curl -X POST "https://apx.didit.me/auth/v2/organizations/me/$ORG_ID/applications/" \
-H "Authorization: Bearer $ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "Acme Customer App",
"website_url": "https://acme.example",
"redirect_uris": ["https://acme.example/callback"]
}'import requests
resp = requests.post(
f"https://apx.didit.me/auth/v2/organizations/me/{org_id}/applications/",
headers={"Authorization": f"Bearer {access_token}"},
json={
"name": "Acme Customer App",
"website_url": "https://acme.example",
"redirect_uris": ["https://acme.example/callback"],
},
timeout=10,
)
resp.raise_for_status()
app = resp.json()
print("Save this:", app["api_key"])const resp = await fetch(
`https://apx.didit.me/auth/v2/organizations/me/${orgId}/applications/`,
{
method: "POST",
headers: {
Authorization: `Bearer ${accessToken}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
name: "Acme Customer App",
website_url: "https://acme.example",
redirect_uris: ["https://acme.example/callback"],
}),
},
);
if (!resp.ok) throw new Error(`Create app failed: ${resp.status}`);
const app = await resp.json();
console.log("Save this:", app.api_key);<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://apx.didit.me/auth/v2/organizations/me/{org_id}/applications/",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'Acme Customer App',
'website_url' => 'https://acme.example',
'redirect_uris' => [
'https://acme.example/callback'
],
'terms_url' => 'https://acme.example/terms',
'privacy_url' => 'https://acme.example/privacy'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://apx.didit.me/auth/v2/organizations/me/{org_id}/applications/"
payload := strings.NewReader("{\n \"name\": \"Acme Customer App\",\n \"website_url\": \"https://acme.example\",\n \"redirect_uris\": [\n \"https://acme.example/callback\"\n ],\n \"terms_url\": \"https://acme.example/terms\",\n \"privacy_url\": \"https://acme.example/privacy\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://apx.didit.me/auth/v2/organizations/me/{org_id}/applications/")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"Acme Customer App\",\n \"website_url\": \"https://acme.example\",\n \"redirect_uris\": [\n \"https://acme.example/callback\"\n ],\n \"terms_url\": \"https://acme.example/terms\",\n \"privacy_url\": \"https://acme.example/privacy\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://apx.didit.me/auth/v2/organizations/me/{org_id}/applications/")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"Acme Customer App\",\n \"website_url\": \"https://acme.example\",\n \"redirect_uris\": [\n \"https://acme.example/callback\"\n ],\n \"terms_url\": \"https://acme.example/terms\",\n \"privacy_url\": \"https://acme.example/privacy\"\n}"
response = http.request(request)
puts response.read_body{
"uuid": "b2c3d4e5-6789-01bc-defg-222222222222",
"name": "Acme Customer App",
"client_id": "S9LIYGSoWNuGMLHsvEt9dQ",
"api_key": "05mHcOWL8GathLZlz8oIDawYj9qFAcoSHtz-75PAkuo",
"website_url": "https://acme.example",
"redirect_uris": [
"https://acme.example/callback"
],
"terms_url": "https://acme.example/terms",
"privacy_url": "https://acme.example/privacy",
"description": null,
"created_at": "2025-06-01T10:00:00Z"
}{
"website_url": [
"Enter a valid URL."
]
}{
"detail": "Invalid access token"
}{
"detail": "You do not have permission to perform this action."
}{
"detail": "Not found."
}Create Application
Create an application inside an organization. The response includes api_key; persist it now (recoverable via GET). Requires owner/admin JWT.
curl -X POST "https://apx.didit.me/auth/v2/organizations/me/$ORG_ID/applications/" \
-H "Authorization: Bearer $ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "Acme Customer App",
"website_url": "https://acme.example",
"redirect_uris": ["https://acme.example/callback"]
}'import requests
resp = requests.post(
f"https://apx.didit.me/auth/v2/organizations/me/{org_id}/applications/",
headers={"Authorization": f"Bearer {access_token}"},
json={
"name": "Acme Customer App",
"website_url": "https://acme.example",
"redirect_uris": ["https://acme.example/callback"],
},
timeout=10,
)
resp.raise_for_status()
app = resp.json()
print("Save this:", app["api_key"])const resp = await fetch(
`https://apx.didit.me/auth/v2/organizations/me/${orgId}/applications/`,
{
method: "POST",
headers: {
Authorization: `Bearer ${accessToken}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
name: "Acme Customer App",
website_url: "https://acme.example",
redirect_uris: ["https://acme.example/callback"],
}),
},
);
if (!resp.ok) throw new Error(`Create app failed: ${resp.status}`);
const app = await resp.json();
console.log("Save this:", app.api_key);<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://apx.didit.me/auth/v2/organizations/me/{org_id}/applications/",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'Acme Customer App',
'website_url' => 'https://acme.example',
'redirect_uris' => [
'https://acme.example/callback'
],
'terms_url' => 'https://acme.example/terms',
'privacy_url' => 'https://acme.example/privacy'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://apx.didit.me/auth/v2/organizations/me/{org_id}/applications/"
payload := strings.NewReader("{\n \"name\": \"Acme Customer App\",\n \"website_url\": \"https://acme.example\",\n \"redirect_uris\": [\n \"https://acme.example/callback\"\n ],\n \"terms_url\": \"https://acme.example/terms\",\n \"privacy_url\": \"https://acme.example/privacy\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://apx.didit.me/auth/v2/organizations/me/{org_id}/applications/")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"Acme Customer App\",\n \"website_url\": \"https://acme.example\",\n \"redirect_uris\": [\n \"https://acme.example/callback\"\n ],\n \"terms_url\": \"https://acme.example/terms\",\n \"privacy_url\": \"https://acme.example/privacy\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://apx.didit.me/auth/v2/organizations/me/{org_id}/applications/")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"Acme Customer App\",\n \"website_url\": \"https://acme.example\",\n \"redirect_uris\": [\n \"https://acme.example/callback\"\n ],\n \"terms_url\": \"https://acme.example/terms\",\n \"privacy_url\": \"https://acme.example/privacy\"\n}"
response = http.request(request)
puts response.read_body{
"uuid": "b2c3d4e5-6789-01bc-defg-222222222222",
"name": "Acme Customer App",
"client_id": "S9LIYGSoWNuGMLHsvEt9dQ",
"api_key": "05mHcOWL8GathLZlz8oIDawYj9qFAcoSHtz-75PAkuo",
"website_url": "https://acme.example",
"redirect_uris": [
"https://acme.example/callback"
],
"terms_url": "https://acme.example/terms",
"privacy_url": "https://acme.example/privacy",
"description": null,
"created_at": "2025-06-01T10:00:00Z"
}{
"website_url": [
"Enter a valid URL."
]
}{
"detail": "Invalid access token"
}{
"detail": "You do not have permission to perform this action."
}{
"detail": "Not found."
}https://apx.didit.me/auth/v2. Use the returned api_key as x-api-key when calling https://verification.didit.me/v3/... endpoints such as sessions and workflows.Authorizations
RS256-signed JWT access_token returned by POST /programmatic/login/ or POST /programmatic/verify-email/. Send as Authorization: Bearer <access_token>. Default lifetime is 86400 seconds (24h). This token is only valid against the Account Management endpoints on apx.didit.me/auth/v2. The verification API (verification.didit.me/v3) uses the long-lived api_key as x-api-key instead.
Path Parameters
UUID of the organization. Look it up with GET /organizations/me/.
"a1b2c3d4-5678-90ab-cdef-111111111111"
Body
All fields are optional. Omitting the body creates an application with default name "<organization name> App" and no public URLs configured.
All fields are optional. Sending an empty body creates an application with a default name.
Application display name. Defaults to "<organization name> App".
"Acme Customer App"
Website or app URL associated with this application.
"https://acme.example"
Allowed redirect URIs for OAuth-style and verification redirect flows.
["https://acme.example/callback"]
Terms of service URL shown in the verification flow.
"https://acme.example/terms"
Privacy policy URL shown in the verification flow.
"https://acme.example/privacy"
Internal description for the application (not shown to end users).
Response
Application created. The response includes the long-lived api_key; persist it now and use it as the x-api-key header on every https://verification.didit.me/v3/... call.
Full application record. uuid, client_id, and api_key never change after creation.
Application UUID. Use as {app_id} in subsequent calls.
"b2c3d4e5-6789-01bc-defg-222222222222"
Application display name shown in the Didit console.
"Acme Production App"
Public client identifier, safe to embed in OAuth-style flows.
"S9LIYGSoWNuGMLHsvEt9dQ"
Long-lived secret (also called client_secret). Use as the x-api-key header for every call to https://verification.didit.me/v3/... (sessions, workflows, AML, etc.). Treat as a credential; never expose client-side.
"05mHcOWL8GathLZlz8oIDawYj9qFAcoSHtz-75PAkuo"
Website or app URL associated with this application.
"https://acme.example"
Allowed redirect URIs for OAuth-style and verification redirect flows.
["https://acme.example/callback"]
Terms of service URL shown in the verification flow.
"https://acme.example/terms"
Privacy policy URL shown in the verification flow.
"https://acme.example/privacy"
Internal description for the application (not shown to end users).
"2025-06-01T10:00:00Z"