> ## Documentation Index
> Fetch the complete documentation index at: https://docs.polygon.technology/llms.txt
> Use this file to discover all available pages before exploring further.

# Get a customer's risk identifier

> Reads the existing opaque risk identifier without enrolling the customer or creating a session. Returns null when the customer is not enrolled. Accepts a normal backend bearer token, or a publishable Api-Key together with a customer-bound bearer token from /customers/{customerId}/token. Browser requests require a nonempty merchant Origin validated against the publishable key's origin policy. An empty origin allowlist permits any valid origin. The browser token must match the customer, project, and environment and grants no general customer access.



## OpenAPI

````yaml /api-reference/openapi.yaml get /customers/{customerId}/risk-id
openapi: 3.0.3
info:
  title: Polygon OMS Public API
  version: v26.09.30-0002
  description: >-
    Unified API for moving money between crypto and fiat. Three ways to move
    money: Transactions (instant, wallet or card funded, including Cash-In for
    in-person cash deposits), Deposit Addresses (reusable crypto deposit
    configurations), and Virtual Accounts (dedicated bank accounts that
    auto-convert fiat to crypto). Standard transactions follow a two-step flow:
    create a Quote (pricing), then create a Transaction (execution). Cash-in
    codes generate a one-time deposit code for in-person cash deposits at retail
    locations.
  contact:
    name: Polygon OMS
    url: https://oms.polygon.technology
servers:
  - url: https://sandbox-api.polygon.technology/v0.13
    description: Sandbox
  - url: https://api.polygon.technology/v0.13
    description: Production
security:
  - BearerAuth: []
tags:
  - name: Auth
    description: Authentication via FrontEgg
  - name: Customers
    description: Customer management and KYC
  - name: Customer
  - name: Wallet
  - name: Quote
  - name: Transaction
  - name: CashIns
  - name: CashLocation
  - name: Sandbox
  - name: VirtualAccount
  - name: Counterparty
  - name: ExternalAccount
  - name: Reference
  - name: DepositAddress
paths:
  /customers/{customerId}/risk-id:
    get:
      tags:
        - Customers
      summary: Get a customer's risk identifier
      description: >-
        Reads the existing opaque risk identifier without enrolling the customer
        or creating a session. Returns null when the customer is not enrolled.
        Accepts a normal backend bearer token, or a publishable Api-Key together
        with a customer-bound bearer token from /customers/{customerId}/token.
        Browser requests require a nonempty merchant Origin validated against
        the publishable key's origin policy. An empty origin allowlist permits
        any valid origin. The browser token must match the customer, project,
        and environment and grants no general customer access.
      operationId: getCustomerRiskId
      parameters:
        - name: customerId
          in: path
          required: true
          schema:
            type: string
      responses:
        '200':
          description: Existing risk identifier, or null when not enrolled
          headers:
            Cache-Control:
              schema:
                type: string
                enum:
                  - no-store
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CustomerRiskId'
        '400':
          description: Malformed customer ID
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: Missing or invalid credentials
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: Customer token scope mismatch
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '422':
          description: Customer missing, deleted, or outside the authenticated project
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - BearerAuth: []
        - CustomerTokenAuth: []
          PublishableKeyAuth: []
components:
  schemas:
    CustomerRiskId:
      type: object
      required:
        - riskId
      properties:
        riskId:
          type: string
          nullable: true
          description: Opaque existing risk identifier. Null when not enrolled.
    ErrorResponse:
      type: object
      required:
        - error
        - code
        - msg
        - status
      description: >-
        Canonical OMSX error envelope, matching the webrpc shape every OMSX
        service emits. Names and numeric codes are stable identifiers defined in
        `schema/omsx/errors.ridl`.
      properties:
        error:
          type: string
          description: Stable error name from schema/omsx/errors.ridl
          example: Unauthorized
        code:
          type: integer
          description: Stable numeric code from schema/omsx/errors.ridl
          example: 1000
        msg:
          type: string
          description: Human-readable message (kept stable across releases)
          example: unauthorized access
        cause:
          type: string
          description: >-
            Optional internal cause for operator triage; filtered before
            reaching end customers
          example: signature
        status:
          type: integer
          description: HTTP status mirrored in the body for client convenience
          example: 401
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: Token from POST /auth/token
    CustomerTokenAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: Short-lived customer-bound token with the omsx-customer-token audience.
    PublishableKeyAuth:
      type: apiKey
      in: header
      name: Api-Key

````