---
title: "Create a Legal User (SCA)"
method: POST
path: "/v2.01/{ClientId}/sca/users/legal"
tags: ["Users"]
---

# Create a Legal User (SCA)

`POST /v2.01/{ClientId}/sca/users/legal`

Register a Legal Payer or Owner (with SCA enrollment).

<Note icon="fa-regular fa-circle-info">
**Note – SCA triggered for Owners**

If `UserCategory` is `OWNER`, this endpoint triggers SCA enrollment. SCA applies to all `LegalPersonType`.

Your platform needs to use the returned `PendingUserAction.RedirectUrl` (and add an encoded `returnUrl` query parameter) to redirect the user so they can enroll. Read more about how to redirect them in the [SCA session](/guides/sca/session) guide.

In Sandbox, you can bypass SCA by including the word `accept` in the Legal User's `LegalRepresentative.Email` – for example `accept@example.com` or `john.doe+accept@example.com`.
</Note>

<Note icon="fa-regular fa-circle-info">
**Note – Legal representative's email required for Owners**

If `UserCategory` is `OWNER`, the `LegalRepresentative.Email` address is required.

SCA uses this email address for the individual who will complete SCA to build a [behavioral biometrics profile](/guides/sca/factors#email-confirmation-behavioral-biometrics) and as a backup communication channel. Prior to SCA, it was possible to create a Legal `OWNER` without the `LegalRepresentativeEmail`.
</Note>

<Note icon="fa-regular fa-circle-info">
**Note – Country-based restrictions apply to users**

Due to Mangopay's [country restrictions](/guides/users/country-restrictions), it is not possible to use blocked countries as the following:
- `HeadquartersAddress.Country`
- `LegalRepresentative.Nationality`
- `LegalRepresentative.CountryOfResidence`
- `LegalRepresentativeAddress.Country`
</Note>

## Path parameters

- `ClientId` string, required

## Headers

- `Authorization` string, required

## Request body

- union
  - CreateALegalPayerSCARequest — Request body for creating a Legal User with `UserCategory` `PAYER`.
    - `Name` string, required — Max. length: 255 characters The registered legal name of the entity. The `Name` value should be the one registered with the relevant national authority.
    - `LegalPersonType` string, required — **Allowed values:** BUSINESS, PARTNERSHIP, ORGANIZATION, SOLETRADER The type of legal user. For information on which `LegalPersonType` to use for a particular local legal structure, see the <a href="/guides/users/verification/requirements" target="_blank">verification requirements</a>. **Caution:** Modification of the `LegalPersonType` may result in a <a href="/guides/users/verification/downgrade" target="_blank">verification downgrade</a>.
    - `HeadquartersAddress` AddressSubPropsRequired — The postal address.
      - `AddressLine1` string, required — The first line of the address.
      - `AddressLine2` string — The second line of the address.
      - `City` string, required — The city of the address.
      - `Region` string — Required if `Country` is US, CA, or MX. The region of the address.
      - `PostalCode` string, required — The postal code of the address. The postal code can contain the following characters: alphanumeric, dashes, and spaces.
      - `Country` string, required — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The country of the address.
    - `LegalRepresentativeAddress` AddressSubPropsRequired — The postal address.
      - `AddressLine1` string, required — The first line of the address.
      - `AddressLine2` string — The second line of the address.
      - `City` string, required — The city of the address.
      - `Region` string — Required if `Country` is US, CA, or MX. The region of the address.
      - `PostalCode` string, required — The postal code of the address. The postal code can contain the following characters: alphanumeric, dashes, and spaces.
      - `Country` string, required — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The country of the address.
    - `Tag` string — Max. length: 255 characters Custom data that you can add to this object.
    - `Email` string, required — Format: A valid email address The email address for the entity.
    - `TermsAndConditionsAccepted` boolean, required — Whether the user has accepted Mangopay's terms and conditions (as defined by your contract, see the [T&Cs guide](/guides/users/terms) for details). Must be `true` if `UserCategory` is `OWNER`.
    - `UserCategory` string, required — **Allowed values:** `PAYER` The [category](/guides/users/categories) of the user: - `PAYER` – User who can only make pay-ins to their wallets and transfers to other wallets (as well as refunds for pay-ins and transfers). - `OWNER` – User who can also receive transfers to their wallets. Owners are able to request [KYC verification](/guides/users/verification), which if successful gives them the `KYCLevel` of `REGULAR` and the ability to request payouts.
    - `LegalRepresentative` LegalRepresentativeCreatePayerRequest, required — Information about the legal representative declared for a `PAYER` Legal User.
      - `FirstName` string, required — Min. length: 1; max. length: 100 The first name of the legal representative.
      - `LastName` string, required — Min. length: 1; max. length: 100 The last name of the legal representative.
      - `PhoneNumber` string — Format: International E.164 standard (preceded by plus sign and country code) or local format. The legal representative's phone number. The local format (recommended) requires `PhoneNumberCountry` to ensure correct formatting. If present, the phone number forms part of card transaction data that is passed to issuers to improve authentication rates.
      - `PhoneNumberCountry` string — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)). Required if the `PhoneNumber` is provided in local format (recommended), to render the value in the E.164 standard.
    - `CompanyNumber` string — Has no effect if `UserCategory` is `PAYER`.
  - CreateALegalOwnerSCARequest — Request body for creating a Legal User with `UserCategory` `OWNER`. Owners must provide additional data, accept Mangopay's T&Cs, and enroll in SCA via the `PendingUserAction.RedirectUrl` returned.
    - `Name` string, required — Max. length: 255 characters The registered legal name of the entity. The `Name` value should be the one registered with the relevant national authority.
    - `LegalPersonType` string, required — **Allowed values:** BUSINESS, PARTNERSHIP, ORGANIZATION, SOLETRADER The type of legal user. For information on which `LegalPersonType` to use for a particular local legal structure, see the <a href="/guides/users/verification/requirements" target="_blank">verification requirements</a>. **Caution:** Modification of the `LegalPersonType` may result in a <a href="/guides/users/verification/downgrade" target="_blank">verification downgrade</a>.
    - `HeadquartersAddress` AddressSubPropsRequired, required — The postal address.
      - `AddressLine1` string, required — The first line of the address.
      - `AddressLine2` string — The second line of the address.
      - `City` string, required — The city of the address.
      - `Region` string — Required if `Country` is US, CA, or MX. The region of the address.
      - `PostalCode` string, required — The postal code of the address. The postal code can contain the following characters: alphanumeric, dashes, and spaces.
      - `Country` string, required — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The country of the address.
    - `LegalRepresentativeAddress` AddressSubPropsRequired — The postal address.
      - `AddressLine1` string, required — The first line of the address.
      - `AddressLine2` string — The second line of the address.
      - `City` string, required — The city of the address.
      - `Region` string — Required if `Country` is US, CA, or MX. The region of the address.
      - `PostalCode` string, required — The postal code of the address. The postal code can contain the following characters: alphanumeric, dashes, and spaces.
      - `Country` string, required — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The country of the address.
    - `Tag` string — Max. length: 255 characters Custom data that you can add to this object.
    - `Email` string, required — Format: A valid email address The email address for the entity.
    - `TermsAndConditionsAccepted` boolean, required — Whether the user has accepted Mangopay's terms and conditions (as defined by your contract, see the [T&Cs guide](/guides/users/terms) for details). Must be `true` if `UserCategory` is `OWNER`.
    - `UserCategory` string, required — **Allowed values:** `OWNER` The [category](/guides/users/categories) of the user: - `PAYER` – User who can only make pay-ins to their wallets and transfers to other wallets (as well as refunds for pay-ins and transfers). - `OWNER` – User who can also receive transfers to their wallets. Owners are able to request [KYC verification](/guides/users/verification), which if successful gives them the `KYCLevel` of `REGULAR` and the ability to request payouts.
    - `LegalRepresentative` LegalRepresentativeCreateOwnerRequest, required — Information about the legal representative declared for an `OWNER` Legal User.
      - `FirstName` string, required — Min. length: 1; max. length: 100 The first name of the legal representative.
      - `LastName` string, required — Min. length: 1; max. length: 100 The last name of the legal representative.
      - `Birthday` integer, required — Required if `UserCategory` is `OWNER`. The date of birth of the legal representative. **Note:** This is a Unix timestamp in UTC. Ensure you convert your timezone to UTC to avoid midnight being interpreted as the day before.
      - `Nationality` string, required — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)). Required if `UserCategory` is `OWNER`. The nationality of the legal representative.
      - `CountryOfResidence` string, required — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)). Required if `UserCategory` is `OWNER`. The country of residence of the legal representative.
      - `Email` string, required — Format: A valid email address Required if `UserCategory` is `OWNER`. The legal representative's email address. SCA uses this email address to build a [behavioral biometrics profile](/guides/sca/factors#email-confirmation-behavioral-biometrics) and as a backup communication channel.
      - `PhoneNumber` string — Format: International E.164 standard (preceded by plus sign and country code) or local format. The legal representative's phone number. The local format (recommended) requires `PhoneNumberCountry` to ensure correct formatting. If present, the phone number forms part of card transaction data that is passed to issuers to improve authentication rates. For users with `UserCategory` `OWNER` , the phone number is used to pre-populate the SCA session for them to confirm and receive an SMS OTP. If the individual modifies the phone number during the session, this data is not updated in the API.
      - `PhoneNumberCountry` string — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)). Required if the `PhoneNumber` is provided in local format (recommended), to render the value in the E.164 standard.
    - `CompanyNumber` string — Required if `LegalPersonType` is `BUSINESS`. The registration number of the entity, assigned by the relevant national authority. For information on the expected format for a specific country, see the [Company number](/guides/users/verification/company-number) guide. To validate the format of a number before submitting documents for verification, use [POST Validate the format of User data](/api-reference/user-data-format/validate-user-data-format).
    - `ScaContext` string, required — **Possible values:** `USER_PRESENT`, `USER_NOT_PRESENT` **Default value:** `USER_PRESENT` The SCA context of the request, which is **required** if the `OWNER` value is being assigned for `UserCategory`: - `USER_PRESENT` – The user is on session during `OWNER` account creation and can enroll in SCA at the same time. The platform must [redirect the user](/guides/sca/session) using the `PendingUserAction.RedirectUrl` returned so that the user can complete the SCA session. - `USER_NOT_PRESENT` – The platform has explicit permission from Mangopay to create the `OWNER` user account without simultaneous SCA enrollment. Read more about [asynchronous SCA enrollment](/guides/sca/proxy-management#user-account-creation) **&rarr;** **Note:** On User endpoints, `ScaContext` is not returned in the API response as it does not form part of the User data – it's only related to the action being performed on the user.

## Response `200`

Success

- LegalUserSCAResponse — Response body for a Legal User. The same schema is returned for `PAYER` and `OWNER` users. If `UserCategory` is `PAYER`, the following are returned `null`: - `LegalRepresentative.Birthday` - `LegalRepresentative.Nationality` - `LegalRepresentative.CountryOfResidence` - `LegalRepresentative.Email` - All `HeadquartersAddress` sub-properties - `CompanyNumber` - `TermsAndConditionsAcceptedDate`
  - `Name` string — Max. length: 255 characters The registered legal name of the entity. The `Name` value should be the one registered with the relevant national authority.
  - `LegalPersonType` string — **Returned values:** BUSINESS, PARTNERSHIP, ORGANIZATION, SOLETRADER The type of legal user. For information on which `LegalPersonType` to use for a particular local legal structure, see the <a href="/guides/users/verification/requirements" target="_blank">verification requirements</a>. **Caution:** Modification of the `LegalPersonType` may result in a <a href="/guides/users/verification/downgrade" target="_blank">verification downgrade</a>.
  - `LegalRepresentative` LegalRepresentativeResponse — Information about the legal representative declared for the user.
    - `FirstName` string — Min. length: 1; max. length: 100 The first name of the individual.
    - `LastName` string — Min. length: 1; max. length: 100 The last name of the individual.
    - `ProofOfIdentity` string, nullable — The `Id` of the KYC Document whose `Type` is `IDENTITY_PROOF` if validated for the user. If no identity proof is validated, then this value is `null`.
    - `Birthday` integer, nullable — Returned `null` if `UserCategory` is `PAYER`. The date of birth of the individual. **Note:** This is a Unix timestamp in UTC. Ensure you convert your timezone to UTC to avoid midnight being interpreted as the day before.
    - `Nationality` string, nullable — Returned `null` if `UserCategory` is `PAYER`. The nationality of the individual.
    - `CountryOfResidence` string, nullable — Returned `null` if `UserCategory` is `PAYER`. The country of residence of the individual.
    - `Email` string, nullable — Format: A valid email address Required if `UserCategory` is `OWNER`. Returned `null` if `UserCategory` is `PAYER`. The individual's email address. For `OWNER` users, SCA uses this email address to build a [behavioral biometrics profile](/guides/sca/factors#email-confirmation-behavioral-biometrics) and as a backup communication channel.
    - `PhoneNumberCountry` string, nullable — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) Required if the `PhoneNumber` is provided in local format (recommended), to render the value in the E.164 standard.
    - `PhoneNumber` string, nullable — Format: International E.164 standard (preceded by plus sign and country code) or local format The individual's phone number. The local format (recommended) requires `PhoneNumberCountry` to ensure correct formatting. If present, the phone number forms part of card transaction data that is passed to issuers to improve authentication rates. For users with `UserCategory` `OWNER` , the phone number is used to pre-populate the SCA session for them to confirm and receive an SMS OTP. If the individual modifies the phone number during the session, this data is not updated in the API.
  - `ProofOfRegistration` string, nullable — The `Id` of the KYC Document whose `Type` is `REGISTRATION_PROOF` if validated for the user. If no registration proof is validated, then this value is `null`.
  - `ShareholderDeclaration` string, nullable — The `Id` of the KYC Document whose `Type` is `SHAREHOLDERS_DECLARATION` if validated for the user. If no Shareholder Declaration is validated, then this value is `null`.
  - `Statute` string, nullable — The `Id` of the KYC Document whose `Type` is `ARTICLES_OF_ASSOCIATION` if validated for the user. If no articles of association document is validated, then this value is `null`.
  - `CompanyNumber` string, nullable — Required if `UserCategory` is `OWNER` and `LegalPersonType` is `BUSINESS`. Returned `null` if `UserCategory` is `PAYER`. The registration number of the entity, assigned by the relevant national authority. For information on the expected format for a specific country, see the [Company number](/guides/users/verification/company-number) guide. To validate the format of a number before submitting documents for verification, use [POST Validate the format of User data](/api-reference/user-data-format/validate-user-data-format).
  - `PendingUserAction` LegalUserScaResponsePendingUserAction — Object containing the `RedirectUrl` needed for SCA redirection if triggered by the API call (otherwise returned `null`).
    - `RedirectUrl` string — The URL to which to redirect the user to perform strong customer authentication (SCA) via a Mangopay-hosted webpage. This value is a variable and should not be hardcoded. The SCA session link expires 10 minutes after it's generated. **Caution:** Before redirecting the user on this URL, you must add the query parameter `ReturnUrl` with the percent-encoded URL to which you want the SCA session to return the user after authentication (whether successful or not). For more details, see [How to redirect a user for an SCA session](/guides/sca/session#how-to-redirect-a-user-for-sca).
  - `HeadquartersAddress` LegalUserScaResponseHeadquartersAddress — The legally registered address of the entity’s administrative center. This object’s sub-parameters are `null` if the `UserCategory` is `PAYER`.
    - `AddressLine1` string, nullable — Max. length: 255 characters The first line of the address.
    - `AddressLine2` string, nullable — Max. length: 255 characters The second line of the address.
    - `City` string, nullable — Max. length: 255 characters The city of the address.
    - `Region` string, nullable — Max. length: 255 characters The region of the address. This field is optional except if the `Country` is US, CA, or MX.
    - `PostalCode` string, nullable — Max. length: 255 characters The postal code of the address. The postal code can contain the following characters: alphanumeric, dashes, and spaces.
    - `Country` string, nullable — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The country of the address.
  - `LegalRepresentativeAddress` LegalUserScaResponseLegalRepresentativeAddress — The address of the entity’s legal representative.
    - `AddressLine1` string, nullable — Max. length: 255 characters The first line of the address.
    - `AddressLine2` string, nullable — Max. length: 255 characters The second line of the address.
    - `City` string, nullable — Max. length: 255 characters The city of the address.
    - `Region` string, nullable — Max. length: 255 characters The region of the address. This field is optional except if the `Country` is US, CA, or MX.
    - `PostalCode` string, nullable — Max. length: 255 characters The postal code of the address. The postal code can contain the following characters: alphanumeric, dashes, and spaces.
    - `Country` string, nullable — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The country of the address.
  - `Id` string — Max length: 128 characters (see [data formats](/api-reference/overview/data-formats) for details) The unique identifier of the object.
  - `Tag` string — Max. length: 255 characters Custom data that you can add to this object.
  - `CreationDate` integer — Unix timestamp (UTC) of the date and time the object was created.
  - `PersonType` string — **Returned values:** NATURAL, LEGAL The type of the user: - `NATURAL` – Natural users are individuals (natural persons). - `LEGAL` – Legal users are legal entities (legal persons) like companies, non-profits, and sole proprietors. The `PersonType` is defined by the endpoint used to create the user and can’t be modified.
  - `Email` string — Format: A valid email address The email address for the entity.
  - `KYCLevel` string — **Default value:** `LIGHT` **Returned values:** `LIGHT`, `REGULAR` The verification status of the user set by Mangopay: - `LIGHT` – Unverified, assigned by default to all users. - `REGULAR` – Verified, meaning the user has successfully completed the verification process and had the necessary documents validated by Mangopay. Only users whose `UserCategory` is `OWNER` can submit verification documents for validation. Only users whose `KYCLevel` is `REGULAR` can request payouts.
  - `TermsAndConditionsAccepted` boolean — Whether the user has accepted Mangopay's terms and conditions (as defined by your contract, see the [T&Cs guide](/guides/users/terms) for details). Must be `true` if `UserCategory` is `OWNER`.
  - `TermsAndConditionsAcceptedDate` integer, nullable — The date and time at which the `TermsAndConditionsAccepted` value was set to `true`. Returned `null` if `UserCategory` is `PAYER`.
  - `UserCategory` string — **Possible values:** `PAYER`, `OWNER`, `PLATFORM` The [category](/guides/users/categories) of the user: - `PAYER` – User who can only make pay-ins to their wallets and transfers to other wallets (as well as refunds for pay-ins and transfers). - `OWNER` – User who can also receive transfers to their wallets. Owners are able to request [KYC verification](/guides/users/verification), which if successful gives them the `KYCLevel` of `REGULAR` and the ability to request payouts. - `PLATFORM` – Single specific user that represents the platform. The `PLATFORM` value is only assigned by Mangopay and may be used as part of the validated workflow implemented by the platform.
  - `UserStatus` string — **Returned values:** `PENDING_USER_ACTION`, `ACTIVE`, `CLOSED` The status of the user: - `PENDING_USER_ACTION` – The user must enroll in SCA before they can become `ACTIVE`. - `ACTIVE` – The user account is active and the user can access Mangopay features. - `CLOSED` – The user account is permanently closed. This value is used by Mangopay to close an account following the procedure outlined in the terms and conditions.

## Other responses

- `400` — Bad Request

---

[API](https://skmtc.net/mangopay/apis/api-reference.md) · [All operations](https://skmtc.net/mangopay/apis/api-reference/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/mangopay/api-reference/versions/795281070285/schema)
