Skip to main content
POST
Create a verification session

Authorizations

X-API-Key
string
header
required

Your workspace public key (pk_test_… or pk_live_…).

X-HMAC-Signature
string
header
required

HMAC-SHA256 of the request, hex-encoded, keyed with the workspace secret key. See API authentication.

Body

application/json
callback_url
string<uri> | null

Where the person's browser is sent after the final screen, an http or https URL. Ignored unless the request is HMAC-signed.

Maximum string length: 2048
external_id
string | null

Your identifier for the person. Ignored unless the request is HMAC-signed: the public key alone cannot tie a session to your user.

Maximum string length: 255
external_metadata
object | null

Free-form data returned in the API and webhooks. Accepted without a signature, so treat it as client-supplied.

metadata
object | null

Free-form data kept on the session and not returned to integrations.

Response

The verification session, with the url the person opens to complete it.

id
string
required
external_id
string | null
required
external_metadata
object | null
required
redirect_url
string | null
required
status
string
required
reason
string | null
required
duplicate_check
object
required
erasure
object | null
required
created_at
string
required
updated_at
string
required
url
string
required