Skip to main content

Capture API (0.1.0)

Download OpenAPI specification:Download

Frontend Capture API — endpoints used by mobile Apps and the IDV redirect web to collect data.

Authentication

  • POST /api/v1/session: Authorization: Bearer with a Keycloak access token

Health

Service health check

Health check

Returns { status: "ok" } when the service is up.

Responses

Response samples

Content type
{
  • "status": "ok"
}

Session

Create an ID verification workflow session

Create a new session

Creates a frontend session for the onboarding flow.

Gateway must inject x-org-id header before forwarding the request.

Returns a sessionToken (JWT) that must be passed as X-Session-Token on GET /info and POST /submit. Also returns the ordered steps[] list and nextStep (first step to render).

Call GET /info to retrieve locale and branding URLs before starting submissions.

Error codes:

  • NO_ACTIVE_FLOW (400) — customer has no active flow configured
  • SANDBOX_LIMIT_REACHED (403) — sandbox time or verification limit exceeded
header Parameters
x-org-id
required
string

Organization ID injected by gateway

Request Body schema:
required
object
workflowId
string

Requested workflow ID. Defaults to the customer's default workflow if omitted.

enrolmentCustomerId
string

ID of the customer that is targeted with this workflow.

Responses

Request samples

Content type
{
  • "configuration": {
    },
  • "workflowId": "string",
  • "enrolmentCustomerId": "string"
}

Response samples

Content type
{
  • "nextStep": {
    },
  • "sessionToken": "string",
  • "steps": [
    ],
  • "workflowId": "string"
}

Info

Session information and steps

Get session and workflow steps

Returns locale, branding URLs and the ordered workflow step list for this session.

Call this once after POST /session before starting step submissions.

Error codes:

  • SESSION_NOT_FOUND (404) — session token is missing or expired
  • INVALID_TOKEN (401) — token signature is invalid
header Parameters
x-session-token
required
string

JWT session token obtained from POST /session

Responses

Response samples

Content type
{
  • "locale": "string",
  • "logoUrl": "string",
  • "rejectedUrl": "string",
  • "steps": [
    ],
  • "unverifiedUrl": "string",
  • "verifiedUrl": "string"
}

Submit

Upload step data to advance to the next step in the workflow

Submit current step data

Advances the session through the current workflow step.

The server reads the current step from the session — the client never sends a step name.

Set cancel: true to abort from any step. The captured data is deleted and the session ends.

Business-logic errors are returned as HTTP 200 with an error object in the body. The nextStep always indicates where the flow is now (step id only — resolve metadata from session steps[]).

On a tenant that stores records, the outcome may still be settling when the captures are complete: nextStep.step is then enrolment_pending rather than complete, so the client can show a pending state, and the final result arrives on the configured callback. On a tenant that stores nothing, the result is delivered on the callback and is not included in this response.

Error codes (4xx/5xx):

  • SESSION_NOT_FOUND (404) — session token is missing or expired
  • INVALID_TOKEN (401) — token signature is invalid
header Parameters
x-session-token
required
string

JWT session token obtained from POST /session

Request Body schema:
required
boolean or "true" (string) or "false" (string)

Abort the verification. When true, the server deletes the session.

boolean or "true" (string) or "false" (string)

Abort the workflow if the step performed on a phone after redirect aborts.

string or string or any

Image or NFC data capture in the proprietary format from the capture components — required when the current step's requiresFile is true.

redirectToken
string

If the process continues after redirection on the phone, provide the redirection token here to continue the session.

number or string

Number of steps to skip from the current position. Only steps whose skippable flag is true can be skipped.

Responses

Request samples

Content type
{
  • "cancel": true,
  • "clearRedirectToken": true,
  • "file": "File",
  • "redirectToken": "string",
  • "skipSteps": 1
}

Response samples

Content type
{
  • "error": {
    },
  • "nextStep": {
    }
}