Skip to main content
POST
curl

Authorizations

x-api-key
string
header
required

Your application's API key, from Developers -> API keys in the Business Console. The primary key has full access. A named key can be scoped: none, read or write per resource, limited to some workflows or to approved sessions, to a list of IP addresses, and to an expiry date. 401 means the key is missing, wrong, revoked or expired; 403 means the key has no access to this resource or action, or the request came from an address outside its IP list; 404 on a session route means the session is outside the key's workflows or statuses. A key without media access receives image, video and PDF URLs as null, and a key without sessions write receives session links and tokens as null. See https://docs.didit.me/console/api-keys.

Body

application/json
vendor_data
string
required

Your internal identifier for the end user this token is scoped to. Enforced as the subject identity of every transaction submitted with the token.

Example:

"user-042"

ttl_seconds
integer
default:900

Token lifetime in seconds. Defaults to 900 (15 minutes); maximum 86400 (24 hours).

Required range: x <= 86400
max_uses
integer | null

Maximum number of successful submissions allowed with this token. Omit or null for unlimited uses within the TTL.

Response

The minted token. Hand sdk_token to your app; it authenticates the device-facing /v1/transactions/ endpoints via the X-Transaction-Token header until expires_at.

sdk_token
string

The scoped transaction token to pass to the SDK.

expires_at
string<date-time>

When the token stops being accepted.