Skip to main content
POST
Create an identity verification session

Authorizations

Authorization
string
header
required

Basic authentication header of the form Basic <encoded-value>, where <encoded-value> is the base64-encoded string username:password.

Path Parameters

nsid
string<uuid>
required

Globally unique namespace ID. These IDs are opaque, not guessable, and not sequential.

Bango provides each Bango partner with a unique set of resource URIs. All resource URI paths start with /ns/{nsid}, where {nsid} is the namespace ID. No other Bango partner shares this namespace. Partner credentials permit access only to URIs with this namespace.

Example:

"673c74de-ce5b-4f79-9851-2544d1d836cb"

Body

application/json

Data needed to create an identity verification session.

Partners can optionally include an action property. If present, the Bango Platform processes the action immediately after a successful session creation.

partnerSessionId
string

A session ID supplied by the partner. This is assumed to be unique across all the partner's identity verification sessions.

Minimum string length: 1
Example:

"e9342a9f-ff3f-44ad-8e30-8a6f9a820060"

private
object

A place for the merchant partner to store private data related to the identity verification session. Once the payment instrument token is generated, this data is associated with the token.

Merchant partners can initialize the data when creating a session, and can patch this data later when starting a flow or using an UPDATE_SESSION_DATA action.

Supports any data (constraints TBD). This schema defines some commonly used properties.

shared
Data shared betweeen merchant and payment provider · object

Initial details of the negotiation between the merchant partner and the payment provider, from the merchant partner's perspective

action
START_TRUSTED_FLOW action · object

Optional action to send immediately after a successful resource creation.

Response

Resource created.

An identity verification session when no flow has been selected.

rid
string<uuid>
required

Globally unique resource ID. These IDs are opaque, not guessable, and not sequential.

Each individual resource in a partner's namespace has a unique identifier: this is the identifier immediately after the resource type in the URI path.

For example, in the URI /ns/673c74de-ce5b-4f79-9851-2544d1d836cb/elephants/581b2e40-741c-4683-ae66-46c9fe6f4d5e:

  • The namespace id is 673c74de-ce5b-4f79-9851-2544d1d836cbde
  • elephants indicates the resource type is elephant
  • The resource id is 581b2e40-741c-4683-ae66-46c9fe6f4d5e

Every resource has a read-only property rid that contains the resource ID, for convenience.

Example:

"581b2e40-741c-4683-ae66-46c9fe6f4d5e"

lastUpdate
string<date-time>
required

RFC 3339 datetime of the last update to this resource

Example:

"2022-12-21T08:59:32Z"

flow
any
required

No flow has been selected

state
enum<string>
required

Describes the state of the resource when no flow has been selected.

state is one of:

  • authorizing - the Bango Platform is checking for permission to create the session
  • new - the session is created and the Bango Platform is ready for the partner to select a flow
  • failed - the Bango Platform has denied the request to create the session
  • closed - the partner has decided to cancel the session without selecting a flow

Typically partners see only new. authorizing is very short-lived, failed is possible but unlikely, and closed is only entered at the partner's request.

Available options:
authorizing,
new,
failed,
closed
partnerSessionId
string

A session ID supplied by the partner. This is assumed to be unique across all the partner's identity verification sessions.

Minimum string length: 1
Example:

"e9342a9f-ff3f-44ad-8e30-8a6f9a820060"

private
object

A place for the merchant partner to store private data related to the identity verification session. Once the payment instrument token is generated, this data is associated with the token.

Merchant partners can initialize the data when creating a session, and can patch this data later when starting a flow or using an UPDATE_SESSION_DATA action.

Supports any data (constraints TBD). This schema defines some commonly used properties.

shared
Shared identity verification session properties · object

Data shared between the merchant partner and the payment provider as part of an identity verification session.

result
Action result, if any · object

The result of the most recent action. There are three outcomes for an action:

  1. The action was performed and completed with a positive outcome
  2. The action was performed and completed with a negative outcome
  3. The action was not performed because a required constraint was not met

The result code indicates which outcome applied and is always a string in lower-kebab-case.

The result reasons indicates any additional explanations available for the outcome (outcomes 2 and 3 above). For outcome 1 above, reasons is an empty array.