Skip to main content
With the REST API, your backend starts the verification, your UI handles the user step, and your backend reads the result. Before you start Every call uses HTTP Basic auth with the App ID and App Secret against https://api.hopae.com/connect/v2.

1. Find a connection

status=enabled returns exactly the connections you can start for the default workflow. For each one, note connectionId, flowTypes, and userInputSchema (the fields to send). See Get Connections.

2. Create a verification

  • Send one of connectionId, connectionInstanceId, or providerId. Add credentialId to narrow a providerId that has several connections. An ambiguous one returns 400.
  • Optional: workflowId (otherwise the default workflow), redirectUri (for redirect flows).
  • The workflow decides which claims are returned. You do not send claims.
See Create Verification and User Input.

3. Handle the flow

Act on flowType:
Full responses and diagrams for each type: Flow Types.

4. Poll until finished

Skip this for query: its create response is already final. Poll GET /verifications/{id} until the status is completed, failed, or cancelled. Wait polling.intervalMs between calls (each non-terminal response has it). Stop at expiresAt: a verification not finished by then has expired and is deleted, so later calls return 404. See Expiry.
For qr and push, your polls drive the verification: Hopae checks the provider only when you poll. If you stop polling, the status stops updating and no terminal webhook is sent. Redirect and dc verifications finish without polling.
Statuses are explained in Verification Flow.

5. Read the result

When the status is completed:
Response (abridged)
  • Read identity data from user. To recognise a returning person, use user.source_id, not sub.
  • Add provenance=true and missing_claims=true to the query for the audit trail and the claims the source could not provide.
  • Read it before expiresAt. After that the result is gone. See Expiry.
The full payload, including match results, is in Return Data.

Cancel

DELETE /verifications/{id} cancels a verification that has not finished (204). A completed, failed, or cancelled one answers 409 SESSION_INVALID_STATUS_TRANSITION. See Cancel Verification.

Errors

Errors share one envelope. Switch on error.code and quote request_id to support.
Every code and what to do: Error Codes.