Overview
A verification goes through several states from creation to completion.CREATED
Verification created via
POST /verifications/. The user has not yet opened the verification link.STARTED
The user has opened the verification link. The status stays
STARTED from that point, whether they keep going or abandon the flow, until their data is collected.USER_DATA_COLLECTED
Every check the workflow requires has been collected and is now being processed by the pawaPass system.
REVIEW (optional)
Manual action is required. A pawaPass agent reviews the verification when automated checks are inconclusive.
Final status
The verification resolves to one of three final states (see below).
Final statuses
APPROVED
Identity verified. Document data extracted.
DECLINED
Failed face scan attempts or agent decision.
EXPIRED
Session expired. Default: 30 days.
Re-verifying the same user
A verification is active until it reaches one of the final statuses above. While a verification for anexternalId is still active, creating another verification with the same externalId returns the existing one (200 OK) instead of starting a new flow.
Once the verification reaches a final status (APPROVED, DECLINED, or EXPIRED), creating a verification with the same externalId starts a fresh one (201 Created). If short links are enabled, the new verification reuses the same url as the previous one, so any link you already shared keeps pointing to the latest verification.
Example flows
Successful verification (auto-approved)
Successful verification (auto-approved)
CREATED → STARTED → USER_DATA_COLLECTED → APPROVEDThe most common flow. User completes all steps, system auto-approves.Manual review then declined
Manual review then declined
CREATED → STARTED → USER_DATA_COLLECTED → REVIEW → DECLINEDAutomated checks are inconclusive, agent reviews and declines.User never starts
User never starts
CREATED → EXPIREDUser doesn’t open the verification link within the expiration window.