Skip to main content
The chmod API is what your backend talks to. It does three things: registers the people you verify, opens verifications with the rules you want enforced, and hands back the decision. Everything a user sees on their phone is the Client SDK, and the two halves meet through a single token your backend mints.
Most integrations should start with the Quickstart — one complete verification, end to end, in five requests. Come back here for the reference.

Base URL

Every endpoint lives under one prefix on your account’s host:
Your chmod account manager provides the host, the OAuth token URL and your client credentials.

Endpoints

Create customer

POST /customer — register a person once, reuse the id forever.

Create transaction

POST /transaction — open a verification and mint the SDK token.

Get transaction

GET /transaction/{id} — read the status and the decision.
That is the whole surface. The SDK calls its own session endpoints on the same host using the token you minted — you never call those yourself.

Two tokens

The API uses two credentials, and confusing them is the most common integration mistake: The access token comes from Authentication and never leaves your server. The sdk_token is returned by Create transaction and is safe to hand to a device precisely because it can only act on that one transaction.

Conventions

  • JSON in and out, Content-Type: application/json.
  • Field names are snake_case.
  • Identifiers are UUIDs.
  • Timestamps are ISO-8601 in UTC, for example 2026-09-10T14:22:00.000Z.
  • Dates without time (date of birth, expiry) are YYYY-MM-DD.
  • Countries are ISO 3166-1 alpha-2 (AR, CO, MX).
  • HTTPS only. Webhook URLs must be HTTPS too.

Errors

Failures return an HTTP error status and a single-field body:
See Errors for status codes, what to retry, and the difference between an API error and a REJECTED verification — which is not an error at all.

Reference

Transaction configuration

Every rule you can enforce, field by field, with defaults.

Reading a result

The decision, the issues, and the extracted data.

Webhooks

The notification request, its signature, and how to verify it.

Issue codes

The stable catalogue of rejection and warning reasons.