Systems and methods for generating and using secure sharded onboarding user interfaces
A method and apparatus for generating and using secure sharded onboarding user interfaces are described. The method may include determining, based on account type of a merchant account being onboarded for a merchant by a first user, that information for a user type associated with a second user associated with the merchant is to be collected to satisfy minimum merchant account compliance requirements. The method may also include allocating a person object in an accounts data store maintained by the commerce platform system, the person object associated in the accounts data store with the merchant account. Furthermore, the method can include generating a secure link and transmitting the secure link to the second user, the secure link resolving at the commerce platform system and comprising a unique identifier that is associated with the person object. In response to receiving selection of the secure link by the second user, the method includes generating a secure application programming interface (API) based graphical user interface to collect account information for the person object associated with the unique identifier.
1 . A method comprising:
initiating, by a service provider system, a first onboarding for a user type associated with a user account being onboarded to the service provider system, the user account for use of one or more services of the service provider system;
generating, by the service provider system, a secure link comprising a unique identifier associated with a user object allocated for the user type in a data store of the service provider system, the user object being one of a plurality of different types of user object;
transmitting, by the service provider system to a user system of a user of the user type, the secure link for collection of a subset of user data associated with the user object;
in response to receiving user selection of the secure link:
verifying, by the service provider system, that the user selection of the secure link is valid and corresponds to the user of the user system, including determining that the secure link had not been selected before, and in response:
generating, by the service provider system, an application programming interface (API) key comprising the unique identifier that associates the API key with the user object in the data store of the service provider system, and
transmitting the API key to the user system;
receiving, by the service provider system from the user system, the API key with information for the subset of user data associated with the user object; and
in response to verification that the unique identifier comprised in the API key is associated with the user object, updating, by the service provider system, the user account with the information collected for the subset of user data to satisfy a minimum account compliance requirement for the user type for the user account.
2 . The method of claim 1 , wherein updating the user account with the information collected for the subset of user data, comprises:
adding the information for the subset of user data received from the user system to the user object associated with the unique identifier in the data store of the service provider system.
3 . The method of claim 1 , wherein the first onboarding for the user type is performed by the service processing system during a second onboarding for a second user type, and wherein the second onboarding collects a different subset of user data for the second user type.
4 . The method of claim 1 , wherein verifying that the user selection of the secure link is valid and corresponds to the user of the user system comprises:
performing an identity verification of the user of the user system, wherein performing the identity verification of the user system comprises:
matching an Internet Protocol (IP) address associated with the selection of the secure link with prior known information associated with the user of the user system.
5 . The method of claim 1 , wherein generating the API key comprising the unique identifier further comprises:
generating a period of validity for the API key; and
updating the user account with the information collected for the subset of user data when the information is received (i) with the API key comprising the unique identifier and (ii) during the period of validity.
6 . The method of claim 1 , further comprising:
in response to receiving the user selection of the secure link, extracting the unique identifier from the secure link;
generating a secure API based user interface for the user based on the user object associated with the unique identifier extracted from the secure link and associated with the user object in the data store of the service provider system; and
transmitting, by the service provider system, the secure API based user interface with the API key to the user system causing the user system to render the secure API based user interface to the user for collection of the subset of user data.
7 . The method of claim 1 , wherein verification that the unique identifier comprised in the API key is associated with the user object, comprises:
determining that the API key received with the information matches the API key generated by the service provider system; and
in response to determining the match, updating the user object with the information for the subset of user data.
8 . The method of claim 1 , wherein the user account is a first type of user account among a plurality of different types of user account, wherein the subset of user data associated with the user object is defined based on a compliance plan associated with the first type of user account, and wherein the compliance plan comprises an indication of the user object and the subset of information to be collected from the user as part of satisfying the minimum account compliance requirement for the user type for the user account.
9 . The method of claim 1 , wherein the first onboarding is initiated after an initial onboarding of the user account by an initial user, different from the user.
10 . The method of claim 9 , further comprising:
receiving, from a second user processing system used by a second user during the initial onboarding of the user account, second information associated with the user;
transmitting, by the service provider system, the secure link to the user system used by the user; and
receiving, by the service provider system, the user selection of the secure link from the user system.
11 . A non-transitory computer readable storage medium including instructions that, when executed by a processor, cause the processor to perform operations comprising:
initiating, by a service provider system, a first onboarding for a user type associated with a user account being onboarded to the service provider system, the user account for use of one or more services of the service provider system;
generating, by the service provider system, a secure link comprising a unique identifier associated with a user object allocated for the user type in a data store of the service provider system, the user object being one of a plurality of different types of user object;
transmitting, by the service provider system to a user system of a user of the user type, the secure link for collection of a subset of user data associated with the user object;
in response to receiving user selection of the secure link:
verifying, by the service provider system, that the user selection of the secure link is valid and corresponds to the user of the user system, including determining that the secure link had not been selected before, and in response:
generating, by the service provider system, an application programming interface (API) key comprising the unique identifier that associates the API key with the user object in the data store of the service provider system, and transmitting the API key to the user system;
receiving, by the service provider system from the user system, the API key with information for the subset of user data associated with the user object; and
in response to verification that the unique identifier comprised in the API key is associated with the user object, updating, by the service provider system, the user account with the information collected for the subset of user data to satisfy a minimum account compliance requirement for the user type for the user account.
12 . The non-transitory computer readable storage medium of claim 11 , wherein updating the user account with the information collected for the subset of user data, comprises:
adding the information for the subset of user data received from the user system to the user object associated with the unique identifier in the data store of the service provider system.
13 . The non-transitory computer readable storage medium of claim 11 , wherein generating the API key comprising the unique identifier further comprises:
generating a period of validity for the API key; and
updating the user account with the information collected for the subset of user data when the information is received (i) with the API key comprising the unique identifier and (ii) during the period of validity.
14 . The non-transitory computer readable storage medium of claim 11 , wherein the user account is a first type of user account among a plurality of different types of user account, wherein the subset of user data associated with the user object is defined based on a compliance plan associated with the first type of user account, and wherein the compliance plan comprises an indication of the user object and the subset of information to be collected from the user as part of satisfying the minimum account compliance requirement for the user type for the user account.
15 . The non-transitory computer readable storage medium of claim 11 , wherein verifying that the user selection of the secure link is valid and corresponds to the user of the user system comprises:
performing an identity verification of the user of the user system, wherein performing the identity verification of the user system comprises:
matching an Internet Protocol (IP) address associated with the selection of the secure link with prior known information associated with the user of the user system.
16 . A service provider system, comprising:
a memory; and
a processor coupled with the memory configured to:
initiate a first onboarding for a user type associated with a user account being onboarded to the service provider system, the user account for use of one or more services of the service provider system;
generate a secure link comprising a unique identifier associated with a user object allocated for the user type in a data store of the service provider system, the user object being one of a plurality of different types of user object;
transmit, to a user system of a user of the user type, the secure link for collection of a subset of user data associated with the user object;
in response to receipt of a user selection of the secure link:
verify that the user selection of the secure link is valid and corresponds to the user of the user system, including determining that the secure link had not been selected before, and in response:
generate an application programming interface (API) key comprising the unique identifier that associates the API key with the user object in the data store of the service provider system, and transmit the API key to the user system;
receive, from the user system, the API key with information for the subset of user data associated with the user object; and
in response to verification that the unique identifier comprised in the API key is associated with the user object, update the user account with the information collected for the subset of user data to satisfy a minimum account compliance requirement for the user type for the user account.
17 . The system of claim 16 , wherein the processor configured to update the user account with the information collected for the subset of user data, comprises the processor further configured to:
add the information for the subset of user data received from the user system to the user object associated with the unique identifier in the data store of the service provider system.
18 . The system of claim 16 , wherein the processor configured to generate the API key comprising the unique identifier comprises the processor further configured to:
generate a period of validity for the API key; and
update the user account with the information collected for the subset of user data when the information is received (i) with the API key comprising the unique identifier and (ii) during the period of validity.
19 . The system of claim 16 , wherein the user account is a first type of user account among a plurality of different types of user account, wherein the subset of user data associated with the user object is defined based on a compliance plan associated with the first type of user account, and wherein the compliance plan comprises an indication of the user object and the subset of information to be collected from the user as part of satisfying the minimum account compliance requirement for the user type for the user account.
20 . The system of claim 16 , wherein verifying that the user selection of the secure link is valid and corresponds to the user of the user system comprises:
performing an identity verification of the user of the user system, wherein performing the identity verification of the user system comprises:
matching an Internet Protocol (IP) address associated with the selection of the secure link with prior known information associated with the user of the user system.