---
title: "Update ITIN"
method: POST
path: "/programs/{programCode}/accounts/{accountIdentifier}/users/{userIdentifier}/identity"
tags: ["Account"]
---

# Update ITIN

`POST /programs/{programCode}/accounts/{accountIdentifier}/users/{userIdentifier}/identity`

Structure of API Call: POST /accounts/{accountIdentifier}/users/{userIdentifier}/identity 

 This endpoint allows an Individual Taxpayer Identification Number (ITIN) to be added to a customer’s account that originally enrolled using a Mexican Matricula ID only. This is primarily for U.S. tax purposes. 

 ITIN Limits: 
- Up to 1 active account with the same ITIN per consumer program is allowed 
- Up to 3 lifetime accounts with the same ITIN per consumer program are allowed

## Path parameters

- `accountIdentifier` string, required
- `userIdentifier` string, required
- `programCode` string, required

## Headers

- `X-GD-RequestId` string, required

## Request body

- UpdateItinResquestEncrypted — Represents a request to update an ITIN using encrypted identification number data. Inherits all properties from Gd.Bos.DataTransfer.Request.UpdateItinResquest.
  - `encryptedIdNumber` EncryptedData — Represents a container for encrypted data used in secure data transfer operations. Contains the encrypted payload and associated cryptographic metadata, including encryption version, ephemeral public key, and public key hash. Used to securely transmit sensitive information such as user data, ensuring confidentiality and integrity during transport.
    - `version` string, nullable — The version of the encryption algorithm used to encrypt the data (e.g., "v1", "v2").
    - `ephemeralPublicKey` string, nullable — The ephemeral public key used in the encryption process, typically for key exchange or session establishment.
    - `publicKeyHash` string, nullable — The hash of the public key used to verify the integrity and authenticity of the encryption key.
    - `data` string, nullable — The encrypted data payload, typically base64-encoded, containing the sensitive information.
  - `accountIdentifier` string, nullable — The unique identifier (UID or GUID) of the account for which the ITIN is being updated.
  - `userIdentifier` string, nullable — The unique identifier (UID or GUID) of the user whose ITIN is being updated.

## Response `200`

OK

- UpdateItinResponse — Represents the response for an ITIN (Individual Taxpayer Identification Number) update operation.
  - `responseDetails` ResponseDetail[], nullable — Required: A list of response details providing status codes, descriptions, and additional information about the result of the operation.
    - `code` integer — The primary status or error code for the response (e.g., 200 for success, 400 for validation error).
    - `subCode` integer, nullable — An optional subcode providing more granular detail about the response or error.
    - `description` string, nullable — A human-readable description of the response, error, or status.
    - `url` string, nullable — A URL linking to documentation or a web page with more information about the response code.

## Other responses

- `401` — Unauthorized
- `403` — Forbidden
- `500` — Internal Server Error
- `503` — Service Unavailable

---

[API](https://skmtc.net/greendot/apis/baas-apis.md) · [All operations](https://skmtc.net/greendot/apis/baas-apis/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/greendot/baas-apis/versions/666553766b78/schema)
