Skip to main content
Opens a verification for a customer and returns the sdk_token your app needs to run the flow. This is where you declare what should be verified and what counts as acceptable: the whole configuration is documented on this page.

Request

string
required
Bearer {access_token} — see Authentication.
string (UUID)
required
The customer this verification belongs to, from Create customer.
string
required
Which checks to run.
  • DOCUMENT_AND_BIOMETRIC — document capture and liveness
  • DOCUMENT_ONLY — document capture only
  • BIOMETRIC_ONLY — liveness only
object
The rules to enforce. Every field is optional and falls back to the default listed below, so {} is valid. Build it on your server from your own records — never from values sent by the app.

Response

string (UUID)
The transaction identifier. Use it to fetch the result; it also arrives on the webhook and is returned to your app by the SDK.
string (JWT)
Pass this to your mobile app and hand it to the SDK. Scoped to this transaction only.
string
Always Bearer.
integer
SDK token lifetime in seconds, derived from transaction_ttl_minutes.

Example

A full onboarding configuration, with every policy set:
Response

Defaults

What you get when you omit a field entirely:

Going deeper

Each policy has a reference page with the supporting detail — the supported document matrix, how the three face comparisons work, what happens when a device signal is missing, and how to pick thresholds:

Device policy

Document policy

Biometric policy

Blacklist policy

Next

Get transaction

Read the status and the decision.

Webhooks

Be notified as soon as the decision exists.