VerySafe Talk to us

Developers

Two endpoints to a verdict

Start a check, show the link, read the verdict. Signed requests, encrypted responses, trust lists and revocation all happen in the service.

Code sample language
curl -X POST "$VERYSAFE_HOST/v1/verifications" \
  -H "Authorization: Bearer $VERYSAFE_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "credentialType": "eu_pid", "claims": ["age_equal_or_over.18"] }'
const res = await fetch(process.env.VERYSAFE_HOST + "/v1/verifications", {
  method: "POST",
  headers: {
    Authorization: "Bearer " + process.env.VERYSAFE_KEY,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({ credentialType: "eu_pid", claims: ["age_equal_or_over.18"] }),
});
const check = await res.json(); // show check.authorizationRequestUri as a QR code
import os, requests

check = requests.post(
    os.environ["VERYSAFE_HOST"] + "/v1/verifications",
    headers={"Authorization": "Bearer " + os.environ["VERYSAFE_KEY"]},
    json={"credentialType": "eu_pid", "claims": ["age_equal_or_over.18"]},
).json()
# show check["authorizationRequestUri"] as a QR code

201 Created

{ "id": "0f6c1a2e…",
  "status": "pending",
  "credentialType": "eu_pid",
  "requestedClaims": ["age_equal_or_over.18"],
  "authorizationRequestUri": "openid4vp://?client_id=…",
  "pollUrl": "/v1/verifications/0f6c1a2e…" }

Quickstart

  1. Get a key

    Sandbox keys are free and cover the full API.

  2. Start a check

    POST the claims you need. You get a link and a QR code to show.

  3. Read the verdict

    Poll the check. Verified, or a reason why not.

The API at a glance

Six endpoints for your application. The wallet exchange runs on its own endpoints and needs nothing from you.

  • GET/v1/credential-typesWhat each credential can disclose
  • POST/v1/verificationsStart a check and get a wallet link
  • GET/v1/verifications/{id}Status and result: pending, verified, failed or expired
  • GET/v1/verdictsYour verdict history for audits, without personal values
  • GET/v1/metricsCounters and the health of each EU trusted list
  • POST/v1/mcpThe same checks as tools for AI agents

Every refusal has a reason

Your application can act on the reason, not just the no.

  • Provider is not on the EU trusted list
  • Provider withdrawn or suspended
  • Credential revoked by its issuer
  • Issuer certificate revoked
  • Credential expired
  • Proof not bound to this request
  • Revocation status could not be checked, so the answer is no

For AI agents

Three tools: list_supported_credential_types, verify_credential and check_verification. The agent gets the verdict and the names of the facts proven, never their values.

tools/call · check_verification
POST /v1/mcp

{ "jsonrpc": "2.0", "id": 1, "method": "tools/call",
  "params": { "name": "check_verification",
    "arguments": { "session_id": "0f6c1a2e…" } } }

→ { "session_id": "0f6c1a2e…",
    "verdict": "verified",
    "credential_type": "eu_pid",
    "disclosed_claim_names": ["age_equal_or_over.18"] }

Get a sandbox key

Test environment and test credentials. No card needed. A person replies with your key and the full API reference.

Resources

Be ready before your deadline

Design partners get free checks until launch and a working integration in weeks.

Talk to us