Server API

Verify authorization codes and fetch user data from your backend.

Every client SDK (Android, iOS, Web / QR) hands your app a one-time authorization code. Your server exchanges that code with the Paspo ID Server API for the user's verified profile data — this is the only place credentials are ever resolved.

Source: github.com/paspoid/server-api

Reference is growing

The public reference for this API is still being written up. The two endpoints below reflect what's documented in the paspoid/server-api repository today; the shapes of requests/responses will be filled in as the API stabilizes.

Endpoints

EndpointPurpose
GetKeyChecks/validates the calling service (your server) before it can exchange codes or verify tokens.
ValidateExchanges a token/authorization code for the list of user data the client requested (phone, e-mail, national ID, or Paspo ID).

Example: verifying a token

curl -X POST https://api.paspo.id/v1/verify \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"token": "USER_AUTH_TOKEN"}'

YOUR_API_KEY is issued during onboarding — see Support. Never expose it to the client; this call must run server-to-server.

Security notes

  • Treat the authorization code / token the same way you'd treat a password reset link: single-use, short-lived, and never logged.
  • The nonce your server generates before calling a client SDK is your defense against replay attacks — always verify it server-side when exchanging the resulting code.
  • See How it works for where GetKey/Validate fit into the full sign-in flow.