List IDPasses
/idpasses
Returns a paginated list of IDPasses on the calling account. Each IDPass is a remote
identity verification that the individual completes via a hosted link; the result is
updated asynchronously, so poll show IDPass until status is
terminal.
Example Request
GETRequest Schema
page
per_page
filter[status]
filter[verification_status]
filter[source]
filter[entity_uuid]
filter[program_uuid]
filter[created_after]
filter[created_before]
sort
Sort field. Prefix with `-` for descending. Defaults to `-created_at`.
Available Response Data
14 Data Pointsuuid uuid
source enum
Whether the IDPass is bound to a saved entity or was launched adhoc: entity, adhoc
status enum
new, opened, in_progress, complete, expired, failed, …
status_name string
completed boolean
True once the IDPass has reached a terminal status
verification_status enum
passed, review, failed
verification_status_name string
requester_name string
check_liveness boolean
require_id_photo boolean
document_allowed_types object (The allowed document types for each of the (up to three) verification steps)
link_validity_days integer
meta object
pagination: current_page, per_page, total, last_page
api_reference uuid
unique request identifier for log tracing and audit
API Data Scale & Coverage tag
Unmatched data depth to power your compliance and verification workflows.
Sandbox Environment
Build and test against a sandbox account. Sandbox is a separate account with its own UUID and its own API keys, and the environment is fixed at the account level, so you cannot switch an existing key between live and sandbox with a parameter or header. Both share the same base URL, so the account behind your key is what determines which environment you are in. GET /v1/account returns an environment field of live or sandbox, and that is the authoritative answer.
Calls on a sandbox key are not billed. Every endpoint, response shape, error envelope, idempotency and rate-limit behaviour mirrors live, so the only change when you move to production should be the credentials. Sandbox accounts are provisioned by your Global Data account manager.
Identity verification works end to end in sandbox using the same endpoints and response shapes as live. No real SMS is sent for an IDPass delivered by SMS on a sandbox account; the message is recorded instead of delivered.
Technical Use Cases tag
Reconciliation against your own system
Page through every IDPass on the account and compare it with your own records, so the two stay aligned without anyone exporting a spreadsheet. Filters use the filter[key]=value syntax and results are paginated.
Scheduled sync jobs
Sort by -created_at or -updated_at and pull only what has changed since the last run, which keeps a nightly sync proportional to the delta, not the whole book.
Operational dashboards
Drive an internal dashboard from live counts. meta.total gives the size of the filtered set without fetching every page.
Compliance & Security tag
Enterprise-grade infrastructure audited against the standards your regulators require.
Common Questions tag
Everything you need to know about implementation details and compliance infrastructure.
rocket_launch Implementation
How do I filter and page through the results?
add
How do I filter and page through the results?
Filters use the filter[key]=value syntax, and unknown keys are ignored, not rejected. Sorting uses the sort parameter, with a leading - for descending order.
One behaviour worth designing around: a filter targeting a UUID that is unknown, or that belongs to a different account, returns an empty page (data: [], meta.total: 0) instead of a 404. That is the same response as a filter which legitimately matches nothing, so an empty result does not on its own tell you the UUID was valid.
rocket_launch Implementation
What are the rate limits?
add
What are the rate limits?
600 requests per minute by default, enforced with a 60-second fixed window. Every response carries X-RateLimit-Limit and X-RateLimit-Remaining.
Exceeding the limit returns 429 Too Many Requests with a Retry-After header giving the number of seconds to wait, and X-RateLimit-Reset giving the reset timestamp. Schedule retries from Retry-After instead of a fixed sleep, and slow down before you hit zero, not after.
Higher limits can be arranged case by case through WatchEye support.
Ready to integrate List IDPasses?
Talk to our team about credentials, sandbox access and the right combination of endpoints for your workflow.
