Read the status of a release. After the exchange, the response also carries the released data for 30 days, while access.status is ACTIVE. data is null before the exchange, and when access is REVOKED, EXPIRED or UNAVAILABLE. A release of another business answers 404. Every response carries Cache-Control: no-store. Signa ID release must be enabled for your business. The call must use an OAuth access token with the signa-id:release scope. API keys cannot call it. No scope bundle contains this scope, full-access included, so select it by name when you create or rotate your credentials.
Authorization
oauth2ClientCredentials signa-id:releaseUse your OAuth client credentials to obtain a short-lived Bearer token from POST /oauth/token.
In: header
Scope: signa-id:release
Path Parameters
The release id. It is the id field of the release request, and the releaseId that the web SDK returns.
uuidResponse Body
application/json
application/json
application/json
application/json
curl --request GET \ --url 'https://example.com/api/external/signa-id/releases/b84c0427-231c-44c2-b397-e528a775962f'{ "message": "Signa ID release retrieved.", "data": { "release": { "id": "b84c0427-231c-44c2-b397-e528a775962f", "status": "EXCHANGED", "purpose": "Open your trading account", "scopes": [ "document_images", "id_document", "identity" ], "origin": "https://yourapp.com", "reference": "user_10482", "expires_at": "2026-10-05T10:44:22.000Z", "released_at": "2026-10-05T10:19:47.000Z", "exchanged_at": "2026-10-05T10:20:03.000Z", "access": { "status": "ACTIVE", "expires_at": "2026-11-04T10:19:47.000Z" }, "created_at": "2026-10-05T10:14:22.000Z" }, "data": { "verification": { "status": "VERIFIED", "verified_at": "2026-09-12T14:03:51.000Z", "released_at": "2026-10-05T10:19:47.000Z", "liveness": "PASSED", "face_match": "PASSED" }, "identity": { "first_name": "Amara", "middle_name": null, "last_name": "Okafor", "date_of_birth": "1993-04-17", "nationality": "NGA" }, "id_document": { "type": "PASSPORT", "number": "A05729314", "issuing_country": "NGA", "issue_date": "2021-06-02", "expiry_date": "2031-06-01" }, "document_images": [ { "id": "doc:901", "document_type": "PASSPORT", "document_side": "FRONT_SIDE", "content_type": "image/jpeg", "available": true, "unavailable_reason": null } ] } }}POSTExchange a release code
Exchange the code from the popup for the released data. Call this endpoint from your server. The code works one time only, for 5 minutes, and only for your business. If the code expires before the exchange, the data cannot be read: create a new release request. Check that `data.release.id` is the release that you created for this person. When access is not ACTIVE at the exchange, the code is used up and the call answers 404. This endpoint allows 30 requests each minute for each business. Every response carries `Cache-Control: no-store`. Signa ID release must be enabled for your business. The call must use an OAuth access token with the `signa-id:release` scope. API keys cannot call it. No scope bundle contains this scope, `full-access` included, so select it by name when you create or rotate your credentials.
GETGet a release document URL
Get a short-lived download URL for one image in `data.document_images`. The URL is valid for 15 minutes. The release must include the document_images scope, you must have exchanged the code, and `access.status` must be ACTIVE. Otherwise the call answers 404. This endpoint allows 30 requests each minute and 600 requests each hour for each business, together with the session document URL endpoint. Every response carries `Cache-Control: no-store`. Signa ID release must be enabled for your business. The call must use an OAuth access token with the `signa-id:release` scope. API keys cannot call it. No scope bundle contains this scope, `full-access` included, so select it by name when you create or rotate your credentials.