Verified 1-Click API

This documents the API for performing phone number verification and PII queries with the Verified Inc. 1-Click Verify and Signup integrations. The API permits an ISV to implement these features with their own UI elements. All endpoints are server-to-server and require signed JWT authentication to identify the ISV. The user-level claims sub and subsig are not required, since this API is used before a user has been created.

ProphetX also provides an embedded modal to perform these functions — see Verified Modal if you'd rather embed ProphetX's own UI instead of building your own.

The phone number verification flow currently requires an SMS code to be sent from Verified to the user. Additional methods that don't require an SMS code on mobile devices are also available but not yet implemented.

The full API specification is documented in Swagger — click the doc.json link at the top to get the OpenAPI specification in YAML format.


1. Begin a 1-Click Verify session

POST /private/v1/one-click/verifications

{
  "channel": "sms",        // must be "sms"
  "phone": "+12125550021"  // must include the "+1" international prefix
}

The response includes a uuid field to pass to the following endpoints.

2. Deliver an SMS verification code

Required disclosure. Before calling /deliver, you must display the following text to the user:

I authorize Verified to send me SMS verification texts at the number provided. Msg & Data rates may apply.

"Verified" must link to https://verified.inc, underlined and in a different color than the rest of the text, so the user can tell it's a link.

POST /private/v1/one-click/verifications/{uuid}/deliver

{
  "format": "code" // must be "code"
}

3. Verify the SMS code

POST /private/v1/one-click/verifications/{uuid}/verify

{
  "code": "111111"
}

The response should include "verified": true and a new uuid field.

4. Query user PII with 1-Click Signup

Required disclosure. Before calling /signups, you must display the following text to the user:

By {taking this action}, you agree that ProphetX's service provider Verified and its vendors may receive your personal info and autofill more info about you, including the last 4 digits of your social security number.

Replace {taking this action} with whatever the user actually does to start 1-Click Signup (e.g. "tapping Sign Up"). "Verified" must link to https://verified.inc, underlined and in a different color than the rest of the text, same as above. You must also display the "Powered by Verified" graphic — get it from Verified's own asset guide.

POST /private/v1/one-click/signups

{
  "verificationUuid": "f3d1682e-4b52-43ea-a8ee-8118091fb4ee", // the "uuid" field from /verify
  "birthDate": "1989-08-01", // provide "birthDate" or "ssn4" or both
  "ssn4": "6789"
}

The response is formatted to match the request for user creation (POST /private/v1/users), minus email and emailVerifiedAt — Verified doesn't deliver an email address, so the ISV must supply both of those fields itself before forwarding to POST /private/v1/users.


Did this page help you?