Skip to content

Use the Verifier API

Use the Verifier API to verify a payslip payload. The generated Verifier API reference defines the exact HTTP contract.

https://verify.verifiabl.io

Use https://verify.sandbox.verifiabl.io in sandbox.

The Verifier API uses OAuth 2.0 client credentials. Exchange the client ID and client secret from your onboarding for a short-lived access token.

POST /oauth/token
POST https://auth.verifiabl.io/oauth/token
Content-Type: application/json
{
"grant_type": "client_credentials",
"client_id": "YOUR_CLIENT_ID",
"client_secret": "YOUR_CLIENT_SECRET",
"audience": "https://verify.verifiabl.io"
}

Use https://auth.sandbox.verifiabl.io/oauth/token in sandbox. Set audience to https://verify.sandbox.verifiabl.io.

Send the returned access token with each request:

Authorization header
Authorization: Bearer YOUR_ACCESS_TOKEN

Cache the token until its expiry is near. After a 401, request a new token and retry once. Issuer API credentials do not give access to the Verifier API.

Send the text from the QR code or the PDF metadata to verifyPayload. Preserve the complete fragment after the # character in a scan URL.

Follow the verification guide for the complete workflow.

The generated operation lists its status codes and error responses. Use code in conditional statements. Do not compare error or detail, because that text can change.

You can send the same payload again after a timeout, rate limit, or server error. Use exponential backoff. The same payload gives the same verification result.