Integration requires a single call on the client — authenticate(scope, nonce) — which returns a one-time authorization code. Your app forwards that code to your server, which exchanges it with Paspo ID for the user's data.
All communication between your app and Paspo ID is end-to-end encrypted (ECDH P-256 + AES-256-GCM, with ephemeral keys held only in memory) and handled entirely by the SDK — no cryptographic work is required on your side.
sequenceDiagram
participant B as Your server
participant A as Your app (SDK)
participant P as Paspo ID app
participant PS as Paspo ID server
A->>B: request nonce
B-->>A: nonce
A->>P: authenticate(scope, nonce)
Note over A,P: ephemeral ECDH key, end-to-end encrypted
P->>PS: verify app signature & package
Note over P: user consent screen
P-->>A: encrypted response
Note over A: decrypt -> Success(authCode)
A->>B: authCode
B->>PS: exchange authCode (server-to-server)
PS-->>B: user profile data
authenticate(scope, nonce). The SDK generates an ephemeral ECDH key pair and opens the Paspo ID app.authCode.authCode to your server, which exchanges it — server-to-server — with Paspo ID for the user's verified profile data.These can't be moved to the client — they're what makes the flow secure:
authCode is single-use and carries no personal data on its own; user data only ever travels over your secure server-to-server channel.The SDK detects this, stores the nonce, opens the app/Play Store page for Paspo ID, and returns a NotInstalled result instead of throwing. Once the user installs Paspo ID and retries, the stored nonce is passed along for install attribution. See the Android reference for the exact result type.
Your server receives whichever profile fields you requested in scope — phone number, e-mail, national ID, or the user's permanent Paspo ID — never raw biometric data. Face ID and Voice ID matching happens entirely on-device, inside the Paspo ID app.