Skip to main content
When you capture in your own UI, you upload each image to POST /v1/verifications/{id}/media and then submit. Consent must be recorded first.

Request fields

Uploads are multipart/form-data.

Documents and their sides

File requirements

Signing

A multipart/form-data request, such as a media upload, is not signed over its raw body. Its canonical string has three lines:
For a selfie upload with the single field type=selfie:
Nested fields are sorted at every level. The signature is the hex HMAC-SHA256 of that string with the secret key, as for any other request.

When an image is refused

Each image is checked as it arrives. An unusable one is refused with 422 and a code that says what to fix, such as FACE_TOO_BLURRY; nothing is stored, and the person retakes it. Every code, with what to ask the person, is on Errors. A new selfie on a facial age estimation that has already asked for a document is refused with 422 MAX_ATTEMPTS_REACHED when no attempts are left. Otherwise running out of attempts is decided after submit: the verification is declined, and its reason is the last attempt’s reason, not a separate code.

Ready to submit

Before POST /v1/verifications/{id}/submit, the required images must be uploaded: If one is missing, submit answers 422 MISSING_REQUIRED_MEDIA.

Uploading an image again

  • A new selfie replaces the previous selfie of the attempt.
  • A new document image replaces the previous one of the same side, but only while the attempt is still missing an image. Once every required image is in, further document uploads are refused with a 422 validation error: submit instead.
  • After resubmission_requested, the first upload moves the verification back to started, even if that image is then refused.

Examples

A selfie

200 OK with an empty body.

The front and back of an ID card

A refused image

422
403

Next steps