---
title: "Create a public Visitor Pass application"
method: POST
path: "/api/v1/visitor_pass_applications"
tags: ["Visitor passes"]
---

# Create a public Visitor Pass application

`POST /api/v1/visitor_pass_applications`

This endpoint is intentionally unauthenticated. The applicant must provide consent and a signature.

## Request body

- CreateVisitorPassRequest
  - `firstName` string, required
  - `lastName` string, required
  - `dateOfBirth` string, required
  - `email` string, email, required
  - `signature` string, required
  - `consentToBackgroundCheck` boolean, required
  - `referralSource` string, required

## Response `200`

Visitor Pass application accepted.

- CreateVisitorPassResponse
  - `success` true, required
  - `data` object, required
    - `ok` true, required

## Other responses

- `400` — Validation error or precondition failure.
- `401` — Missing or invalid credential.
- `403` — Credential lacks the required scope (Agent Key) or insufficient OAuth scope.
- `404` — Resource does not exist or is invisible to the caller. The two are intentionally indistinguishable.
- `409` — Conflicting state (e.g. legal-entity name already taken).
- `429` — Rate limit exceeded. No `Retry-After` header is currently emitted; back off exponentially.
- `500` — Server error.

---

[API](https://skmtc.dev/eprospera/apis/e-pro-spera-api.md) · [All operations](https://skmtc.dev/eprospera/apis/e-pro-spera-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/eprospera/e-pro-spera-api/revisions/9ecdd3ca5a8c/schema)
