curl --request POST \
--url 'https://api.hopae.com/connect/v2/verifications' \
--user '{appId}:{appSecret}' \
--header 'Content-Type: application/json' \
--data '{
"connectionId": "smart-id",
"userInput": { "registrationId": "PNOEE-38001085718" }
}'
{
"verificationId": "019bc4f2-8a31-7c5e-9d02-4f7a1b3e60d8",
"status": "awaiting_user_action",
"flowType": "push",
"flowDetails": {
"verificationCode": "4823",
"description": "Confirm this code matches the one shown in your Smart-ID app"
},
"createdAt": "2026-09-03T09:18:31.774Z",
"expiresAt": "2026-09-03T09:48:31.774Z",
"polling": { "intervalMs": 2000, "maxDurationMs": 1800000 },
"connectionInstanceId": "conn_01J8XK2P4M9QR3TV",
"connectionId": "smart-id",
"credentialId": "smart-id",
"providerId": "smart-id",
"verificationModel": "disclosure"
}
{
"verificationId": "019bc4f6-2b41-7f0c-9a55-3e8d1c7b2a90",
"status": "completed",
"flowType": "query",
"createdAt": "2026-09-03T09:24:10.512Z",
"expiresAt": "2026-09-03T09:54:10.512Z",
"connectionInstanceId": "conn_01J8XP4T2H7MCV5N",
"connectionId": "ng-nin",
"credentialId": "ng-nin",
"providerId": "ng-nin",
"verificationModel": "disclosure"
}
{
"verificationId": "019bc4f6-7d18-7a2e-8c61-5b9f0e3d4c21",
"status": "failed",
"flowType": "query",
"error": {
"type": "verification_error",
"code": "INVALID_ID_NUMBER",
"message": "Invalid or unknown ID number. Please check and try again."
},
"createdAt": "2026-09-03T09:25:47.093Z",
"expiresAt": "2026-09-03T09:55:47.093Z",
"connectionInstanceId": "conn_01J8XP4T2H7MCV5N",
"connectionId": "ng-nin",
"credentialId": "ng-nin",
"providerId": "ng-nin",
"verificationModel": "disclosure"
}
{
"verificationId": "019bc4f3-1c02-7d4a-8b7e-2e0f9c5a7d11",
"status": "awaiting_user_action",
"flowType": "redirect",
"flowDetails": {
"authorizationUrl": "https://connect.hopae.com/v/019bc4f3-1c02-7d4a-8b7e-2e0f9c5a7d11"
},
"createdAt": "2026-09-03T09:15:02.118Z",
"expiresAt": "2026-09-03T09:45:02.118Z",
"polling": { "intervalMs": 2000, "maxDurationMs": 1800000 },
"connectionInstanceId": "conn_01J8XM0R7C2VHK4Y",
"connectionId": "mitid",
"credentialId": "mitid",
"providerId": "mitid",
"verificationModel": "disclosure"
}
{
"verificationId": "019bc4f4-5e77-7a9c-b0d1-6c3a2f8e9b44",
"status": "awaiting_user_action",
"flowType": "qr",
"flowDetails": {
"qrData": "<value to render as a QR code>"
},
"createdAt": "2026-09-03T09:12:44.301Z",
"expiresAt": "2026-09-03T09:42:44.301Z",
"polling": { "intervalMs": 2000, "maxDurationMs": 1800000 },
"connectionInstanceId": "conn_01J8XN2C6QF9W1AZ",
"connectionId": "freja-plus",
"credentialId": "freja-plus",
"providerId": "freja",
"verificationModel": "disclosure"
}
{
"verificationId": "019bc4f5-9a10-7e3b-8f42-7d1c0b9a3e55",
"status": "awaiting_user_action",
"flowType": "dc",
"flowDetails": {
"linkData": "https://connect.hopae.com/dc/us-mdl?verification_id=019bc4f5-9a10-7e3b-8f42-7d1c0b9a3e55"
},
"createdAt": "2026-09-03T09:21:09.442Z",
"expiresAt": "2026-09-03T09:51:09.442Z",
"polling": { "intervalMs": 2000, "maxDurationMs": 1800000 },
"connectionInstanceId": "conn_01J8XN9W3D6BQZ1F",
"connectionId": "google-wallet-us-mdl",
"credentialId": "us-mdl",
"providerId": "google-wallet",
"verificationModel": "disclosure"
}
Create Verification
Start a new identity verification session against one of your activated connections.
curl --request POST \
--url 'https://api.hopae.com/connect/v2/verifications' \
--user '{appId}:{appSecret}' \
--header 'Content-Type: application/json' \
--data '{
"connectionId": "smart-id",
"userInput": { "registrationId": "PNOEE-38001085718" }
}'
{
"verificationId": "019bc4f2-8a31-7c5e-9d02-4f7a1b3e60d8",
"status": "awaiting_user_action",
"flowType": "push",
"flowDetails": {
"verificationCode": "4823",
"description": "Confirm this code matches the one shown in your Smart-ID app"
},
"createdAt": "2026-09-03T09:18:31.774Z",
"expiresAt": "2026-09-03T09:48:31.774Z",
"polling": { "intervalMs": 2000, "maxDurationMs": 1800000 },
"connectionInstanceId": "conn_01J8XK2P4M9QR3TV",
"connectionId": "smart-id",
"credentialId": "smart-id",
"providerId": "smart-id",
"verificationModel": "disclosure"
}
{
"verificationId": "019bc4f6-2b41-7f0c-9a55-3e8d1c7b2a90",
"status": "completed",
"flowType": "query",
"createdAt": "2026-09-03T09:24:10.512Z",
"expiresAt": "2026-09-03T09:54:10.512Z",
"connectionInstanceId": "conn_01J8XP4T2H7MCV5N",
"connectionId": "ng-nin",
"credentialId": "ng-nin",
"providerId": "ng-nin",
"verificationModel": "disclosure"
}
{
"verificationId": "019bc4f6-7d18-7a2e-8c61-5b9f0e3d4c21",
"status": "failed",
"flowType": "query",
"error": {
"type": "verification_error",
"code": "INVALID_ID_NUMBER",
"message": "Invalid or unknown ID number. Please check and try again."
},
"createdAt": "2026-09-03T09:25:47.093Z",
"expiresAt": "2026-09-03T09:55:47.093Z",
"connectionInstanceId": "conn_01J8XP4T2H7MCV5N",
"connectionId": "ng-nin",
"credentialId": "ng-nin",
"providerId": "ng-nin",
"verificationModel": "disclosure"
}
{
"verificationId": "019bc4f3-1c02-7d4a-8b7e-2e0f9c5a7d11",
"status": "awaiting_user_action",
"flowType": "redirect",
"flowDetails": {
"authorizationUrl": "https://connect.hopae.com/v/019bc4f3-1c02-7d4a-8b7e-2e0f9c5a7d11"
},
"createdAt": "2026-09-03T09:15:02.118Z",
"expiresAt": "2026-09-03T09:45:02.118Z",
"polling": { "intervalMs": 2000, "maxDurationMs": 1800000 },
"connectionInstanceId": "conn_01J8XM0R7C2VHK4Y",
"connectionId": "mitid",
"credentialId": "mitid",
"providerId": "mitid",
"verificationModel": "disclosure"
}
{
"verificationId": "019bc4f4-5e77-7a9c-b0d1-6c3a2f8e9b44",
"status": "awaiting_user_action",
"flowType": "qr",
"flowDetails": {
"qrData": "<value to render as a QR code>"
},
"createdAt": "2026-09-03T09:12:44.301Z",
"expiresAt": "2026-09-03T09:42:44.301Z",
"polling": { "intervalMs": 2000, "maxDurationMs": 1800000 },
"connectionInstanceId": "conn_01J8XN2C6QF9W1AZ",
"connectionId": "freja-plus",
"credentialId": "freja-plus",
"providerId": "freja",
"verificationModel": "disclosure"
}
{
"verificationId": "019bc4f5-9a10-7e3b-8f42-7d1c0b9a3e55",
"status": "awaiting_user_action",
"flowType": "dc",
"flowDetails": {
"linkData": "https://connect.hopae.com/dc/us-mdl?verification_id=019bc4f5-9a10-7e3b-8f42-7d1c0b9a3e55"
},
"createdAt": "2026-09-03T09:21:09.442Z",
"expiresAt": "2026-09-03T09:51:09.442Z",
"polling": { "intervalMs": 2000, "maxDurationMs": 1800000 },
"connectionInstanceId": "conn_01J8XN9W3D6BQZ1F",
"connectionId": "google-wallet-us-mdl",
"credentialId": "us-mdl",
"providerId": "google-wallet",
"verificationModel": "disclosure"
}
Headers
Basic <base64(appId:appSecret)>. See Authentication.application/json.Request Body
smart-id, google-wallet-us-mdl). It resolves to your app’s activated instance of that connection. Provide exactly one of connectionId, connectionInstanceId, or providerId.connectionId or providerId: the activated connection instance (conn_…) from Get Connections.provider.id from Get Connections). Resolves among the workflow’s enabled connections. If several match, the request returns 400 and names the candidates. Add credentialId or use connectionId.credential.id from Get Connections). Only accepted together with providerId. The pair identifies one catalog connection. A credential id alone does not identify a provider.400 VALIDATION_INVALID_PARAMETER. An app with no workflow returns 409 WORKFLOW_NOT_CONFIGURED.match connection. One flat map. The fields come from the connection’s userInputSchema. Required fields are validated before the session starts: a missing field or an out-of-range select value returns HTTP 400, and a value the connection rejects returns HTTP 422 VALIDATION_INVALID_USER_DATA. Keys the schema does not declare are dropped. See User Input.{
"registrationId": "PNOEE-38001085718"
}
redirect flow (otherwise 400 VALIDATION_REDIRECT_URI_REQUIRED). REST creation does not select a default from the app’s OIDC redirect URI allowlist.qr, redirect, push, dc, or query. The response’s flowType reports the flow that was actually started.requestedClaims, requestedLoa, and matchData from v1 are not accepted. Unknown fields are ignored. See Workflows.Provider-key example
{
"providerId": "google-wallet",
"credentialId": "us-mdl"
}
Response
Returns201 Created.
sub of the userinfo response.awaiting_user_action immediately after creation. Later values: authenticating, completed, failed, cancelled (processing is reserved and not currently returned). An unfinished verification expires at expiresAt and is then deleted. See Verification Flow.A query connection (lookup eID such as ng-nin or br-cpf) runs its lookup inside this call, so status is already completed or failed. See Flow Types.qr, redirect, push, dc, or query. See Flow Types.flowType.Show Properties
Show Properties
qr flows: the payload to render as a QR code.qr and dc flows: a Hopae-hosted URL that opens the wallet or app on a phone. Safe to open directly on the user’s device.qr flows on some providers: token for same-device app launch.redirect flows: the URL to send the user to.push flows: the code the user must confirm in their app. Absent for providers that do not issue one (then flowDetails is omitted).push flows: instruction to show next to verificationCode.query connection. Same shape as in Get Verification: type, code (for example INVALID_ID_NUMBER), message.GET /verifications/{id} returns 404. Stop polling at this time and start a new verification. See Expiry.google-wallet-us-mdl.us-mdl.google-wallet.disclosure or match. Tells you which userinfo shape to expect.curl --request POST \
--url 'https://api.hopae.com/connect/v2/verifications' \
--user '{appId}:{appSecret}' \
--header 'Content-Type: application/json' \
--data '{
"connectionId": "smart-id",
"userInput": { "registrationId": "PNOEE-38001085718" }
}'
{
"verificationId": "019bc4f2-8a31-7c5e-9d02-4f7a1b3e60d8",
"status": "awaiting_user_action",
"flowType": "push",
"flowDetails": {
"verificationCode": "4823",
"description": "Confirm this code matches the one shown in your Smart-ID app"
},
"createdAt": "2026-09-03T09:18:31.774Z",
"expiresAt": "2026-09-03T09:48:31.774Z",
"polling": { "intervalMs": 2000, "maxDurationMs": 1800000 },
"connectionInstanceId": "conn_01J8XK2P4M9QR3TV",
"connectionId": "smart-id",
"credentialId": "smart-id",
"providerId": "smart-id",
"verificationModel": "disclosure"
}
{
"verificationId": "019bc4f6-2b41-7f0c-9a55-3e8d1c7b2a90",
"status": "completed",
"flowType": "query",
"createdAt": "2026-09-03T09:24:10.512Z",
"expiresAt": "2026-09-03T09:54:10.512Z",
"connectionInstanceId": "conn_01J8XP4T2H7MCV5N",
"connectionId": "ng-nin",
"credentialId": "ng-nin",
"providerId": "ng-nin",
"verificationModel": "disclosure"
}
{
"verificationId": "019bc4f6-7d18-7a2e-8c61-5b9f0e3d4c21",
"status": "failed",
"flowType": "query",
"error": {
"type": "verification_error",
"code": "INVALID_ID_NUMBER",
"message": "Invalid or unknown ID number. Please check and try again."
},
"createdAt": "2026-09-03T09:25:47.093Z",
"expiresAt": "2026-09-03T09:55:47.093Z",
"connectionInstanceId": "conn_01J8XP4T2H7MCV5N",
"connectionId": "ng-nin",
"credentialId": "ng-nin",
"providerId": "ng-nin",
"verificationModel": "disclosure"
}
{
"verificationId": "019bc4f3-1c02-7d4a-8b7e-2e0f9c5a7d11",
"status": "awaiting_user_action",
"flowType": "redirect",
"flowDetails": {
"authorizationUrl": "https://connect.hopae.com/v/019bc4f3-1c02-7d4a-8b7e-2e0f9c5a7d11"
},
"createdAt": "2026-09-03T09:15:02.118Z",
"expiresAt": "2026-09-03T09:45:02.118Z",
"polling": { "intervalMs": 2000, "maxDurationMs": 1800000 },
"connectionInstanceId": "conn_01J8XM0R7C2VHK4Y",
"connectionId": "mitid",
"credentialId": "mitid",
"providerId": "mitid",
"verificationModel": "disclosure"
}
{
"verificationId": "019bc4f4-5e77-7a9c-b0d1-6c3a2f8e9b44",
"status": "awaiting_user_action",
"flowType": "qr",
"flowDetails": {
"qrData": "<value to render as a QR code>"
},
"createdAt": "2026-09-03T09:12:44.301Z",
"expiresAt": "2026-09-03T09:42:44.301Z",
"polling": { "intervalMs": 2000, "maxDurationMs": 1800000 },
"connectionInstanceId": "conn_01J8XN2C6QF9W1AZ",
"connectionId": "freja-plus",
"credentialId": "freja-plus",
"providerId": "freja",
"verificationModel": "disclosure"
}
{
"verificationId": "019bc4f5-9a10-7e3b-8f42-7d1c0b9a3e55",
"status": "awaiting_user_action",
"flowType": "dc",
"flowDetails": {
"linkData": "https://connect.hopae.com/dc/us-mdl?verification_id=019bc4f5-9a10-7e3b-8f42-7d1c0b9a3e55"
},
"createdAt": "2026-09-03T09:21:09.442Z",
"expiresAt": "2026-09-03T09:51:09.442Z",
"polling": { "intervalMs": 2000, "maxDurationMs": 1800000 },
"connectionInstanceId": "conn_01J8XN9W3D6BQZ1F",
"connectionId": "google-wallet-us-mdl",
"credentialId": "us-mdl",
"providerId": "google-wallet",
"verificationModel": "disclosure"
}
Errors
| HTTP | Code | When |
|---|---|---|
| 400 | VALIDATION_INVALID_PARAMETER | Unknown workflowId. Missing or multiple start keys. credentialId without providerId. An ambiguous providerId. The connection is not available for this app or not activated for your app. A required userInput field is missing or invalid |
| 400 | VALIDATION_REDIRECT_URI_REQUIRED | The connection starts a redirect flow and the request has no redirectUri |
| 403 | PROVIDER_DISABLED_IN_WORKFLOW | The connection is activated but not enabled in the resolved workflow |
| 404 | RESOURCE_NOT_FOUND | Unknown connectionId or provider/credential pair, or a connectionInstanceId that does not belong to your app |
| 409 | WORKFLOW_NOT_CONFIGURED | The app has no workflow. Create one before starting a verification |
| 422 | VALIDATION_INVALID_USER_DATA | A userInput value is present but the connection or its provider rejects it |
| 502 | PROVIDER_INITIALIZATION_FAILED | The provider refused to start the session. The verification is recorded as failed |
Authorizations
Basic base64(appId:appSecret). See Authentication.
Body
- Option 1
- Option 2
- Option 3
Provide exactly one of connectionId, connectionInstanceId, or providerId. credentialId is valid only with providerId.
Catalog connection id from Get Connections. Mutually exclusive with connectionInstanceId and providerId.
"smart-id"
Activated instance (conn_…). Mutually exclusive with connectionId and providerId.
Workflow to run. Defaults to the app's default workflow. An unknown id returns 400. An app with no workflow returns 409 WORKFLOW_NOT_CONFIGURED.
Values the connection needs, per its userInputSchema.
{ "registrationId": "PNOEE-38001085718" }
Where to send the user after a redirect flow. Supply it explicitly when the flow needs a return destination. REST does not default from the OIDC allowlist.
Preferred flow when the connection supports several.
qr, redirect, push, dc, query Catalog provider id. Mutually exclusive with connectionId and connectionInstanceId. Add credentialId when the provider has multiple enabled credentials.
Catalog credential id. Accepted only together with providerId.
Response
Created.
The session id.
awaiting_user_action after creation.
awaiting_user_action, authenticating, processing, completed, failed, expired, cancelled The flow that was started.
qr, redirect, push, dc, query What your UI needs next. Keys depend on flowType.
Show child attributes
Show child attributes
Present only when the session already failed at creation (a query connection): type, code, message.
ISO 8601.
ISO 8601, 30 minutes after creation.
The instance used.
Catalog connection id.
The credential.
The provider.
disclosure or match.
disclosure, match Present while the session is not terminal. Wait intervalMs between polls. It is set per connection, because some providers reject faster status reads. maxDurationMs is the session window.
Show child attributes
Show child attributes

