Create a DiligenceID verification session for a server-managed verification policy
GENERATED — DO NOT EDIT DIRECTLY. Produced from the canonical OpenAPI specification by
developer-docs/tools/generate-reference.mjs. Edits are overwritten on the next run.
POST
/v1.0/verification-sessionsWraps /presentations/request. The caller selects an approved policy identifier; DiligenceID resolves the required claims and issuer trust from that policy's frozen snapshot. Never accepts raw claim names from external callers. Supports an optional Idempotency-Key header, scoped to tenant + authenticated client. Scope: verification.execute.
| Operation ID | VerificationSessions_Create |
| Plane | Product |
| Versioning | In the path |
| Authentication | Authorization: ApiKey {key} |
| Required scope | verification.execute |
| Concurrency | Not applicable |
Request headers
| Name | Type | Required | Description |
|---|---|---|---|
Idempotency-Key |
string |
No | Replays the original result for a repeated call. The same key with a different payload is rejected with 409. |
x-ms-client-request-id |
string |
No | Optional caller-supplied correlation value, echoed back on the response and recorded in diagnostics. It never influences authentication, tenant or environment selection, resource lookup or idempotency. |
Request body
Type: CreateVerificationSessionRequest
| Field | Type | Required | Description |
|---|---|---|---|
policy |
string |
Yes | |
purpose |
string, nullable |
No |
Responses
| Status | Body | Meaning |
|---|---|---|
201 |
ApiEnvelopeOfVerificationSessionResponse |
Created. |
400 |
ErrorEnvelope |
The request was not valid. See error model. |
401 |
ErrorEnvelope |
Authentication failed — the API key is missing, malformed, revoked or expired. |
403 |
ErrorEnvelope |
Authenticated, but the key does not carry the required scope. |
409 |
ErrorEnvelope |
The request conflicts with the resource state, or an idempotency key was reused with a different payload. |
429 |
ErrorEnvelope |
Throttled. See rate limits. |
Response headers: x-ms-request-id
Example
curl -X POST "https://api.example.diligence.id/v1.0/verification-sessions" \
-H "Authorization: ApiKey YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{ }'