Knox Docs Sign in

API reference

Test mode. Use your secret key on your server; live processing is currently disabled.

https://api.knoxapi.com

Send form-encoded requests with Authorization: Bearer sk_test_....

Complete OpenAPI specification · Integration guide

Operations and schemas are based on the pinned Stripe OpenAPI specification (MIT). Nested object definitions and enums are available in the complete specification.

GET /v1/identity/verification_reports

List VerificationReports

List all verification reports.

Request parameters

ParameterLocationTypeDescription
client_reference_idquerystringA string to reference this user. This can be a customer ID, a session ID, or similar, and can be used to reconcile this verification with your internal systems.
createdqueryone of multiple schemasOnly return VerificationReports that were created during the given date interval.
ending_beforequerystringA cursor for use in pagination. `ending_before` is an object ID that defines your place in the list. For instance, if you make a list request and receive 100 objects, starting with `obj_bar`, your subsequent call can include `ending_before=obj_bar` in order to fetch the previous page of the list.
expandqueryarray of stringSpecifies which fields in the response should be expanded.
limitqueryintegerA limit on the number of objects to be returned. Limit can range between 1 and 100, and the default is 10.
starting_afterquerystringA cursor for use in pagination. `starting_after` is an object ID that defines your place in the list. For instance, if you make a list request and receive 100 objects, ending with `obj_foo`, your subsequent call can include `starting_after=obj_foo` in order to fetch the next page of the list.
typequerystringOnly return VerificationReports of this type
verification_sessionquerystringOnly return VerificationReports created by this VerificationSession ID. It is allowed to provide a VerificationIntent ID.

object. See the OpenAPI specification for the complete schema.

Responses

HTTP 200: Successful response.
FieldTypeDescription
data requiredarray of identity.verification_report
has_more requiredbooleanTrue if this list has another page of items after this one that can be fetched.
object requiredstringString representing the object's type. Objects of the same type share the same value. Always has the value `list`.
url requiredstringThe URL where this list can be accessed.
HTTP default: Error response.
FieldTypeDescription
error requiredapi_errors
GET /v1/identity/verification_sessions

List VerificationSessions

Returns a list of VerificationSessions

Request parameters

ParameterLocationTypeDescription
client_reference_idquerystringA string to reference this user. This can be a customer ID, a session ID, or similar, and can be used to reconcile this verification with your internal systems.
createdqueryone of multiple schemasOnly return VerificationSessions that were created during the given date interval.
ending_beforequerystringA cursor for use in pagination. `ending_before` is an object ID that defines your place in the list. For instance, if you make a list request and receive 100 objects, starting with `obj_bar`, your subsequent call can include `ending_before=obj_bar` in order to fetch the previous page of the list.
expandqueryarray of stringSpecifies which fields in the response should be expanded.
limitqueryintegerA limit on the number of objects to be returned. Limit can range between 1 and 100, and the default is 10.
related_customerquerystringCustomer ID
related_customer_accountquerystringThe ID of the Account representing a customer.
starting_afterquerystringA cursor for use in pagination. `starting_after` is an object ID that defines your place in the list. For instance, if you make a list request and receive 100 objects, ending with `obj_foo`, your subsequent call can include `starting_after=obj_foo` in order to fetch the next page of the list.
statusquerystringOnly return VerificationSessions with this status. [Learn more about the lifecycle of sessions](https://docs.stripe.com/identity/how-sessions-work).

object. See the OpenAPI specification for the complete schema.

Responses

HTTP 200: Successful response.
FieldTypeDescription
data requiredarray of identity.verification_session
has_more requiredbooleanTrue if this list has another page of items after this one that can be fetched.
object requiredstringString representing the object's type. Objects of the same type share the same value. Always has the value `list`.
url requiredstringThe URL where this list can be accessed.
HTTP default: Error response.
FieldTypeDescription
error requiredapi_errors
POST /v1/identity/verification_sessions

Create a VerificationSession

Creates a VerificationSession object. After the VerificationSession is created, display a verification modal using the session client_secret or send your users to the session’s url. If your API key is in test mode, verification checks won’t actually process, though everything else will occur as if in live mode. Related guide: Verify your users’ identity documents

Request parameters

FieldTypeDescription
client_reference_idstringA string to reference this user. This can be a customer ID, a session ID, or similar, and can be used to reconcile this verification with your internal systems.
expandarray of stringSpecifies which fields in the response should be expanded.
metadataobjectSet of [key-value pairs](https://docs.stripe.com/api/metadata) that you can attach to an object. This can be useful for storing additional information about the object in a structured format. Individual keys can be unset by posting an empty value to them. All keys can be unset by posting an empty value to `metadata`.
optionsobjectA set of options for the session’s verification checks.
provided_detailsobjectDetails provided about the user being verified. These details might be shown to the user.
related_customerstringCustomer ID
related_customer_accountstringThe ID of the Account representing a customer.
related_personobjectTokens referencing a Person resource and its associated account.
return_urlstringThe URL that the user will be redirected to upon completing the verification flow.
typestringThe type of [verification check](https://docs.stripe.com/identity/verification-checks) to be performed. You must provide a `type` if not passing `verification_flow`.
verification_flowstringThe ID of a verification flow from the Dashboard. See https://docs.stripe.com/identity/verification-flows.

Responses

HTTP 200: Successful response.
FieldTypeDescription
client_reference_idstringA string to reference this user. This can be a customer ID, a session ID, or similar, and can be used to reconcile this verification with your internal systems.
client_secretstringThe short-lived client secret used by Stripe.js to [show a verification modal](https://docs.stripe.com/js/identity/modal) inside your app. This client secret expires after 24 hours and can only be used once. Don’t store it, log it, embed it in a URL, or expose it to anyone other than the user. Make sure that you have TLS enabled on any page that includes the client secret. Refer to our docs on [passing the client secret to the frontend](https://docs.stripe.com/identity/verification-sessions#client-secret) to learn more.
created requiredintegerTime at which the object was created. Measured in seconds since the Unix epoch.
id requiredstringUnique identifier for the object.
last_errorone of multiple schemasIf present, this property tells you the last error encountered when processing the verification.
last_verification_reportone of multiple schemasID of the most recent VerificationReport. [Learn more about accessing detailed verification results.](https://docs.stripe.com/identity/verification-sessions#results)
livemode requiredbooleanIf the object exists in live mode, the value is `true`. If the object exists in test mode, the value is `false`.
metadata requiredobjectSet of [key-value pairs](https://docs.stripe.com/api/metadata) that you can attach to an object. This can be useful for storing additional information about the object in a structured format.
object requiredstringString representing the object's type. Objects of the same type share the same value.
optionsone of multiple schemasA set of options for the session’s verification checks.
provided_detailsone of multiple schemasDetails provided about the user being verified. These details may be shown to the user.
redactionone of multiple schemasRedaction status of this VerificationSession. If the VerificationSession is not redacted, this field will be null.
related_customerstringCustomer ID
related_customer_accountstringThe ID of the Account representing a customer.
related_persongelato_related_person
status requiredstringStatus of this VerificationSession. [Learn more about the lifecycle of sessions](https://docs.stripe.com/identity/how-sessions-work).
type requiredstringThe type of [verification check](https://docs.stripe.com/identity/verification-checks) to be performed.
urlstringThe short-lived URL that you use to redirect a user to Stripe to submit their identity information. This URL expires after 48 hours and can only be used once. Don’t store it, log it, send it in emails or expose it to anyone other than the user. Refer to our docs on [verifying identity documents](https://docs.stripe.com/identity/verify-identity-documents?platform=web&type=redirect) to learn how to redirect users to Stripe.
verification_flowstringThe configuration token of a verification flow from the dashboard.
verified_outputsone of multiple schemasThe user’s verified data.
HTTP default: Error response.
FieldTypeDescription
error requiredapi_errors
GET /v1/identity/verification_reports/{report}

Retrieve a VerificationReport

Retrieves an existing VerificationReport

Request parameters

ParameterLocationTypeDescription
expandqueryarray of stringSpecifies which fields in the response should be expanded.
reportpathstring

object. See the OpenAPI specification for the complete schema.

Responses

HTTP 200: Successful response.
FieldTypeDescription
client_reference_idstringA string to reference this user. This can be a customer ID, a session ID, or similar, and can be used to reconcile this verification with your internal systems.
created requiredintegerTime at which the object was created. Measured in seconds since the Unix epoch.
documentgelato_document_report
emailgelato_email_report
id requiredstringUnique identifier for the object.
id_numbergelato_id_number_report
livemode requiredbooleanIf the object exists in live mode, the value is `true`. If the object exists in test mode, the value is `false`.
object requiredstringString representing the object's type. Objects of the same type share the same value.
optionsgelato_verification_report_options
phonegelato_phone_report
selfiegelato_selfie_report
type requiredstringType of report.
verification_flowstringThe configuration token of a verification flow from the dashboard.
verification_sessionstringID of the VerificationSession that created this report.
HTTP default: Error response.
FieldTypeDescription
error requiredapi_errors
GET /v1/identity/verification_sessions/{session}

Retrieve a VerificationSession

Retrieves the details of a VerificationSession that was previously created. When the session status is requires_input, you can use this method to retrieve a valid client_secret or url to allow re-submission.

Request parameters

ParameterLocationTypeDescription
expandqueryarray of stringSpecifies which fields in the response should be expanded.
sessionpathstring

object. See the OpenAPI specification for the complete schema.

Responses

HTTP 200: Successful response.
FieldTypeDescription
client_reference_idstringA string to reference this user. This can be a customer ID, a session ID, or similar, and can be used to reconcile this verification with your internal systems.
client_secretstringThe short-lived client secret used by Stripe.js to [show a verification modal](https://docs.stripe.com/js/identity/modal) inside your app. This client secret expires after 24 hours and can only be used once. Don’t store it, log it, embed it in a URL, or expose it to anyone other than the user. Make sure that you have TLS enabled on any page that includes the client secret. Refer to our docs on [passing the client secret to the frontend](https://docs.stripe.com/identity/verification-sessions#client-secret) to learn more.
created requiredintegerTime at which the object was created. Measured in seconds since the Unix epoch.
id requiredstringUnique identifier for the object.
last_errorone of multiple schemasIf present, this property tells you the last error encountered when processing the verification.
last_verification_reportone of multiple schemasID of the most recent VerificationReport. [Learn more about accessing detailed verification results.](https://docs.stripe.com/identity/verification-sessions#results)
livemode requiredbooleanIf the object exists in live mode, the value is `true`. If the object exists in test mode, the value is `false`.
metadata requiredobjectSet of [key-value pairs](https://docs.stripe.com/api/metadata) that you can attach to an object. This can be useful for storing additional information about the object in a structured format.
object requiredstringString representing the object's type. Objects of the same type share the same value.
optionsone of multiple schemasA set of options for the session’s verification checks.
provided_detailsone of multiple schemasDetails provided about the user being verified. These details may be shown to the user.
redactionone of multiple schemasRedaction status of this VerificationSession. If the VerificationSession is not redacted, this field will be null.
related_customerstringCustomer ID
related_customer_accountstringThe ID of the Account representing a customer.
related_persongelato_related_person
status requiredstringStatus of this VerificationSession. [Learn more about the lifecycle of sessions](https://docs.stripe.com/identity/how-sessions-work).
type requiredstringThe type of [verification check](https://docs.stripe.com/identity/verification-checks) to be performed.
urlstringThe short-lived URL that you use to redirect a user to Stripe to submit their identity information. This URL expires after 48 hours and can only be used once. Don’t store it, log it, send it in emails or expose it to anyone other than the user. Refer to our docs on [verifying identity documents](https://docs.stripe.com/identity/verify-identity-documents?platform=web&type=redirect) to learn how to redirect users to Stripe.
verification_flowstringThe configuration token of a verification flow from the dashboard.
verified_outputsone of multiple schemasThe user’s verified data.
HTTP default: Error response.
FieldTypeDescription
error requiredapi_errors
POST /v1/identity/verification_sessions/{session}

Update a VerificationSession

Updates a VerificationSession object. When the session status is requires_input, you can use this method to update the verification check and options.

Request parameters

ParameterLocationTypeDescription
sessionpathstring
FieldTypeDescription
expandarray of stringSpecifies which fields in the response should be expanded.
metadataobjectSet of [key-value pairs](https://docs.stripe.com/api/metadata) that you can attach to an object. This can be useful for storing additional information about the object in a structured format. Individual keys can be unset by posting an empty value to them. All keys can be unset by posting an empty value to `metadata`.
optionsobjectA set of options for the session’s verification checks.
provided_detailsobjectDetails provided about the user being verified. These details may be shown to the user.
typestringThe type of [verification check](https://docs.stripe.com/identity/verification-checks) to be performed.

Responses

HTTP 200: Successful response.
FieldTypeDescription
client_reference_idstringA string to reference this user. This can be a customer ID, a session ID, or similar, and can be used to reconcile this verification with your internal systems.
client_secretstringThe short-lived client secret used by Stripe.js to [show a verification modal](https://docs.stripe.com/js/identity/modal) inside your app. This client secret expires after 24 hours and can only be used once. Don’t store it, log it, embed it in a URL, or expose it to anyone other than the user. Make sure that you have TLS enabled on any page that includes the client secret. Refer to our docs on [passing the client secret to the frontend](https://docs.stripe.com/identity/verification-sessions#client-secret) to learn more.
created requiredintegerTime at which the object was created. Measured in seconds since the Unix epoch.
id requiredstringUnique identifier for the object.
last_errorone of multiple schemasIf present, this property tells you the last error encountered when processing the verification.
last_verification_reportone of multiple schemasID of the most recent VerificationReport. [Learn more about accessing detailed verification results.](https://docs.stripe.com/identity/verification-sessions#results)
livemode requiredbooleanIf the object exists in live mode, the value is `true`. If the object exists in test mode, the value is `false`.
metadata requiredobjectSet of [key-value pairs](https://docs.stripe.com/api/metadata) that you can attach to an object. This can be useful for storing additional information about the object in a structured format.
object requiredstringString representing the object's type. Objects of the same type share the same value.
optionsone of multiple schemasA set of options for the session’s verification checks.
provided_detailsone of multiple schemasDetails provided about the user being verified. These details may be shown to the user.
redactionone of multiple schemasRedaction status of this VerificationSession. If the VerificationSession is not redacted, this field will be null.
related_customerstringCustomer ID
related_customer_accountstringThe ID of the Account representing a customer.
related_persongelato_related_person
status requiredstringStatus of this VerificationSession. [Learn more about the lifecycle of sessions](https://docs.stripe.com/identity/how-sessions-work).
type requiredstringThe type of [verification check](https://docs.stripe.com/identity/verification-checks) to be performed.
urlstringThe short-lived URL that you use to redirect a user to Stripe to submit their identity information. This URL expires after 48 hours and can only be used once. Don’t store it, log it, send it in emails or expose it to anyone other than the user. Refer to our docs on [verifying identity documents](https://docs.stripe.com/identity/verify-identity-documents?platform=web&type=redirect) to learn how to redirect users to Stripe.
verification_flowstringThe configuration token of a verification flow from the dashboard.
verified_outputsone of multiple schemasThe user’s verified data.
HTTP default: Error response.
FieldTypeDescription
error requiredapi_errors
POST /v1/identity/verification_sessions/{session}/cancel

Cancel a VerificationSession

A VerificationSession object can be canceled when it is in requires_input status. Once canceled, future submission attempts are disabled. This cannot be undone. Learn more.

Request parameters

ParameterLocationTypeDescription
sessionpathstring
FieldTypeDescription
expandarray of stringSpecifies which fields in the response should be expanded.

Responses

HTTP 200: Successful response.
FieldTypeDescription
client_reference_idstringA string to reference this user. This can be a customer ID, a session ID, or similar, and can be used to reconcile this verification with your internal systems.
client_secretstringThe short-lived client secret used by Stripe.js to [show a verification modal](https://docs.stripe.com/js/identity/modal) inside your app. This client secret expires after 24 hours and can only be used once. Don’t store it, log it, embed it in a URL, or expose it to anyone other than the user. Make sure that you have TLS enabled on any page that includes the client secret. Refer to our docs on [passing the client secret to the frontend](https://docs.stripe.com/identity/verification-sessions#client-secret) to learn more.
created requiredintegerTime at which the object was created. Measured in seconds since the Unix epoch.
id requiredstringUnique identifier for the object.
last_errorone of multiple schemasIf present, this property tells you the last error encountered when processing the verification.
last_verification_reportone of multiple schemasID of the most recent VerificationReport. [Learn more about accessing detailed verification results.](https://docs.stripe.com/identity/verification-sessions#results)
livemode requiredbooleanIf the object exists in live mode, the value is `true`. If the object exists in test mode, the value is `false`.
metadata requiredobjectSet of [key-value pairs](https://docs.stripe.com/api/metadata) that you can attach to an object. This can be useful for storing additional information about the object in a structured format.
object requiredstringString representing the object's type. Objects of the same type share the same value.
optionsone of multiple schemasA set of options for the session’s verification checks.
provided_detailsone of multiple schemasDetails provided about the user being verified. These details may be shown to the user.
redactionone of multiple schemasRedaction status of this VerificationSession. If the VerificationSession is not redacted, this field will be null.
related_customerstringCustomer ID
related_customer_accountstringThe ID of the Account representing a customer.
related_persongelato_related_person
status requiredstringStatus of this VerificationSession. [Learn more about the lifecycle of sessions](https://docs.stripe.com/identity/how-sessions-work).
type requiredstringThe type of [verification check](https://docs.stripe.com/identity/verification-checks) to be performed.
urlstringThe short-lived URL that you use to redirect a user to Stripe to submit their identity information. This URL expires after 48 hours and can only be used once. Don’t store it, log it, send it in emails or expose it to anyone other than the user. Refer to our docs on [verifying identity documents](https://docs.stripe.com/identity/verify-identity-documents?platform=web&type=redirect) to learn how to redirect users to Stripe.
verification_flowstringThe configuration token of a verification flow from the dashboard.
verified_outputsone of multiple schemasThe user’s verified data.
HTTP default: Error response.
FieldTypeDescription
error requiredapi_errors
POST /v1/identity/verification_sessions/{session}/redact

Redact a VerificationSession

Redact a VerificationSession to remove all collected information from Stripe. This will redact the VerificationSession and all objects related to it, including VerificationReports, Events, request logs, etc. A VerificationSession object can be redacted when it is in requires_input or verified status. Redacting a VerificationSession in requires_action state will automatically cancel it. The redaction process may take up to four days. When the redaction process is in progress, the VerificationSession’s redaction.status field will be set to processing; when the process is finished, it will change to redacted and an identity.verification_session.redacted event will be emitted. Redaction is irreversible. Redacted objects are still accessible in the Stripe API, but all the fields that contain personal data will be replaced by the string [redacted] or a similar placeholder. The metadata field will also be erased. Redacted objects cannot be updated or used for any purpose. Learn more.

Request parameters

ParameterLocationTypeDescription
sessionpathstring
FieldTypeDescription
expandarray of stringSpecifies which fields in the response should be expanded.

Responses

HTTP 200: Successful response.
FieldTypeDescription
client_reference_idstringA string to reference this user. This can be a customer ID, a session ID, or similar, and can be used to reconcile this verification with your internal systems.
client_secretstringThe short-lived client secret used by Stripe.js to [show a verification modal](https://docs.stripe.com/js/identity/modal) inside your app. This client secret expires after 24 hours and can only be used once. Don’t store it, log it, embed it in a URL, or expose it to anyone other than the user. Make sure that you have TLS enabled on any page that includes the client secret. Refer to our docs on [passing the client secret to the frontend](https://docs.stripe.com/identity/verification-sessions#client-secret) to learn more.
created requiredintegerTime at which the object was created. Measured in seconds since the Unix epoch.
id requiredstringUnique identifier for the object.
last_errorone of multiple schemasIf present, this property tells you the last error encountered when processing the verification.
last_verification_reportone of multiple schemasID of the most recent VerificationReport. [Learn more about accessing detailed verification results.](https://docs.stripe.com/identity/verification-sessions#results)
livemode requiredbooleanIf the object exists in live mode, the value is `true`. If the object exists in test mode, the value is `false`.
metadata requiredobjectSet of [key-value pairs](https://docs.stripe.com/api/metadata) that you can attach to an object. This can be useful for storing additional information about the object in a structured format.
object requiredstringString representing the object's type. Objects of the same type share the same value.
optionsone of multiple schemasA set of options for the session’s verification checks.
provided_detailsone of multiple schemasDetails provided about the user being verified. These details may be shown to the user.
redactionone of multiple schemasRedaction status of this VerificationSession. If the VerificationSession is not redacted, this field will be null.
related_customerstringCustomer ID
related_customer_accountstringThe ID of the Account representing a customer.
related_persongelato_related_person
status requiredstringStatus of this VerificationSession. [Learn more about the lifecycle of sessions](https://docs.stripe.com/identity/how-sessions-work).
type requiredstringThe type of [verification check](https://docs.stripe.com/identity/verification-checks) to be performed.
urlstringThe short-lived URL that you use to redirect a user to Stripe to submit their identity information. This URL expires after 48 hours and can only be used once. Don’t store it, log it, send it in emails or expose it to anyone other than the user. Refer to our docs on [verifying identity documents](https://docs.stripe.com/identity/verify-identity-documents?platform=web&type=redirect) to learn how to redirect users to Stripe.
verification_flowstringThe configuration token of a verification flow from the dashboard.
verified_outputsone of multiple schemasThe user’s verified data.
HTTP default: Error response.
FieldTypeDescription
error requiredapi_errors