Exchange the code from the popup for the released data. Call this endpoint from your server. The code works one time only, for 5 minutes, and only for your business. If the code expires before the exchange, the data cannot be read: create a new release request. Check that data.release.id is the release that you created for this person. When access is not ACTIVE at the exchange, the code is used up and the call answers 404. This endpoint allows 30 requests each minute for each business. Every response carries Cache-Control: no-store. Signa ID release must be enabled for your business. The call must use an OAuth access token with the signa-id:release scope. API keys cannot call it. No scope bundle contains this scope, full-access included, so select it by name when you create or rotate your credentials.
Authorization
oauth2ClientCredentials signa-id:releaseUse your OAuth client credentials to obtain a short-lived Bearer token from POST /oauth/token.
In: header
Scope: signa-id:release
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
curl --request POST \ --url 'https://example.com/api/external/signa-id/releases/exchange' \ --header 'Content-Type: application/json' \ --data '{ "code": "EthamT0KfpkGpItLjuYmLuo8-_PfnkFV1sVo7yVNz70"}'{ "message": "Signa ID data released.", "data": { "release": { "id": "b84c0427-231c-44c2-b397-e528a775962f", "status": "EXCHANGED", "purpose": "Open your trading account", "scopes": [ "document_images", "id_document", "identity" ], "origin": "https://yourapp.com", "reference": "user_10482", "expires_at": "2026-10-05T10:44:22.000Z", "released_at": "2026-10-05T10:19:47.000Z", "exchanged_at": "2026-10-05T10:20:03.000Z", "access": { "status": "ACTIVE", "expires_at": "2026-11-04T10:19:47.000Z" }, "created_at": "2026-10-05T10:14:22.000Z" }, "data": { "verification": { "status": "VERIFIED", "verified_at": "2026-09-12T14:03:51.000Z", "released_at": "2026-10-05T10:19:47.000Z", "liveness": "PASSED", "face_match": "PASSED" }, "identity": { "first_name": "Amara", "middle_name": null, "last_name": "Okafor", "date_of_birth": "1993-04-17", "nationality": "NGA" }, "id_document": { "type": "PASSPORT", "number": "A05729314", "issuing_country": "NGA", "issue_date": "2021-06-02", "expiry_date": "2031-06-01" }, "document_images": [ { "id": "doc:901", "document_type": "PASSPORT", "document_side": "FRONT_SIDE", "content_type": "image/jpeg", "available": true, "unavailable_reason": null } ] } }}POSTCreate a release request
Create a request for a person to release Signa ID data to your business. Send `request_token` to your page, and call `signa.requestData({ requestToken })` from a click. The request expires 30 minutes after the create. Blaaiz sends no webhook when a request expires. A release request does not count against your open session cap. This endpoint allows 30 requests each minute for each business. Every response carries `Cache-Control: no-store`. Signa ID release must be enabled for your business. The call must use an OAuth access token with the `signa-id:release` scope. API keys cannot call it. No scope bundle contains this scope, `full-access` included, so select it by name when you create or rotate your credentials.
GETGet a release
Read the status of a release. After the exchange, the response also carries the released data for 30 days, while `access.status` is ACTIVE. `data` is null before the exchange, and when access is REVOKED, EXPIRED or UNAVAILABLE. A release of another business answers 404. Every response carries `Cache-Control: no-store`. Signa ID release must be enabled for your business. The call must use an OAuth access token with the `signa-id:release` scope. API keys cannot call it. No scope bundle contains this scope, `full-access` included, so select it by name when you create or rotate your credentials.