GET /v1/instruments/FUND/admission-consent answers credentialIssuerKind: "register-keeper" for an asset that requires its register keeper’s credential. The steps below are the venue’s credential’s; Under the register keeper’s admission consent gives what changes.
$OPERATOR and $APPROVER are two bearers.
Register the investor
A holder id names the investor’s party, hosted on its custodian’s node. Each is registered once.curl
lei (ISO 17442, checked by its check digits) and externalRefs (your own ids for the investor, by key, at most 16) are optional. The holder read, the register and its CSV, the distribution export and the tax statement carry them, so your systems match a line to their own records; a successor takes its predecessor’s unless its succession names its own.
Record what the KYC verified
The record holds codes and no personal data: residency (ISO 3166-1 alpha-2), investor type (retail, professional, institutional) and accreditation, each with its status, expiry, and the sha256: hash of the evidence you keep. It takes four eyes.
curl
Tx 1 · Offer the admission
The offer carries the claims the verified, unexpired attributes support. A holder that cannot show what the asset requires is refused on the operation, with the rule.curl
not-eligible:
policy-refused with its rule’s check.
Tx 2 · The investor accepts
The investor’s custodian accepts the offer in its wallet (AdmissionOffer_Accept), which creates the credential the registry checks on every mint, transfer and burn.
GET /v1/holders/inv-001 then lists the admission, and GET /v1/holders/inv-001/attributes the claims the attributes support.
When the facts change
Record the new attributes (four eyes again): any open offer they leave stale is cancelled in the same step. The nextPUT /v1/holders/inv-001/admissions/FUND offers a re-issue (reissue-offered), which replaces the live credential when the investor accepts it, so the investor is never left with none, or with two. DELETE /v1/holders/inv-001/admissions/FUND revokes the credential of an investor that holds no units.
Each write of the attributes is kept as a version. GET /v1/holders/inv-001/attribute-versions lists them, newest first, each with when it was recorded, its maker and its approvers. GET /v1/holders/inv-001/attributes?asOf=2026-09-30T23:59:59Z reads the attributes as they stood at that instant, with the claims they supported then.
Under the register keeper’s admission consent
For an asset that requires its register keeper’s credential, the claims are the KYC providers’ own, read on the ledger off the investor’s live credentials from the providers the register keeper trusts. The attributes the venue records are not read, so there is nothing to record: the KYC provider issues the investor its credential, naming the venue’s party among its observers. Tx 1 is the same call, and it is the whole admission: under the consent it creates the register keeper’s own credential about the investor, which the register keeper holds, naming the investor as the subject of its claims. There is no offer and no Tx 2: the investor and its custodian accept nothing, and vet nothing of the venue’s. The operation’s result names the register keeper as the credential’sissuer, the credential (credentialCid, state admitted), the KYC credentials it read (kyc) and the claims read off them. The ledger checks them against the consent’s terms in effect, and the venue checks them first, so a shortfall is refused before anything is submitted, with the consent as the gate:
eligibility:trusted-credential; providers that disagree on a claim, eligibility:claims-conflict; a claim the terms require and no credential carries, its topic’s rule, such as eligibility:residency. The admission names no end: the register keeper’s credential is open-ended, and a body that names validUntil is refused (admission-open-ended).
An investor admitted on the venue’s credential before the asset moved to the register keeper’s is re-issued by the same call: its result names the venue’s credential under replaces, and the one transaction revokes it and creates the register keeper’s, so the investor is never left with both, or with none. When the investor’s KYC credentials say something new, the same call re-issues the register keeper’s credential the same way. Only the register keeper ends an admission on its credential, by revoking it: DELETE /v1/holders/inv-001/admissions/FUND cancels the venue’s offers and revokes a credential the venue issued, and names the register keeper’s under keptCredentials, which the venue cannot revoke.
Next: Subscribe and redeem · Back to the workflow: Onboard investors
