1. Create a session
Build a browser link with requester_id and access_code: https://idcheck.noviqent.co.uk/user?req=<requester_id>&code=<access_code> - no app install needed, opens straight to your check in any browser (the /user page also shows "<your organisation> is requesting an identity check" using requester_id), and handles every check type (id_check, proof_of_address, age_verification, in any combination) without an app. Send that link however you like (email, SMS, an in-app redirect); the same page also accepts the bare access_code typed in by hand for channels that can't carry a clickable link. The IdCheck mobile app remains available as an alternative - the same access_code works there too.
expected_full_name is optional: when set, the id_check only passes if the name OCR'd off the ID document also matches it (in addition to the usual face match) - useful when you already know who the check is for, e.g. requiring the claimant to be a specific company's registered director. Leave it unset for a plain "is this a real, verified person" check.
expected_address works the same way for proof_of_address, comparing on the postcode and house/flat number rather than a literal address string match. If you already collected the person's name and/or address on your own form before starting the check, pass them both here - if you leave either unset, the /user page asks the person to type it themselves right before the proof-of-address step instead of skipping the check.
retain_id_documents/retain_poa_documents are optional overrides of your template's own default retention setting, for this one session only - request a copy of just this check's documents without changing what every other session sent through the same template does. Retrieve a retained document with GET /sessions/{id}/documents/{check_type} below; the live selfie is never retained regardless of any setting.
reference_id is opaque to IdCheck; encode whatever you need to route the result back to your own record.
POST /api/v1/sessions
Authorization: Bearer <prefix>.<secret>
Content-Type: application/json
{
"reference_id": "your-own-id-for-this-check",
"expected_full_name": "Optional - e.g. a Companies House director name",
"expected_address": "Optional - e.g. what the person entered on your own signup form",
"retain_id_documents": false,
"retain_poa_documents": false
}
→ 201
{
"id": "…",
"magic_link_token": "…",
"access_code": "K7XH9F2A",
"expires_at": "2026-08-24T00:00:00Z",
"requester_id": "…"
}2. Receive the result
Verify X-IdCheck-Callback-Secret matches your stored callback secret before trusting the payload.
POST <your callback_url>
X-IdCheck-Client: <client id>
X-IdCheck-Callback-Secret: <your callback secret>
{
"reference_id": "your-own-id-for-this-check",
"results": [
{ "check_type": "id_check", "passed": true, "confidence": 0.71 }
]
}3. Pull full detail (optional)
extracted_data and retained documents (GET /api/v1/sessions/{id}/documents/{check_type}) depend on your template's own retention settings.
GET /api/v1/sessions/{id}/data
Authorization: Bearer <prefix>.<secret>
→ 200
{
"reference_id": "…",
"status": "completed",
"results": [
{
"check_type": "id_check",
"passed": true,
"confidence": 0.71,
"extracted_data": { "full_name": "…", "date_of_birth": "…" },
"document_retained": false
}
]
}