canonical: https://jentic.com/apis/veriff.com/veriff

# Veriff Public API

Veriff's Identity Verification API allows you to create verification sessions, upload end-user media, and retrieve verification decisions. Use this API when you wish to implement your own front-end or collect media yourself without using Veriff's native SDKs. The API exposes 13 endpoints secured with apiKey authentication.

## For AI agents

Programmatically create a verification session, update a verification session. Covers 13 operations with apiKey authentication.

## Scope

Does not handle payments, communications, or crm - use for identity and authentication only.

## Capabilities

- Create a verification session
- Update a verification session
- Delete a verification session
- Upload media for a session
- Query session media

## Use cases

### Identity and Authentication Operations

Use the Veriff Public API to perform identity auth operations programmatically. The API provides 13 endpoints covering core functionality including create a verification session, update a verification session, delete a verification session.

Example prompt: Call POST /sessions to create a verification session

### Automated Sessions Management

Automate sessions operations by combining multiple Veriff Public API endpoints. Agents can update a verification session and then delete a verification session in a single workflow.

Example prompt: Call PATCH `/sessions/{sessionId}` to update a verification session, then verify the result

### AI Agent Integration via Jentic

AI agents discover and call Veriff Public API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle apiKey tokens manually.

Example prompt: Search Jentic for 'create a verification session', load the operation schema, and execute with Jentic-managed credentials

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| POST | `/sessions` | Create a verification session |
| PATCH | `/sessions/{sessionId}` | Update a verification session |
| DELETE | `/sessions/{sessionId}` | Delete a verification session |
| POST | `/sessions/validate-registry` | Create session and validate national ID |
| POST | `/sessions/{sessionId}/media` | Upload media for a session |
| GET | `/sessions/{sessionId}/media` | Query session media |
| POST | `/sessions/{sessionId}/collected-data` | Upload collected data |
| GET | `/sessions/{sessionId}/decision` | Get verification decision |

## Key resources

- **Sessions** — Create and manage verification sessions.
- **Media** — Upload and retrieve media for verification sessions.
- **Decisions** — Retrieve verification decisions and extracted data.
- **Feedback** — Submit and retrieve fraud reports.
- **Registries** — Mexican registry verification endpoints.

## Why Jentic

- **Setup:** Wiring the Veriff Public API by hand means setting the x-auth-client key header, signing requests with the HMAC header, and pointing at the base URL from your Customer Portal before you can run identity sessions. Through Jentic you install once, import the Veriff Public API from the API Directory, store the key once, and your agent calls it.
- **Permission scoping:** Veriff puts the session id in the URL path (`/sessions/{sessionId}`), so a rule can pin your agent to one verification session. You choose the operations it may call, so destructive ones like deleting a session are not included unless you add them.
- **Credential handling:** Your Veriff API key is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'create a verification session' or 'get a session decision', and Jentic returns the matching Veriff operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

## Related APIs

- **Auth0** — Alternative identity auth API
- **Okta** — Alternative identity auth API

## FAQ

### What authentication does the Veriff Public API use?

The Veriff Public API uses an API key passed in the `x-auth-client` header. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.

### Can I create a verification session with the Veriff Public API?

Yes. Use the POST /sessions endpoint. The API returns structured JSON responses that agents can parse and act on directly.

### What are the rate limits for the Veriff Public API?

Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.

### How do I create a verification session through Jentic?

Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'create a verification session'. Jentic returns the matching Veriff Public API operation with its input schema. Load the schema and execute the call - credentials are injected automatically.

### How many endpoints does the Veriff Public API have?

The Veriff Public API exposes 13 endpoints covering sessions, media, decisions operations.

### Can I limit what my agent is allowed to do with the Veriff Public API?

Yes. Because you run Jentic One yourself, you decide which Veriff operations your agent may call, so you can grant it POST /sessions to create a verification session and GET `/sessions/{sessionId}/decision` to read a result while leaving destructive calls like DELETE `/sessions/{sessionId}` out. Since Veriff carries the session id in the URL path, a rule can pin the agent to a single verification session rather than the whole account. The API key stays with your own instance and is injected only for the calls you have allowed.
