Skip to main content
GET
Returns the verified user data and, for match connections, the match outcome. The audit trail (provenance) and missing_claims are returned only when you request them with the query parameters below. Available when the session is completed, or when it failed with error.code: "loa_insufficient" (the lax assurance result).

Headers

string
required
Basic <base64(appId:appSecret)>. See Authentication.

Path Parameters

string
required
The session id.

Query Parameters

boolean
default:"false"
true (or 1) adds the provenance block, including the connection identity under provenance._metadata. Omitted or any other value leaves it out.
boolean
default:"false"
true (or 1) adds the missing_claims list. Omitted or any other value leaves it out.

Response

Connection identity appears only under provenance._metadata, never as top-level userinfo fields, so request provenance=true to read it. The IDs are snapshotted when the session is created.
string
required
Subject identifier. In Hopae Connect this is the verificationId. A verification is a one-time event, not an account. Use user.source_id to recognise a returning person.
number
Numeric Level of Assurance, 1 to 5.
string
Human-readable assurance label (e.g. substantial).
string
Authentication Context Class Reference. Present when the provider asserted a LoA explicitly.
string
With provenance=true. The provider of the connection that ran, as a catalog provider id (e.g. smart-id, google-wallet).
string
The catalog connection id (e.g. google-wallet-us-mdl). Human-readable but opaque: read provider_id and credential_id instead of parsing it.
string
The credential that was verified (e.g. us-mdl).
string
With provenance=true. The activated connection instance the session ran on (conn_…), the instance resolved at creation.
string
required
disclosure (attributes under user) or match (comparison under match, with user echoing the verified subset of what you submitted). See Verification Model.
string[]
Returned only with missing_claims=true. Requested claims the source could not provide. Includes source_id when it was requested but could not be derived for this person. [] when nothing is missing.
object | null
The verified attributes, limited to the claims the workflow requested. For match connections it contains the verified subset of the values you submitted in userInput. Per-field providers: only fields with matched: true. Aggregate providers: every submitted field when the aggregate outcome is true, otherwise empty.See Normalized User Data for the full catalog. Provider-specific claims may also appear.
object
Present only when verification_model is match.
object
Returned only with provenance=true. What the source returned, as handed over by the provider. See Return Data Model.Catalog identity is carried by provenance._metadata.provider_id, connection_id, credential_id, and connection_instance_id. It is never repeated at the top level of userinfo.
object
Present only for the one non-completed state this endpoint serves: a session that failed with code: "loa_insufficient" (the provider returned a lower LoA than the workflow asked for). The data is still returned so you can decide how to handle it.
Workflow decision nodes (check-min-loa, check-claim, evaluate) add their outputs to this response, for example metLoa, hasClaim, or computed.<field>. See Workflow Nodes.
provenance.presentation.credentials[].claims is the provider’s own response in its native field names (for match providers, typically per-field confirmations). userInput, match.submitted_fields, and match.details use OIDC-normalized keys (e.g. name, birthdate), so the audit trail stays aligned with the source while your request and the outcome stay normalized.

Errors

Authorizations

Authorization
string
header
required

Basic base64(appId:appSecret). See Authentication.

Path Parameters

verificationId
string
required

The session id.

Query Parameters

provenance
boolean
default:false

true (or 1) adds the provenance block, including the connection identity under provenance._metadata. Off by default.

missing_claims
boolean
default:false

true (or 1) adds the missing_claims list. Off by default.

Response

Verified data.

user
object

Verified attributes, limited to the claims the workflow requested. source_id appears only when selected in the workflow and the source provided it. See Normalized User Data.

missing_claims
string[]

Returned only with missing_claims=true. Requested claims the source could not provide (may include source_id).

acr
string

Authentication Context Class Reference.

hopae_loa
number

Numeric Level of Assurance, 1 to 5.

hopae_loa_label
string

LoA label.

verification_model
enum<string>

disclosure or match.

Available options:
disclosure,
match
match
object

Match outcome: matched, granularity, submitted_fields, details. Match connections only.

error
object

Present when the achieved LoA was lower than requested (loa_insufficient).

provenance
object

Returned only with provenance=true. What the source returned, plus verification metadata. See Return Data Model.

sub
string

The verification id. New for every verification, so it is not a stable user identifier. Use user.source_id to recognise a returning person. Always the last key.