Read the status of a release. After the exchange, the response also carries the released data for 30 days, while access.status is ACTIVE. data is null before the exchange, and when access is REVOKED, EXPIRED or UNAVAILABLE. A release of another business answers 404. Every response carries Cache-Control: no-store. Signa ID release must be enabled for your business. The call must use an OAuth access token with the signa-id:release scope. API keys cannot call it. No scope bundle contains this scope, full-access included, so select it by name when you create or rotate your credentials.

GETapi-prod.blaaiz.com/api/external/signa-id/releases/{releaseId}

Authorization

oauth2ClientCredentials signa-id:release
AuthorizationBearer <token>

Use your OAuth client credentials to obtain a short-lived Bearer token from POST /oauth/token.

In: header

Scope: signa-id:release

Path Parameters

releaseId*string

The release id. It is the id field of the release request, and the releaseId that the web SDK returns.

Formatuuid

Response Body

application/json

application/json

application/json

application/json

Get a release
curl --request GET \  --url 'https://example.com/api/external/signa-id/releases/b84c0427-231c-44c2-b397-e528a775962f'

{  "message": "Signa ID release retrieved.",  "data": {    "release": {      "id": "b84c0427-231c-44c2-b397-e528a775962f",      "status": "EXCHANGED",      "purpose": "Open your trading account",      "scopes": [        "document_images",        "id_document",        "identity"      ],      "origin": "https://yourapp.com",      "reference": "user_10482",      "expires_at": "2026-10-05T10:44:22.000Z",      "released_at": "2026-10-05T10:19:47.000Z",      "exchanged_at": "2026-10-05T10:20:03.000Z",      "access": {        "status": "ACTIVE",        "expires_at": "2026-11-04T10:19:47.000Z"      },      "created_at": "2026-10-05T10:14:22.000Z"    },    "data": {      "verification": {        "status": "VERIFIED",        "verified_at": "2026-09-12T14:03:51.000Z",        "released_at": "2026-10-05T10:19:47.000Z",        "liveness": "PASSED",        "face_match": "PASSED"      },      "identity": {        "first_name": "Amara",        "middle_name": null,        "last_name": "Okafor",        "date_of_birth": "1993-04-17",        "nationality": "NGA"      },      "id_document": {        "type": "PASSPORT",        "number": "A05729314",        "issuing_country": "NGA",        "issue_date": "2021-06-02",        "expiry_date": "2031-06-01"      },      "document_images": [        {          "id": "doc:901",          "document_type": "PASSPORT",          "document_side": "FRONT_SIDE",          "content_type": "image/jpeg",          "available": true,          "unavailable_reason": null        }      ]    }  }}

POSTExchange a release code

Exchange the code from the popup for the released data. Call this endpoint from your server. The code works one time only, for 5 minutes, and only for your business. If the code expires before the exchange, the data cannot be read: create a new release request. Check that `data.release.id` is the release that you created for this person. When access is not ACTIVE at the exchange, the code is used up and the call answers 404. This endpoint allows 30 requests each minute for each business. Every response carries `Cache-Control: no-store`. Signa ID release must be enabled for your business. The call must use an OAuth access token with the `signa-id:release` scope. API keys cannot call it. No scope bundle contains this scope, `full-access` included, so select it by name when you create or rotate your credentials.

GETGet a release document URL

Get a short-lived download URL for one image in `data.document_images`. The URL is valid for 15 minutes. The release must include the document_images scope, you must have exchanged the code, and `access.status` must be ACTIVE. Otherwise the call answers 404. This endpoint allows 30 requests each minute and 600 requests each hour for each business, together with the session document URL endpoint. Every response carries `Cache-Control: no-store`. Signa ID release must be enabled for your business. The call must use an OAuth access token with the `signa-id:release` scope. API keys cannot call it. No scope bundle contains this scope, `full-access` included, so select it by name when you create or rotate your credentials.