Skip to main content
GET
Returns the connections that are activated for your app. Each item carries the connection’s catalog connectionId and its connectionInstanceId (either one starts a verification with Create Verification), the connection’s userInputSchema, the claims it can return, and whether it is enabled in the resolved workflow.
Only activated connections appear here. A connection that is requested, processing, or rejected in the Console is not listed. Activation happens in the Console under Configuration → Connections. See Connection Activation.

Headers

string
required
Basic <base64(appId:appSecret)>. See Authentication.

Query Parameters

string
The workflow whose enabled set and claim curation apply. Defaults to the app’s default workflow. An unknown id returns 404 RESOURCE_NOT_FOUND. There is no silent fallback.
string
default:"all"
all lists every activated connection with its enabled flag. enabled returns only the connections that can be started in the resolved workflow, exactly what POST /verifications will accept.

Response

Returns an array of connection objects.
string
required
Your app’s activated instance of this connection. Format conn_… (connections activated before August 2026 carry cred_…). Accepted by Create Verification as an alternative to connectionId. Also reported as provenance._metadata.connection_instance_id in userinfo.
string
required
The catalog connection id (for example smart-id, cz-bankid-identify, google-wallet-us-mdl). This is the id you pass to Create Verification and to ui_connection_id on OIDC. Human-readable but opaque. Read provider.id and credential.id instead of parsing it.
object
required
Catalog provider with required id, name, and logoUrl. Use provider.id as the providerId start key.
object
required
Catalog credential with required id, name, logoUrl, countries (lowercase ISO country codes), loa (numeric assurance levels), types (presentation types 1, 2, 3), and verificationModel (disclosure or match).Optional fields: displayName, displayGroupId, and matchGranularity (per_field or aggregate). Use credential.displayName ?? credential.name for the label, and credential.displayGroupId ?? connectionId for the display group. Use credential.id with providerId to select a specific credential.
string[]
required
Supported delivery mechanics, primary first: redirect, qr, push, dc, or query. See Flow Types.
object
The userInput fields this connection needs at creation time. Absent when the connection needs no input. See User Input.
string[]
required
Every claim this connection can return for your app. Includes source_id when the connection can derive a stable per-person identifier.
object
Present only when availableClaims contains source_id. primary lists the claims Hopae requests to derive source_id. fallback lists the claims tried only when a primary value is absent. Both empty means source_id is derived from protocol data and nothing extra is requested.
string[]
required
The claims the resolved workflow requests specifically for this connection (the workflow’s Claims tab in the Console). Empty when the workflow does not curate this connection.
boolean
required
Whether the resolved workflow enables this connection. A connection listed with enabled: false is activated for the app but cannot be started in that workflow. POST /verifications answers 403 PROVIDER_DISABLED_IN_WORKFLOW.
provider, credential, flowTypes, and userInputSchema are read live from the catalog. availableClaims belongs to your activated instance. connectionClaims and enabled come from the resolved workflow. Refresh cached lists when configuration or catalog data changes.

Authorizations

Authorization
string
header
required

Basic base64(appId:appSecret). See Authentication.

Query Parameters

workflowId
string

Workflow to resolve against. Defaults to the app's default workflow. An unknown id returns 404 RESOURCE_NOT_FOUND.

status
enum<string>
default:all

enabled returns only connections the workflow can start.

Available options:
all,
enabled

Response

Connections.

connectionInstanceId
string
required

Your app's activated instance: conn_…, or cred_… for older instances.

connectionId
string
required

Opaque catalog connection id. Use provider.id and credential.id instead of parsing it.

provider
object
required
credential
object
required
flowTypes
enum<string>[]
required

Supported flows, primary first.

Available options:
redirect,
qr,
push,
dc,
query
availableClaims
string[]
required
connectionClaims
string[]
required
enabled
boolean
required

Whether the resolved workflow enables this connection.

userInputSchema
object

Fields to send as userInput. Absent when no input is needed.

sourceIdBackedBy
object