curl --request POST \
--url https://api.verify.privue.ai/verifications/{verification_id}/documents/download \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"document_ids": [
"bb9909b4-44e4-414a-af82-bad690d434ed",
"4fd79a54-a8a7-4e07-b902-a2e75af3e467"
]
}
'import requests
url = "https://api.verify.privue.ai/verifications/{verification_id}/documents/download"
payload = { "document_ids": ["bb9909b4-44e4-414a-af82-bad690d434ed", "4fd79a54-a8a7-4e07-b902-a2e75af3e467"] }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
document_ids: ['bb9909b4-44e4-414a-af82-bad690d434ed', '4fd79a54-a8a7-4e07-b902-a2e75af3e467']
})
};
fetch('https://api.verify.privue.ai/verifications/{verification_id}/documents/download', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));{
"documents": [
{
"id": "bb9909b4-44e4-414a-af82-bad690d434ed",
"slot": "gst-certificate",
"kind": "gst-certificate",
"label": "gst_certificate",
"filename": "gst-certificate.pdf",
"content_type": "application/pdf",
"size_bytes": 182044,
"sha256": "63f90f32e899197edb4f038322e354f3c6b907602a44a58a0ae52b40a2cd9811",
"received_at": "2026-08-10T14:21:58",
"step_key": "gst",
"step_label": "tax_registration",
"url": "https://storage.privue.ai/verification-4b8f21c6-59ad-4a70-9e11-7c3d0a52f8b4/3f2504e0-4f89-41d3-9a0c-0305e82c3301/gst/bb9909b4-44e4-414a-af82-bad690d434ed/gst-certificate.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Date=20260810T151244Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=8f0c1d4a7b6e2593c04f1a8d7b3e69a2"
},
{
"id": "4fd79a54-a8a7-4e07-b902-a2e75af3e467",
"slot": "pan-card",
"kind": "pan-card",
"label": "entity_pan",
"filename": "pan-card.jpg",
"content_type": "image/jpeg",
"size_bytes": 92412,
"sha256": "42b7e28cf9a26dcef6e275de42f7516ad36ee86c6aa45888821a81217e62a670",
"received_at": "2026-08-10T14:09:12",
"step_key": "pan",
"step_label": "entity_pan",
"url": "https://storage.privue.ai/verification-4b8f21c6-59ad-4a70-9e11-7c3d0a52f8b4/3f2504e0-4f89-41d3-9a0c-0305e82c3301/pan/4fd79a54-a8a7-4e07-b902-a2e75af3e467/pan-card.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Date=20260810T151244Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=2d71e4c908ba53f6710d8e2fb945c3a7"
}
],
"expires_in_seconds": 300
}{
"code": "unauthenticated",
"detail": "Missing or malformed Authorization header"
}{
"code": "environment-mismatch",
"detail": "workflow 'merchant-onboarding' is production and this request is for uat"
}{
"code": "document-not-found",
"detail": "no such document: 4fd79a54-a8a7-4e07-b902-a2e75af3e467"
}{
"code": "document-not-stored",
"detail": "document 4fd79a54-a8a7-4e07-b902-a2e75af3e467 was read in the request that carried it and was not stored"
}{
"code": "request-invalid",
"detail": "document_ids.1: Input should be a valid UUID, invalid character: found `n` at 1"
}{
"code": "rate-limited",
"detail": "Unauthorized: RATE_LIMITED"
}{
"code": "auth-unavailable",
"detail": "Auth provider unavailable"
}Link to documents
Link to the files on the record, whoever provided them.
Name the documents you want by id, or ask for the whole record at once. Each link is short-lived and yours to fetch: this call hands back addresses rather than the files themselves, and following one saves the file under the name the record states.
Every entry states the file as the record does, its name, type, size, hash and the slot and kind it was provided as, and names the step it answers with your own label for it. A download of the whole record is a list of files from across it, so what each one is comes with the link to it.
A verification run in one request keeps no files: its documents were read as they arrived and stored nowhere, so asking for the whole record links nothing and naming one of them answers 409. The record still carries each file’s name, type and hash, which is what it was checked as.
Once a verification has expired its files are gone too, so asking for the whole record links nothing and naming an id answers 404.
curl --request POST \
--url https://api.verify.privue.ai/verifications/{verification_id}/documents/download \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"document_ids": [
"bb9909b4-44e4-414a-af82-bad690d434ed",
"4fd79a54-a8a7-4e07-b902-a2e75af3e467"
]
}
'import requests
url = "https://api.verify.privue.ai/verifications/{verification_id}/documents/download"
payload = { "document_ids": ["bb9909b4-44e4-414a-af82-bad690d434ed", "4fd79a54-a8a7-4e07-b902-a2e75af3e467"] }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
document_ids: ['bb9909b4-44e4-414a-af82-bad690d434ed', '4fd79a54-a8a7-4e07-b902-a2e75af3e467']
})
};
fetch('https://api.verify.privue.ai/verifications/{verification_id}/documents/download', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));{
"documents": [
{
"id": "bb9909b4-44e4-414a-af82-bad690d434ed",
"slot": "gst-certificate",
"kind": "gst-certificate",
"label": "gst_certificate",
"filename": "gst-certificate.pdf",
"content_type": "application/pdf",
"size_bytes": 182044,
"sha256": "63f90f32e899197edb4f038322e354f3c6b907602a44a58a0ae52b40a2cd9811",
"received_at": "2026-08-10T14:21:58",
"step_key": "gst",
"step_label": "tax_registration",
"url": "https://storage.privue.ai/verification-4b8f21c6-59ad-4a70-9e11-7c3d0a52f8b4/3f2504e0-4f89-41d3-9a0c-0305e82c3301/gst/bb9909b4-44e4-414a-af82-bad690d434ed/gst-certificate.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Date=20260810T151244Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=8f0c1d4a7b6e2593c04f1a8d7b3e69a2"
},
{
"id": "4fd79a54-a8a7-4e07-b902-a2e75af3e467",
"slot": "pan-card",
"kind": "pan-card",
"label": "entity_pan",
"filename": "pan-card.jpg",
"content_type": "image/jpeg",
"size_bytes": 92412,
"sha256": "42b7e28cf9a26dcef6e275de42f7516ad36ee86c6aa45888821a81217e62a670",
"received_at": "2026-08-10T14:09:12",
"step_key": "pan",
"step_label": "entity_pan",
"url": "https://storage.privue.ai/verification-4b8f21c6-59ad-4a70-9e11-7c3d0a52f8b4/3f2504e0-4f89-41d3-9a0c-0305e82c3301/pan/4fd79a54-a8a7-4e07-b902-a2e75af3e467/pan-card.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Date=20260810T151244Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=2d71e4c908ba53f6710d8e2fb945c3a7"
}
],
"expires_in_seconds": 300
}{
"code": "unauthenticated",
"detail": "Missing or malformed Authorization header"
}{
"code": "environment-mismatch",
"detail": "workflow 'merchant-onboarding' is production and this request is for uat"
}{
"code": "document-not-found",
"detail": "no such document: 4fd79a54-a8a7-4e07-b902-a2e75af3e467"
}{
"code": "document-not-stored",
"detail": "document 4fd79a54-a8a7-4e07-b902-a2e75af3e467 was read in the request that carried it and was not stored"
}{
"code": "request-invalid",
"detail": "document_ids.1: Input should be a valid UUID, invalid character: found `n` at 1"
}{
"code": "rate-limited",
"detail": "Unauthorized: RATE_LIMITED"
}{
"code": "auth-unavailable",
"detail": "Auth provider unavailable"
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
Body
Which of a verification's files to link.
The documents to link, at most 25 per call. Omit the field to link every file on the record; send an empty list to link none. Every id must belong to this verification, otherwise the whole call is refused and no links are issued.
25Response
Every file asked for, with a short-lived download link.
Short-lived links to the documents that were asked for, all minted together.
One entry per document, in the order the ids were given, or oldest first when the whole record was linked. Each states the file the way the record does, names the step it answers, and carries the link to it.
Show child attributes
Show child attributes
How long the URLs stay valid; every link shares the window.
