Base URLs
Youverify provides two fully isolated environments. Use the sandbox for integration and testing; switch to production when you are ready for live, billed checks.Request Format
All requests and responses are JSON over HTTPS. Set the following headers on every call:Authentication
Youverify authenticates server-to-server calls with a singletoken header. There is no OAuth handshake — possession of the secret key is authority, so it must never leave your backend. See the Authentication reference for full details, key types, and security best practices.
Response Envelope
Every successful response shares the same shape, so you write your deserialization logic once:boolean
true on all successful responses.integer
HTTP status code mirrored in the body, e.g.
200, 201.string
A human-readable description of the outcome.
object | array
The primary payload — an object for single-resource endpoints, an array for list endpoints.
array
Hypermedia links for navigation (pagination cursors, related resources).
Error Envelope
When a request fails, the response uses the same skeleton withsuccess: false and a machine-readable error name:
boolean
Always
false for error responses.integer
The HTTP status code for the error.
string
A machine-readable error identifier, e.g.
ResourceNotFoundError, ValidationError, UnauthorizedError.string
A human-readable explanation of what went wrong.
Common HTTP Status Codes
Pagination
Offset Pagination
Most list endpoints support offset-based pagination viapage and limit query parameters:
integer
default:"1"
The page number to retrieve.
integer
default:"20"
Number of results per page. Maximum is
100.data array:
Cursor Pagination
High-volume streams such as Signals support cursor-based pagination, which is preferred for production polling because it handles real-time data without skipping or duplicating records. Pass thecursor value returned in links as a query parameter on the next request.
Entity IDs
All entities carry a stable, globally unique identifier prefixed withent_:
Rate Limits
Youverify enforces per-workspace rate limits. When you exceed them, the API returns429 Too Many Requests with a Retry-After header indicating how many seconds to wait before retrying:
Resource Groups
The API is organized around the following resource groups:Entities
Create, retrieve, and manage individual and business entities. The central object everything else references.
KYC
Run identity checks against government ID databases — BVN, NIN, passport, driver’s license, and more.
KYB
Verify businesses against company registries. Retrieve registration details, directors, shareholders, and UBOs.
AML
Screen entities against PEP lists, global sanctions databases, and adverse media sources.
KYT
Ingest transactions and receive real-time risk evaluations and fraud signals for transaction monitoring.
Cases
Open, update, and close investigation cases linked to entities. The human-in-the-loop layer.
Signals
Retrieve detected events, patterns, and alerts generated by fraud traps and monitoring rules.
Risk
Access risk scores, scoring breakdowns, and risk model configuration for your workspace.