Skip to main content
The Idesify API is the server-side half of every integration. Your backend calls it with your API key; your frontend never does.
Building a browser integration? Start with the Browser SDK. The SDK covers identity verification, consent, and rights requests as embeddable widgets, and it never needs your API key.

Authentication

Requests are authenticated with a Bearer token:
Your API key is a server-side secret. Never ship it to a browser, embed it in a frontend bundle, or commit it to a repository. If a key is ever exposed, rotate it — treat it as compromised regardless of how briefly it was visible.

Session tokens for the browser

Browser widgets do not use your API key. Instead, your backend exchanges the key for a short-lived session token and returns that to your frontend, which hands it to the SDK.
Mint the token immediately before mounting a widget, and mint it from an endpoint that authenticates the caller — an unauthenticated token endpoint hands anyone a session. See the Security model for the full picture.

Endpoint reference

Full endpoint documentation is being prepared. In the meantime, contact support@idesify.com for the current API specification.