Create a session, send an applicant through a hosted country-aware flow, and consume a signed outcome without coupling your product to each downstream verification vendor.
Create a tenant-scoped session against an active, immutable policy version.
Applicant access
Issue time-limited applicant links without placing identity evidence in the URL or staff interface.
Security model
Preserve policy checksums, authorization boundaries, and an auditable operational timeline.
Signed webhooks
Consume signed status events with stable event IDs, retry handling, and receiver-side deduplication.
Current release boundary
The API is operating as a synthetic sandbox preview. Endpoint schemas, idempotency, tenant isolation, API-key scope, signed webhook behavior, and deterministic test identities are built; public partner credentials and production provider access remain gated.