Versioned REST API
Create, upload, finalize, read the decision. Idempotency key, remaining call budget in the headers, a wait time announced when the limit is reached.
For engineering teams
Everything the app does goes through the API. You keep your flow, your screens and your rules; we supply the proof and the page that makes it verifiable by a third party.
30 days, 100 test proofs. No card. The guide covers access, the first proof, idempotency, webhooks and sharing.
The excerpt is copied from the code, not from a mock-up. On the right, what each line means for your integration.
# 1 · Create a proof request for a third party POST /api/v1/capture-links # → 201 { "captureLinkUrl": "https://evidiq.io/c/…", "expiresAt": "2026-09-24T17:41:00Z", "proofReference": "EV-1789926114284-5899", … } # 2 · When the proof is verified, your endpoint receives X-Evidiq-Event: proof.verified X-Evidiq-Signature: sha256=… { "event": "proof.verified", "data": { "proofId": …, "reference": …, "decision": …, "score": … } }
The request carries your instruction and the expected place. The response gives you the link to pass on, its expiry and the reference of the proof to come, to match it against your case.
The webhook is signed over the raw bytes. Verify the signature before reading the body. We refuse to send an unsigned webhook. Delivery id, retries, a circuit breaker per account: all of it is followed from the dashboard, with a button to replay what did not get through.
The decision is Evidiq’s. Your tool applies it: automatic acceptance or human review. No call rewrites it.
The sandbox gives you the API: upload, finalize, read the decision, 100 test proofs. Proof requests by link and webhook deliveries open with a business plan, in a pilot: until then, you read the decision through the API.
Create, upload, finalize, read the decision. Idempotency key, remaining call budget in the headers, a wait time announced when the limit is reached.
HMAC signature over the raw bytes, delivery id, retries, a circuit breaker per account. We refuse to send an unsigned webhook.
Public, without expiry, revocable one by one. You set by default what a link shows.
A proof posted through the API, with no attested device, does not borrow the trust of an attested capture: it is scored on a separate, read-only rubric, and the verification page shows “Not measured” for the device. To get an attested capture from your own product, the capture has to happen inside an app: ours, through the capture link, or yours, with the mobile SDK.
What is self-service today, and what comes with a pilot.
Today’s integration path: upload, proof request from a third party, verdict through a signed webhook. Idempotency, errors, limits: documented in the integration guide. The sandbox covers the API; capture links and webhooks come with the business plan.
The engine of our own apps, Kotlin Multiplatform for Android and iOS, inside yours: live capture, device attestation, submission. On request, within a pilot. The API key never goes into a mobile app: the SDK talks to your server, which talks to Evidiq.
The sandbox is open to all: 30 days, 100 test proofs, no card. For the mobile SDK or real volume, write to us.
Hosted in France Webhooks always signed Non-extractable signing key, held in a KMS What proves it