Skip to main content
POST
Redeem a verification session ticket

Authorizations

x-juno-jwt
string
header
required

Session JWT from the identity provider that signed the user in — Dynamic Labs, Privy, or Clerk (consumer sign-in). Send it in the x-juno-jwt header on every authenticated request. An Authorization: Bearer <jwt> header carrying the same JWT is also accepted, and takes precedence when both are present.

Headers

x-sumvin-kyc-ticket
string | null

Ticket issued when the verification session was created. Treat it as a secret: it is single-use, short-lived, and buys a token that acts as the user.

Idempotency-Key
string | null

Client-generated key identifying one logical redemption. Reuse the same value when retrying so a lost response cannot spend the session twice.

x-juno-jwt
string | null
x-juno-orgid
string | null

Tenant org ID for multi-tenant auth

X-Timestamp-Format
string

Controls how timestamp fields are serialized in JSON response bodies.

Default (header omitted or any other value): epoch milliseconds as integers. iso8601: UTC ISO 8601 strings of the form YYYY-MM-DDTHH:MM:SSZ.

Example: with X-Timestamp-Format: iso8601, the field value 1704067200000 becomes "2024-01-01T00:00:00Z".

Affected fields (recursively, in dicts and arrays): any field whose name ends in _at, plus the literal field names timestamp, period_start, and period_end. All other fields are passed through unchanged.

Only iso8601 is recognized. Any other value (or omitting the header) yields the default epoch-ms representation; the server does not reject unknown values, so this is documented as an example rather than an enum to keep generated clients permissive.

Example:

"iso8601"

Response

Session redeemed

The verification credential a redeemed session buys.

HAL-style hypermedia links for navigation.

access_token
string
required

Short-lived access token for Sumsub Web SDK initialization.

expires_in
integer
required

Token validity period in seconds.

user_id
string
required

User ID associated with this token.

level_name
string
required

Verification level the token was minted against — use it to configure the SDK.

session_id
string
required

Identifier of the verification session that was redeemed.

origin
enum<string> | null

Where this person began verification, so the completion screen can send them back to it: cli for a terminal, connector for a conversation with an assistant, app for the Sumvin app. Null when the session predates this field.

Available options:
cli,
connector,
app