overlay: 1.0.0 info: title: API Evangelist enhancements for Kriya Onboarding API version: 1.0.0 extends: openapi/kriya-onboarding-openapi.yaml x-generated: '2026-07-19' x-method: generated x-source: >- Derived from the Kriya Onboarding documentation at https://docs.kriya.co/onboarding. Captures enhancements API Evangelist would apply without mutating the harvested original. actions: - target: $.info update: version: '1.0.0' contact: name: Kriya API Support email: apisupport@kriya.co url: https://www.kriya.co/contact-us x-apievangelist-artifacts: authentication: authentication/kriya-authentication.yml conventions: conventions/kriya-conventions.yml errors: errors/kriya-problem-types.yml sandbox: sandbox/kriya-sandbox.yml data_model: data-model/kriya-data-model.yml - target: $ description: >- Declare the API key security scheme. The Onboarding API reuses the Kriya Payments credentials but declares no securitySchemes of its own. update: components: securitySchemes: KriyaApiKey: type: apiKey in: header name: X-Kriya-ApiKey description: >- The same partner API key used for the Kriya Payments API. Access is available to all valid users through the same KriyaPaymentsApi credentials. security: - KriyaApiKey: [] - target: $.tags description: Declare the tag set the operations already reference. update: - name: Onboarding API description: >- Create Onboarding Journeys for limited companies, government entities and sole traders, and run company plus additional onboarding checks. - name: OnboardingJourney description: Hosted onboarding flow initiation. - name: Scenario description: >- Test-environment-only simulators for forcing onboarding state. Not available in Production. - target: $.paths['/scenario/onboardingStatus'].put description: >- Flag the scenario simulator as test-environment only so consumers and agents do not attempt it against Production. update: x-environment: test-only x-sandbox-only: true x-artifact: sandbox/kriya-sandbox.yml - target: $.paths['/create'].get description: >- Flag that this operation is a redirect-producing journey initiator rather than a data-returning read, despite being modelled as GET. update: x-side-effects: >- Creates a blank Onboarding Journey. Despite the GET method this operation is not safe or idempotent in the HTTP sense — it creates server-side state and returns a Location header for redirect. - target: $.info description: Record the alternative redirect-based journey initiation path. update: x-journey-initiation: api: CreateOnboardingJourney redirect: >- https://api.kriya.co/onboardingJourney/create?merchantIdentifier=&merchantCompanyIdentifier=&onboardingCompletedUrl=&onboardingIneligibleUrl= required_parameters: - merchantIdentifier defaults: merchantCompanyIdentifier: autogenerated when not provided onboardingCompletedUrl: https://kriya.co onboardingIneligibleUrl: https://kriya.co