How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Transmit Security Verification API

The Verification API from Transmit Security — 6 operation(s) for verification.

Transmit Security Verification API is one of 9 APIs that Transmit Security publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

This API exposes 7 JSON Schema definitions.

Tagged areas include Verification. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and 7 JSON Schemas.

This API exposes 6 operations across 6 paths, and defines 37 schemas. It is described by OpenAPI 3.2.0, at version 1.0.

Requests are made against 5 base URLs: https://api.sbx.transmitsecurity.io/cis, https://api.transmitsecurity.io/cis, https://api.eu.transmitsecurity.io/cis, https://api.ca.transmitsecurity.io/cis, https://api.au.transmitsecurity.io/cis.

6 operations 6 paths 37 schemas 1 DELETE4 GET1 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0
Base URL
https://api.transmitsecurity.io
Authentication
HTTP Bearer, HTTP Bearer, OAuth 2.0, OAuth 2.0, OAuth 2.0
Resource Areas
1

Authentication & Security 5

Transmit Security Verification API declares 5 security schemes for authenticating requests. It accepts HTTP bearer tokens (JWT) (bearer). It accepts HTTP bearer tokens (JWT) (UserAccessToken). It supports OAuth 2.0 (AdminAccessToken) using the clientCredentials flow. It supports OAuth 2.0 (ClientAccessToken) using the clientCredentials flow. It supports OAuth 2.0 (OrgAdminAccessToken) using the clientCredentials flow.

  • UserAccessToken — A token returned upon end-user authentication, which provides access to resources and data for the user and app for which it was generated
  • AdminAccessToken — A token generated by a management application using the [token endpoint](/openapi/token.openapi/other/getaccesstoken). It provides access to all resources for…
  • ClientAccessToken — A token generated by an end-user application using the [token endpoint](/openapi/token.openapi/other/getaccesstoken). It provides access to resources and data…
  • OrgAdminAccessToken — A token returned upon B2B authentication for a user that has the organizationAdmin or organizationCreator role.

Paths & Operations 6

Across 6 paths, the API surfaces 6 operations — 1 DELETE, 4 GET, 1 POST. Each is listed below with its method, path, parameters, and response codes.

Verification 6
POST
/api/v1/verification
Create verification session
createSession body → 201400401
GET
/api/v1/verification/{sid}/result
Get verification result
getResult 2 params → 200400401404
DELETE
/api/v1/verification/{sid}
Delete verification session
deleteSession 1 param → 200400401404
GET
/api/v1/verification/{sid}/images
Get all images for session
getImages 1 param → 200400401
GET
/api/v1/verification/{sid}/images/{id}
Get image by ID
getImage 3 params → 200400401404
GET
/api/v1/verification/{sid}/consent
Get consent
getConsent 1 param → 200400401404

Schemas 37

The contract defines 37 schemas that model the data the API accepts and returns. The most detailed are RiskDetailsDeviceDto (13 properties), DeprecatedDocumentDto (11 properties), RiskDetailsNetworkDto (9 properties), CompleteSessionResult (9 properties). Each schema is shown below with its type and property counts.

MockBehavior
object
5 properties
VerificationImageDto
object
2 properties 2 required
RiskDetailsDeviceDto
object
13 properties
RiskDetailsGeneralDto
object
4 properties
AdditionalInfoDto
object
3 properties
FlaggedIdentityCheckDto
object
2 properties 1 required
CustomerInformation
object
3 properties
DeprecatedExtractedInfoDto
object
2 properties
DeprecatedDocumentDto
object
11 properties 1 required
CreateSessionRequest
object
7 properties
CompleteSessionResult
object
9 properties 7 required
RiskDetailsNetworkDto
object
9 properties
SessionImageDto
object
6 properties 3 required
DeprecatedPersonDto
object
7 properties
StartSessionConfigDto
object
1 property
BiometricMatchingCheckDto
object
2 properties 1 required
GetConsentApprovalResponse
object
2 properties 1 required
DocumentValidationCheckDto
object
2 properties 1 required
DocumentAuthenticationCheckDto
object
2 properties 1 required
RiskRecommendationCheckDto
object
2 properties 1 required
BiometricLivenessCheckDto
object
2 properties 1 required
PersonDto
object
7 properties
DeprecatedSessionResult
object
6 properties 2 required
NationalStatusDto
object
2 properties
IncompleteSessionResult
object
2 properties 2 required
CreateSessionResponse
object
4 properties 3 required
DocumentDto
object
7 properties 1 required
SessionImagesResponse
object
1 property 1 required
AddressDto
object
8 properties
SessionConsent
object
2 properties 2 required
EmploymentDto
object
1 property
DocumentLivenessCheckDto
object
2 properties 1 required
RiskDetailsDto
object
4 properties
SessionChecksDto
object
7 properties
DeprecatedAddressDetailsDto
object
8 properties
VerifiedInfoDto
object
2 properties
ExtractedDetails
object
2 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

transmit-security-verification-api-openapi.yml Raw ↑

Other APIs Transmit Security publishes across the network.

Mosaic Orchestration API
Transmit Security Applications API
Transmit Security Auth API
Transmit Security Manage API
Transmit Security Organizations API
Transmit Security Recommendation API
Transmit Security Token API
Transmit Security Users API
Where this information came from

This is an independent, third-party profile of Transmit Security Verification API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.