Developers

One call, one flow, one webhook.

Create a verification through the API, send your customer to the hosted flow, receive the decision on your server. The sandbox runs on synthetic identities: you integrate without any real data.

Access by invitation: no account yet? Ask for your sandbox workspace.

requests per second per key, reads and writes
20 / 10
of retries for every webhook, replayable from the console
24 h
validity of an idempotency key
24 h
API version, in the Atlas-Version header
2026-10-01

Quickstart

Get started in three steps

1

Create the verification

With a sandbox key created in the console. The response holds the flow link for your customer.

Request

curl -X POST https://verify.atlasidv.com/v1/verifications \
  -H "Authorization: Bearer atlas_sk_sandbox_…" \
  -d '{
    "template": "onboarding_bank",
    "document_types": ["id_card", "passport"],
    "applicant": { "reference": "client-4821" }
  }'

Response 202 Accepted

{
  "id": "7f3c9a2e-…",
  "status": "created",
  "flow": {
    "url": "https://flow.atlasidv.com/…"
  }
}
2

Send your customer to the flow

A redirect from your app, a link by SMS or email, or a QR code to scan in branch. The flow follows the phone's language (French, English, Arabic) and takes your colours.

Your customer's flow

  1. 1Timestamped consent
  2. 2Country and document type
  3. 3Photo of the document, front and back
  4. 4Selfie
  5. 5Submit, then an end screen with your brand
3

Receive the decision

A signed webhook arrives at each key step. Check the signature, then read the detail of every check with GET /v1/verifications/{id}.

Webhook received

{
  "event": "verification.completed",
  "verification": {
    "id": "7f3c9a2e-…",
    "status": "approved",
    "decision": "approved",
    "reason_codes": [],
    "template": "onboarding_bank"
  },
  "sent_at": "2026-10-03T09:41:12Z"
}

Verify the signature (Node.js)

import crypto from 'node:crypto';

const signed = `${headers['x-atlas-timestamp']}.${rawBody}`;
const expected = 'v1=' + crypto
  .createHmac('sha256', webhookSecret)
  .update(signed)
  .digest('hex');
const received = headers['x-atlas-signature'] ?? '';
const ok = received.length === expected.length &&
  crypto.timingSafeEqual(Buffer.from(received), Buffer.from(expected));

Reference

What the API covers

Authentication with an API key (Bearer), one key per environment, with read, write or review rights.

  • Verifications

    /v1/verifications

    Create, track, read every check with its score, status and explanation, download the PDF report in French or Arabic.

  • Review cases

    /v1/cases

    The review queue: assign, dispose of a list match, decide, approve under four-eyes.

  • Users

    /v1/users

    Your customers by their reference: history, status (active, flagged, blocked), reference faces, deletion.

  • Documents

    /v1/documents

    Atlas Read: upload a document, declare its type and the fields you want, read the extracted fields with their confidence.

  • Webhooks

    verification.*

    Case to review, verification completed or failed, user updated. HMAC SHA-256 signed body, retried on failure.

  • Environments

    atlas_sk_sandbox_ / atlas_sk_prod_

    Sandbox and production kept apart: keys, webhooks and data. The key prefix tells you where you are.

Tooling

Tools: where we stand

What you can use today, and what we are preparing.

  • Available

    REST API and OpenAPI specification

    The specification is downloaded from the console.

  • Available

    Hosted flow (mobile web)

    French, English and Arabic; your logo and colours; camera or file upload.

  • Available

    Signed webhooks

    Every delivery attempt is visible in the console.

  • Available

    Sandbox

    Synthetic identities provided: no real document is accepted there.

  • Available

    Postman collection

    For Atlas Read today; Atlas ID to follow.

  • Coming soon

    iOS and Android mobile SDK

    With NFC chip reading for documents that have one.

  • Coming soon

    Public online documentation

    Meanwhile it lives in the console, and we support you during the integration.

Sandbox

Your first verification in the sandbox.

Sign in to the console, create a sandbox key and run the call above. No account yet? Ask for your workspace: we create your organisation and send you the invitation.