Create an identity verification session
Use this endpoint to create an identity verification session. API consumers use this session to authenticate/verify the end user and obtain a Payment Instrument Token for them.
Include the action property to send an action immediately after the session is created.
400 response error codes:
invalid-jsonif the request body isn’t valid JSON formatmissing-parameterfor any mandatory parameter missing from the request bodyinvalid-parameterfor any parameter that’s syntactically or semantically incorrect. For example:- If this specification defines a parameter as a string, and an array of strings is supplied
- If this specification defines a parameter as a datetime, and an invalid datetime is supplied
- If parameters should be in a particular order (eg chronological datetimes) and they aren’t
Authorizations
Basic authentication header of the form Basic <encoded-value>, where <encoded-value> is the base64-encoded string username:password.
Path Parameters
Globally unique namespace ID. These IDs are opaque, not guessable, and not sequential.
Bango provides each Bango partner with a unique set of resource URIs. All resource URI paths start with /ns/{nsid}, where {nsid} is the namespace ID. No other Bango partner shares this namespace. Partner credentials permit access only to URIs with this namespace.
"673c74de-ce5b-4f79-9851-2544d1d836cb"
Body
Data needed to create an identity verification session.
Partners can optionally include an action property. If present, the Bango Platform processes the action immediately after a successful session creation.
A session ID supplied by the partner. This is assumed to be unique across all the partner's identity verification sessions.
1"e9342a9f-ff3f-44ad-8e30-8a6f9a820060"
A place for the merchant partner to store private data related to the identity verification session. Once the payment instrument token is generated, this data is associated with the token.
Merchant partners can initialize the data when creating a session, and can patch this data later when starting a flow or using an UPDATE_SESSION_DATA action.
Supports any data (constraints TBD). This schema defines some commonly used properties.
Initial details of the negotiation between the merchant partner and the payment provider, from the merchant partner's perspective
Optional action to send immediately after a successful resource creation.
- START_TRUSTED_FLOW action
- START_NEGOTIATED_FLOW action
- START_MO_FLOW action
- START_MT_FLOW action
- CANCEL_SESSION action [plan-later]
Response
Resource created.
- Identity verification session - no flow selected
- Identity verification session - Trusted flow selected
- Identity verification session - Negotiated flow selected
- Identity verification session - MO flow selected
- Identity verification session - MT flow selected
An identity verification session when no flow has been selected.
Globally unique resource ID. These IDs are opaque, not guessable, and not sequential.
Each individual resource in a partner's namespace has a unique identifier: this is the identifier immediately after the resource type in the URI path.
For example, in the URI /ns/673c74de-ce5b-4f79-9851-2544d1d836cb/elephants/581b2e40-741c-4683-ae66-46c9fe6f4d5e:
- The namespace id is
673c74de-ce5b-4f79-9851-2544d1d836cbde elephantsindicates the resource type iselephant- The resource id is
581b2e40-741c-4683-ae66-46c9fe6f4d5e
Every resource has a read-only property rid that contains the resource ID, for convenience.
"581b2e40-741c-4683-ae66-46c9fe6f4d5e"
RFC 3339 datetime of the last update to this resource
"2022-12-21T08:59:32Z"
No flow has been selected
Describes the state of the resource when no flow has been selected.
state is one of:
authorizing- the Bango Platform is checking for permission to create the sessionnew- the session is created and the Bango Platform is ready for the partner to select a flowfailed- the Bango Platform has denied the request to create the sessionclosed- the partner has decided to cancel the session without selecting a flow
Typically partners see only new. authorizing is very short-lived, failed is possible but unlikely, and closed is only entered at the partner's request.
authorizing, new, failed, closed A session ID supplied by the partner. This is assumed to be unique across all the partner's identity verification sessions.
1"e9342a9f-ff3f-44ad-8e30-8a6f9a820060"
A place for the merchant partner to store private data related to the identity verification session. Once the payment instrument token is generated, this data is associated with the token.
Merchant partners can initialize the data when creating a session, and can patch this data later when starting a flow or using an UPDATE_SESSION_DATA action.
Supports any data (constraints TBD). This schema defines some commonly used properties.
Data shared between the merchant partner and the payment provider as part of an identity verification session.
The result of the most recent action. There are three outcomes for an action:
- The action was performed and completed with a positive outcome
- The action was performed and completed with a negative outcome
- The action was not performed because a required constraint was not met
The result code indicates which outcome applied and is always a string in lower-kebab-case.
The result reasons indicates any additional explanations available for the outcome (outcomes 2 and 3 above). For outcome 1 above, reasons is an empty array.

