Consent
- The consent
urlof a KYC workspace shows the KYC text.GET /v1/consentreturnedhttps://app.proofage.net/consentto every workspace, and that page showed the age-verification text, so an identity-verification integration that shows the page aturlshowed a text other than the one its users accept. A KYC workspace now getshttps://app.proofage.net/consent?type=kyc; age-verification workspaces keep the address they had. The response shape is unchanged. If you stored the address instead of reading it from the response, read it again. See Consent. - New consent versions. The age-verification text is now version 4 and the KYC text version 2. The only change is the contact address, now
[email protected]. The previous versions are no longer active: accepting them answers409, so an integration that storedidandtext_sha256instead of readingGET /v1/consentbefore each acceptance must read them again. The hosted widget needs nothing.
Domains
- ProofAge moved to proofage.net. The API is now
https://api.proofage.net/v1, the consolehttps://app.proofage.net, these docshttps://docs.proofage.net, and new verification links are issued onidv.proofage.net. The API spec, the Postman collection and the examples on these pages name the new hosts. - Nothing you have breaks.
api.proofage.xyzkeeps answering, with the same keys and the same signatures, so an integration or an SDK release that names it needs no change. Links issued before the move keep working on the host they were issued on, the browser SDK loader is still served fromapp.proofage.xyz, and MCP clients connected toapp.proofage.xyz/mcp/adminstay connected. Console pages opened on the old host are sent to the new one. - If your site has a Content Security Policy that names
idv.proofage.xyzinframe-src, addidv.proofage.net: the verification URL the API returns is now on that host. - SDK releases to match:
@proofage/node0.14.0,proofage(Python) 0.9.0,proofage/php-sdk0.9.0 andproofage/laravel-client0.11.0 default tohttps://api.proofage.net. Earlier releases keep working againstapi.proofage.xyz.
Plugins
- PrestaShop module. Age verification for PrestaShop 8.1 to 9.x, without code: protect products, categories, CMS pages, controllers, URL paths or the whole shop, with add-to-cart, checkout and order creation blocked server-side until the shopper is verified. Download it from GitHub. See PrestaShop.
API, webhooks and Zapier
- List verifications.
GET /v1/verificationslists the workspace’s verifications, newest first, as{"data": [...], "next_cursor": ...}. Filter bystatus(comma-separated) andexternal_id; page withlimit(1 to 100, 20 by default) andcursor. Use it to find a verification by your own ID. The query string is part of the signature, sorted by name, with a comma written as%2C. See Reading results. - Webhook subscriptions.
POST,GETandDELETE /v1/webhook-subscriptionssubscribe more URLs to the decision webhooks, in addition to the workspace’s webhook URL, and remove them: up to 50 per workspace (422 WEBHOOK_SUBSCRIPTION_LIMITpast that), optionally for some statuses only. A subscription getsstatus.updatedwebhooks only, neverdata.updated. Unless it was created withinclude_document_data: true, its body leaves outdocument,fingerprint_signalsandmanual_moderation.performed_by. Its deliveries are signed with the secret key that created it, or with the active key once that key is deleted. A410answer deletes the subscription. See Webhooks. - Because a subscription’s body can leave it out,
documentis no longer required in the webhook schema. The workspace’s webhook URL still receives it on every webhook. - Set a test outcome from your code.
POST /v1/verifications/{id}/test-outcomesetsapproved,declined,revieworresubmission_requestedon a test workspace’s verification that is not final, with an optionalreasonnote. One nobody has opened is moved throughstartedandsubmittedfirst, so exactly one decision webhook is sent. A live workspace answers403 TEST_WORKSPACE_ONLY; a final verification422 INVALID_STATUS. See Sandbox and test data. - Webhook URLs must be public. A new webhook URL, on a workspace or a subscription, must be
https; private, loopback, link-local and cloud-metadata addresses, local names and URLs with credentials are refused, and a Unicode host name must be written in punycode. The address is checked again before each delivery, and a delivery to one that has become private is skipped. AnhttpURL saved before keeps working. See The webhook URL. - Redirects are no longer followed. A
3xxfrom your webhook URL is recorded as the answer and not retried; set the URL your handler serves. Only the first 2 KB of your response body are kept with each attempt. callback_urland the workspace’s redirect URL accepthttpandhttpsURLs only.- The per-IP rate limit counts each workspace separately, so workspaces calling from one IP address no longer share it. The per-workspace limit is unchanged. See Rate limiting.
- ProofAge for Zapier. Send verification links from any Zap and act on the decision, without code. Shared by invite for now. See Zapier.
- SDK releases to match:
@proofage/node0.13.0,proofage(Python) 0.8.0,proofage/php-sdk0.8.0 andproofage/laravel-client0.10.0 add listing verifications, webhook subscriptions and test outcomes. In the SDK typesmanual_moderation.performed_byis now optional, because subscription deliveries leave it out.
Webhooks and console
- Correct document fields the reader got wrong. An administrator or a support specialist can correct a field on an approved, declined or in-review verification, in the console or with the new MCP tool
correct-document-fields. The status does not change and no check runs again. The recognised value is kept; your corrected value is what the webhook andGET /v1/verifications/{id}/documentreturn. See Verifications and review. - New webhook event
data.updated. Every webhook payload now hasevent:status.updatedfor the status webhooks you already receive, anddata.updatedwhen a correction is made. Adata.updatedhas the same fields as a status webhook, with the currentstatus, the correcteddocumentand a newchanged_fields(the names of the fields changed, no values). A payload withouteventis astatus.updated, soeventis optional in the schema. Readeventbeforestatus: a handler that ignores it sees what looks like a repeat of the status it already has, and must not treat it as a new decision. See Webhooks. - The document type, issuing country and issuing state or province can be corrected too, on every workspace. A corrected country clears the state or province that was read with the old one, unless that is corrected as well.
changed_fieldsthen namestype,issuing_countryorissuing_subdivision. - Resending or retrying an older webhook sends the document as it is now, corrections included.
- SDK releases to match:
@proofage/node0.12.0,proofage(Python) 0.7.0,proofage/php-sdk0.7.0 andproofage/laravel-client0.9.7. The new keys are optional in their types.
Dashboard and MCP
- Resubmission insights count people, not verifications. The dashboard card and the
resubmissionpart of the MCPget-verification-statsnow merge a person’s verifications byexternal_idwithin a workspace, and count each person once, on the day of their final outcome. Someone declined on one link and approved on the next is one approval on the 2nd attempt, on the day of the approval, and no longer a decline plus a first-attempt approval. A new verification after an approval starts a new count of its own, and verifications without anexternal_idare counted one by one. The response keys are unchanged,volumestays per verification, and the MCPlegendhas a newpersonentry.
API
DOCUMENT_PORTRAIT_NOT_FOUNDon a document front upload. A front image with no photo of the holder on it, such as a closed passport cover or the back of a card, is now refused at upload with422and this code, instead of failing later in the verification. Ask the person to retake the document photo. Not sent for every workspace; handle it like the other upload codes in Error handling.
Billing
- The 500 free verifications no longer expire after 15 days. They are used before your card is charged, and there is no monthly minimum while any are left or in a month that used them. Your administrators get an email when 100, 30 and 0 are left. See Pricing.
API
issuing_subdivisionin the document result.issuing_subdivisionindocumentis the state or province that issued the document, as a bare code right afterissuing_country(for exampleFLwithUS), ornull. Today it is filled for US driving licences and ID cards. It is on every workspace, inGET /v1/verifications/{id}/document, in the webhookdocumentand in the MCPlist-verificationsdocument, and it is kept after erasure. See Reading results.- SDK releases to match:
@proofage/node0.11.0,proofage(Python) 0.6.0,proofage/php-sdk0.6.0 andproofage/laravel-client0.9.6.
API
addressin the document result, on identity (KYC) workspaces only.GET /v1/verifications/{id}/documentnow returnsaddressinfields: the printed text as read, trimmed,nullwhen empty, not parsed and not normalised. It may contain line breaks.fieldscarries eleven keys on KYC workspaces, seven of them KYC-only. Age workspaces do not receiveaddress.- The decision webhook carries
document. Every decision webhook now has the samedocumentobject asGET /v1/verifications/{id}/document, without the images:type,issuing_countryandfields, with eleven fields on identity (KYC) workspaces and four on age workspaces. It is present on every status and is allnullwhen nothing was read, and on test workspaces. A resend or a manual retry carries the document as it is now; an automatic retry carries the body as first sent. Stored webhook bodies in your logs now hold the person’s name and birth date until erasure. If your handler validates the body with a strict schema, allow the new key. See Webhooks. nationalityis published only when the document itself states it.- MCP
list-webhook-deliveriesreturns the last attempt’srequest_bodyonly withinclude_payload: true, likepayload. - Erasure covers every stored copy of a webhook body. The copy of the body kept with each delivery attempt, and what a receiver answered, are now erased with the rest of the person’s data, and an erasure that lands while a delivery is in flight is no longer undone.
gendercan beX.F,MorX, whereXmeans the document states that the sex is unspecified.- SDK releases to match:
@proofage/node0.10.0,proofage(Python) 0.5.0,proofage/php-sdk0.5.0 andproofage/laravel-client0.9.5. They typeaddressand the webhookdocument, both optional. See Reading results and Data models.