Get a short-lived download URL for one image in data.document_images. The URL is valid for 15 minutes. The release must include the document_images scope, you must have exchanged the code, and access.status must be ACTIVE. Otherwise the call answers 404. This endpoint allows 30 requests each minute and 600 requests each hour for each business, together with the session document URL endpoint. Every response carries Cache-Control: no-store. Signa ID release must be enabled for your business. The call must use an OAuth access token with the signa-id:release scope. API keys cannot call it. No scope bundle contains this scope, full-access included, so select it by name when you create or rotate your credentials.
Authorization
oauth2ClientCredentials signa-id:releaseUse your OAuth client credentials to obtain a short-lived Bearer token from POST /oauth/token.
In: header
Scope: signa-id:release
Path Parameters
The release id. It is the id field of the release request, and the releaseId that the web SDK returns.
uuidThe id of the image, from data.document_images. Letters, digits, _, : and - only.
^[A-Za-z0-9_:-]+$Response Body
application/json
application/json
application/json
application/json
application/json
curl --request GET \ --url 'https://example.com/api/external/signa-id/releases/b84c0427-231c-44c2-b397-e528a775962f/documents/doc:901'{ "message": "Document URL generated.", "data": { "url": "https://storage.example.com/releases/b84c0427/doc-901.jpg?expires=900&signature=EXAMPLE", "content_type": "image/jpeg", "expires_at": "2026-10-05T10:35:03.000Z" }}GETGet a release
Read the status of a release. After the exchange, the response also carries the released data for 30 days, while `access.status` is ACTIVE. `data` is null before the exchange, and when access is REVOKED, EXPIRED or UNAVAILABLE. A release of another business answers 404. Every response carries `Cache-Control: no-store`. Signa ID release must be enabled for your business. The call must use an OAuth access token with the `signa-id:release` scope. API keys cannot call it. No scope bundle contains this scope, `full-access` included, so select it by name when you create or rotate your credentials.
GETGet a wallet status
Check if a wallet belongs to a verified Signa ID. The endpoint needs no authentication and allows calls from any origin, so a page or a smart-contract front end can call it. The answer has no personal data: it holds only the facts that the on-chain attestation already makes public. A wallet that Blaaiz does not know, a wallet with no verification and an expired verification all get the same answer: verified false, null values, an empty list and status 200. The response is the status object at the root, with no message and no data wrapper. A 200 response carries `Cache-Control: public, max-age=60`, so a change can take up to one minute to show. This endpoint allows 60 requests each minute and 1,000 requests each hour for each IP address.