Why server-side token generation is required
The Youverify SDK uses two separate tokens to authenticate a session:- Session ID — a short-lived identifier that scopes the session and links it to a specific user or entity record on your account.
- Liveness token — an authentication token that authorizes the SDK to submit liveness data to Youverify’s verification infrastructure.
Endpoint 1 — Generate SDK Session ID
Use this endpoint for Web SDK flows and document capture sessions.POST /v2/api/sdk/session-id
Request
Request parameters
string
required
Your public merchant key from the Cowork dashboard.
number
default:"120"
How long the session ID remains valid, in seconds. Must be between
30 and 600. Defaults to 120.object
default:"{}"
Optional key-value metadata to attach to the session, for example your internal user ID.
Response
string
The session ID to pass to the SDK constructor.
string
ISO 8601 timestamp when this session ID expires.
string
Always
active on a successful response.Endpoint 2 — Generate SDK Liveness Token
Use this endpoint for liveness detection flows on all platforms (Web, Android, iOS).POST /v2/api/sdk/liveness-token
Request
Request parameters
string
required
Your public merchant key from the Cowork dashboard.
string
A unique identifier for this device or user session. Use a UUID generated per session. This helps Youverify detect and prevent token reuse across devices.
string
An alternative device identifier from which Youverify can derive
deviceCorrelationId. Use either deviceCorrelationId or deviceId, not both.Response
string
The liveness token to pass as
sessionToken in the SDK constructor.string
A session ID associated with this liveness token.
Token expiry and caching
Tokens are short-lived by design. Generate a fresh pair of tokens immediately before each SDK initialization. Do not store tokens in a database or cache for reuse across sessions.
onFailure callback fires with error.key = "invalid_or_expired_session". Your app should generate new tokens and re-initialize the SDK.