rieckflow.com/v1/customer-checks \
-H "Authorization: Bearer $RIECK_API_KEY"
200 Newest first. riskCalculated is the system’s indication and riskDecided the PERSON’s decision — two fields on purpose, because AMLR art. 76(5)(b) requires meaningful human intervention to be identifiable. ⚠️ The values are the Danish domain terms (UNDER_INDSAMLING, SKAERPET, HOEJ) and are not translated: the AML act’s concepts have no agreed English vocabulary, and an invented one would look canonical without being it.application/json
Possible errors 5
HTTPCodeMeaning
400invalid_cursorThe cursor is malformed, expired or belongs to another list shape.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
429rate_limitedThe organisation’s rate budget is exhausted.

Start a customer check

customerchecks:write

On an existing customer. ⚠️ If your template carries a legal-basis gate you must answer it here — fetch the questions from GET /v1/customer-checks/legal-basis. An answer of UNDTAGET means the work falls outside the AML act and NOTHING is created (422 not_in_scope): a check must not exist with personal data in it if there is no basis for holding them. 409 already_active when the customer already has a check running.

Request body fields 7
FieldTypeRequiredDescription
customerIdstringYesThe customer this resource belongs to.
serviceKeystringNoField in the request payload.
withoutRegistryLookupbooleanNoField in the request payload.
legalBasisobject[]NoField in the request payload.
legalBasis[].moduleIdstringYesField in the request payload.
legalBasis[].valuestringYesField in the request payload.
legalBasis[].internalReferencestringNoField in the request payload.
Request exampleapplication/json
curl -X POST https://api.rieckflow.com/v1/customer-checks \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041" \
-H "Content-Type: application/json" \
-d '{
"customerId": "9b2f1c1e-…",
"withoutRegistryLookup": true,
"legalBasis": [
{
"moduleId": "9b2f1c1e-…",
"value": "…",
"internalReference": "crm-9001"
}
]
}'
201 Success envelopeapplication/json
Possible errors 9
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
400invalid_requestThe request body or parameter failed validation.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
413payload_too_largeThe JSON or uploaded file exceeds this endpoint’s size limit.
429rate_limitedThe organisation’s rate budget is exhausted.
Request body — fuldt JSON Schema
{
"type": "object",
"properties": {
"customerId": {
"type": "string",
"pattern": "^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$"
},
"serviceKey": {
"anyOf": [
{
"type": "string",
"pattern": "^[a-z0-9_]{2,60}$"
},
{
"type": "null"
}
]
},
"withoutRegistryLookup": {
"type": "boolean"
},
"legalBasis": {
"maxItems": 20,
"type": "array",
"items": {
"type": "object",
"properties": {
"moduleId": {
"type": "string",
"pattern": "^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$"
},
"value": {
"type": "string",
"minLength": 1,
"maxLength": 120
},
"internalReference": {
"type": "string",
"maxLength": 140
}
},
"required": [
"moduleId",
"value"
],
"additionalProperties": false
}
}
},
"required": [
"customerId"
],
"additionalProperties": false
}

Questions that must be answered first

customerchecks:read
Request exampleNo request body
curl https://api.rieckflow.com/v1/customer-checks/legal-basis \
-H "Authorization: Bearer $RIECK_API_KEY"
200 The gates on your standard template, with both Danish and English wording and each option’s outcome (OMFATTET | UNDTAGET | FORKERT_MODUL — three outcomes, not two). An EMPTY list is a valid answer: your template carries no gate, and legalBasis must then be omitted.application/json
Possible errors 4
HTTPCodeMeaning
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
429rate_limitedThe organisation’s rate budget is exhausted.

Get customer check

customerchecks:read
ParameterInTypeRequiredDescription
customerCheckIdpathstringYes
Request exampleNo request body
curl https://api.rieckflow.com/v1/customer-checks/9b2f1c1e-… \
-H "Authorization: Bearer $RIECK_API_KEY"
200 ⚠️ Deliberately narrower than the portal’s own view: no rejection reason and no rejection category. A reason can reveal that a suspicious-activity report was considered, and disclosing that is a criminal offence under the Danish AML act § 38. THAT the check was rejected is the fact you act on.application/json
Possible errors 4
HTTPCodeMeaning
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
429rate_limitedThe organisation’s rate budget is exhausted.

GET /v1/customer-checks/{customerCheckId}/parties

Section titled “GET /v1/customer-checks/{customerCheckId}/parties”

Owners and management

customerchecks:read
ParameterInTypeRequiredDescription
customerCheckIdpathstringYes
Request exampleNo request body
curl https://api.rieckflow.com/v1/customer-checks/9b2f1c1e-…/parties \
-H "Authorization: Bearer $RIECK_API_KEY"
200 source + derived together ARE the § 15a discrepancy: LEGAL_EJER/REGISTRERET_REEL_EJER are the REGISTRY’s claims, REEL_EJER with derived: true is your own conclusion. ⚠️ No national identity number, not even masked — hasNationalId tells you whether one is on file.application/json
Possible errors 4
HTTPCodeMeaning
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
429rate_limitedThe organisation’s rate budget is exhausted.

GET /v1/customer-checks/{customerCheckId}/documents

Section titled “GET /v1/customer-checks/{customerCheckId}/documents”

Documentation on file

customerchecks:read
ParameterInTypeRequiredDescription
customerCheckIdpathstringYes
Request exampleNo request body
curl https://api.rieckflow.com/v1/customer-checks/9b2f1c1e-…/documents \
-H "Authorization: Bearer $RIECK_API_KEY"
200 Metadata only, including the database-computed sha256. ⚠️ There is deliberately no download: these are passport and driving-licence scans, and the portal’s own download sits behind a NAMED person with the right to handle customer checks, while an API key is a bearer credential you may hand to an integrator. The metadata answers what an integration actually needs — is the customer still missing something?application/json
Possible errors 4
HTTPCodeMeaning
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
429rate_limitedThe organisation’s rate budget is exhausted.

POST /v1/customer-checks/{customerCheckId}/reassess

Section titled “POST /v1/customer-checks/{customerCheckId}/reassess”

Start a periodic review

customerchecks:write

Not the same as POST /v1/customer-checks on the same customer: the review inherits the previous template, copies the customer’s answers — except the ownership list and identity numbers, which must be obtained afresh — and links the two checks in the audit trail. ⚠️ The legal-basis gate must be answered AGAIN if your template carries one: it is not inherited, because whether the work is in scope is exactly the kind of thing a review exists to re-examine. Only from an APPROVED check (409 not_approved) and only from the LATEST one (409 superseded).

ParameterInTypeRequiredDescription
customerCheckIdpathstringYes
Request body fields 4
FieldTypeRequiredDescription
legalBasisobject[]NoField in the request payload.
legalBasis[].moduleIdstringYesField in the request payload.
legalBasis[].valuestringYesField in the request payload.
legalBasis[].internalReferencestringNoField in the request payload.
Request exampleapplication/json
curl -X POST https://api.rieckflow.com/v1/customer-checks/9b2f1c1e-…/reassess \
-H "Authorization: Bearer $RIECK_API_KEY" \
-H "Idempotency-Key: order-2041" \
-H "Content-Type: application/json" \
-d '{
"legalBasis": [
{
"moduleId": "9b2f1c1e-…",
"value": "…",
"internalReference": "crm-9001"
}
]
}'
201 data is the NEW check; meta.answersCopied is how many answers carried over.application/json
Possible errors 9
HTTPCodeMeaning
400invalid_idempotency_keyIdempotency-Key is missing or malformed.
400invalid_requestThe request body or parameter failed validation.
401invalid_api_keyThe API key is missing, invalid, expired or revoked.
403api_not_includedThe organisation’s plan does not include API access.
403insufficient_scopeThe key does not have the required scope.
409idempotency_conflictThe same key was used with a different request.
409idempotency_in_progressThe same operation is currently being processed. Retry later.
413payload_too_largeThe JSON or uploaded file exceeds this endpoint’s size limit.
429rate_limitedThe organisation’s rate budget is exhausted.
Request body — fuldt JSON Schema
{
"type": "object",
"properties": {
"legalBasis": {
"maxItems": 20,
"type": "array",
"items": {
"type": "object",
"properties": {
"moduleId": {
"type": "string",
"pattern": "^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$"
},
"value": {
"type": "string",
"minLength": 1,
"maxLength": 120
},
"internalReference": {
"type": "string",
"maxLength": 140
}
},
"required": [
"moduleId",
"value"
],
"additionalProperties": false
}
}
},
"additionalProperties": false
}