How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Didit Sessions API

The Sessions API from Didit — 20 operation(s) for sessions.

Didit Sessions API is one of 17 APIs that Didit publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Sessions. The published artifact set on APIs.io includes an OpenAPI specification, an API reference, and API documentation.

This API exposes 21 operations across 20 paths, and defines 3 schemas. It is described by OpenAPI 3.0.0, at version 3.0.0.

Requests are made against a single base URL, https://verification.didit.me.

21 operations 20 paths 3 schemas 1 DELETE6 GET7 PATCH7 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.0.0
API Version
3.0.0
Base URL
https://verification.didit.me
Authentication
API Key, API Key, API Key
Resource Areas
1

Authentication & Security 3

Didit Sessions API declares 3 security schemes for authenticating requests. An API key is passed in the header as x-api-key (ApiKeyAuth). An API key is passed in the header as X-Transaction-Token (TransactionTokenAuth). An API key is passed in the header as Session-Token (SessionTokenAuth).

  • TransactionTokenAuth — Short-lived scoped token minted by your backend via POST /v3/transactions/sdk-token/. Used by the Didit SDKs on the device-facing /v1/transactions/ endpoints.
  • SessionTokenAuth — Short-lived token returned in the sessiontoken field of POST /v3/session/. Used by the hosted verification flow (and custom sandbox UIs) to call session-scoped…

Paths & Operations 21

Across 20 paths, the API surfaces 21 operations — 1 DELETE, 6 GET, 7 PATCH, 7 POST. Each is listed below with its method, path, parameters, and response codes.

Sessions 21
POST
/v3/session/
Create a verification session
post_v3_session_create body → 201400403429
POST
/v3/session/imports/
Create a verification import job
post_v3_session_imports_create body → 201400403429
GET
/v3/session/imports/template/
Download verification import template
get_v3_session_imports_template 1 param → 200403
GET
/v3/session/imports/{importId}/
Retrieve a verification import job
get_v3_session_imports_retrieve 1 param → 200403404
GET
/v3/session/imports/{importId}/errors/
List verification import row errors
get_v3_session_imports_errors 3 params → 200403404
DELETE
/v3/session/{sessionId}/delete/
Soft-delete a verification session (KYC or KYB)
delete_v3_session_by_id 1 param → 204403404429
GET
/v3/session/{sessionId}/generate-pdf/
Download a PDF report for a verification session
get_v3_session_generate_pdf 1 param → 200403404429
POST
/v3/session/{sessionId}/sandbox/arm/
Arm a sandbox scenario on a session
post_v3_session_sandbox_arm 1 param body → 200400404
PATCH
/v3/session/{sessionId}/update-status/
Approve, decline, or request resubmission for a verification session
patch_v3_session_update_status 1 param body → 200400403404
GET
/v3/sessions/
List verification sessions (KYC and/or KYB) with filters and pagination
get_v3_sessions 22 params → 200301400403
POST
/v3/session/{sessionId}/share/
Mint a share token for a finished verification session
post_v3_session_share 1 param body → 200400401403404
POST
/v3/session/import-shared/
Redeem a share token to clone a verification session into your application
post_v3_session_import_shared body → 201400403404
POST
/v3/sessions/delete/
Bulk soft-delete KYC sessions by sessionnumber
batch_delete_sessions body → 204400403429
GET
/v3/sessions/{session_id}/reviews/
List session reviews and activity log
list_session_reviews 4 params → 200403404429
POST
/v3/sessions/{session_id}/reviews/
Add a review note to a session's audit trail
create_session_review 2 params body → 201400403404429
PATCH
/v3/session/{sessionId}/update-data/
Update KYC data extracted from the ID document on a verification session
patch_v3_session_update_data 2 params body → 200400403404429
PATCH
/v3/session/{sessionId}/features/{nodeId}/update-status/
Update an individual feature (step) status
patch_v3_session_update_feature_status 2 params body → 200400403404
PATCH
/v3/session/{sessionId}/update-aml-hit-status/
Update an AML hit review status
patch_v3_session_update_aml_hit_status 2 params body → 200400403404
PATCH
/v3/session/{sessionId}/bulk-update-aml-hit-status/
Bulk update AML hit review statuses
patch_v3_session_bulk_update_aml_hit_status 2 params body → 200400403404
PATCH
/v3/session/{sessionId}/update-poa-data/
Update Proof of Address data extracted from the POA document on a verification session
patch_v3_session_update_poa_data 2 params body → 200400403404429
PATCH
/v3/session/{sessionId}/kyb/{companyUuid}/update-data/
Update registry-extracted company data on a Business Verification (KYB) session
patch_v3_session_kyb_company_update_data 2 params body → 200400403404429

Schemas 3

The contract defines 3 schemas that model the data the API accepts and returns. The most detailed are SessionImportJob (18 properties), ReviewItem (14 properties), SessionImportError (6 properties). Each schema is shown below with its type and property counts.

ReviewItem
object
One entry in a session's review / activity feed. Status changes carry previousstatus, newstatus, previousvalue, newvalue, and changedfields; comments carry com…
14 properties
SessionImportError
object
6 properties 4 required
SessionImportJob
object
18 properties 11 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

didit-sessions-api-openapi.yml Raw ↑

Other APIs Didit publishes across the network.

Didit Billing API
Didit Businesses API
Didit Case Blueprints API
Didit Cases API
Didit Customization API
Didit Questionnaires API
Didit Regulatory Reports API
Didit Report Templates API
Didit Session API
Didit Standalone APIs API
Didit System API
Didit Transactions API
Where this information came from

This is an independent, third-party profile of Didit Sessions API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.