Start a biometric identity verification

Mints a session credential the payee's client uses to submit their document and selfie, and moves the verification to Pending.

Issued to the payee only; any other caller gets 404. Each call mints a fresh credential rather than returning a live one, so an abandoned attempt can simply be restarted. A verification that already reached Passed or Failed returns 400 — start a new one instead.

The session opens on the individual compliance entity of the account's principal person, so the provider sends its one-time code to the email or phone stored there. The call returns 422 with detailCode users.BiometricIdentityVerificationPrincipalRequired when the account has no principal person, and users.BiometricIdentityVerificationPrincipalComplianceEntityRequired when that person has no individual compliance entity; after fixing either, retry with a new Idempotency-Key. When the principal's compliance entity belongs to the person rather than the account, only that person may start the verification; any other caller, including an account API key, gets 403. 409 means the verification changed while starting, which a retry with a new Idempotency-Key resolves, or that an earlier attempt on another record is still under review.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
string
required

Unique identifier of a BiometricIdentityVerification.

Headers
string
length between 1 and 255
^[\x21-\x7e]{1,255}$

Optional idempotency token for authenticated POST and PATCH requests. Reusing the same key and body returns the cached response for 24 hours, except credential operations that explicitly document a 409 because one-time secret material is never cached; reusing it with a different body returns 409 IdempotencyKeyConflict. Use 1-255 printable ASCII characters.

string
^(?:[A-Za-z0-9_.]{22}|[a-f0-9]{24})$

Select the Account for an Account-scoped operation. A direct ServiceAccount API key MUST supply this header, and the target must be within the ServiceAccount owner's or Authorization grant's Account boundary. A Person bearer may select an Account on which it has an active Stakeholder, and an Account session may select its bound Account (or a descendant only when the session explicitly includes descendants).

string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json