Message purposes
Document uploads currently accept JPEG, PNG and WebP images up to 5 MB.
Only the purposes applicable to the case subject appear.
Customer email templates are currently available in English, Spanish and Portuguese.
The console uses the same email field and language selector as session resubmission.
Verified recipients and fixed templates
A recipient must have completed email verification in a session belonging to the case subject and application. An address imported or edited in a user profile does not establish verification. If no verified contact exists, the composer explains this and sending stays disabled. Reviewers cannot supply arbitrary email text, links, sender addresses or recipients. The email uses the existing Didit or white-label branding. A custom sender requires the configured email domain to be verified. Every template tells the recipient that the email will not request passwords, verification codes or payment. Session resubmission remains a separate action for repeating verification checks. Its preview shows the actual resubmission email and the selected checks.Delivery and responses
The message history distinguishes queued, sending, sent, simulated and unknown delivery outcomes. A simulated email is not sent. An unknown outcome means the provider might have accepted the email; the system does not automatically send it again. Retrying a confirmed request uses the same request ID to avoid duplicate delivery. An actionable request has a secure response link valid for seven days. Cancelling the request or resolving the case invalidates that link, including after a case is reopened. The customer page does not disclose private case findings or other source records. A submitted response appears in Customer messages as evidence pending review. The case returns to Open, and an existing pending resolution must be reviewed again. Responses cannot replace an earlier submission, approve the original verification, overwrite a customer’s identity or contribute a fraud outcome. Deleting the source verification or case deletes its customer requests and their uploaded evidence.API workflow
All console endpoints are scoped to an organization, application and case:read:cases.
Composing, previewing, confirming and cancelling requires write:cases.
Confirmation must include the same contact_id, purpose and language, plus the request_id, expires_at and preview_token returned by the preview.
The confirmation receipt expires after 15 minutes, independently of the customer’s response deadline.
The customer endpoint is GET or POST /v3/case-requests/{request_uuid}/ with its request-specific X-Case-Request-Token header.
The response link carries that credential in its fragment; the page removes the fragment when it opens.
The token grants access only to that request.