API guide
A public view of the planned lifecycle and resources. This page prepares integrations; it is not yet a stable API contract.
Candidate conventions
- HTTPS exchanges with UTF-8 JSON bodies.
- Access token limited to an organisation, roles and scopes.
- Opaque identifiers;
tenant_idis derived from authorisation and never trusted as access proof. Idempotency-Keyheader required for replayable mutations.- RFC 3339 UTC timestamps and a correlation identifier in every response.
- Cursor pagination for collections; no raw biometric data in the API.
The base URL, token issuance, final scopes and quotas are not published. Integration secrets will never be delivered through this website.
Create and conclude a verification
- Create an event with its context, time window and requested level.
- Add authorised participants and activate the event.
- Start a round; applications perform the required controls.
- Read a factual verdict and any degradation reasons.
- Complete the event, then request a report and evidence bundle.
POST /events
Authorization: Bearer <access_token>
Idempotency-Key: 7dd95eb4-5983-48c6-80bd-a7a857ba0e9a
Content-Type: application/json
{
"context": "Executive committee, 8 April 2026",
"assurance_level": "HIGH",
"starts_at": "2026-04-08T08:00:00Z",
"ends_at": "2026-04-08T10:00:00Z"
}Field names and values may change before a stable OpenAPI specification is released.
Events and participants
/eventsCreate a time-bounded event.
/events/{event_id}Read context and current state.
/events/{event_id}Edit a draft before activation.
/events/{event_id}/activateFreeze the applicable policy and open the event.
/events/{event_id}/participantsInvite a participant under minimisation rules.
/events/{event_id}/participantsRead authorised factual statuses.
/events/{event_id}/completeClose the event and prevent new rounds.
Rounds and challenges
/events/{event_id}/roundsStart a control with a fresh temporal context.
/rounds/{round_id}/subjects/{subject_id}/readyConfirm readiness from the subject’s bound device.
/challenges/{challenge_id}Retrieve the challenge authorised for the caller.
/challenges/{challenge_id}/observations/finalizeFinalise a signed observation.
/rounds/{round_id}/finalizeStop collection and calculate the result.
/rounds/{round_id}/verdictRead the achieved level and associated reasons.
Raw frames, challenge secrets and anti-fraud parameters are not exposed through management APIs.
Reports and verification
/events/{event_id}/reportsCreate a report from a completed event.
/reports/{report_id}Read metadata and generation status.
/reports/{report_id}/bundleDownload the authorised evidence bundle.
/reports/verifyVerify the integrity and signatures of a bundle.
The API reports completed controls and their limits. Integrators remain responsible for payment, authorisation and approval rules.
Statuses and errors
| HTTP | Use | Expected behaviour |
|---|---|---|
400 | Invalid request | Correct the reported fields. |
401 | Missing or expired authentication | Obtain a fresh token. |
403 | Insufficient scope, role or tenant | Do not retry without an authorisation change. |
409 | Incompatible state or idempotency conflict | Read the resource before acting again. |
422 | Business rule not satisfied | Display the reason; never turn failure into success. |
429 | Temporary limit | Honor Retry-After with backoff. |
{
"error": {
"code": "EVENT_NOT_ACTIVE",
"message": "The event is not active.",
"correlation_id": "req_01J...",
"retryable": false
}
}Try “event”, “round” or “report”.
