Skip to main content
Use this when you capture the selfie and the documents in your own app instead of ProofAge’s hosted widget. This page is the order of the requests; Consent and Uploading media have the detail of each. Every request is signed with your secret key (see API authentication), so they all run on your backend: your app sends the images to your backend, which forwards them.

Before you build it

The hosted widget does a lot that you would take over:
  • the consent screen and the consent text in the person’s language, in 28 languages;
  • camera access, including recovery when the browser or an in-app browser blocks it;
  • capture guidance: framing, light, the head movement for liveness, and retakes;
  • moving from a desktop to a phone by QR code.
Build your own UI when you need capture inside a native app or a flow the widget cannot fit. Otherwise use the Browser SDK or a redirect.

The requests, in order

1

Create the verification

Returns the verification in created status with its id. The check comes from the workspace. See the Quick start.
2

Record consent

Show the person the consent page at the url that GET /v1/consent returns, and record their acceptance with its id and text_sha256. Uploads answer 403 CONSENT_REQUIRED until you do. See Consent.
3

Upload the images

Each image is checked as it arrives; an unusable one is refused with 422 and a code that says what to retake. The signature for a file upload covers the form fields and a hash of each file: see Uploading media.
4

Submit

Answers 200 with an empty body, and the verification moves to submitted. If an image is missing it answers 422 MISSING_REQUIRED_MEDIA. In a test workspace the verification goes to review and waits for you to set the outcome: see Sandbox and test data.
5

Receive the decision

A webhook arrives when the verification reaches approved, declined, resubmission_requested or review (and later abandoned or expired if the person never finishes).On resubmission_requested, the person retakes what failed in a new attempt of the same verification: repeat steps 3 and 4. Attempts are limited; when they run out the verification is declined, and reason is the last attempt’s reason. Treat declined as final whatever the code. See Handle a resubmission.
6

Read the result

See Reading results.

The same calls in the SDKs

The SDKs sign every request, including the multipart uploads. See SDKs and integrations.