Get the access token for a HOSTED session, so that the web SDK can open the verification page in a popup on your own page. Call this endpoint from your server, then send access_token to your page and call signa.startSession({ accessToken }). The token is valid for 30 minutes from when Blaaiz made it. While the current token has more than 10 minutes left, a new call returns the same token. With 10 minutes or less left, the call returns a new token, and the previous token and the previous verification link stop working. A new verification link also stops the current access token. The session must be HOSTED and AWAITING_INPUT, and its verification page must be a page that Blaaiz hosts. The request takes no body. Signa must be enabled for your business. Required scope: compliance-kyc:create.

POSTapi-prod.blaaiz.com/api/external/compliance/kyc/sessions/{sessionId}/access-token

Authorization

oauth2ClientCredentials compliance-kyc:create
AuthorizationBearer <token>

Use your OAuth client credentials to obtain a short-lived Bearer token from POST /oauth/token.

In: header

Scope: compliance-kyc:create

Path Parameters

sessionId*string

The verification session id returned by the create endpoint.

Formatuuid

Response Body

application/json

application/json

application/json

application/json

application/json

Issue a web SDK access token
curl --request POST \  --url 'https://example.com/api/external/compliance/kyc/sessions/9f2c7b41-6d3e-4c8a-9a20-1e6f0b5d7c33/access-token'
{  "message": "Access token issued successfully.",  "data": {    "access_token": "L3iqv7TWu9lsfaYAriq_6krLJrYQ0F2uPmhDOhevNWo",    "expires_at": "2026-10-05T10:44:22.000Z"  }}