External attestation

For users in external_attestation mode: you run the identity check with your own provider and report the outcome here. UrbanPayX stores the status, provider label, and reference, and runs no check of its own.

These endpoints drive external_verification_status, not kyc_status, which stays none for such users.