GET requests. Their fields are described in Data models.
The decision
status, reason, duplicate_check, your external_id and external_metadata, and erasure. This is what the webhook told you, and the place to confirm it. The webhook also carries the document object described below, without the images.
Finding a verification by your ID
When you have only your ownexternal_id, for example to check whether a user already has a verification, list the workspace’s verifications:
GET /v1/verifications/{id} returns it (shortened above), newest first.
external_id: exact, case-sensitive match.status: one or more statuses, comma-separated, such asstatus=approved,declined. A verification waiting for an ID document is filtered asstartedand listed asdocuments_required.limit: 1 to 100; 20 by default.cursor: thenext_cursorof the previous page, sent with the same filters.next_cursorisnullon the last page.
%2C; see API authentication. Learn about outcomes from webhooks rather than by listing again and again; see Rate limiting.
The document
type, issuing_country and four fields. The other seven keys are absent, not null:
nullmeans the field was not read, or is not printed on that document. A passport has no address, many cards print no place of birth, and the German identity card prints no sex.typeis an open enum (passport,id,driver_license,residence_permit,other): handle values you do not know.otheris a readable document that is not an identity card, passport, driving licence or residence permit, such as a health insurance card.idis the same value the upload endpoint takes.issuing_subdivisionis the state or province that issued the document, as a bare code (FL,CA,PR; up to three uppercase letters or digits), ornull. Today it is filled for US driving licences and ID cards. It isnullwhenissuing_countryis, it is on every workspace, and it is kept after erasure.issuing_countryandnationalityare ISO 3166-1 alpha-2 (XKfor Kosovo).nationalityis published only when the document itself states it. They differ on a residence permit and can differ on any document.genderisF,MorX.Xmeans the document states that the sex is unspecified. On a Mexican voter card or driving licence created before 20 August 2026 17:00 UTC,genderisnull.date_of_birth,issue_dateandexpiry_dateareYYYY-MM-DD. A document that prints only the month or year of expiry reports the last day of that period. A birth or issue date printed partially isnull, never rounded. A permanent document (for examplePERMANENTEorINDEFINIDA) reads as anullexpiry_date.place_of_birthis the printed text, not normalised.addressis the printed text as read: trimmed,nullwhen empty, not parsed and not normalised. It may contain line breaks. KYC workspaces only.- Text fields are trimmed; an empty one is
null.
The age estimate
passed answers whether the person is at or above the workspace’s minimum age. The estimate itself is not returned as an age.
The images
urls from the document result; they are API URLs, so the request must be signed like any other. The server SDKs stream the download for you.
When data is gone
Images and personal data are kept for a limited time and can be erased on request; see Data retention and erasure. After that:erasureon the verification is set and says when and why;- document fields are
nulland imageurls arenull; - downloading an image answers
404 MEDIA_NOT_FOUND.