Get the access token for a HOSTED session, so that the web SDK can open the verification page in a popup on your own page. Call this endpoint from your server, then send access_token to your page and call signa.startSession({ accessToken }). The token is valid for 30 minutes from when Blaaiz made it. While the current token has more than 10 minutes left, a new call returns the same token. With 10 minutes or less left, the call returns a new token, and the previous token and the previous verification link stop working. A new verification link also stops the current access token. The session must be HOSTED and AWAITING_INPUT, and its verification page must be a page that Blaaiz hosts. The request takes no body. Signa must be enabled for your business. Required scope: compliance-kyc:create.
Authorization
oauth2ClientCredentials compliance-kyc:createUse your OAuth client credentials to obtain a short-lived Bearer token from POST /oauth/token.
In: header
Scope: compliance-kyc:create
Path Parameters
The verification session id returned by the create endpoint.
uuidResponse Body
application/json
application/json
application/json
application/json
application/json
curl --request POST \ --url 'https://example.com/api/external/compliance/kyc/sessions/9f2c7b41-6d3e-4c8a-9a20-1e6f0b5d7c33/access-token'{ "message": "Access token issued successfully.", "data": { "access_token": "L3iqv7TWu9lsfaYAriq_6krLJrYQ0F2uPmhDOhevNWo", "expires_at": "2026-10-05T10:44:22.000Z" }}POSTIssue a verification link
Issue a new verification link for a HOSTED session. The create response already carries the first link, so call this endpoint only to replace a link that expired or leaked. Read link_expires_at for the new deadline. The previous link may stop working as soon as Blaaiz issues a new one. A new link also stops the current web SDK access token of the session. The link is a live credential for one session: send it over a private channel and keep it out of your logs. The request takes no body. Blaaiz refuses the call when the session is terminal, and when the session is HEADLESS. Every HOSTED session can take a verification link, including a session with no selfie step. Signa must be enabled for your business. Required scope: `compliance-kyc:create`.
POSTCancel a verification session
Cancel a session that you no longer need. CANCELLED is terminal: Blaaiz sends no webhook for the session after a cancel, and the verification link stops working. A cancel frees a slot under your open session cap. A cancel on a session that is already terminal is refused with `422`: `This session has already been cancelled.` for a cancelled session, and `This session has already reached a final state and cannot be cancelled.` for an approved, rejected or expired one. A cancel also closes the person's verification page. The request takes no body. This endpoint stays available even when Signa is disabled for your business. Required scope: `compliance-kyc:cancel`.