VettiGuard API reference
Search every published endpoint, inspect placeholder requests and responses, and download the machine-readable contract generated from the same route catalogue used by the application.
https://api.vettiguard.com/v1https://vettiguard.com/api/v1Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postApiProtectionAssess- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/api-protection/assess"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"method": "POST",
"path": "/api/orders",
"action": "order-create",
"authentication_present": true,
"content_type": "application/json",
"subject_id": "customer-1842",
"device_id": "browser-device",
"request_id": "request-uuid",
"idempotency_key": "order-create-9942",
"payload_fingerprint": "sha256-canonical-payload",
"body_bytes": 2048,
"page_size": 0,
"query_depth": 2,
"resource_cost": 25
}'
{
"secret": "vg_secret_replace_me",
"method": "POST",
"path": "/api/orders",
"action": "order-create",
"authentication_present": true,
"content_type": "application/json",
"subject_id": "customer-1842",
"device_id": "browser-device",
"request_id": "request-uuid",
"idempotency_key": "order-create-9942",
"payload_fingerprint": "sha256-canonical-payload",
"body_bytes": 2048,
"page_size": 0,
"query_depth": 2,
"resource_cost": 25
}
{
"success": true,
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"policy_name": "Order writes",
"risk_score": 0.7199999999999999733546474089962430298328399658203125,
"classification": "high",
"recommended_decision": "challenge",
"decision": "challenge",
"retry_after_seconds": 0,
"reason_codes": [
"resource-cost-exceeded",
"subject-velocity-high"
],
"enforcement_mode": "challenge"
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postApiProtectionFeedback- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/api-protection/feedback"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"label": "legitimate",
"reason_code": "customer-confirmed"
}'
{
"secret": "vg_secret_replace_me",
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"label": "legitimate",
"reason_code": "customer-confirmed"
}
{
"success": true,
"feedback_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"accepted": true
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postAccountAssess- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/account/assess"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"subject_id": "customer-1842",
"device_id": "browser-session-device",
"event_type": "login",
"outcome": "failure",
"account_age_days": 420,
"compromised_password": false
}'
{
"secret": "vg_secret_replace_me",
"subject_id": "customer-1842",
"device_id": "browser-session-device",
"event_type": "login",
"outcome": "failure",
"account_age_days": 420,
"compromised_password": false
}
{
"success": true,
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"risk_score": 0.7199999999999999733546474089962430298328399658203125,
"classification": "high",
"recommended_decision": "step_up",
"decision": "step_up",
"trusted_device": false,
"reasons": [
"subject-failure-velocity",
"unfamiliar-device"
]
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postAccountFeedback- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/account/feedback"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"label": "credential_stuffing",
"reason_code": "customer-confirmed"
}'
{
"secret": "vg_secret_replace_me",
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"label": "credential_stuffing",
"reason_code": "customer-confirmed"
}
{
"success": true,
"feedback_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"accepted": true
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postAccountPasswordRange- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/account/password/range"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"prefix": "5BAA6"
}'
{
"secret": "vg_secret_replace_me",
"prefix": "5BAA6"
}
{
"success": true,
"prefix": "5BAA6",
"suffixes": [
{
"suffix": "1E4C9B93F3F0682250B6CF8331B7EE68FD8",
"count": 100
}
]
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postAccountTrustedDevice- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/account/trusted-device"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"action": "trust",
"subject_id": "customer-1842",
"device_id": "browser-session-device",
"label": "Customer laptop"
}'
{
"secret": "vg_secret_replace_me",
"action": "trust",
"subject_id": "customer-1842",
"device_id": "browser-session-device",
"label": "Customer laptop"
}
{
"success": true,
"status": "trusted"
}
Signed agent request using HMAC-SHA256 over timestamp, nonce, and the exact raw JSON body. Agent secrets must remain in a trusted server-side secret manager.
- Operation ID
postAgentsApprovalStatus- Security model
- Agent Hmac
- Scopes
- No scoped credential required
curl --request POST \
"https://api.vettiguard.com/v1/agents/approval/status"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"approval_id": "70f05cc7-989e-41f0-9a37-c9884d323a67"
}'
{
"approval_id": "70f05cc7-989e-41f0-9a37-c9884d323a67"
}
{
"success": true,
"approval_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"status": "approved",
"action": "refund-create",
"scope": "refund.create",
"consumed": false
}
Signed agent request using HMAC-SHA256 over timestamp, nonce, and the exact raw JSON body. Agent secrets must remain in a trusted server-side secret manager.
- Operation ID
postAgentsDecision- Security model
- Agent Hmac
- Scopes
- No scoped credential required
curl --request POST \
"https://api.vettiguard.com/v1/agents/decision"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"request_id": "agent-request-991",
"action": "order-status",
"scope": "orders.read",
"resource_id": "ORDER-9942",
"subject_id": "customer-1842",
"summary": "Read an order status for an authenticated customer."
}'
{
"request_id": "agent-request-991",
"action": "order-status",
"scope": "orders.read",
"resource_id": "ORDER-9942",
"subject_id": "customer-1842",
"summary": "Read an order status for an authenticated customer."
}
{
"success": true,
"decision_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"agent_id": "4d6ac1b0-2d0e-4b0b-9f50-42f36a0d3a24",
"identity_verified": true,
"recommended_decision": "approval_required",
"decision": "approval_required",
"risk_score": 0.61999999999999999555910790149937383830547332763671875,
"classification": "elevated",
"reason_codes": [
"human-approval-required"
],
"approval_request_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5"
}
Provider-to-provider callback. The signature must be verified before the event changes application state.
- Operation ID
postBillingStripeWebhook- Security model
- Stripe Signature
- Scopes
- No scoped credential required
curl --request POST \
"https://api.vettiguard.com/v1/billing/stripe/webhook"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Stripe-Signature: generated-by-stripe' \
--data '[]'
[]
{
"success": true
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postConcurrencyAcquire- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/concurrency/acquire"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"action": "report.generate",
"method": "POST",
"subject_id": "customer-1842",
"route": "/api/reports",
"lease_ttl_seconds": 120,
"idempotency_key": "report-request-9942"
}'
{
"secret": "vg_secret_replace_me",
"action": "report.generate",
"method": "POST",
"subject_id": "customer-1842",
"route": "/api/reports",
"lease_ttl_seconds": 120,
"idempotency_key": "report-request-9942"
}
{
"success": true,
"decision_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"allowed": true,
"recommended_decision": "allow",
"decision": "allow",
"retry_after_ms": 0,
"matched_policy_count": 2,
"in_flight": 2,
"limit": 5,
"lease": {
"lease_token": "vgcl.70f05cc7-989e-41f0-9a37-c9884d323a67.signature",
"expires_at": "2026-08-08T18:15:00Z"
},
"reason_codes": []
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postConcurrencyRelease- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/concurrency/release"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"lease_token": "vgcl.70f05cc7-989e-41f0-9a37-c9884d323a67.signature"
}'
{
"secret": "vg_secret_replace_me",
"lease_token": "vgcl.70f05cc7-989e-41f0-9a37-c9884d323a67.signature"
}
{
"success": true,
"released": true,
"lease_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"status": "released"
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postConcurrencyRenew- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/concurrency/renew"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"lease_token": "vgcl.70f05cc7-989e-41f0-9a37-c9884d323a67.signature",
"lease_ttl_seconds": 120
}'
{
"secret": "vg_secret_replace_me",
"lease_token": "vgcl.70f05cc7-989e-41f0-9a37-c9884d323a67.signature",
"lease_ttl_seconds": 120
}
{
"success": true,
"renewed": true,
"lease_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"status": "active",
"expires_at": "2026-08-08T18:17:00Z"
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postDependencyResilienceAdmit- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/dependency-resilience/admit"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"dependency_key": "payments-provider",
"action": "payment.capture",
"method": "POST",
"subject_id": "customer-1842",
"route": "/api/payments",
"is_retry": false,
"admission_ttl_seconds": 45
}'
{
"secret": "vg_secret_replace_me",
"dependency_key": "payments-provider",
"action": "payment.capture",
"method": "POST",
"subject_id": "customer-1842",
"route": "/api/payments",
"is_retry": false,
"admission_ttl_seconds": 45
}
{
"success": true,
"decision_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"allowed": true,
"recommended_decision": "allow",
"decision": "allow",
"circuit_state": "closed",
"sample_count": 42,
"failure_rate": 4.7599999999999997868371792719699442386627197265625,
"in_flight": 2,
"retry_budget": {
"used": 1,
"limit": 8
},
"retry_after_seconds": 0,
"admission": {
"admission_token": "vgdr.70f05cc7-989e-41f0-9a37-c9884d323a67.signature",
"expires_at": "2026-08-08T18:45:00Z"
},
"reason_codes": []
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postDependencyResilienceFeedback- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/dependency-resilience/feedback"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"admission_token": "vgdr.70f05cc7-989e-41f0-9a37-c9884d323a67.signature",
"outcome": "success",
"latency_ms": 240
}'
{
"secret": "vg_secret_replace_me",
"admission_token": "vgdr.70f05cc7-989e-41f0-9a37-c9884d323a67.signature",
"outcome": "success",
"latency_ms": 240
}
{
"success": true,
"accepted": true,
"admission_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"status": "completed",
"outcome": "success",
"circuit_state": "closed",
"sample_count": 43,
"failure_rate": 4.6500000000000003552713678800500929355621337890625
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postDetectionFeedback- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/detection/feedback"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"assessment_id": "4d6ac1b0-2d0e-4b0b-9f50-42f36a0d3a24",
"label": "abuse",
"reason_code": "confirmed-credential-stuffing"
}'
{
"secret": "vg_secret_replace_me",
"assessment_id": "4d6ac1b0-2d0e-4b0b-9f50-42f36a0d3a24",
"label": "abuse",
"reason_code": "confirmed-credential-stuffing"
}
{
"success": true,
"feedback_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"accepted": true
}
Public metadata endpoint that does not reveal private infrastructure details.
- Operation ID
postSandboxIssue- Security model
- None
- Scopes
- No scoped credential required
curl --request POST \
"https://api.vettiguard.com/v1/sandbox/issue"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"site_key": "vg_test_site_key",
"scenario": "success",
"action": "checkout",
"hostname": "sandbox.example.test"
}'
{
"site_key": "vg_test_site_key",
"scenario": "success",
"action": "checkout",
"hostname": "sandbox.example.test"
}
{
"success": true,
"response": "vgsbx.generated-token",
"scenario": "success",
"expires_in": 900,
"production_compatible": false
}
Public metadata endpoint that does not reveal private infrastructure details.
- Operation ID
getSandboxScenarios- Security model
- None
- Scopes
- No scoped credential required
curl --request GET \
"https://api.vettiguard.com/v1/sandbox/scenarios"
--header 'Accept: application/json'
[]
{
"success": true,
"site_key": "vg_test_site_key",
"production_compatible": false,
"scenarios": {
"success": {
"label": "Successful verification",
"description": "Returns an accepted proof with a high score and matching context.",
"http_status": 200
},
"low_score": {
"label": "Low risk score",
"description": "Returns a structurally valid proof that fails the configured score threshold.",
"http_status": 200
},
"expired": {
"label": "Expired response",
"description": "Returns timeout-or-duplicate so expiry handling can be exercised.",
"http_status": 200
},
"action_mismatch": {
"label": "Action mismatch",
"description": "Returns a valid proof for a different protected action.",
"http_status": 200
},
"hostname_mismatch": {
"label": "Hostname mismatch",
"description": "Returns an accepted proof bound to a different hostname.",
"http_status": 200
},
"replayed": {
"label": "Replayed response",
"description": "Returns timeout-or-duplicate for idempotency and replay handling.",
"http_status": 200
},
"service_unavailable": {
"label": "Temporary service failure",
"description": "Returns HTTP 503 with a stable service-unavailable error.",
"http_status": 503
}
}
}
Public metadata endpoint that does not reveal private infrastructure details.
- Operation ID
postSandboxSiteverify- Security model
- None
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/sandbox/siteverify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_test_secret_demo_only",
"response": "vgsbx.generated-token",
"action": "checkout"
}'
{
"secret": "vg_test_secret_demo_only",
"response": "vgsbx.generated-token",
"action": "checkout"
}
{
"success": true,
"action": "checkout",
"hostname": "sandbox.example.test",
"score": 0.95999999999999996447286321199499070644378662109375,
"sandbox": true,
"production_compatible": false,
"error-codes": []
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postDeviceAssess- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/device/assess"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"subject_id": "customer-1842",
"device_id": "browser-device",
"platform": "web",
"new_device": false,
"device_integrity_score": 0.92000000000000003996802888650563545525074005126953125
}'
{
"secret": "vg_secret_replace_me",
"subject_id": "customer-1842",
"device_id": "browser-device",
"platform": "web",
"new_device": false,
"device_integrity_score": 0.92000000000000003996802888650563545525074005126953125
}
{
"success": true
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postCredentialsIssue- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.credentials
curl --request POST \
"https://api.vettiguard.com/v1/credentials/issue"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"holder_token": "vgid_replace_me",
"holder_jwk": {
"kty": "EC",
"crv": "P-256",
"x": "base64url-x",
"y": "base64url-y"
},
"claims": [
"identity_verified",
"assurance_level",
"age_over_18"
],
"valid_days": 180
}'
{
"secret": "vg_secret_replace_me",
"holder_token": "vgid_replace_me",
"holder_jwk": {
"kty": "EC",
"crv": "P-256",
"x": "base64url-x",
"y": "base64url-y"
},
"claims": [
"identity_verified",
"assurance_level",
"age_over_18"
],
"valid_days": 180
}
{
"success": true,
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"format": "dc+sd-jwt",
"credential": "issuer-jwt~disclosure~",
"claim_names": [
"identity_verified",
"assurance_level"
],
"holder_binding": {
"required": true,
"method": "cnf.jwk + kb+jwt"
}
}
Public metadata endpoint that does not reveal private infrastructure details.
- Operation ID
getCredentialsIssuer- Security model
- None
- Scopes
- No scoped credential required
curl --request GET \
"https://api.vettiguard.com/v1/credentials/issuer"
--header 'Accept: application/json'
[]
{
"issuer": "https://api.vettiguard.com/v1/credentials/issuer",
"jwks_uri": "https://api.vettiguard.com/v1/credentials/jwks",
"credential_formats_supported": [
"dc+sd-jwt"
],
"credential_types_supported": [
"https://api.vettiguard.com/v1/credentials/types/verified-identity-v1"
]
}
Public metadata endpoint that does not reveal private infrastructure details.
- Operation ID
getCredentialsJwks- Security model
- None
- Scopes
- No scoped credential required
curl --request GET \
"https://api.vettiguard.com/v1/credentials/jwks"
--header 'Accept: application/json'
[]
{
"keys": [
{
"kty": "RSA",
"use": "sig",
"alg": "RS256",
"kid": "vgcred-20260922-example",
"n": "base64url-modulus",
"e": "AQAB"
}
]
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postCredentialsPresent- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.credentials
curl --request POST \
"https://api.vettiguard.com/v1/credentials/present"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"credential": "issuer-jwt~disclosure~",
"claims": [
"identity_verified",
"age_over_18"
],
"audience": "https://app.example.com",
"nonce": "challenge-nonce"
}'
{
"secret": "vg_secret_replace_me",
"credential": "issuer-jwt~disclosure~",
"claims": [
"identity_verified",
"age_over_18"
],
"audience": "https://app.example.com",
"nonce": "challenge-nonce"
}
{
"success": true,
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"presentation_without_key_binding": "issuer-jwt~disclosure~",
"disclosed_claim_names": [
"identity_verified"
],
"sd_hash": "base64url-sha256",
"key_binding_required": true
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postCredentialsPresentationChallenge- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.credentials
curl --request POST \
"https://api.vettiguard.com/v1/credentials/presentation/challenge"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"audience": "https://app.example.com"
}'
{
"secret": "vg_secret_replace_me",
"audience": "https://app.example.com"
}
{
"success": true,
"challenge_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"challenge_token": "opaque-challenge-token",
"audience": "https://app.example.com",
"nonce": "base64url-nonce",
"expires_at": "2026-09-22T00:30:00+00:00"
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postCredentialsRevoke- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.credentials
curl --request POST \
"https://api.vettiguard.com/v1/credentials/revoke"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"holder_token": "vgid_replace_me"
}'
{
"secret": "vg_secret_replace_me",
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"holder_token": "vgid_replace_me"
}
{
"success": true,
"revoked": true,
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67"
}
Public metadata endpoint that does not reveal private infrastructure details.
- Operation ID
getCredentialsStatusList- Security model
- None
- Scopes
- No scoped credential required
curl --request GET \
"https://api.vettiguard.com/v1/credentials/status-list"
--header 'Accept: application/json'
[]
{
"content_type": "application/statuslist+jwt"
}
Public metadata endpoint that does not reveal private infrastructure details.
- Operation ID
getCredentialsTypesVerifiedIdentityV1- Security model
- None
- Scopes
- No scoped credential required
curl --request GET \
"https://api.vettiguard.com/v1/credentials/types/verified-identity-v1"
--header 'Accept: application/json'
[]
{
"vct": "https://api.vettiguard.com/v1/credentials/types/verified-identity-v1",
"name": "VettiGuard Verified Identity Credential"
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postCredentialsVerify- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.credentials
curl --request POST \
"https://api.vettiguard.com/v1/credentials/verify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"presentation": "issuer-jwt~disclosure~kb-jwt",
"challenge_token": "opaque-challenge-token",
"audience": "https://app.example.com",
"nonce": "challenge-nonce"
}'
{
"secret": "vg_secret_replace_me",
"presentation": "issuer-jwt~disclosure~kb-jwt",
"challenge_token": "opaque-challenge-token",
"audience": "https://app.example.com",
"nonce": "challenge-nonce"
}
{
"valid": true,
"presentation_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"claims": {
"identity_verified": true
},
"holder_binding_verified": true,
"status": "valid"
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postEdgeDecision- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/edge/decision"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"method": "POST",
"path": "/checkout/confirm",
"hostname": "shop.example.com",
"action": "checkout-confirm",
"subject_id": "customer-1842",
"device_id": "browser-device",
"fraud_assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67"
}'
{
"secret": "vg_secret_replace_me",
"method": "POST",
"path": "/checkout/confirm",
"hostname": "shop.example.com",
"action": "checkout-confirm",
"subject_id": "customer-1842",
"device_id": "browser-device",
"fraud_assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67"
}
{
"success": true,
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"decision": "challenge",
"recommended_decision": "challenge",
"risk_score": 0.70999999999999996447286321199499070644378662109375,
"classification": "high",
"preclearance_valid": false,
"reason_codes": [
"fraud-risk",
"edge-policy"
]
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postEdgePreclearanceIssue- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/edge/preclearance/issue"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"decision_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"verification_succeeded": true,
"hostname": "shop.example.com",
"action": "checkout-confirm",
"path_prefix": "/checkout",
"subject_id": "customer-1842",
"device_id": "browser-device"
}'
{
"secret": "vg_secret_replace_me",
"decision_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"verification_succeeded": true,
"hostname": "shop.example.com",
"action": "checkout-confirm",
"path_prefix": "/checkout",
"subject_id": "customer-1842",
"device_id": "browser-device"
}
{
"success": true,
"clearance_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"token": "vgec.payload.signature",
"expires_at": "2026-08-06T22:00:00Z",
"max_uses": 100
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postEdgePreclearanceVerify- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/edge/preclearance/verify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"token": "vgec.payload.signature",
"hostname": "shop.example.com",
"path": "/checkout/confirm",
"action": "checkout-confirm",
"subject_id": "customer-1842",
"device_id": "browser-device"
}'
{
"secret": "vg_secret_replace_me",
"token": "vgec.payload.signature",
"hostname": "shop.example.com",
"path": "/checkout/confirm",
"action": "checkout-confirm",
"subject_id": "customer-1842",
"device_id": "browser-device"
}
{
"valid": true,
"clearance_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"expires_at": "2026-08-06T22:00:00Z",
"remaining_uses": 99
}
Called by a VettiGuard browser client. The real request validates the supplied public site key and the registered request origin.
- Operation ID
postFacialAuthorizationComplete- Security model
- Site Key And Origin
- Scopes
- site.facial_identity
curl --request POST \
"https://api.vettiguard.com/v1/facial/authorization/complete"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Origin: https://app.example.com' \
--data '{
"site_key": "vg_site_replace_me",
"intent_token": "vg_authorization_intent_replace_me",
"consent_accepted": true
}'
{
"site_key": "vg_site_replace_me",
"intent_token": "vg_authorization_intent_replace_me",
"consent_accepted": true
}
{
"success": true,
"response": "single-use-response-token",
"expires_in": 120
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postFacialAuthorizationIntent- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.facial_identity
curl --request POST \
"https://api.vettiguard.com/v1/facial/authorization/intent"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"subject_id": "customer-4821",
"action": "approve-transfer",
"operation_reference": "TRANSFER-12345"
}'
{
"secret": "vg_secret_replace_me",
"subject_id": "customer-4821",
"action": "approve-transfer",
"operation_reference": "TRANSFER-12345"
}
{
"success": true,
"intent_token": "vg_intent_replace_me",
"expires_in": 300
}
Called by a VettiGuard browser client. The real request validates the supplied public site key and the registered request origin.
- Operation ID
postFacialAuthorizationSession- Security model
- Site Key And Origin
- Scopes
- site.facial_identity
curl --request POST \
"https://api.vettiguard.com/v1/facial/authorization/session"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Origin: https://app.example.com' \
--data '{
"site_key": "vg_site_replace_me",
"intent_token": "vg_authorization_intent_replace_me",
"consent_accepted": true
}'
{
"site_key": "vg_site_replace_me",
"intent_token": "vg_authorization_intent_replace_me",
"consent_accepted": true
}
{
"success": true,
"session_token": "vg_session_replace_me",
"expires_in": 300
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postFacialAuthorizationSiteverify- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.facial_identity
curl --request POST \
"https://api.vettiguard.com/v1/facial/authorization/siteverify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"site_key": "vg_site_replace_me",
"intent_token": "vg_authorization_intent_replace_me",
"consent_accepted": true
}'
{
"site_key": "vg_site_replace_me",
"intent_token": "vg_authorization_intent_replace_me",
"consent_accepted": true
}
{
"success": true,
"action": "requested-action",
"error-codes": []
}
Called by a VettiGuard browser client. The real request validates the supplied public site key and the registered request origin.
- Operation ID
postFacialEnrollmentComplete- Security model
- Site Key And Origin
- Scopes
- site.facial_identity
curl --request POST \
"https://api.vettiguard.com/v1/facial/enrollment/complete"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Origin: https://app.example.com' \
--data '{
"site_key": "vg_site_replace_me",
"intent_token": "vg_enrollment_intent_replace_me",
"consent_accepted": true
}'
{
"site_key": "vg_site_replace_me",
"intent_token": "vg_enrollment_intent_replace_me",
"consent_accepted": true
}
{
"success": true,
"response": "single-use-response-token",
"expires_in": 120
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postFacialEnrollmentIntent- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.facial_identity
curl --request POST \
"https://api.vettiguard.com/v1/facial/enrollment/intent"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"subject_id": "customer-4821",
"action": "identity-enrollment",
"consent_version": "2026-08"
}'
{
"secret": "vg_secret_replace_me",
"subject_id": "customer-4821",
"action": "identity-enrollment",
"consent_version": "2026-08"
}
{
"success": true,
"intent_token": "vg_intent_replace_me",
"expires_in": 300
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postFacialEnrollmentRevoke- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.facial_identity
curl --request POST \
"https://api.vettiguard.com/v1/facial/enrollment/revoke"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"subject_id": "customer-4821",
"reason": "customer-request"
}'
{
"secret": "vg_secret_replace_me",
"subject_id": "customer-4821",
"reason": "customer-request"
}
{
"success": true,
"status": "revoked"
}
Called by a VettiGuard browser client. The real request validates the supplied public site key and the registered request origin.
- Operation ID
postFacialEnrollmentSession- Security model
- Site Key And Origin
- Scopes
- site.facial_identity
curl --request POST \
"https://api.vettiguard.com/v1/facial/enrollment/session"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Origin: https://app.example.com' \
--data '{
"site_key": "vg_site_replace_me",
"intent_token": "vg_enrollment_intent_replace_me",
"consent_accepted": true
}'
{
"site_key": "vg_site_replace_me",
"intent_token": "vg_enrollment_intent_replace_me",
"consent_accepted": true
}
{
"success": true,
"session_token": "vg_session_replace_me",
"expires_in": 300
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postFacialEnrollmentSiteverify- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.facial_identity
curl --request POST \
"https://api.vettiguard.com/v1/facial/enrollment/siteverify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"site_key": "vg_site_replace_me",
"intent_token": "vg_enrollment_intent_replace_me",
"consent_accepted": true
}'
{
"site_key": "vg_site_replace_me",
"intent_token": "vg_enrollment_intent_replace_me",
"consent_accepted": true
}
{
"success": true,
"action": "requested-action",
"error-codes": []
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postFacialEnrollmentStatus- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.facial_identity
curl --request POST \
"https://api.vettiguard.com/v1/facial/enrollment/status"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"subject_id": "customer-4821"
}'
{
"secret": "vg_secret_replace_me",
"subject_id": "customer-4821"
}
{
"success": true,
"status": "pending"
}
Called by a VettiGuard browser client. The real request validates the supplied public site key and the registered request origin.
- Operation ID
postFacialComplete- Security model
- Site Key And Origin
- Scopes
- No scoped credential required
curl --request POST \
"https://api.vettiguard.com/v1/facial/complete"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Origin: https://app.example.com' \
--data '{
"site_key": "vg_site_replace_me",
"session_token": "vg_facial_session_replace_me",
"capture": {
"frames": [
"base64-jpeg-frame"
]
}
}'
{
"site_key": "vg_site_replace_me",
"session_token": "vg_facial_session_replace_me",
"capture": {
"frames": [
"base64-jpeg-frame"
]
}
}
{
"success": true,
"response": "single-use-response-token",
"expires_in": 120
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postFacialDecision- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- No scoped credential required
curl --request POST \
"https://api.vettiguard.com/v1/facial/decision"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"action": "account-recovery",
"subject_id": "customer-4821",
"risk_level": "high"
}'
{
"secret": "vg_secret_replace_me",
"action": "account-recovery",
"subject_id": "customer-4821",
"risk_level": "high"
}
{
"success": true,
"decision": "verify",
"method": "facial_identity_authorization",
"requested_assurance": "high",
"risk_level": "high",
"risk": {
"outcome": "challenge",
"score": 0.68000000000000004884981308350688777863979339599609375,
"level": "high",
"engine_status": "evaluated",
"matched_rules": [
{
"policy_name": "Transaction protection",
"rule_name": "High request velocity",
"reason_code": "velocity-high",
"score_delta": 0.200000000000000011102230246251565404236316680908203125,
"outcome": "challenge"
}
]
}
}
Called by a VettiGuard browser client. The real request validates the supplied public site key and the registered request origin.
- Operation ID
postFacialSession- Security model
- Site Key And Origin
- Scopes
- No scoped credential required
curl --request POST \
"https://api.vettiguard.com/v1/facial/session"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Origin: https://app.example.com' \
--data '{
"site_key": "vg_site_replace_me",
"action": "account-recovery",
"consent_accepted": true
}'
{
"site_key": "vg_site_replace_me",
"action": "account-recovery",
"consent_accepted": true
}
{
"success": true,
"session_token": "vg_session_replace_me",
"expires_in": 300
}
Called by a VettiGuard browser client. The real request validates the supplied public site key and the registered request origin.
- Operation ID
postFacialSessionCancel- Security model
- Site Key And Origin
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/facial/session/cancel"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Origin: https://app.example.com' \
--data '{
"site_key": "vg_site_replace_me",
"session_token": "vg_facial_session_replace_me"
}'
{
"site_key": "vg_site_replace_me",
"session_token": "vg_facial_session_replace_me"
}
{
"success": true,
"status": "cancelled"
}
Called by a VettiGuard browser client. The real request validates the supplied public site key and the registered request origin.
- Operation ID
postFacialSessionStatus- Security model
- Site Key And Origin
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/facial/session/status"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Origin: https://app.example.com' \
--data '{
"site_key": "vg_site_replace_me",
"session_token": "vg_facial_session_replace_me"
}'
{
"site_key": "vg_site_replace_me",
"session_token": "vg_facial_session_replace_me"
}
{
"success": true,
"status": "pending"
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postFacialSiteverify- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/facial/siteverify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"response": "vg_facial_response_replace_me",
"action": "account-recovery"
}'
{
"secret": "vg_secret_replace_me",
"response": "vg_facial_response_replace_me",
"action": "account-recovery"
}
{
"success": true,
"action": "requested-action",
"error-codes": []
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postFraudEmailAssess- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/fraud/email/assess"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"subject_id": "customer-1842",
"email": "customer@example.com",
"device_id": "browser-device",
"event_type": "signup",
"outcome": "attempt",
"email_verified": false,
"disposable_email": false,
"domain_age_days": 3200
}'
{
"secret": "vg_secret_replace_me",
"subject_id": "customer-1842",
"email": "customer@example.com",
"device_id": "browser-device",
"event_type": "signup",
"outcome": "attempt",
"email_verified": false,
"disposable_email": false,
"domain_age_days": 3200
}
{
"success": true,
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"assessment_type": "transaction",
"risk_score": 0.7399999999999999911182158029987476766109466552734375,
"classification": "high",
"recommended_decision": "step_up",
"decision": "step_up",
"reasons": [
"transaction-velocity",
"new-payee"
]
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postFraudFeedback- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/fraud/feedback"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"label": "payment_fraud",
"reason_code": "customer-confirmed"
}'
{
"secret": "vg_secret_replace_me",
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"label": "payment_fraud",
"reason_code": "customer-confirmed"
}
{
"success": true,
"feedback_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"accepted": true
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postFraudSmsAssess- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/fraud/sms/assess"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"subject_id": "customer-1842",
"phone": "+2348000000000",
"device_id": "browser-device",
"event_type": "otp_request",
"outcome": "attempt",
"phone_verified": false,
"high_cost_destination": false
}'
{
"secret": "vg_secret_replace_me",
"subject_id": "customer-1842",
"phone": "+2348000000000",
"device_id": "browser-device",
"event_type": "otp_request",
"outcome": "attempt",
"phone_verified": false,
"high_cost_destination": false
}
{
"success": true,
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"assessment_type": "transaction",
"risk_score": 0.7399999999999999911182158029987476766109466552734375,
"classification": "high",
"recommended_decision": "step_up",
"decision": "step_up",
"reasons": [
"transaction-velocity",
"new-payee"
]
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postFraudTransactionAssess- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/fraud/transaction/assess"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"subject_id": "customer-1842",
"transaction_id": "ORDER-9942",
"device_id": "browser-device",
"event_type": "payment",
"outcome": "attempt",
"amount": 125000,
"currency": "NGN",
"high_value": true,
"new_payee": true,
"email_verified": true,
"phone_verified": true
}'
{
"secret": "vg_secret_replace_me",
"subject_id": "customer-1842",
"transaction_id": "ORDER-9942",
"device_id": "browser-device",
"event_type": "payment",
"outcome": "attempt",
"amount": 125000,
"currency": "NGN",
"high_value": true,
"new_payee": true,
"email_verified": true,
"phone_verified": true
}
{
"success": true,
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"assessment_type": "transaction",
"risk_score": 0.7399999999999999911182158029987476766109466552734375,
"classification": "high",
"recommended_decision": "step_up",
"decision": "step_up",
"reasons": [
"transaction-velocity",
"new-payee"
]
}
Returns a normalized PNG logo for the UUID branding profile referenced by a challenge response. The asset contains presentation data only and is safe for cross-origin image rendering.
- Operation ID
getBrandingProfileLogo- Security model
- None
- Scopes
- No scoped credential required
curl --request GET \
"https://api.vettiguard.com/v1/branding/{profile_id}/logo"
--header 'Accept: application/json' \
--header 'Origin: https://app.example.com'
[]
[]
Called by a VettiGuard browser client. The real request validates the supplied public site key and the registered request origin.
- Operation ID
postChallenge- Security model
- Site Key And Origin
- Scopes
- No scoped credential required
curl --request POST \
"https://api.vettiguard.com/v1/challenge"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Origin: https://app.example.com' \
--data '{
"site_key": "vg_site_replace_me",
"action": "contact-form"
}'
{
"site_key": "vg_site_replace_me",
"action": "contact-form"
}
{
"success": true,
"challenge": {
"challenge_id": "4d6ac1b0-2d0e-4b0b-9f50-42f36a0d3a24",
"type": "visual",
"expires_in": 120,
"branding": {
"display_name": "",
"primary_color": "#1A73E8",
"primary_foreground": "#FFFFFF",
"primary_soft": "#E8F0FE",
"locale": "auto",
"widget_title": "Verify you are human",
"widget_description": "Complete this quick security check to continue.",
"logo_url": null,
"support_url": null,
"privacy_url": null,
"terms_url": null,
"show_vettiguard_attribution": true
}
}
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postSiteverify- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/siteverify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"response": "single-use-response-token",
"remoteip": "203.0.113.10",
"action": "contact-form"
}'
{
"secret": "vg_secret_replace_me",
"response": "single-use-response-token",
"remoteip": "203.0.113.10",
"action": "contact-form"
}
{
"success": true,
"action": "requested-action",
"score": 0.91000000000000003108624468950438313186168670654296875,
"assessment_id": "4d6ac1b0-2d0e-4b0b-9f50-42f36a0d3a24",
"error-codes": []
}
Called by a VettiGuard browser client. The real request validates the supplied public site key and the registered request origin.
- Operation ID
postSolve- Security model
- Site Key And Origin
- Scopes
- No scoped credential required
curl --request POST \
"https://api.vettiguard.com/v1/solve"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Origin: https://app.example.com' \
--data '{
"site_key": "vg_site_replace_me",
"challenge_id": "4d6ac1b0-2d0e-4b0b-9f50-42f36a0d3a24",
"answer": true,
"action": "contact-form",
"telemetry": {
"elapsed_ms": 2450
}
}'
{
"site_key": "vg_site_replace_me",
"challenge_id": "4d6ac1b0-2d0e-4b0b-9f50-42f36a0d3a24",
"answer": true,
"action": "contact-form",
"telemetry": {
"elapsed_ms": 2450
}
}
{
"success": true,
"response": "single-use-response-token",
"expires_in": 120
}
Returns an opaque challenge image after validating the challenge and item references. The asset URL is intentionally short-lived and must not be cached as application content.
- Operation ID
getVisualChallengeAsset- Security model
- None
- Scopes
- No scoped credential required
curl --request GET \
"https://api.vettiguard.com/v1/visual-assets/{challenge_id}/{item_id}"
--header 'Accept: application/json' \
--header 'Origin: https://app.example.com'
[]
[]
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileApiProtectionAssess- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/api-protection/assess"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"method": "GET",
"path": "/api/catalog",
"action": "catalog-list",
"authentication_present": true,
"device_id": "installation-id",
"request_id": "request-uuid",
"page_size": 50,
"query_depth": 1,
"resource_cost": 10
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"method": "GET",
"path": "/api/catalog",
"action": "catalog-list",
"authentication_present": true,
"device_id": "installation-id",
"request_id": "request-uuid",
"page_size": 50,
"query_depth": 1,
"resource_cost": 10
}
{
"success": true,
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"policy_name": "Order writes",
"risk_score": 0.7199999999999999733546474089962430298328399658203125,
"classification": "high",
"recommended_decision": "challenge",
"decision": "challenge",
"retry_after_seconds": 0,
"reason_codes": [
"resource-cost-exceeded",
"subject-velocity-high"
],
"enforcement_mode": "challenge"
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileApiProtectionFeedback- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/api-protection/feedback"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"label": "legitimate"
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"label": "legitimate"
}
{
"success": true,
"feedback_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"accepted": true
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileAccountAssess- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/account/assess"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"subject_id": "customer-1842",
"device_id": "installation-id",
"event_type": "login",
"outcome": "success"
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"subject_id": "customer-1842",
"device_id": "installation-id",
"event_type": "login",
"outcome": "success"
}
{
"success": true,
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"risk_score": 0.7199999999999999733546474089962430298328399658203125,
"classification": "high",
"recommended_decision": "step_up",
"decision": "step_up",
"trusted_device": false,
"reasons": [
"subject-failure-velocity",
"unfamiliar-device"
]
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileAccountFeedback- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/account/feedback"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"label": "legitimate"
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"label": "legitimate"
}
{
"success": true,
"feedback_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"accepted": true
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileAccountPasswordRange- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/account/password/range"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"prefix": "5BAA6"
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"prefix": "5BAA6"
}
{
"success": true,
"prefix": "5BAA6",
"suffixes": [
{
"suffix": "1E4C9B93F3F0682250B6CF8331B7EE68FD8",
"count": 100
}
]
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileAccountTrustedDevice- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/account/trusted-device"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"action": "trust",
"subject_id": "customer-1842",
"device_id": "installation-id"
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"action": "trust",
"subject_id": "customer-1842",
"device_id": "installation-id"
}
{
"success": true,
"status": "trusted"
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileConcurrencyAcquire- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/concurrency/acquire"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"action": "report.generate",
"method": "POST",
"subject_id": "customer-1842",
"device_id": "installation-id",
"route": "/api/reports",
"lease_ttl_seconds": 120,
"idempotency_key": "report-request-9942"
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"action": "report.generate",
"method": "POST",
"subject_id": "customer-1842",
"device_id": "installation-id",
"route": "/api/reports",
"lease_ttl_seconds": 120,
"idempotency_key": "report-request-9942"
}
{
"success": true,
"decision_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"allowed": true,
"recommended_decision": "allow",
"decision": "allow",
"retry_after_ms": 0,
"matched_policy_count": 2,
"in_flight": 2,
"limit": 5,
"lease": {
"lease_token": "vgcl.70f05cc7-989e-41f0-9a37-c9884d323a67.signature",
"expires_at": "2026-08-08T18:15:00Z"
},
"reason_codes": []
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileConcurrencyRelease- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/concurrency/release"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"lease_token": "vgcl.70f05cc7-989e-41f0-9a37-c9884d323a67.signature"
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"lease_token": "vgcl.70f05cc7-989e-41f0-9a37-c9884d323a67.signature"
}
{
"success": true,
"released": true,
"lease_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"status": "released"
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileConcurrencyRenew- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/concurrency/renew"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"lease_token": "vgcl.70f05cc7-989e-41f0-9a37-c9884d323a67.signature",
"lease_ttl_seconds": 120
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"lease_token": "vgcl.70f05cc7-989e-41f0-9a37-c9884d323a67.signature",
"lease_ttl_seconds": 120
}
{
"success": true,
"renewed": true,
"lease_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"status": "active",
"expires_at": "2026-08-08T18:17:00Z"
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileDependencyResilienceAdmit- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/dependency-resilience/admit"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"dependency_key": "payments-provider",
"action": "payment.capture",
"method": "POST",
"subject_id": "customer-1842",
"device_id": "installation-id",
"route": "/api/payments",
"is_retry": false,
"admission_ttl_seconds": 45
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"dependency_key": "payments-provider",
"action": "payment.capture",
"method": "POST",
"subject_id": "customer-1842",
"device_id": "installation-id",
"route": "/api/payments",
"is_retry": false,
"admission_ttl_seconds": 45
}
{
"success": true,
"decision_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"allowed": true,
"recommended_decision": "allow",
"decision": "allow",
"circuit_state": "closed",
"sample_count": 42,
"failure_rate": 4.7599999999999997868371792719699442386627197265625,
"in_flight": 2,
"retry_budget": {
"used": 1,
"limit": 8
},
"retry_after_seconds": 0,
"admission": {
"admission_token": "vgdr.70f05cc7-989e-41f0-9a37-c9884d323a67.signature",
"expires_at": "2026-08-08T18:45:00Z"
},
"reason_codes": []
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileDependencyResilienceFeedback- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/dependency-resilience/feedback"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"admission_token": "vgdr.70f05cc7-989e-41f0-9a37-c9884d323a67.signature",
"outcome": "success",
"latency_ms": 240
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"admission_token": "vgdr.70f05cc7-989e-41f0-9a37-c9884d323a67.signature",
"outcome": "success",
"latency_ms": 240
}
{
"success": true,
"accepted": true,
"admission_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"status": "completed",
"outcome": "success",
"circuit_state": "closed",
"sample_count": 43,
"failure_rate": 4.6500000000000003552713678800500929355621337890625
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileCredentialsIssue- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.credentials
curl --request POST \
"https://api.vettiguard.com/v1/mobile/credentials/issue"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '[]'
[]
{
"success": true,
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"format": "dc+sd-jwt",
"credential": "issuer-jwt~disclosure~",
"claim_names": [
"identity_verified",
"assurance_level"
],
"holder_binding": {
"required": true,
"method": "cnf.jwk + kb+jwt"
}
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileCredentialsPresent- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.credentials
curl --request POST \
"https://api.vettiguard.com/v1/mobile/credentials/present"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '[]'
[]
{
"success": true,
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"presentation_without_key_binding": "issuer-jwt~disclosure~",
"disclosed_claim_names": [
"identity_verified"
],
"sd_hash": "base64url-sha256",
"key_binding_required": true
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileCredentialsPresentationChallenge- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.credentials
curl --request POST \
"https://api.vettiguard.com/v1/mobile/credentials/presentation/challenge"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '[]'
[]
{
"success": true,
"challenge_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"challenge_token": "opaque-challenge-token",
"audience": "https://app.example.com",
"nonce": "base64url-nonce",
"expires_at": "2026-09-22T00:30:00+00:00"
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileCredentialsRevoke- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.credentials
curl --request POST \
"https://api.vettiguard.com/v1/mobile/credentials/revoke"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '[]'
[]
{
"success": true,
"revoked": true,
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67"
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileCredentialsVerify- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.credentials
curl --request POST \
"https://api.vettiguard.com/v1/mobile/credentials/verify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '[]'
[]
{
"valid": true,
"presentation_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"claims": {
"identity_verified": true
},
"holder_binding_verified": true,
"status": "valid"
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileFraudEmailAssess- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/fraud/email/assess"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"subject_id": "customer-1842",
"email": "customer@example.com",
"device_id": "installation-id",
"event_type": "signup"
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"subject_id": "customer-1842",
"email": "customer@example.com",
"device_id": "installation-id",
"event_type": "signup"
}
{
"success": true,
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"assessment_type": "transaction",
"risk_score": 0.7399999999999999911182158029987476766109466552734375,
"classification": "high",
"recommended_decision": "step_up",
"decision": "step_up",
"reasons": [
"transaction-velocity",
"new-payee"
]
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileFraudFeedback- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/fraud/feedback"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"label": "legitimate"
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"label": "legitimate"
}
{
"success": true,
"feedback_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"accepted": true
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileFraudSmsAssess- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/fraud/sms/assess"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"subject_id": "customer-1842",
"phone": "+2348000000000",
"device_id": "installation-id",
"event_type": "otp_request"
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"subject_id": "customer-1842",
"phone": "+2348000000000",
"device_id": "installation-id",
"event_type": "otp_request"
}
{
"success": true,
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"assessment_type": "transaction",
"risk_score": 0.7399999999999999911182158029987476766109466552734375,
"classification": "high",
"recommended_decision": "step_up",
"decision": "step_up",
"reasons": [
"transaction-velocity",
"new-payee"
]
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileFraudTransactionAssess- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/fraud/transaction/assess"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"subject_id": "customer-1842",
"transaction_id": "ORDER-9942",
"device_id": "installation-id",
"event_type": "payment",
"amount": 125000,
"currency": "NGN",
"high_value": true
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"subject_id": "customer-1842",
"transaction_id": "ORDER-9942",
"device_id": "installation-id",
"event_type": "payment",
"amount": 125000,
"currency": "NGN",
"high_value": true
}
{
"success": true,
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"assessment_type": "transaction",
"risk_score": 0.7399999999999999911182158029987476766109466552734375,
"classification": "high",
"recommended_decision": "step_up",
"decision": "step_up",
"reasons": [
"transaction-velocity",
"new-payee"
]
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileStepUpOzibusEvidenceVerify- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/step-up/ozibus/evidence/verify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '[]'
[]
{
"success": true
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileStepUpOzibusStart- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/step-up/ozibus/start"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '[]'
[]
{
"success": true,
"session_token": "vg_journey_replace_me",
"method": "visual",
"expires_in": 600
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileStepUpOzibusVerify- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/step-up/ozibus/verify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '[]'
[]
{
"success": true
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileRateLimitCheck- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/rate-limit/check"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"action": "payment.create",
"method": "POST",
"subject_id": "customer-1842",
"device_id": "installation-id",
"route": "/api/payments",
"cost": 1
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"action": "payment.create",
"method": "POST",
"subject_id": "customer-1842",
"device_id": "installation-id",
"route": "/api/payments",
"cost": 1
}
{
"success": true,
"decision_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"allowed": true,
"recommended_decision": "allow",
"decision": "allow",
"retry_after_ms": 0,
"matched_policy_count": 3,
"remaining": 74,
"adaptive_multiplier": 1,
"reason_codes": []
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileSessionAssess- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/session/assess"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"session_token": "vgsess_replace_me",
"device_id": "installation-id",
"network_reference": "mobile-network-bucket",
"action": "approve-transfer"
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"session_token": "vgsess_replace_me",
"device_id": "installation-id",
"network_reference": "mobile-network-bucket",
"action": "approve-transfer"
}
{
"success": true,
"assessment_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"session_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"status": "challenged",
"recommended_decision": "challenge",
"decision": "challenge",
"risk_score": 0.7399999999999999911182158029987476766109466552734375,
"classification": "high",
"reason_codes": [
"device-binding-changed"
],
"step_up_required": true,
"session_revoked": false
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileSessionRevoke- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/session/revoke"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"session_token": "vgsess_replace_me",
"reason": "device-sign-out"
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"session_token": "vgsess_replace_me",
"reason": "device-sign-out"
}
{
"success": true,
"session_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"status": "revoked"
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileSessionStart- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/session/start"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"subject_id": "customer-1842",
"device_id": "installation-id",
"network_reference": "mobile-network-bucket",
"country_code": "NG",
"action": "sign-in"
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"subject_id": "customer-1842",
"device_id": "installation-id",
"network_reference": "mobile-network-bucket",
"country_code": "NG",
"action": "sign-in"
}
{
"success": true,
"session_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"session_token": "vgsess_replace_me",
"status": "active",
"trust_level": "standard",
"expires_at": "2026-08-07T22:00:00Z",
"enforcement_mode": "observe"
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileTrustFeedback- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/trust/feedback"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"decision_id": "9ecb38c1-fc29-4cb8-bbd5-18272070db4d",
"label": "legitimate"
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"decision_id": "9ecb38c1-fc29-4cb8-bbd5-18272070db4d",
"label": "legitimate"
}
{
"success": true,
"feedback_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"accepted": true
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileTrustOrchestrate- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/trust/orchestrate"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"action": "transfer.submit",
"subject_id": "customer-1842",
"session_id": "session-uuid",
"transaction_id": "transfer-9942",
"resource_id": "beneficiary-204",
"context": "native-transfer",
"evidence": [
{
"source": "device",
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67"
},
{
"source": "stepup",
"evidence": "vgstep.payload.signature"
},
{
"source": "graph",
"device_id": "native-installation"
}
]
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"action": "transfer.submit",
"subject_id": "customer-1842",
"session_id": "session-uuid",
"transaction_id": "transfer-9942",
"resource_id": "beneficiary-204",
"context": "native-transfer",
"evidence": [
{
"source": "device",
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67"
},
{
"source": "stepup",
"evidence": "vgstep.payload.signature"
},
{
"source": "graph",
"device_id": "native-installation"
}
]
}
{
"success": true,
"decision_id": "9ecb38c1-fc29-4cb8-bbd5-18272070db4d",
"risk_score": 0.2800000000000000266453525910037569701671600341796875,
"assurance_level": "high",
"classification": "low",
"recommended_decision": "allow",
"decision": "allow",
"reason_codes": [
"evidence-within-policy"
],
"next_action": {
"type": "none",
"required": false,
"requirements": [],
"enforced": true
},
"receipt": {
"receipt_id": "61df2804-779a-48cb-97fd-b5b2c44d5903",
"token": "vgtr.payload.signature",
"expires_at": "2026-08-06T23:30:00+00:00",
"max_uses": 1
}
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileTrustReceiptVerify- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/trust/receipt/verify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"receipt": "vgtr.payload.signature",
"action": "transfer.submit",
"subject_id": "customer-1842",
"resource_id": "beneficiary-204",
"context": "native-transfer"
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"receipt": "vgtr.payload.signature",
"action": "transfer.submit",
"subject_id": "customer-1842",
"resource_id": "beneficiary-204",
"context": "native-transfer"
}
{
"success": true,
"valid": true,
"decision_id": "9ecb38c1-fc29-4cb8-bbd5-18272070db4d",
"decision": "challenge",
"action": "checkout.submit",
"remaining_uses": 0
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileDeviceCredentialsRegister- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.device_authorization
curl --request POST \
"https://api.vettiguard.com/v1/mobile/device-credentials/register"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"credential_label": "Primary phone",
"public_key": "base64url-public-key",
"installation_id": "opaque-installation-id"
}'
{
"credential_label": "Primary phone",
"public_key": "base64url-public-key",
"installation_id": "opaque-installation-id"
}
{
"success": true
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileDeviceCredentialsRevoke- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.device_authorization
curl --request POST \
"https://api.vettiguard.com/v1/mobile/device-credentials/revoke"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"credential_key": "vg_device_replace_me",
"reason": "device-replaced"
}'
{
"credential_key": "vg_device_replace_me",
"reason": "device-replaced"
}
{
"success": true,
"status": "revoked"
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileDeviceAuthorizationComplete- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.device_authorization
curl --request POST \
"https://api.vettiguard.com/v1/mobile/device/authorization/complete"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"authorization_token": "vg_authorization_replace_me",
"credential_key": "vg_device_replace_me",
"signature": "base64url-signature"
}'
{
"authorization_token": "vg_authorization_replace_me",
"credential_key": "vg_device_replace_me",
"signature": "base64url-signature"
}
{
"success": true,
"response": "single-use-response-token",
"expires_in": 120
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileDeviceAuthorizationIntent- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.device_authorization
curl --request POST \
"https://api.vettiguard.com/v1/mobile/device/authorization/intent"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"subject_id": "customer-4821",
"action": "approve-transfer",
"operation_reference": "TRANSFER-12345"
}'
{
"subject_id": "customer-4821",
"action": "approve-transfer",
"operation_reference": "TRANSFER-12345"
}
{
"success": true,
"intent_token": "vg_intent_replace_me",
"expires_in": 300
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileDeviceAuthorizationSiteverify- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.device_authorization
curl --request POST \
"https://api.vettiguard.com/v1/mobile/device/authorization/siteverify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"response": "vg_device_response_replace_me",
"action": "approve-transfer",
"operation_reference": "TRANSFER-12345"
}'
{
"response": "vg_device_response_replace_me",
"action": "approve-transfer",
"operation_reference": "TRANSFER-12345"
}
{
"success": true,
"action": "requested-action",
"error-codes": []
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileDeviceAssess- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/device/assess"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '[]'
[]
{
"success": true
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileFacialAuthorizationComplete- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.facial_identity
curl --request POST \
"https://api.vettiguard.com/v1/mobile/facial/authorization/complete"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}'
{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}
{
"success": true,
"response": "single-use-response-token",
"expires_in": 120
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileFacialAuthorizationIntent- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.facial_identity
curl --request POST \
"https://api.vettiguard.com/v1/mobile/facial/authorization/intent"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}'
{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}
{
"success": true,
"intent_token": "vg_intent_replace_me",
"expires_in": 300
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileFacialAuthorizationSession- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.facial_identity
curl --request POST \
"https://api.vettiguard.com/v1/mobile/facial/authorization/session"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}'
{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}
{
"success": true,
"session_token": "vg_session_replace_me",
"expires_in": 300
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileFacialAuthorizationSiteverify- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.facial_identity
curl --request POST \
"https://api.vettiguard.com/v1/mobile/facial/authorization/siteverify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}'
{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}
{
"success": true,
"action": "requested-action",
"error-codes": []
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileFacialEnrollmentComplete- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.facial_identity
curl --request POST \
"https://api.vettiguard.com/v1/mobile/facial/enrollment/complete"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}'
{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}
{
"success": true,
"response": "single-use-response-token",
"expires_in": 120
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileFacialEnrollmentIntent- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.facial_identity
curl --request POST \
"https://api.vettiguard.com/v1/mobile/facial/enrollment/intent"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}'
{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}
{
"success": true,
"intent_token": "vg_intent_replace_me",
"expires_in": 300
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileFacialEnrollmentRevoke- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.facial_identity
curl --request POST \
"https://api.vettiguard.com/v1/mobile/facial/enrollment/revoke"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}'
{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}
{
"success": true,
"status": "revoked"
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileFacialEnrollmentSession- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.facial_identity
curl --request POST \
"https://api.vettiguard.com/v1/mobile/facial/enrollment/session"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}'
{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}
{
"success": true,
"session_token": "vg_session_replace_me",
"expires_in": 300
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileFacialEnrollmentSiteverify- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.facial_identity
curl --request POST \
"https://api.vettiguard.com/v1/mobile/facial/enrollment/siteverify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}'
{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}
{
"success": true,
"action": "requested-action",
"error-codes": []
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileFacialEnrollmentStatus- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.facial_identity
curl --request POST \
"https://api.vettiguard.com/v1/mobile/facial/enrollment/status"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}'
{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}
{
"success": true,
"status": "pending"
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileFacialComplete- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- No scoped credential required
curl --request POST \
"https://api.vettiguard.com/v1/mobile/facial/complete"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}'
{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}
{
"success": true,
"response": "single-use-response-token",
"expires_in": 120
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileFacialDecision- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- No scoped credential required
curl --request POST \
"https://api.vettiguard.com/v1/mobile/facial/decision"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}'
{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}
{
"success": true,
"decision": "verify",
"method": "facial_identity_authorization",
"requested_assurance": "high",
"risk_level": "high",
"risk": {
"outcome": "challenge",
"score": 0.68000000000000004884981308350688777863979339599609375,
"level": "high",
"engine_status": "evaluated",
"matched_rules": [
{
"policy_name": "Transaction protection",
"rule_name": "High request velocity",
"reason_code": "velocity-high",
"score_delta": 0.200000000000000011102230246251565404236316680908203125,
"outcome": "challenge"
}
]
}
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileFacialSession- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- No scoped credential required
curl --request POST \
"https://api.vettiguard.com/v1/mobile/facial/session"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}'
{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}
{
"success": true,
"session_token": "vg_session_replace_me",
"expires_in": 300
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileFacialSessionCancel- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/facial/session/cancel"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}'
{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}
{
"success": true,
"status": "cancelled"
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileFacialSessionStatus- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/facial/session/status"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}'
{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}
{
"success": true,
"status": "pending"
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileFacialSiteverify- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/facial/siteverify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}'
{
"action": "account-recovery",
"subject_id": "customer-4821",
"platform": "android",
"app_id": "com.example.app",
"consent_accepted": true
}
{
"success": true,
"action": "requested-action",
"error-codes": []
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileIdentityReusablePresent- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/identity/reusable/present"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '[]'
[]
{
"success": true
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileIdentityReusableVerify- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/identity/reusable/verify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '[]'
[]
{
"success": true
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileTransactionsAuthorize- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/transactions/authorize"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '[]'
[]
{
"success": true
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileTransactionsVerify- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/transactions/verify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '[]'
[]
{
"success": true
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileTrustDecision- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/trust/decision"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"action": "approve-transfer",
"subject_id": "customer-4821",
"requested_assurance": "device-bound",
"platform": "android",
"app_id": "com.example.app",
"risk_score": 0.419999999999999984456877655247808434069156646728515625,
"failed_attempts_5m": 2,
"new_device": true,
"anonymous_network": false
}'
{
"action": "approve-transfer",
"subject_id": "customer-4821",
"requested_assurance": "device-bound",
"platform": "android",
"app_id": "com.example.app",
"risk_score": 0.419999999999999984456877655247808434069156646728515625,
"failed_attempts_5m": 2,
"new_device": true,
"anonymous_network": false
}
{
"success": true,
"decision": "verify",
"method": "facial_identity_authorization",
"requested_assurance": "high",
"risk_level": "high",
"risk": {
"outcome": "challenge",
"score": 0.68000000000000004884981308350688777863979339599609375,
"level": "high",
"engine_status": "evaluated",
"matched_rules": [
{
"policy_name": "Transaction protection",
"rule_name": "High request velocity",
"reason_code": "velocity-high",
"score_delta": 0.200000000000000011102230246251565404236316680908203125,
"outcome": "challenge"
}
]
}
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileTrustSiteverify- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/trust/siteverify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"action": "approve-transfer",
"subject_id": "customer-4821",
"requested_assurance": "device-bound",
"platform": "android",
"app_id": "com.example.app",
"risk_score": 0.419999999999999984456877655247808434069156646728515625,
"failed_attempts_5m": 2,
"new_device": true,
"anonymous_network": false
}'
{
"action": "approve-transfer",
"subject_id": "customer-4821",
"requested_assurance": "device-bound",
"platform": "android",
"app_id": "com.example.app",
"risk_score": 0.419999999999999984456877655247808434069156646728515625,
"failed_attempts_5m": 2,
"new_device": true,
"anonymous_network": false
}
{
"success": true,
"action": "requested-action",
"error-codes": []
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileTrustGraphIntelligence- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/trust/graph/intelligence"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"subject_id": "customer-1842",
"device_id": "native-installation",
"network_id": "mobile-network-bucket"
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"subject_id": "customer-1842",
"device_id": "native-installation",
"network_id": "mobile-network-bucket"
}
{
"success": true
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileTrustGraphObserve- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/trust/graph/observe"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"action": "approve-transfer",
"subject_id": "customer-4821",
"requested_assurance": "device-bound",
"platform": "android",
"app_id": "com.example.app",
"risk_score": 0.419999999999999984456877655247808434069156646728515625,
"failed_attempts_5m": 2,
"new_device": true,
"anonymous_network": false
}'
{
"action": "approve-transfer",
"subject_id": "customer-4821",
"requested_assurance": "device-bound",
"platform": "android",
"app_id": "com.example.app",
"risk_score": 0.419999999999999984456877655247808434069156646728515625,
"failed_attempts_5m": 2,
"new_device": true,
"anonymous_network": false
}
{
"success": true
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileTrustGraphRisk- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/trust/graph/risk"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"action": "approve-transfer",
"subject_id": "customer-4821",
"requested_assurance": "device-bound",
"platform": "android",
"app_id": "com.example.app",
"risk_score": 0.419999999999999984456877655247808434069156646728515625,
"failed_attempts_5m": 2,
"new_device": true,
"anonymous_network": false
}'
{
"action": "approve-transfer",
"subject_id": "customer-4821",
"requested_assurance": "device-bound",
"platform": "android",
"app_id": "com.example.app",
"risk_score": 0.419999999999999984456877655247808434069156646728515625,
"failed_attempts_5m": 2,
"new_device": true,
"anonymous_network": false
}
{
"success": true
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileJourneysEscalate- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.journeys
curl --request POST \
"https://api.vettiguard.com/v1/mobile/journeys/escalate"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"journey_key": "account-recovery",
"subject_id": "customer-4821",
"action": "recover-account",
"platform": "ios",
"app_id": "com.example.app",
"risk_score": 0.5500000000000000444089209850062616169452667236328125,
"new_device": true,
"unusual_time": true
}'
{
"journey_key": "account-recovery",
"subject_id": "customer-4821",
"action": "recover-account",
"platform": "ios",
"app_id": "com.example.app",
"risk_score": 0.5500000000000000444089209850062616169452667236328125,
"new_device": true,
"unusual_time": true
}
{
"success": true
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileJourneysSiteverify- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.journeys
curl --request POST \
"https://api.vettiguard.com/v1/mobile/journeys/siteverify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"journey_key": "account-recovery",
"subject_id": "customer-4821",
"action": "recover-account",
"platform": "ios",
"app_id": "com.example.app",
"risk_score": 0.5500000000000000444089209850062616169452667236328125,
"new_device": true,
"unusual_time": true
}'
{
"journey_key": "account-recovery",
"subject_id": "customer-4821",
"action": "recover-account",
"platform": "ios",
"app_id": "com.example.app",
"risk_score": 0.5500000000000000444089209850062616169452667236328125,
"new_device": true,
"unusual_time": true
}
{
"success": true,
"action": "requested-action",
"error-codes": []
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileJourneysStart- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.journeys
curl --request POST \
"https://api.vettiguard.com/v1/mobile/journeys/start"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"journey_key": "account-recovery",
"subject_id": "customer-4821",
"action": "recover-account",
"platform": "ios",
"app_id": "com.example.app",
"risk_score": 0.5500000000000000444089209850062616169452667236328125,
"new_device": true,
"unusual_time": true
}'
{
"journey_key": "account-recovery",
"subject_id": "customer-4821",
"action": "recover-account",
"platform": "ios",
"app_id": "com.example.app",
"risk_score": 0.5500000000000000444089209850062616169452667236328125,
"new_device": true,
"unusual_time": true
}
{
"success": true,
"session_token": "vg_journey_replace_me",
"method": "visual",
"expires_in": 600
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileJourneysStatus- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.journeys
curl --request POST \
"https://api.vettiguard.com/v1/mobile/journeys/status"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"journey_key": "account-recovery",
"subject_id": "customer-4821",
"action": "recover-account",
"platform": "ios",
"app_id": "com.example.app",
"risk_score": 0.5500000000000000444089209850062616169452667236328125,
"new_device": true,
"unusual_time": true
}'
{
"journey_key": "account-recovery",
"subject_id": "customer-4821",
"action": "recover-account",
"platform": "ios",
"app_id": "com.example.app",
"risk_score": 0.5500000000000000444089209850062616169452667236328125,
"new_device": true,
"unusual_time": true
}
{
"success": true,
"status": "pending"
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileTrustCredentialsAuthenticationComplete- Security model
- Mobile App Key And Possession Signature
- Scopes
- No scoped credential required
curl --request POST \
"https://api.vettiguard.com/v1/mobile/trust-credentials/authentication/complete"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"app_key": "vg_mobile_replace_me",
"platform": "android",
"app_id": "com.example.app",
"installation_id": "opaque-installation-id",
"challenge_token": "opaque-one-use-token",
"signature": "base64url-es256-signature",
"signature_counter": 13
}'
{
"app_key": "vg_mobile_replace_me",
"platform": "android",
"app_id": "com.example.app",
"installation_id": "opaque-installation-id",
"challenge_token": "opaque-one-use-token",
"signature": "base64url-es256-signature",
"signature_counter": 13
}
{
"success": true,
"evidence": "vgmk.payload.signature",
"authentication_method": "native-mobile-key",
"platform_integrity_verified": true,
"strong_integrity": true,
"remote_hardware_key_attested": false
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileTrustCredentialsAuthenticationOptions- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.trust_credentials
curl --request POST \
"https://api.vettiguard.com/v1/mobile/trust-credentials/authentication/options"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"subject_id": "customer-1842",
"installation_id": "opaque-installation-id",
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"action": "payment.approve",
"context": "ORDER-9942",
"signature_counter": 12
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"subject_id": "customer-1842",
"installation_id": "opaque-installation-id",
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"action": "payment.approve",
"context": "ORDER-9942",
"signature_counter": 12
}
{
"success": true,
"challenge_token": "opaque-one-use-token",
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"action": "payment.approve",
"signature_counter": 12,
"signing_payload": "base64url-canonical-payload"
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileTrustCredentialsEvidenceVerify- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.trust_credentials
curl --request POST \
"https://api.vettiguard.com/v1/mobile/trust-credentials/evidence/verify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"evidence": "vgmk.payload.signature",
"action": "payment.approve",
"subject_id": "customer-1842",
"context": "ORDER-9942",
"consume": true
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"evidence": "vgmk.payload.signature",
"action": "payment.approve",
"subject_id": "customer-1842",
"context": "ORDER-9942",
"consume": true
}
{
"valid": true,
"authentication_method": "native-mobile-key",
"platform_integrity_verified": true,
"strong_integrity": true,
"consumed": true
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileTrustCredentialsRegistrationComplete- Security model
- Mobile App Key And Possession Signature
- Scopes
- No scoped credential required
curl --request POST \
"https://api.vettiguard.com/v1/mobile/trust-credentials/registration/complete"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"app_key": "vg_mobile_replace_me",
"platform": "android",
"app_id": "com.example.app",
"installation_id": "opaque-installation-id",
"challenge_token": "opaque-one-use-token",
"signature": "base64url-es256-signature"
}'
{
"app_key": "vg_mobile_replace_me",
"platform": "android",
"app_id": "com.example.app",
"installation_id": "opaque-installation-id",
"challenge_token": "opaque-one-use-token",
"signature": "base64url-es256-signature"
}
{
"success": true,
"registered": true,
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"subject_ref": "vgmksub_pairwise",
"algorithm": "ES256",
"platform_integrity_bound": true,
"remote_hardware_key_attested": false
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileTrustCredentialsRegistrationOptions- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.trust_credentials
curl --request POST \
"https://api.vettiguard.com/v1/mobile/trust-credentials/registration/options"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"subject_id": "customer-1842",
"installation_id": "opaque-installation-id",
"public_jwk": {
"kty": "EC",
"crv": "P-256",
"x": "base64url-x",
"y": "base64url-y"
},
"label": "Primary phone"
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"subject_id": "customer-1842",
"installation_id": "opaque-installation-id",
"public_jwk": {
"kty": "EC",
"crv": "P-256",
"x": "base64url-x",
"y": "base64url-y"
},
"label": "Primary phone"
}
{
"success": true,
"challenge_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"challenge_token": "opaque-one-use-token",
"subject_ref": "vgmksub_pairwise",
"algorithm": "ES256",
"signing_payload": "base64url-canonical-payload",
"integrity": {
"verified": true,
"provider": "play_integrity",
"strong_integrity": true
},
"key_assurance": {
"platform_integrity_bound": true,
"remote_hardware_key_attested": false
}
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileTrustCredentialsRevoke- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.trust_credentials
curl --request POST \
"https://api.vettiguard.com/v1/mobile/trust-credentials/revoke"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"reason": "device-replaced"
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"reason": "device-replaced"
}
{
"success": true,
"revoked": true,
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67"
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileAttest- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- No scoped credential required
curl --request POST \
"https://api.vettiguard.com/v1/mobile/attest"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"app_key": "vg_mobile_replace_me",
"platform": "ios",
"app_id": "com.example.app",
"nonce_token": "signed-nonce",
"attestation": "base64-attestation"
}'
{
"app_key": "vg_mobile_replace_me",
"platform": "ios",
"app_id": "com.example.app",
"nonce_token": "signed-nonce",
"attestation": "base64-attestation"
}
{
"success": true
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileChallenge- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- No scoped credential required
curl --request POST \
"https://api.vettiguard.com/v1/mobile/challenge"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"app_key": "vg_mobile_replace_me",
"platform": "android",
"app_id": "com.example.app",
"nonce_token": "signed-nonce",
"integrity_token": "provider-token"
}'
{
"app_key": "vg_mobile_replace_me",
"platform": "android",
"app_id": "com.example.app",
"nonce_token": "signed-nonce",
"integrity_token": "provider-token"
}
{
"success": true,
"challenge": {
"challenge_id": "4d6ac1b0-2d0e-4b0b-9f50-42f36a0d3a24",
"type": "visual",
"expires_in": 120,
"branding": {
"display_name": "",
"primary_color": "#1A73E8",
"primary_foreground": "#FFFFFF",
"primary_soft": "#E8F0FE",
"locale": "auto",
"widget_title": "Verify you are human",
"widget_description": "Complete this quick security check to continue.",
"logo_url": null,
"support_url": null,
"privacy_url": null,
"terms_url": null,
"show_vettiguard_attribution": true
}
}
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileDetectionFeedback- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/detection/feedback"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"assessment_id": "4d6ac1b0-2d0e-4b0b-9f50-42f36a0d3a24",
"label": "legitimate",
"reason_code": "customer-confirmed"
}'
{
"secret": "vg_mobile_secret_replace_me",
"platform": "android",
"app_id": "com.example.app",
"assessment_id": "4d6ac1b0-2d0e-4b0b-9f50-42f36a0d3a24",
"label": "legitimate",
"reason_code": "customer-confirmed"
}
{
"success": true,
"feedback_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"accepted": true
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileNonce- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- No scoped credential required
curl --request POST \
"https://api.vettiguard.com/v1/mobile/nonce"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"app_key": "vg_mobile_replace_me",
"platform": "android",
"app_id": "com.example.app",
"action": "sign-in",
"installation_id": "opaque-installation-id"
}'
{
"app_key": "vg_mobile_replace_me",
"platform": "android",
"app_id": "com.example.app",
"action": "sign-in",
"installation_id": "opaque-installation-id"
}
{
"success": true
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileSiteverify- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- mobile.verify
curl --request POST \
"https://api.vettiguard.com/v1/mobile/siteverify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"secret": "vg_mobile_secret_replace_me",
"response": "single-use-mobile-token",
"action": "sign-in",
"expected_platform": "android",
"expected_app_id": "com.example.app"
}'
{
"secret": "vg_mobile_secret_replace_me",
"response": "single-use-mobile-token",
"action": "sign-in",
"expected_platform": "android",
"expected_app_id": "com.example.app"
}
{
"success": true,
"action": "requested-action",
"score": 0.91000000000000003108624468950438313186168670654296875,
"assessment_id": "4d6ac1b0-2d0e-4b0b-9f50-42f36a0d3a24",
"error-codes": []
}
Called by a registered native application or its backend using mobile application identity, scoped credentials, and the configured integrity policy.
- Operation ID
postMobileSolve- Security model
- Mobile Bearer Or Legacy Secret
- Scopes
- No scoped credential required
curl --request POST \
"https://api.vettiguard.com/v1/mobile/solve"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer vg_credential_replace_me' \
--data '{
"app_key": "vg_mobile_replace_me",
"challenge_id": "4d6ac1b0-2d0e-4b0b-9f50-42f36a0d3a24",
"answer": true,
"action": "sign-in"
}'
{
"app_key": "vg_mobile_replace_me",
"challenge_id": "4d6ac1b0-2d0e-4b0b-9f50-42f36a0d3a24",
"answer": true,
"action": "sign-in"
}
{
"success": true,
"response": "single-use-response-token",
"expires_in": 120
}
ozibus_hmac
- Operation ID
postIntegrationsOzibusEvents- Security model
- Stripe Signature
- Scopes
- No scoped credential required
curl --request POST \
"https://api.vettiguard.com/v1/integrations/ozibus/events"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Stripe-Signature: generated-by-stripe' \
--data '{
"workspace_id": 1,
"event_id": "ozb-event-2048",
"channel": "sms",
"event_type": "delivered",
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"provider_status": "delivered",
"delivery_latency_ms": 920
}'
{
"workspace_id": 1,
"event_id": "ozb-event-2048",
"channel": "sms",
"event_type": "delivered",
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"provider_status": "delivered",
"delivery_latency_ms": 920
}
{
"success": true,
"accepted": true,
"duplicate": false,
"signal_id": "70f05cc7-989e-41f0-9a37-c9884d323a67"
}
ozibus_hmac
- Operation ID
postIntegrationsOzibusPreflight- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- No scoped credential required
curl --request POST \
"https://api.vettiguard.com/v1/integrations/ozibus/preflight"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"workspace_id": 1,
"channel": "sms",
"event_type": "otp_request",
"subject_id": "customer-1842",
"device_id": "browser-device",
"phone": "+2348000000000",
"high_cost_destination": false
}'
{
"workspace_id": 1,
"channel": "sms",
"event_type": "otp_request",
"subject_id": "customer-1842",
"device_id": "browser-device",
"phone": "+2348000000000",
"high_cost_destination": false
}
{
"success": true,
"assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"decision": "allow",
"risk_score": 0.11999999999999999555910790149937383830547332763671875,
"transport_provider": "ozibus",
"intelligence_mode": "hybrid"
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postStepUpOzibusEvidenceVerify- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/step-up/ozibus/evidence/verify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"evidence": "vgstep.payload.signature",
"action": "account.recovery",
"subject_id": "customer-1842",
"context": "recovery-9942"
}'
{
"secret": "vg_secret_replace_me",
"evidence": "vgstep.payload.signature",
"action": "account.recovery",
"subject_id": "customer-1842",
"context": "recovery-9942"
}
{
"success": true
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postStepUpOzibusStart- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/step-up/ozibus/start"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"action": "account.recovery",
"subject_id": "customer-1842",
"email": "customer@example.com",
"context": "recovery-9942"
}'
{
"secret": "vg_secret_replace_me",
"action": "account.recovery",
"subject_id": "customer-1842",
"email": "customer@example.com",
"context": "recovery-9942"
}
{
"success": true,
"session_token": "vg_journey_replace_me",
"method": "visual",
"expires_in": 600
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postStepUpOzibusVerify- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/step-up/ozibus/verify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"stepup_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"otp": "123456"
}'
{
"secret": "vg_secret_replace_me",
"stepup_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"otp": "123456"
}
{
"success": true
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postPasskeysAuthenticationComplete- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.passkeys
curl --request POST \
"https://api.vettiguard.com/v1/passkeys/authentication/complete"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"challenge_token": "opaque-challenge-token",
"credential": {
"id": "base64url-credential-id",
"rawId": "base64url-credential-id",
"type": "public-key",
"response": {
"clientDataJSON": "base64url-client-data",
"authenticatorData": "base64url-authenticator-data",
"signature": "base64url-signature",
"userHandle": "base64url-user-handle"
}
}
}'
{
"secret": "vg_secret_replace_me",
"challenge_token": "opaque-challenge-token",
"credential": {
"id": "base64url-credential-id",
"rawId": "base64url-credential-id",
"type": "public-key",
"response": {
"clientDataJSON": "base64url-client-data",
"authenticatorData": "base64url-authenticator-data",
"signature": "base64url-signature",
"userHandle": "base64url-user-handle"
}
}
}
{
"success": true,
"authenticated": true,
"subject_ref": "vgsub_pairwise",
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"authentication_method": "passkey",
"user_verification": true,
"evidence": "vgpk.payload.signature",
"evidence_expires_at": "2026-09-21T22:45:00+00:00"
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postPasskeysAuthenticationOptions- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.passkeys
curl --request POST \
"https://api.vettiguard.com/v1/passkeys/authentication/options"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"subject_id": "customer-1842",
"origin": "https://app.example.com",
"action": "sign-in",
"context": "login-9942"
}'
{
"secret": "vg_secret_replace_me",
"subject_id": "customer-1842",
"origin": "https://app.example.com",
"action": "sign-in",
"context": "login-9942"
}
{
"success": true,
"challenge_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"challenge_token": "opaque-challenge-token",
"discoverable": false,
"subject_ref": "vgsub_pairwise",
"action": "sign-in",
"publicKey": {
"challenge": "base64url-challenge",
"rpId": "app.example.com",
"timeout": 60000,
"userVerification": "required"
}
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postPasskeysCredentialsRevoke- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.passkeys
curl --request POST \
"https://api.vettiguard.com/v1/passkeys/credentials/revoke"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"reason": "customer-request"
}'
{
"secret": "vg_secret_replace_me",
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"reason": "customer-request"
}
{
"success": true,
"revoked": true,
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67"
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postPasskeysEvidenceVerify- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.passkeys
curl --request POST \
"https://api.vettiguard.com/v1/passkeys/evidence/verify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"evidence": "vgpk.payload.signature",
"action": "sign-in",
"subject_id": "customer-1842",
"context": "login-9942",
"consume": true
}'
{
"secret": "vg_secret_replace_me",
"evidence": "vgpk.payload.signature",
"action": "sign-in",
"subject_id": "customer-1842",
"context": "login-9942",
"consume": true
}
{
"valid": true,
"evidence_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"subject_ref": "vgsub_pairwise",
"credential_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"action": "sign-in",
"authentication_method": "passkey",
"user_verification": true,
"consumed": true
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postPasskeysRegistrationComplete- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.passkeys
curl --request POST \
"https://api.vettiguard.com/v1/passkeys/registration/complete"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"challenge_token": "opaque-challenge-token",
"credential": {
"id": "base64url-credential-id",
"rawId": "base64url-credential-id",
"type": "public-key",
"response": {
"clientDataJSON": "base64url-client-data",
"attestationObject": "base64url-attestation",
"transports": [
"internal",
"hybrid"
]
}
},
"label": "Primary passkey"
}'
{
"secret": "vg_secret_replace_me",
"challenge_token": "opaque-challenge-token",
"credential": {
"id": "base64url-credential-id",
"rawId": "base64url-credential-id",
"type": "public-key",
"response": {
"clientDataJSON": "base64url-client-data",
"attestationObject": "base64url-attestation",
"transports": [
"internal",
"hybrid"
]
}
},
"label": "Primary passkey"
}
{
"success": true,
"registered": true,
"credential_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"subject_ref": "vgsub_pairwise",
"label": "Primary passkey",
"algorithm": -7,
"backup_eligible": true
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postPasskeysRegistrationOptions- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.passkeys
curl --request POST \
"https://api.vettiguard.com/v1/passkeys/registration/options"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"subject_id": "customer-1842",
"origin": "https://app.example.com",
"display_name": "Customer account"
}'
{
"secret": "vg_secret_replace_me",
"subject_id": "customer-1842",
"origin": "https://app.example.com",
"display_name": "Customer account"
}
{
"success": true,
"challenge_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"challenge_token": "opaque-challenge-token",
"subject_ref": "vgsub_pairwise",
"expires_at": "2026-09-21T22:45:00+00:00",
"publicKey": {
"challenge": "base64url-challenge",
"rp": {
"id": "app.example.com",
"name": "Example App"
},
"user": {
"id": "base64url-user-handle",
"name": "vgsub_pairwise",
"displayName": "Protected account"
},
"pubKeyCredParams": [
{
"type": "public-key",
"alg": -7
},
{
"type": "public-key",
"alg": -257
}
],
"timeout": 60000,
"attestation": "none",
"excludeCredentials": [],
"authenticatorSelection": {
"residentKey": "required",
"requireResidentKey": true,
"userVerification": "required"
}
}
}
Public metadata endpoint that does not reveal private infrastructure details.
- Operation ID
getApiIndex- Security model
- None
- Scopes
- No scoped credential required
curl --request GET \
"https://api.vettiguard.com/v1/"
--header 'Accept: application/json'
[]
{
"service": "VettiGuard API",
"version": "v1",
"status": "available",
"base_url": "https://api.vettiguard.com/v1"
}
Public metadata endpoint that does not reveal private infrastructure details.
- Operation ID
getChangelogJson- Security model
- None
- Scopes
- No scoped credential required
curl --request GET \
"https://api.vettiguard.com/v1/changelog.json"
--header 'Accept: application/json'
[]
{
"version": "v1",
"changes": []
}
Public metadata endpoint that does not reveal private infrastructure details.
- Operation ID
getHealth- Security model
- None
- Scopes
- No scoped credential required
curl --request GET \
"https://api.vettiguard.com/v1/health"
--header 'Accept: application/json'
[]
{
"status": "ok"
}
Public metadata endpoint that does not reveal private infrastructure details.
- Operation ID
getOpenapiJson- Security model
- None
- Scopes
- No scoped credential required
curl --request GET \
"https://api.vettiguard.com/v1/openapi.json"
--header 'Accept: application/json'
[]
{
"openapi": "3.1.0",
"info": {
"title": "VettiGuard API"
}
}
Public metadata endpoint that does not reveal private infrastructure details.
- Operation ID
getPostmanCollectionJson- Security model
- None
- Scopes
- No scoped credential required
curl --request GET \
"https://api.vettiguard.com/v1/postman-collection.json"
--header 'Accept: application/json'
[]
{
"info": {
"name": "VettiGuard API"
}
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postRateLimitCheck- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/rate-limit/check"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"action": "payment.create",
"method": "POST",
"subject_id": "customer-1842",
"device_id": "browser-device",
"route": "/api/payments",
"cost": 1,
"api_protection_assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67"
}'
{
"secret": "vg_secret_replace_me",
"action": "payment.create",
"method": "POST",
"subject_id": "customer-1842",
"device_id": "browser-device",
"route": "/api/payments",
"cost": 1,
"api_protection_assessment_id": "70f05cc7-989e-41f0-9a37-c9884d323a67"
}
{
"success": true,
"decision_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"allowed": true,
"recommended_decision": "allow",
"decision": "allow",
"retry_after_ms": 0,
"matched_policy_count": 3,
"remaining": 74,
"adaptive_multiplier": 1,
"reason_codes": []
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postIdentityReusablePresent- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/identity/reusable/present"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"holder_token": "vgid_replace_me",
"claims": [
"identity_verified",
"assurance_level",
"age_over_18"
]
}'
{
"secret": "vg_secret_replace_me",
"holder_token": "vgid_replace_me",
"claims": [
"identity_verified",
"assurance_level",
"age_over_18"
]
}
{
"success": true
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postIdentityReusableVerify- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/identity/reusable/verify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"presentation": "vgidp.payload.signature"
}'
{
"secret": "vg_secret_replace_me",
"presentation": "vgidp.payload.signature"
}
{
"success": true
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postSessionAssess- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/session/assess"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"session_token": "vgsess_replace_me",
"device_id": "browser-device",
"network_reference": "network-bucket-19",
"country_code": "NG",
"action": "checkout-confirm",
"authentication_age_seconds": 900
}'
{
"secret": "vg_secret_replace_me",
"session_token": "vgsess_replace_me",
"device_id": "browser-device",
"network_reference": "network-bucket-19",
"country_code": "NG",
"action": "checkout-confirm",
"authentication_age_seconds": 900
}
{
"success": true,
"assessment_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"session_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"status": "challenged",
"recommended_decision": "challenge",
"decision": "challenge",
"risk_score": 0.7399999999999999911182158029987476766109466552734375,
"classification": "high",
"reason_codes": [
"device-binding-changed"
],
"step_up_required": true,
"session_revoked": false
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postSessionRevoke- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/session/revoke"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"session_token": "vgsess_replace_me",
"reason": "customer-sign-out"
}'
{
"secret": "vg_secret_replace_me",
"session_token": "vgsess_replace_me",
"reason": "customer-sign-out"
}
{
"success": true,
"session_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"status": "revoked"
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postSessionStart- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/session/start"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"subject_id": "customer-1842",
"device_id": "browser-device",
"network_reference": "network-bucket-19",
"country_code": "NG",
"action": "sign-in",
"trust_level": "standard"
}'
{
"secret": "vg_secret_replace_me",
"subject_id": "customer-1842",
"device_id": "browser-device",
"network_reference": "network-bucket-19",
"country_code": "NG",
"action": "sign-in",
"trust_level": "standard"
}
{
"success": true,
"session_id": "70f05cc7-989e-41f0-9a37-c9884d323a67",
"session_token": "vgsess_replace_me",
"status": "active",
"trust_level": "standard",
"expires_at": "2026-08-07T22:00:00Z",
"enforcement_mode": "observe"
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postTransactionsAuthorize- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/transactions/authorize"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"action": "payment.capture",
"subject_id": "customer-1842",
"resource_id": "ORDER-9942",
"decision_receipt": "vgtr.payload.signature",
"intent": {
"transaction_id": "PAY-9942",
"amount": "125000.00",
"currency": "NGN",
"payee_id": "merchant-88"
}
}'
{
"secret": "vg_secret_replace_me",
"action": "payment.capture",
"subject_id": "customer-1842",
"resource_id": "ORDER-9942",
"decision_receipt": "vgtr.payload.signature",
"intent": {
"transaction_id": "PAY-9942",
"amount": "125000.00",
"currency": "NGN",
"payee_id": "merchant-88"
}
}
{
"success": true
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postTransactionsVerify- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/transactions/verify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"action": "payment.capture",
"proof": "vgtx.payload.signature",
"intent": {
"transaction_id": "PAY-9942",
"amount": "125000.00",
"currency": "NGN",
"payee_id": "merchant-88"
}
}'
{
"secret": "vg_secret_replace_me",
"action": "payment.capture",
"proof": "vgtx.payload.signature",
"intent": {
"transaction_id": "PAY-9942",
"amount": "125000.00",
"currency": "NGN",
"payee_id": "merchant-88"
}
}
{
"success": true
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postTrustFeedback- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/trust/feedback"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"decision_id": "9ecb38c1-fc29-4cb8-bbd5-18272070db4d",
"label": "legitimate",
"reason_code": "order-completed"
}'
{
"secret": "vg_secret_replace_me",
"decision_id": "9ecb38c1-fc29-4cb8-bbd5-18272070db4d",
"label": "legitimate",
"reason_code": "order-completed"
}
{
"success": true,
"feedback_id": "bca30ea6-72d7-42e2-a6d3-2c1b350551c5",
"accepted": true
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postTrustOrchestrate- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/trust/orchestrate"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"action": "checkout.submit",
"subject_id": "customer-1842",
"session_id": "session-uuid",
"transaction_id": "order-9942",
"resource_id": "cart-9942",
"context": "production-checkout",
"evidence": [
{
"source": "device",
"assessment_id": "4d6ac1b0-2d0e-4b0b-9f50-42f36a0d3a24"
},
{
"source": "passkey",
"evidence": "vgpk.payload.signature"
},
{
"source": "graph",
"device_id": "browser-device"
}
]
}'
{
"secret": "vg_secret_replace_me",
"action": "checkout.submit",
"subject_id": "customer-1842",
"session_id": "session-uuid",
"transaction_id": "order-9942",
"resource_id": "cart-9942",
"context": "production-checkout",
"evidence": [
{
"source": "device",
"assessment_id": "4d6ac1b0-2d0e-4b0b-9f50-42f36a0d3a24"
},
{
"source": "passkey",
"evidence": "vgpk.payload.signature"
},
{
"source": "graph",
"device_id": "browser-device"
}
]
}
{
"success": true,
"decision_id": "9ecb38c1-fc29-4cb8-bbd5-18272070db4d",
"risk_score": 0.2800000000000000266453525910037569701671600341796875,
"assurance_level": "high",
"classification": "low",
"recommended_decision": "allow",
"decision": "allow",
"reason_codes": [
"evidence-within-policy"
],
"next_action": {
"type": "none",
"required": false,
"requirements": [],
"enforced": true
},
"receipt": {
"receipt_id": "61df2804-779a-48cb-97fd-b5b2c44d5903",
"token": "vgtr.payload.signature",
"expires_at": "2026-08-06T23:30:00+00:00",
"max_uses": 1
}
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postTrustReceiptVerify- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/trust/receipt/verify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"receipt": "vgtr.payload.signature",
"action": "checkout.submit",
"subject_id": "customer-1842",
"resource_id": "cart-9942",
"context": "production-checkout"
}'
{
"secret": "vg_secret_replace_me",
"receipt": "vgtr.payload.signature",
"action": "checkout.submit",
"subject_id": "customer-1842",
"resource_id": "cart-9942",
"context": "production-checkout"
}
{
"success": true,
"valid": true,
"decision_id": "9ecb38c1-fc29-4cb8-bbd5-18272070db4d",
"decision": "challenge",
"action": "checkout.submit",
"remaining_uses": 0
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postTrustDecision- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/trust/decision"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"action": "approve-transfer",
"subject_id": "customer-4821",
"requested_assurance": "standard",
"risk_score": 0.419999999999999984456877655247808434069156646728515625,
"request_velocity_5m": 12,
"failed_attempts_5m": 2,
"transaction_amount": 250000,
"new_device": true,
"anonymous_network": false,
"country_code": "NG",
"network_type": "mobile"
}'
{
"secret": "vg_secret_replace_me",
"action": "approve-transfer",
"subject_id": "customer-4821",
"requested_assurance": "standard",
"risk_score": 0.419999999999999984456877655247808434069156646728515625,
"request_velocity_5m": 12,
"failed_attempts_5m": 2,
"transaction_amount": 250000,
"new_device": true,
"anonymous_network": false,
"country_code": "NG",
"network_type": "mobile"
}
{
"success": true,
"decision": "verify",
"method": "facial_identity_authorization",
"requested_assurance": "high",
"risk_level": "high",
"risk": {
"outcome": "challenge",
"score": 0.68000000000000004884981308350688777863979339599609375,
"level": "high",
"engine_status": "evaluated",
"matched_rules": [
{
"policy_name": "Transaction protection",
"rule_name": "High request velocity",
"reason_code": "velocity-high",
"score_delta": 0.200000000000000011102230246251565404236316680908203125,
"outcome": "challenge"
}
]
}
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postTrustSiteverify- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/trust/siteverify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"response": "single-use-response-token",
"action": "approve-transfer",
"expected_assurance": "high",
"require_identity": true,
"require_liveness": true
}'
{
"secret": "vg_secret_replace_me",
"response": "single-use-response-token",
"action": "approve-transfer",
"expected_assurance": "high",
"require_identity": true,
"require_liveness": true
}
{
"success": true,
"action": "requested-action",
"error-codes": []
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postTrustGraphIntelligence- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/trust/graph/intelligence"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"subject_id": "customer-1842",
"device_id": "browser-device",
"network_id": "network-bucket"
}'
{
"secret": "vg_secret_replace_me",
"subject_id": "customer-1842",
"device_id": "browser-device",
"network_id": "network-bucket"
}
{
"success": true
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postTrustGraphObserve- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/trust/graph/observe"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"nodes": [
{
"type": "subject",
"value": "customer-1842",
"risk_score": 0.08000000000000000166533453693773481063544750213623046875
},
{
"type": "device",
"value": "browser-device",
"risk_score": 0.1499999999999999944488848768742172978818416595458984375
}
],
"edges": [
{
"from": 0,
"to": 1,
"type": "used",
"strength": 0.90000000000000002220446049250313080847263336181640625
}
]
}'
{
"secret": "vg_secret_replace_me",
"nodes": [
{
"type": "subject",
"value": "customer-1842",
"risk_score": 0.08000000000000000166533453693773481063544750213623046875
},
{
"type": "device",
"value": "browser-device",
"risk_score": 0.1499999999999999944488848768742172978818416595458984375
}
],
"edges": [
{
"from": 0,
"to": 1,
"type": "used",
"strength": 0.90000000000000002220446049250313080847263336181640625
}
]
}
{
"success": true
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postTrustGraphRisk- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.verify
curl --request POST \
"https://api.vettiguard.com/v1/trust/graph/risk"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"subject_id": "customer-1842",
"device_id": "browser-device"
}'
{
"secret": "vg_secret_replace_me",
"subject_id": "customer-1842",
"device_id": "browser-device"
}
{
"success": true
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postJourneysEscalate- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.journeys
curl --request POST \
"https://api.vettiguard.com/v1/journeys/escalate"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"session_token": "vg_journey_replace_me",
"reason_code": "accessibility-alternative-required",
"priority": "normal"
}'
{
"secret": "vg_secret_replace_me",
"session_token": "vg_journey_replace_me",
"reason_code": "accessibility-alternative-required",
"priority": "normal"
}
{
"success": true
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postJourneysSiteverify- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.journeys
curl --request POST \
"https://api.vettiguard.com/v1/journeys/siteverify"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"session_token": "vg_journey_replace_me",
"response": "vg_response_replace_me",
"subject_id": "customer-4821",
"action": "approve-transfer",
"consent_accepted": true
}'
{
"secret": "vg_secret_replace_me",
"session_token": "vg_journey_replace_me",
"response": "vg_response_replace_me",
"subject_id": "customer-4821",
"action": "approve-transfer",
"consent_accepted": true
}
{
"success": true,
"action": "requested-action",
"error-codes": []
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postJourneysStart- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.journeys
curl --request POST \
"https://api.vettiguard.com/v1/journeys/start"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"journey_key": "transaction-approval",
"subject_id": "customer-4821",
"action": "approve-transfer",
"operation_reference": "TRANSFER-12345",
"risk_score": 0.419999999999999984456877655247808434069156646728515625,
"request_velocity_5m": 12,
"transaction_amount": 250000,
"new_device": true
}'
{
"secret": "vg_secret_replace_me",
"journey_key": "transaction-approval",
"subject_id": "customer-4821",
"action": "approve-transfer",
"operation_reference": "TRANSFER-12345",
"risk_score": 0.419999999999999984456877655247808434069156646728515625,
"request_velocity_5m": 12,
"transaction_amount": 250000,
"new_device": true
}
{
"success": true,
"session_token": "vg_journey_replace_me",
"method": "visual",
"expires_in": 600
}
Server-to-server operation. Keep private credentials outside browser and mobile application bundles and validate the complete response contract.
- Operation ID
postJourneysStatus- Security model
- Scoped Credential Or Legacy Secret
- Scopes
- site.journeys
curl --request POST \
"https://api.vettiguard.com/v1/journeys/status"
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
"secret": "vg_secret_replace_me",
"session_token": "vg_journey_replace_me"
}'
{
"secret": "vg_secret_replace_me",
"session_token": "vg_journey_replace_me"
}
{
"success": true,
"status": "pending"
}
No matching operations
Clear one or more filters and try a broader search.