Skip to main content
GET
Fetch the verification result using the access token from /token. With hopae/idv, the response follows the same data model as Get Verification UserInfo on the REST API.
The ID token contains no personal data. user, provenance, match, and missing_claims are only returned here, and only when the authorization request included the hopae (or idv) scope. With openid alone you receive sub, the available LoA fields, and verification_model. provenance (which carries the connection identity) and missing_claims are also opt-in per request: add provenance=true and missing_claims=true.

Headers

string
default:"Bearer eyJhbGci..."
required
Bearer access token issued by /token (valid for 10 minutes).

Query Parameters

Send these on the query string of a GET, or in the form body of a POST.
boolean
default:"false"
true (or 1) adds the provenance block, including the connection identity under provenance._metadata. Omitted or any other value leaves it out.
boolean
default:"false"
true (or 1) adds the missing_claims list. Omitted or any other value leaves it out.

Response

OIDC filters fields by the granted scopes. Unlike REST, it does not expose a top-level error. Assurance failures are available under provenance._metadata.error. Connection identity appears only under provenance._metadata, never as top-level userinfo fields, so request provenance=true to read it. The IDs are snapshotted when the session is created.
string
required
The verification id. A new value for every verification. Use user.source_id to recognise a returning person.
string
Authentication Context Class Reference, present when the provider asserted a LoA.
number
string
Human-readable label (e.g. substantial).
string
The provider of the connection that ran, as a catalog provider id (e.g. smart-id).
string
The catalog connection id (e.g. google-wallet-us-mdl). Opaque. Read provider_id and credential_id for its parts.
string
The credential that was verified (e.g. us-mdl). Requires the hopae scope.
string
The activated connection instance the session ran on (conn_…). Requires the hopae scope.
string
disclosure or match.
string[]
Returned only with missing_claims=true. Requested claims the source could not provide (including source_id when it could not be derived).
object
Verified attributes limited to the workflow’s requested claims. For match, the verified subset of the values you submitted. See Normalized User Data.
object
Match envelope (matched, granularity, submitted_fields, details). Present only for match connections.
object
Returned only with provenance=true. What the source returned: presentation.credentials[] (each with the provider’s raw claims and, when issued, evidence) and _metadata. See Return Data Model.
object
Present only when the verification finished with a lower LoA than requested (code: "loa_insufficient").
Workflow decision nodes add their outputs here (metLoa, hasClaim, computed.*). Dynamic evaluate outputs that are not on the OIDC claims whitelist are only available through the REST userinfo endpoint.

Example

Errors

Authorizations

Authorization
string
header
required

Access token from /token.

Query Parameters

provenance
boolean
default:false

true (or 1) adds the provenance block, including the connection identity under provenance._metadata. Off by default. On POST /userinfo, send it in the form body.

missing_claims
boolean
default:false

true (or 1) adds the missing_claims list. Off by default. On POST /userinfo, send it in the form body.

Response

Verified data.

user
object

Verified attributes, limited to the claims the workflow requested. source_id appears only when selected in the workflow and the source provided it. See Normalized User Data.

missing_claims
string[]

Returned only with missing_claims=true. Requested claims the source could not provide (may include source_id).

acr
string

Authentication Context Class Reference.

hopae_loa
number

Numeric Level of Assurance, 1 to 5.

hopae_loa_label
string

LoA label.

verification_model
enum<string>

disclosure or match.

Available options:
disclosure,
match
match
object

Match outcome: matched, granularity, submitted_fields, details. Match connections only.

error
object

Present when the achieved LoA was lower than requested (loa_insufficient).

provenance
object

Returned only with provenance=true. What the source returned, plus verification metadata. See Return Data Model.

sub
string

The verification id. New for every verification, so it is not a stable user identifier. Use user.source_id to recognise a returning person. Always the last key.