Download OpenAPI specification:Download
Frontend Capture API — endpoints used by mobile Apps and the IDV redirect web to collect data.
Authentication
POST /api/v1/session: Authorization: Bearer with a Keycloak access tokenCreates a frontend session for the onboarding flow.
Gateway must inject x-org-id header before forwarding the request.
Returns a sessionToken (JWT) that must be passed as X-Session-Token on GET /info and POST /submit.
Also returns the ordered steps[] list and nextStep (first step to render).
Call GET /info to retrieve locale and branding URLs before starting submissions.
Error codes:
NO_ACTIVE_FLOW (400) — customer has no active flow configuredSANDBOX_LIMIT_REACHED (403) — sandbox time or verification limit exceeded| x-org-id required | string Organization ID injected by gateway |
object | |
| workflowId | string Requested workflow ID. Defaults to the customer's default workflow if omitted. |
| enrolmentCustomerId | string ID of the customer that is targeted with this workflow. |
{- "configuration": {
- "locale": "string"
}, - "workflowId": "string",
- "enrolmentCustomerId": "string"
}{- "nextStep": {
- "component": "string",
- "requiresFile": true,
- "skippable": true,
- "step": "string"
}, - "sessionToken": "string",
- "steps": [
- {
- "component": "string",
- "requiresFile": true,
- "skippable": true,
- "step": "string"
}
], - "workflowId": "string"
}Returns locale, branding URLs and the ordered workflow step list for this session.
Call this once after POST /session before starting step submissions.
Error codes:
SESSION_NOT_FOUND (404) — session token is missing or expiredINVALID_TOKEN (401) — token signature is invalid| x-session-token required | string JWT session token obtained from POST /session |
{- "locale": "string",
- "logoUrl": "string",
- "rejectedUrl": "string",
- "steps": [
- {
- "component": "string",
- "requiresFile": true,
- "skippable": true,
- "step": "string"
}
], - "unverifiedUrl": "string",
- "verifiedUrl": "string"
}Advances the session through the current workflow step.
The server reads the current step from the session — the client never sends a step name.
Set cancel: true to abort from any step. The captured data is deleted and the session ends.
Business-logic errors are returned as HTTP 200 with an error object in the body. The nextStep always indicates where the flow is now (step id only — resolve metadata from session steps[]).
On a tenant that stores records, the outcome may still be settling when the captures are complete: nextStep.step is then enrolment_pending rather than complete, so the client can show a pending state, and the final result arrives on the configured callback. On a tenant that stores nothing, the result is delivered on the callback and is not included in this response.
Error codes (4xx/5xx):
SESSION_NOT_FOUND (404) — session token is missing or expiredINVALID_TOKEN (401) — token signature is invalid| x-session-token required | string JWT session token obtained from POST /session |
boolean or "true" (string) or "false" (string) Abort the verification. When | |
boolean or "true" (string) or "false" (string) Abort the workflow if the step performed on a phone after redirect aborts. | |
string or string or any Image or NFC data capture in the proprietary format from the capture components — required when the current step's | |
| redirectToken | string If the process continues after redirection on the phone, provide the redirection token here to continue the session. |
number or string Number of steps to skip from the current position. Only steps whose |
{- "cancel": true,
- "clearRedirectToken": true,
- "file": "File",
- "redirectToken": "string",
- "skipSteps": 1
}{- "error": {
- "code": "string",
- "details": { },
- "message": "string",
- "requestId": "string",
- "retryable": true
}, - "nextStep": {
- "step": "string",
- "data": { }
}
}