# Esectra - [Esectra documentation](https://docs.qa.esectra.com/index.md): Identity verification, risk decisions, and customer oversight. - [Quickstart](https://docs.qa.esectra.com/quickstart.md): Open a hosted identity verification session. - [Hosted capture](https://docs.qa.esectra.com/verify/hosted-capture.md): What the person being verified sees. - [Verification branding](https://docs.qa.esectra.com/verify/branding.md): Set the organization name, accent, and logo used on capture links. - [Esectra Control](https://docs.qa.esectra.com/operate/control.md): Customer oversight of cases, verifications, and operations. - [Deployment requirements](https://docs.qa.esectra.com/operate/deployment.md): What a deployment needs before the verification flow can be tested. - [Handles `GET /v1/audit`.](https://docs.qa.esectra.com/api-reference/audit/handles-`get-v1audit`.md): # Errors - [`POST /v1/capture/{token}/complete`: the person says they are finished.](https://docs.qa.esectra.com/api-reference/capture/`post-v1capture-complete`:-the-person-says-they-are-finished.md) - [`POST /v1/capture/{token}/media`: stores one capture against the session.](https://docs.qa.esectra.com/api-reference/capture/`post-v1capture-media`:-stores-one-capture-against-the-session.md) - [`GET /verify/{token}`: the capture flow.](https://docs.qa.esectra.com/api-reference/capture/`get-verify-`:-the-capture-flow.md) - [Handles `GET /v1/cases`.](https://docs.qa.esectra.com/api-reference/cases/handles-`get-v1cases`.md): # Errors - [Handles `GET /v1/cases/{id}`.](https://docs.qa.esectra.com/api-reference/cases/handles-`get-v1cases-`.md): # Errors - [Handles `POST /v1/cases/{id}/decision`.](https://docs.qa.esectra.com/api-reference/cases/handles-`post-v1cases-decision`.md): # Errors - [`GET /v1/control/api-keys`.](https://docs.qa.esectra.com/api-reference/control/`get-v1controlapi-keys`.md): # Errors - [`POST /v1/control/api-keys`.](https://docs.qa.esectra.com/api-reference/control/`post-v1controlapi-keys`.md): # Errors - [`DELETE /v1/control/api-keys/{key_id}`.](https://docs.qa.esectra.com/api-reference/control/`delete-v1controlapi-keys-`.md): # Errors - [Returns this reviewer's tenant theme, falling back to the deployment theme. # Errors](https://docs.qa.esectra.com/api-reference/control/returns-this-reviewers-tenant-theme-falling-back-to-the-deployment-theme#-errors.md): Returns `401` without a session and `403` for an API key, which acts for a tenant rather than a person. `503` when the theme store cannot be read. - [Replaces this tenant's capture theme. Requires the team management permission. # Errors](https://docs.qa.esectra.com/api-reference/control/replaces-this-tenants-capture-theme-requires-the-team-management-permission#-errors.md): Returns `401` without a session, `403` without `TeamManage`, `422` when the theme is not usable, and `503` when the store cannot be written. - [`GET /v1/control/invitations/{token}`: what this invitation is for.](https://docs.qa.esectra.com/api-reference/control/`get-v1controlinvitations-`:-what-this-invitation-is-for.md): Unauthenticated by necessity - the invitee has no account yet. It reveals only the address the invitation was already sent to and the role it grants, and an unknown token is a flat `404` rather than anything that would let somebody probe for live tokens. # Errors - [`POST /v1/control/invitations/{token}/accept`: creates the account.](https://docs.qa.esectra.com/api-reference/control/`post-v1controlinvitations-accept`:-creates-the-account.md): The session it returns is *pending*: the new reviewer must enrol a second factor before it opens anything. - [`GET /v1/control/kyt/sources`.](https://docs.qa.esectra.com/api-reference/control/`get-v1controlkytsources`.md): # Errors - [`GET /v1/control/login-options`: which sign-in methods this deployment offers. Unauthenticated by necessity — it is read before anyone is signed in — and it reveals only which buttons to draw.](https://docs.qa.esectra.com/api-reference/control/`get-v1controllogin-options`:-which-sign-in-methods-this-deploymentoffers-unauthenticated-by-necessity-—-it-is-read-before-anyone-is-signedin-—-and-it-reveals-only-which-buttons-to-draw.md) - [`GET /v1/control/me`: the signed-in reviewer, or `401`. # Errors](https://docs.qa.esectra.com/api-reference/control/`get-v1controlme`:-the-signed-in-reviewer-or-`401`#-errors.md): Returns `403` for an API key, which acts for a tenant rather than a person, `401` when there is no session at all, and `503` when the reviewer or enrolment store cannot be read. - [`POST /v1/control/mfa/confirm`: proves the app works, and finishes enrolment.](https://docs.qa.esectra.com/api-reference/control/`post-v1controlmfaconfirm`:-proves-the-app-works-and-finishes-enrolment.md): The code is required before the enrolment counts. Without it, somebody who mis-scanned the QR would be locked out of their own account with a perfectly valid-looking secret on the server. - [`POST /v1/control/mfa/enroll`: starts or restarts enrolment.](https://docs.qa.esectra.com/api-reference/control/`post-v1controlmfaenroll`:-starts-or-restarts-enrolment.md): Available only to a session that has not yet satisfied its second factor, and refused outright once one is confirmed - otherwise anyone who walked past an unlocked screen could quietly replace the second factor with their own. # Errors - [`POST /v1/control/mfa/verify`: satisfies the second factor for this session.](https://docs.qa.esectra.com/api-reference/control/`post-v1controlmfaverify`:-satisfies-the-second-factor-for-this-session.md) - [Returns the policy in force for this reviewer's tenant.](https://docs.qa.esectra.com/api-reference/control/returns-the-policy-in-force-for-this-reviewers-tenant.md): A tenant with no published policy is under Esectra's strict default, and the route says so rather than answering `404`: there is always a policy, and "none published" is a fact about the tenant, not a missing resource. - [`POST /v1/control/sessions`: signs a reviewer in with a password.](https://docs.qa.esectra.com/api-reference/control/`post-v1controlsessions`:-signs-a-reviewer-in-with-a-password.md): Every failure returns the same `401`. A login form that distinguishes "no such account" from "wrong password" is a staff directory for anyone who asks it politely. - [`DELETE /v1/control/sessions`: signs the reviewer out.](https://docs.qa.esectra.com/api-reference/control/`delete-v1controlsessions`:-signs-the-reviewer-out.md): The session row is deleted, not just the cookie: a token copied off the wire must stop working when its owner signs out. - [`GET /v1/control/sso/callback`: completes a company SSO sign-in.](https://docs.qa.esectra.com/api-reference/control/`get-v1controlssocallback`:-completes-a-company-sso-sign-in.md) - [`GET /v1/control/sso/start`: sends the browser to the company identity provider.](https://docs.qa.esectra.com/api-reference/control/`get-v1controlssostart`:-sends-the-browser-to-the-company-identityprovider.md) - [`GET /v1/control/team`: who is on the team, and who has been invited. # Errors](https://docs.qa.esectra.com/api-reference/control/`get-v1controlteam`:-who-is-on-the-team-and-who-has-been-invited#-errors.md): Returns `401` without a session, `403` without `TeamInvite`, and `503` when the reviewer, enrolment or invitation store cannot be read. - [`POST /v1/control/team/invitations`: invites somebody. # Errors](https://docs.qa.esectra.com/api-reference/control/`post-v1controlteaminvitations`:-invites-somebody#-errors.md): Returns `401` without a session, `403` without `TeamInvite` or when the role is stronger than the caller's, `422` for an unusable address or unknown role, `409` when the address already has an account, and `503` when a store cannot be reached. - [`DELETE /v1/control/team/invitations/{id}`: withdraws an invitation. # Errors](https://docs.qa.esectra.com/api-reference/control/`delete-v1controlteaminvitations-`:-withdraws-an-invitation#-errors.md): Returns `401` without a session, `403` without `TeamInvite`, `404` when the invitation is unknown or already accepted, and `503` when the store cannot be reached. - [`POST /v1/control/team/{id}/mfa-reset`: clears somebody's second factor.](https://docs.qa.esectra.com/api-reference/control/`post-v1controlteam-mfa-reset`:-clears-somebodys-second-factor.md): The path back in for a person who has lost both their phone and their recovery codes. It is deliberately an admin action rather than a self-service one: a self-service reset is a way around the second factor. # Errors - [Handles `GET /v1/control/verification-sessions`.](https://docs.qa.esectra.com/api-reference/control/handles-`get-v1controlverification-sessions`.md): # Errors - [Handles `GET /v1/control/verification-sessions/{session_id}`.](https://docs.qa.esectra.com/api-reference/control/handles-`get-v1controlverification-sessions-`.md): # Errors - [Handles `POST /v1/transactions`.](https://docs.qa.esectra.com/api-reference/transactions/handles-`post-v1transactions`.md): # Errors - [Handles `GET /v1/transactions/:id`.](https://docs.qa.esectra.com/api-reference/transactions/handles-`get-v1transactions:id`.md): # Errors - [`GET /v1/transactions/{transaction_id}/screening`.](https://docs.qa.esectra.com/api-reference/transactions/`get-v1transactions-screening`.md): Answers the question a decision alone cannot: what was actually consulted. A customer holding a transfer needs to tell "we are still waiting on the vendor" apart from "the vendor found something", and from outside those look identical when only the outcome is exposed. - [Handles `POST /v1/verifications`.](https://docs.qa.esectra.com/api-reference/verifications/handles-`post-v1verifications`.md): # Errors - [Handles `POST /v1/verifications/sessions`.](https://docs.qa.esectra.com/api-reference/verifications/handles-`post-v1verificationssessions`.md): Runs the checks the tenant's policy requires and returns the outcome. A provider outage is not an error here: it produces a review-required session, because an unreachable model says nothing about the person. - [Handles `GET /v1/verifications/{id}`.](https://docs.qa.esectra.com/api-reference/verifications/handles-`get-v1verifications-`.md): # Errors - [Handles `POST /v1/verify/face-match`.](https://docs.qa.esectra.com/api-reference/verifications/handles-`post-v1verifyface-match`.md): # Errors - [Handles `POST /v1/wallets/screen`.](https://docs.qa.esectra.com/api-reference/wallets/handles-`post-v1walletsscreen`.md): # Errors - [Handles `GET /v1/wallets/{network}/{address}/screenings`.](https://docs.qa.esectra.com/api-reference/wallets/handles-`get-v1wallets-screenings`.md): # Errors - [Handles `GET /v1/webhooks/deliveries`.](https://docs.qa.esectra.com/api-reference/webhooks/handles-`get-v1webhooksdeliveries`.md): # Errors - [Handles `GET /v1/webhooks/endpoints`.](https://docs.qa.esectra.com/api-reference/webhooks/handles-`get-v1webhooksendpoints`.md): # Errors - [Handles `POST /v1/webhooks/endpoints`.](https://docs.qa.esectra.com/api-reference/webhooks/handles-`post-v1webhooksendpoints`.md): # Errors ## OpenAPI Specs - [openapi](/openapi.json)