Every client SDK (Android, iOS, Web / QR) hands your app a one-time authorization code. Your server exchanges that code with the Paspo ID Server API for the user's verified profile data — this is the only place credentials are ever resolved.
Source: github.com/paspoid/server-api
The public reference for this API is still being written up. The two endpoints below reflect what's documented in the paspoid/server-api repository today; the shapes of requests/responses will be filled in as the API stabilizes.
| Endpoint | Purpose |
|---|---|
GetKey | Checks/validates the calling service (your server) before it can exchange codes or verify tokens. |
Validate | Exchanges a token/authorization code for the list of user data the client requested (phone, e-mail, national ID, or Paspo ID). |
curl -X POST https://api.paspo.id/v1/verify \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"token": "USER_AUTH_TOKEN"}'
YOUR_API_KEY is issued during onboarding — see Support. Never expose it to the client; this call must run server-to-server.
GetKey/Validate fit into the full sign-in flow.