> ## Documentation Index
> Fetch the complete documentation index at: https://docs.didit.me/llms.txt
> Use this file to discover all available pages before exploring further.

# Preview Resubmission Email

> Review the recipient, sender, localized message and verification link before requesting resubmission.

Previewing does not change the session or send an email.
After reviewing the response, call [Update Session Status](/sessions-api/update-status) with the same selected steps, recipient and language, and pass the returned `preview_token` as `email_preview_token`.
The receipt expires after 15 minutes.
A changed or expired receipt returns `409` before the session is changed or an email is sent.
Generate a fresh preview after a conflict.
Existing API integrations may omit the receipt; the console supplies it when confirming a preview.

The sender and branding follow your existing [white-label configuration](/console/white-label).
Message content comes from the translated verification template; arbitrary subjects, message bodies and action URLs are not accepted as template inputs.


## OpenAPI

````yaml POST /v3/session/{sessionId}/resubmission-preview/
openapi: 3.0.0
info:
  version: 3.0.0
  title: Didit Verification API
  description: Identity verification API. Authenticate with x-api-key header.
servers:
  - url: https://verification.didit.me
security: []
tags: []
paths:
  /v3/session/{sessionId}/resubmission-preview/:
    post:
      summary: Preview a resubmission email
      description: >-
        Render the email that would accompany a KYC or KYB resubmission without
        changing the session, resetting checks, extending its expiry, running
        checks or sending mail. Requires write:sessions and an
        application-scoped session in Approved, Declined, In Review, Kyc Expired
        or Abandoned status. The server validates the selected workflow steps
        and renders its fixed translated template with the applicable verified
        white-label sender and branding. The request cannot set a subject,
        message body or action URL.


        The response includes the recipient, sender, subject, HTML, resolved
        steps and a signed preview_token. requires_user_action describes whether
        the selected steps include an interactive check. Email delivery remains
        conditional: if automatic checks finalize the verification during the
        subsequent resubmission, no action-request email is sent.


        This preview does not reserve session state or authorize delivery. After
        reviewing it, call Update Session Status with new_status=Resubmitted,
        the same selection, recipient and language, and email_preview_token set
        to the returned preview_token. The receipt expires after 15 minutes.
        When a receipt is supplied, changed inputs, message content, sender or
        session state return 409 before any mutation or send. Existing
        integrations may omit the receipt. Regenerate the preview after a
        conflict. Treat the response as sensitive verification content;
        responses use Cache-Control: no-store. Render HTML in a sandboxed frame,
        never directly in your application DOM.
      parameters:
        - in: path
          name: sessionId
          required: true
          description: >-
            UUID of the verification session to update. Accepts both user (KYC)
            and business (KYB) session IDs — the service resolves the ID across
            both session types.
          schema:
            type: string
            format: uuid
            example: 11111111-2222-3333-4444-555555555555
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - email_address
              properties:
                nodes_to_resubmit:
                  type: array
                  description: >-
                    Steps to preview, using the same validation, selection and
                    workflow ordering as a resubmission. Omit to auto-select
                    recorded attempts needing resubmission.
                  items:
                    type: object
                    required:
                      - node_id
                      - feature
                    properties:
                      node_id:
                        type: string
                        description: >-
                          Node identifier as it appears in the session's
                          workflow definition (for example `feature_ocr`,
                          `feature_liveness`).
                        example: feature_ocr
                      feature:
                        type: string
                        description: >-
                          Feature type of the node. The aliases
                          `ID_VERIFICATION`, `POA`, `PHONE`, and `EMAIL` are
                          normalized server-side to `OCR`, `PROOF_OF_ADDRESS`,
                          `PHONE_VERIFICATION`, and `EMAIL_VERIFICATION`.
                          `KYB_REGISTRY`, `KYB_KEY_PEOPLE`, and `KYB` pass
                          schema validation but are always rejected with the
                          business-rule `400` shown in the examples.
                        enum:
                          - OCR
                          - OCR_BACK
                          - NFC
                          - AML
                          - FACE
                          - LIVENESS
                          - FACE_MATCH
                          - IP_ANALYSIS
                          - AGE_ESTIMATION
                          - PROOF_OF_ADDRESS
                          - PHONE_VERIFICATION
                          - EMAIL_VERIFICATION
                          - FACE_SEARCH
                          - DATABASE_VALIDATION
                          - QUESTIONNAIRE
                          - DOCUMENT_AI
                          - KYB_DOCUMENTS
                          - ID_VERIFICATION
                          - POA
                          - PHONE
                          - EMAIL
                          - KYB_REGISTRY
                          - KYB_KEY_PEOPLE
                          - KYB
                        example: OCR
                email_address:
                  type: string
                  format: email
                  description: Recipient shown in the preview. No email is sent.
                  example: user@example.com
                email_language:
                  type: string
                  description: >-
                    Language for the notification email. Accepts any string at
                    schema level; unsupported codes silently fall back to
                    English (`en`).
                  default: en
                  example: en
      responses:
        '200':
          description: Preview only. The session is unchanged and no email is sent.
          content:
            application/json:
              schema:
                type: object
                required:
                  - recipient
                  - sender
                  - subject
                  - html
                  - nodes_to_resubmit
                  - requires_user_action
                  - preview_token
                properties:
                  recipient:
                    type: string
                    format: email
                  sender:
                    type: string
                  subject:
                    type: string
                  html:
                    type: string
                    description: >-
                      Rendered email. Inline image attachments use data URLs for
                      preview.
                  nodes_to_resubmit:
                    type: array
                    items:
                      type: object
                      required:
                        - node_id
                        - feature
                      properties:
                        node_id:
                          type: string
                          description: >-
                            Node identifier as it appears in the session's
                            workflow definition (for example `feature_ocr`,
                            `feature_liveness`).
                          example: feature_ocr
                        feature:
                          type: string
                          description: >-
                            Feature type of the node. The aliases
                            `ID_VERIFICATION`, `POA`, `PHONE`, and `EMAIL` are
                            normalized server-side to `OCR`, `PROOF_OF_ADDRESS`,
                            `PHONE_VERIFICATION`, and `EMAIL_VERIFICATION`.
                            `KYB_REGISTRY`, `KYB_KEY_PEOPLE`, and `KYB` pass
                            schema validation but are always rejected with the
                            business-rule `400` shown in the examples.
                          enum:
                            - OCR
                            - OCR_BACK
                            - NFC
                            - AML
                            - FACE
                            - LIVENESS
                            - FACE_MATCH
                            - IP_ANALYSIS
                            - AGE_ESTIMATION
                            - PROOF_OF_ADDRESS
                            - PHONE_VERIFICATION
                            - EMAIL_VERIFICATION
                            - FACE_SEARCH
                            - DATABASE_VALIDATION
                            - QUESTIONNAIRE
                            - DOCUMENT_AI
                            - KYB_DOCUMENTS
                            - ID_VERIFICATION
                            - POA
                            - PHONE
                            - EMAIL
                            - KYB_REGISTRY
                            - KYB_KEY_PEOPLE
                            - KYB
                          example: OCR
                  requires_user_action:
                    type: boolean
                    description: >-
                      Whether at least one selected check requires user
                      interaction. This does not predict the final workflow
                      outcome.
                  preview_token:
                    type: string
                    description: >-
                      Signed confirmation receipt, valid for 15 minutes. Pass it
                      as email_preview_token when confirming the same message.
        '400':
          description: Invalid email, state or workflow selection.
        '403':
          description: Authentication or write:sessions permission is missing.
        '404':
          description: No session exists in the requested application.
      security:
        - ApiKeyAuth: []
components:
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: >-
        Your application's API key, from Developers -> API keys in the Business
        Console. The primary key has full access. A named key can be scoped:
        none, read or write per resource, limited to some workflows or to
        approved sessions, to a list of IP addresses, and to an expiry date. 401
        means the key is missing, wrong, revoked or expired; 403 means the key
        has no access to this resource or action, or the request came from an
        address outside its IP list; 404 on a session route means the session is
        outside the key's workflows or statuses. A key without media access
        receives image, video and PDF URLs as null, and a key without sessions
        write receives session links and tokens as null. See
        https://docs.didit.me/console/api-keys.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.