Update a biometric identity verification request

Partial update via JSON Merge Patch (RFC 7396), limited to externalId and metadata.

No domain field is writable here, and that is deliberate rather than an omission. status, resultFiles, the embedded verification and every timestamp are driven by the identity-verification vendor's webhook, so a write path into any of them would be a second, competing writer on the same row. externalId and metadata have no such driver: the vendor does not know they exist, so a caller owns them outright.

The calling account must be the request's PAYER — externalId is unique per payer account, so a payee write would reserve a value inside the other party's namespace. A payee receives 404, not 403.

Supplying an externalId already in use for this payer account returns 409 ResourceConflict.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
string
required

Unique identifier of a BiometricIdentityVerificationRequest.

Body Params

Patch body for a BiometricIdentityVerificationRequest. Only the fields supplied are changed.

These two are the only mutable fields, and both belong to the caller rather than to the verification lifecycle. Every domain field — status, resultFiles, the embedded verification and every timestamp — is written by the identity-verification vendor's webhook, and a write path into any of them would be a second, competing writer. externalId and metadata have no such driver: the vendor does not know they exist.

The calling account must be the request's PAYER. externalId is unique per payer account, so a payee write would reserve a value inside the other party's namespace; a payee receives 404, not 403.

string

Caller-supplied reconciliation id, unique per payer account. A duplicate returns 409 ResourceConflict.

metadata
object

Keys supplied are set; keys left out are left alone. Sending {} is a no-op rather than a clear — there is no way to remove a key once set. A key containing . or $ is rejected with 422.

Headers
string
length between 1 and 255
^[\x21-\x7e]{1,255}$

Optional idempotency token for authenticated POST and PATCH requests. Reusing the same key and body returns the cached response for 24 hours, except credential operations that explicitly document a 409 because one-time secret material is never cached; reusing it with a different body returns 409 IdempotencyKeyConflict. Use 1-255 printable ASCII characters.

string
^(?:[A-Za-z0-9_.]{22}|[a-f0-9]{24})$

Select the Account for an Account-scoped operation. A direct ServiceAccount API key MUST supply this header, and the target must be within the ServiceAccount owner's or Authorization grant's Account boundary. A Person bearer may select an Account on which it has an active Stakeholder, and an Account session may select its bound Account (or a descendant only when the session explicitly includes descendants).

string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json