Skip to main content
Once an ID Check session is complete, call /verify-id to get the user’s Decision, Risk Score, and Risk Flags. See Response Signals for how to interpret everything the endpoint returns. If you passed an account_id when creating the session, the response also includes account context:
  • lists — names of the lists the account is currently a member of. If the account is on an allow list, decision is Real; on a block list, Fake.
  • rules — names of rules that have triggered for this account.
Both fields are empty arrays ([]) for sessions not linked to an account. See Rules, Lists, and Verifications for details.

Exclude personal data from the response

Add ?excludePII=true to the /verify-id call to leave personal data out of the response. These fields are not returned:
  • document_data
  • photo_urls
  • video_urls
Everything else, including the decision, risk score, flags, and signals, is the same. Without the parameter, the full response is returned. The parameter applies to that call only, and webhooks still carry the full payload.
To link an account_id to a session that has already completed, use the Enroll endpoint.

API Reference

For complete details on all available endpoints and parameters, see the ID Check API Reference.