Enroll a User in SCA

Obtain an SCA redirection link to enroll an Owner user. If `UserCategory` is `OWNER`, this endpoint allows you to enroll a user in SCA. To enroll `PAYER` users for the first time, use the [PUT Categorize a Natural User](/api-reference/users/categorize-natural-user) or [PUT Categorize a Legal User](/api-reference/users/categorize-legal-user) endpoints. Your platform needs to retrieve the returned `PendingUserAction.RedirectUrl`, add an encoded `returnUrl` query parameter for them to be returned to after the SCA session, and redirect the user. [Read more about SCA redirection](/guides/sca/session) **&rarr;** You can use this endpoint to obtain a new session `RedirectUrl`. This is useful to: - Enroll Owners created without SCA enrollment - Retry enrollment if a previous session was unsuccessful or expired (after 10 minutes) Calling this endpoint creates a new valid session that can be used, even if there is one already in progress for the user. Calling this endpoint also doesn't change the user's `UserStatus`, even if the session expires or is unsuccessful. <Note icon="fa-regular fa-circle-info"> **Note – This endpoint doesn't change UserStatus** Calling this endpoint does **not** change the user's status to `PENDING_USER_ACTION` (it stays as `ACTIVE`) and no `USER_ACCOUNT_VALIDATION_ASKED` webhook notification is sent. This ensures that legacy users do not become blocked if they are unable to complete SCA successfully. </Note> <Warning icon="fa-regular fa-triangle-exclamation"> **Caution – Legal representative's email required** For `OWNER` users, the `LegalRepresentative.Email` address is required. SCA uses this email address to build a [behavioral biometrics profile](/guides/sca/factors#email-confirmation-behavioral-biometrics) and as a backup communication channel. Prior to SCA, it was possible to create a Legal `OWNER` without the `LegalRepresentativeEmail`, so this data may be missing. Calling this endpoint without this data will return an error. </Warning>

Authentication

AuthorizationBearer
Bearer authentication of the form `Bearer <token>`, where token is your auth token. If your platform is using a [proxy](/guides/sca/proxy-management) to take SCA-triggering action on behalf of users, you also need to integrate [mTLS authentication](/guides/sca/platform) and use the `api-mtls` base URL.

Path parameters

ClientIdstringRequired
Platform's API account identifier, associated with the API key.
UserIdstringRequired
The unique identifier of the user.

Response

Success
PendingUserActionobject

Object containing the RedirectUrl needed for SCA redirection if triggered by the API call (otherwise returned null).

Errors

400
Bad Request Error