curl --request POST \
--url https://api.verify.privue.ai/verifications/{verification_id}/handoff \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.verify.privue.ai/verifications/{verification_id}/handoff"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.verify.privue.ai/verifications/{verification_id}/handoff', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));{
"url": "https://verify.privue.ai/acme/merchant-onboarding#ticket=2nR9v6QpKZ8mLxT4bYw1dJhSaEfG7uNc",
"expires_in_seconds": 120
}{
"code": "unauthenticated",
"detail": "Missing or malformed Authorization header"
}{
"code": "environment-mismatch",
"detail": "workflow 'merchant-onboarding' is production and this request is for uat"
}{
"code": "verification-not-found",
"detail": "no verification 3f2504e0-4f89-41d3-9a0c-0305e82c3301 for this client"
}{
"code": "workflow-not-walkable",
"detail": "the verification is cancelled, so there is no journey to open"
}{
"code": "request-invalid",
"detail": "verification_id: Input should be a valid UUID, invalid character: found `n` at 1"
}{
"code": "rate-limited",
"detail": "Unauthorized: RATE_LIMITED"
}{
"code": "auth-unavailable",
"detail": "Auth provider unavailable"
}Hand off a signed-in user
Open the journey for a user your own app has already signed in.
This is the second of the two ways into a journey, for users who arrive from inside your own app, in an in-app browser or a webview. Asking them for their mobile number there would ask them to prove what your app already knows, so a handoff signs them in as this verification’s user and lands them on their next step. The record’s journey_url is the other way in, for every channel where you send a link rather than open one.
A handoff is single use and short lived. Create one at the moment you open the browser rather than in advance. While that browser keeps its site storage the user stays signed in, so one handoff carries the whole visit and a new one is only needed for a new browser. Once it has been used, or once expires_in_seconds has passed, it stops signing anyone in and the user is asked for their mobile number instead, so a handoff that arrives late costs a sign-in and not the journey.
Your API key stays on your server: your app asks your backend for the handoff, and your backend asks us.
curl --request POST \
--url https://api.verify.privue.ai/verifications/{verification_id}/handoff \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.verify.privue.ai/verifications/{verification_id}/handoff"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.verify.privue.ai/verifications/{verification_id}/handoff', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));{
"url": "https://verify.privue.ai/acme/merchant-onboarding#ticket=2nR9v6QpKZ8mLxT4bYw1dJhSaEfG7uNc",
"expires_in_seconds": 120
}{
"code": "unauthenticated",
"detail": "Missing or malformed Authorization header"
}{
"code": "environment-mismatch",
"detail": "workflow 'merchant-onboarding' is production and this request is for uat"
}{
"code": "verification-not-found",
"detail": "no verification 3f2504e0-4f89-41d3-9a0c-0305e82c3301 for this client"
}{
"code": "workflow-not-walkable",
"detail": "the verification is cancelled, so there is no journey to open"
}{
"code": "request-invalid",
"detail": "verification_id: Input should be a valid UUID, invalid character: found `n` at 1"
}{
"code": "rate-limited",
"detail": "Unauthorized: RATE_LIMITED"
}{
"code": "auth-unavailable",
"detail": "Auth provider unavailable"
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
Response
A single-use address that opens the journey with the user already signed in.
A single-use address that opens the journey with the user already signed in.
